help button home button JAMIA Hate scrolling?
HOME HELP FEEDBACK SUBSCRIPTIONS ARCHIVE SEARCH TABLE OF CONTENTS

First published April 25, 2007 as JAMIA PrePrint; doi:10.1197/jamia.M2352
This Article
Right arrow Full Text
Right arrow Full Text (PDF)
Right arrow All Versions of this Article:
M2352v1
14/4/397    most recent
Right arrow Submit a response
Right arrow Alert me when this article is cited
Right arrow Alert me when eLetters are posted
Right arrow Alert me if a correction is posted
Services
Right arrow Similar articles in this journal
Right arrow Similar articles in PubMed
Right arrow Alert me to new issues of the journal
Right arrow Download to citation manager
Right arrow reprints & permissions
Citing Articles
Right arrow Citing Articles via Google Scholar
Google Scholar
Right arrow Articles by Wright, A.
Right arrow Articles by Sittig, D. F.
Right arrow Search for Related Content
PubMed
Right arrow PubMed Citation
Right arrow Articles by Wright, A.
Right arrow Articles by Sittig, D. F.
J Am Med Inform Assoc. 2007;14:397-399. DOI 10.1197/jamia.M2352.
© 2007 American Medical Informatics Association


Technical Brief

Encryption Characteristics of Two USB-based Personal Health Record Devices

Adam Wright, PhDa,* and Dean F. Sittig, PhDa,b

a Department of Medical Informatics and Clinical Epidemiology, Oregon Health & Science University, Portland, OR
b Department of Medical Informatics, Northwest Permanente, PC, Portland, OR.

* Correspondence and reprints: Adam Wright, Department of Medical Informatics and Clinical Epidemiology, Oregon Health & Science University, 3181 Sam Jackson Park Rd., Portland, OR 97239 (Email: wrightad{at}ohsu.edu).

Received for publication: 12/15/06; accepted for publication: 04/13/07.

Personal health records (PHRs) hold great promise for empowering patients and increasing the accuracy and completeness of health information. We reviewed two small USB-based PHR devices that allow a patient to easily store and transport their personal health information. Both devices offer password protection and encryption features. Analysis of the devices shows that they store their data in a Microsoft Access database. Due to a flaw in the encryption of this database, recovering the user’s password can be accomplished with minimal effort. Our analysis also showed that, rather than encrypting health information with the password chosen by the user, the devices stored the user’s password as a string in the database and then encrypted that database with a common password set by the manufacturer. This is another serious vulnerability. This article describes the weaknesses we discovered, outlines three critical flaws with the security model used by the devices, and recommends four guidelines for improving the security of similar devices.







HOME HELP FEEDBACK SUBSCRIPTIONS ARCHIVE SEARCH TABLE OF CONTENTS
Copyright © 2007 by the American Medical Informatics Association.