explanations commensurate with the privacy and data
protection impact of the determination.
Although PIA put forward different degrees of
requirements for operators, but the use of RFID
technology in smart medical is very different from
other fields. First of all, medical health data often
involves more personal privacy, that is to say, RFID
operation should be more strictly managed in medical
industry. Second, the four levels of PIA described
above are too general to be fully applicable to the
smart healthcare industry due to RFID usages are
more widely and complex. For example, the
collection and use of patient privacy data in RFID for
human vital signs detection is certainly different from
that in RFID for drug or blood management. Is PIA
perfect for both of these two or more situations?
Therefore, we believe that not only an appropriate
framework should be established for the use of RFID
in smart medical, but a more granular division should
be made on the use of private data at all levels.
6 SOME SUGGESTIONS
In view of the deficiencies and requirements of
existing RFID security and privacy protection
technologies and standards analysed above, the
following Suggestions are put forward for individuals
(patients), hospitals and international standard-setting
agencies:
From electronic medical records to various
medical and health detection products, RFID
technology in smart medical is targeted at a large
number of legal citizens, but once key private data are
leaked or hacked, the victims of adverse effects are
also this group of people. In particular, patients of
smart blood pressure and cardiopulmonary test health
care products are mostly elderly people, who are more
vulnerable to security and privacy threats. Therefore,
individuals should pay attention to personal privacy
protection. First of all, medical IC cards containing
personal sensitive information, electronic medical
records should be properly kept and strong passwords
should be designed. Next, because RFID devices are
generally connected to the Internet, so individuals
also need to pay attention to the network of common
hacker attacks, on time to kill viruses, healthy Internet
access.
Because hospitals are not only the victims of
RFID security and privacy threats, but also the
initiator of many problems, the situation in hospitals
is much more complicated than individuals. On the
one hand, we think hospitals should not only have the
responsibility to ensure the privacy and data security
of patients, although the application of big data, cloud
computing or Internet of things technology is very
popular now. Hospitals should establish specialized
RFID security and privacy protection mechanisms,
which may include cloud computing data service
platform with strong encryption and strict RFID tag
purchase, use and disposal mechanism. At the same
time, hospitals should also arrange and formulate
professional and technical personnel for regular
management and examination, and do their best to
protect patients' sensitive information. On the other
hand, the hospital is also the user of RFID technology,
so RFID should be involved in the hospital
departments of doctors and nurses to popularize RFID
security and privacy protection knowledge, in order
to prevent problems in this part of the hospital.
As for the international RFID standards setting
bodies or committees, they should make more in-
depth research on the RFID standards and should not
neglect them, because we have noticed that the latest
standards specifically targeted at RFID are now some
time apart. “Sb-327 Information Privacy: Connected
Devices”, recently passed in California, is not
specifically related to the security and privacy of
RFID, let alone RFID in smart medical. As mentioned
above, it is very necessary for relevant international
organizations to formulate relevant standards or laws
to restrict hospitals or RFID manufacturers based on
the particularity of RFID application in smart medical
7 CONCLUSIONS
In this survey, we have introduced in detail the
security and privacy threats and protection methods
involved in RFID in smart medical. And we put
forward original and innovative constructive
Suggestions for existing methods or standards
respectively from individuals, hospitals and
international standard-setting agencies, which can
provide some reference for relevant organizations and
individuals involving RFID in the work or life. Only
by restricting and managing RFID industrial chain
from all aspects can users' privacy and security
information not be infringed. Also only like this,
people can enjoy the Gospel brought to mankind by
smart medical instead of information security being
lost in the rapid process of science and technology.
REFERENCES
Cathy Reisenwitz et al., 2018. Smart Medical Devices That
Are Changing Healthcare in 2018. In Medical Software.
IoTBDS 2019 - 4th International Conference on Internet of Things, Big Data and Security
284