Medical Information Privacy Concerns in the Use of the EHR System: A Grounded Theory Approach

의료정보 프라이버시 염려에 대한 근거이론적 연구: 전자건강기록(EHR) 시스템을 중심으로

  • Eom, Doyoung (Graduate School of International Studies, Yonsei University) ;
  • Lee, Heejin (Graduate School of International Studies, ICONS(Institute of Convergence Science), Yonsei University) ;
  • Zoo, Hanah (Center for International Studies, ICONS(Institute of Convergence Science), Yonsei University)
  • 엄도영 (연세대학교 국제학대학원) ;
  • 이희진 (연세대학교 국제학대학원, 미래융합연구원(ICONS)) ;
  • 주한나 (연세대학교 국제학연구소, 미래융합연구원(ICONS))
  • Received : 2017.11.17
  • Accepted : 2018.01.20
  • Published : 2018.01.28


Electronic Health Record (EHR) systems are widely adopted worldwide in hospitals for generating and exchanging records of patient information. Recent developments are moving towards implementing interoperable EHR systems that enable information to be shared seamlessly across healthcare organizations. In this context, this paper explores the factors that cause medical information privacy concerns, identifies how people react to privacy invasion and what their perceptions are towards the acceptance of the EHR system. Interviews were conducted to draw a grounded theory on medical information privacy concerns in the use of EHRs. Medical information privacy concerns are caused by perceived sensitivity of medical information and the weaknesses in security technologies. Trust in medical professionals, medical institutions and technologies plays an important role in determining people's reaction to privacy invasion and their perceptions on the use of EHRs.

본 연구의 목적은 전자건강기록(EHR) 시스템을 통해 환자 개인의 의료정보가 활용되고 공유되는 데에 있어, 사람들이 정보 프라이버시 염려를 갖게 되는 요인은 무엇이며, 프라이버시 침해에 대해 어떠한 대처 전략을 취하고 시스템에 대한 수용 여부는 어떻게 나타나는지 살펴보는 데에 있다. 이를 위해 근거이론 연구방법을 통해 의료기관 방문 경험자들을 대상으로 심층 인터뷰를 수행하여 근거자료를 수집한 후, 의료정보 프라이버시 염려에 대한 근거이론을 구성하고 패러다임 모형을 도출하고자 하였다. 그 결과, 의료정보 프라이버시 염려 발생 요인, 의료정보 프라이버시 염려, 의료정보 프라이버시 침해에 대한 대응 전략, EHR 시스템의 수용 여부에 관한 총체적인 설명이 가능한 근거이론 모형을 개발하였다. 연구결과를 요약하면, 의료정보에 대한 민감성과 기술의 발전이 의료정보 프라이버시 염려를 유발하고, 의사와 기술에 대한 신뢰도에 따라 연구 참여자 사이에 프라이버시 침해 대응 전략과 EHR 시스템 도입에 관한 입장이 달라진다. 지금까지 국내에서 EHR 시스템에 초점을 두고 의료정보 프라이버시에 대한 심층적인 분석을 수행한 연구가 없기 때문에 본 연구는 학술적으로 기여하는 바가 있고, 프라이버시 염려를 완화시킬 수 있는 실질적인 방안을 제시한다는 점에서 실무적 함의가 있다.



  1. H. J. Lee, "A Study of Legislation on the Personal Medical Information Protection Law," Journal of Constitutional Law, Vol. 3, No. 2, pp. 95-123, 2016.
  2. Y. Song and K. Park, "Security/Privacy Requirements for Medical Data Services," Review of KIISC, Vol. 20, No. 3, pp. 90-96, 2010.
  3. H. S. Lee, "Court Ruling in favor of Korean Pharmaceutical Information Center," Available:
  4. R. Parks, C.-H. Chu, and H. Xu, "Healthcare Information Privacy Research: Issues, Gaps and What Next?" Paper presented at the AMCIS 2011 Proceedings, 2011.
  5. E. Park, "EMR.EHR Information Exchange Scores 0,"Available:
  6. M. H. Kim, "Status of Korea's Healthcare Information Technology," KIRI Monthly Vol. 10, 2017.
  7. C. M. Angst and R. Agarwal, "Adoption of Electronic Health Records in the Presence of Privacy Concerns: The Elaboration Likelihood Model and Individual Persuasion," MIS Quarterly, Vol. 33, No. 2, pp. 339-370, 2009.
  8. M. J. Culnan, and P. K. Armstrong, "Information Privacy Concerns, Procedural Fairness, and Impersonal Trust: An Empirical Investigation," Organization Science, Vol. 10, No. 1, pp. 104-115, 1999.
  9. H. J. Smith, S. J. Milberg, and S. J. Burke, "Information Privacy: Measuring Individuals' Concerns About Organizational Practices," MIS Quarterly, Vol. 20, No. 2, pp. 167-196, 1996.
  10. K. A. Stewart and A. H. Segars, "An Empirical Examination of the Concern for Information Privacy Instrument," Information Systems Research, Vol. 13, No. 1, pp. 36-49, 2002.
  11. N. K. Malhotra, S. S. Kim, and J. Agarwal, "Internet Users' Information Privacy Concerns (IUIPC): The Construct, the Scale, and a Causal Model," Information Systems Research, Vol. 15, No. 4, pp. 336-355, 2004.
  12. T. Zhou, "Examining Location-based Services Usage from the Perspectives of Unified Theory of Acceptance and Use of Technology and Privacy Risk," Journal of Electronic Commerce Research, Vol. 13, No. 2, pp. 135-144, 2005.
  13. M-H. Shin, "Influences Information Privacy Concerns and Personal Innovation of Smartphone-based Shopping Mall on Usefulness, Ease-of-Use and Satisfaction," Journal of Digital Convergence, Vol. 12, No. 8, pp. 197-209, 2014.
  14. C-W. Park and J-W. Kim, "An Empirical Research on Information Privacy Concern in the IoT Era," Journal of Digital Convergence, Vol. 14, No. 2, pp. 65-72, 2016.
  15. K. Ishikawa, "Health Data Use and Protection Policy; Based on Differences by Cultural and Social Environment," International Journal of Medical Informatics, Vol. 60, No. 2, pp. 119-125, 2000.
  16. National Research Council(NRC), "For the Record: Protecting Electronic Health Information," Washington DC: National Academy Press, 1997.
  17. T. C. Rindfleisch, "Privacy, information technology, and health care," Communications of the ACM, Vol. 40, No. 8, pp. 93-100, 1997.
  18. A. Appari and E. M. Johnson, "Information Security and Privacy in Healthcare: Current State of Research," International Journal of Internet and Enterprise Management, Vol. 6, No. 4, pp. 279-314, 2010.
  19. G. Bansal, F. M. Zaheid, and D. Gefen, "The Impact of Personal Dispositions on Privacy and Trust in Disclosing Health Information Online," Americas Conference on Information Systems, 2007.
  20. B. Campbell, H. Thomson, J. Slater, C. Coward, K. Wyatt, and K. Sweeney, "Extracting Information from Hospital Records: What Patients Think about Consent," Quality and Safety in Healthcare, Vol. 16, No. 6, pp. 404-408, 2007.
  21. C. M. Angst, R. Agrawal, and J. Downing, "An Empirical Examination of the Importance of Defining the PHR for Research and for Practice," Robert H. Smith School Research Paper, No. RHS-06-011, 2006.
  22. H. Park, S-I. Lee, Y. Kim, E-Y. Heo, J. Lee, J. H. Park, and K. Ha, "Patients' Perceptions of a Health Information Exchange: A Pilot Program in South Korea," International Journal of Medical Informatics, Vol. 82, No. 2, pp. 98-107, 2013.
  23. K-H. Choi, K-Y. Chung, and D-K. Shin, "A Study of Prevention Model the Spread of Phishing Attack for Protection the Medical Information," Journal of Digital Convergence, Vol. 11, No. 3, pp. 273-277, 2013.
  24. Y-Y. Kim and S-S. Shin, "A Study on Reliable Electronic Medical Record Systems," Journal of Digital Convergence, Vol. 10, No. 2, pp. 193-200, 2012.
  25. H. S. Jang, J. T. Lee, J. S. Yoo, S. J. Ahn, and I. K. Kim, "Smart Medical Technology Standards-based Electronic Health Record," Communications of the Korean Institute of Information Scientists and Engineers, Vol. 33, No. 3, pp. 10-20, 2015.
  26. K. Choe, "Grounded Theory Methodology: Strauss' Version vs Glaserian Version," Journal of Korean Academy of Psychiatric Mental Health Nursing, Vol. 14, No. 1, pp. 82-90, 2005.
  27. D. Lee and Y. Kim, "An Inquiry on the Philosophical Backgrounds and Methodological Characteristics of Grounded Theory as Qualitative Research Method," The Journal of Yeolin Education, Vol. 20, No. 2, pp. 1-26, 2012.
  28. A. L. Strauss and J. M. Corbin, "Basics of Qualitative Research: Techniques and Procedures for Developing Grounded Theory," 2nd ed., SAGE Publications, 1998.
  29. B. G. Glaser, "Basics of Grounded Theory Analysis: Emergence vs. Forcing," Sociology Press, 1992.
  30. A. L. Strauss and J. M. Corbin, "Basics of Qualitative Research: Grounded Theory Procedures and Techniques," Newbury Park, CA: Sage Publications, 1990.
  31. S. S. Kim, "Theory: Grounded Theory," Journal of Nursing Query, Vol. 12, No. 1, pp. 69-81, 2003.