Enhancing Transparency and Security in Telehealth Records Using Dual One-Time Password Authorization
Abstract
Background: Many information technologies have supported the growth of the medical field worldwide. Telehealth consultation is a rapidly developing area in healthcare that aims to optimize time utilization during patient–physician consultations. To support telehealth consultations, healthcare providers make patient records available on online platforms to review medical history and treatment progress. Accordingly, government and healthcare organizations have introduced telehealth, telemedicine, and systems for maintaining e-health records. When such data are hosted on online platforms, it becomes vulnerable to unauthorized access and potential security threats. Although security mechanisms such as firewalls and authentication controls protect telehealth records (THRs), these records are frequently accessed by government agencies, researchers, and healthcare professionals for medical analysis and research. However, authorities often do not explicitly enforce transparency regarding how and where THRs are accessed. Often, patients and treating physicians are not fully aware of external access to health records before data disclosure. Methods: To address this limitation, the authors propose an architectural framework for THR access that uses a one-time password (OTP)- based dual-authorization mechanism to ensure both security and transparency. Results: The proposed approach enables health record access only with the knowledge and explicit authorization of both the patient and the physician, thereby embedding transparency within the access control workflow. The system is built using web pages written in Hypertext Markup Language (HTML), and controlled testing is used to ensure the operational workflow functions. Experimental results indicate that the OTP delivery time is 15 ms, the application programming interface (API) response time is 25 ms, the THR load time is 15 ms, and the authentication success rate is 97%. Conclusions: Experimental results indicate: - OTP delivery time is 15 ms, - application programming interface (API) response time is 25 ms,, - THR load time is 15 ms, and - authentication success rate is 97%.