Currently, doctors offices store patient information in a method that suits them. For most of us, the process is seamless – we don’t really care. That is, until we switch doctor’s offices.

Bill Gates is proposing standardizing patient information and making it available across the Internet. The aim is to allow each doctor’s office to communicate patient information with each other, and give patients easier access to their own medical records.

We envision a comprehensive, Internet-based system that enables health-care providers to automatically deliver personal health data to each patient in a form they can understand and use. We also believe that people should have control over who they share this information with. This will help ensure that their privacy is protected and their care providers have everything they need to make fully-informed diagnoses and treatment decisions.

Any such system must make use of strong authentication methods at the offices – and I’m sure they will be. Auditing and logging can mitigate the problems posed by people sharing credentials (which is bound to happen). But what about patients accessing information online?

Just think about how PayPal accounts are authenticated? With a username/password combination. (Sure, they offer hardware tokens, but only security/computer savvy people use them). If that’s how companies, banks, and retailers treat our money, what hope do we have for personal medical information?

Since any system like this is still in the imaginary stage, there are many possibilities. The technology is there, the concerns are there, what needs to happen next?