PubMed HealthSearch

Biomedical subjects

N Gaunt

Publications and source records attributed to N Gaunt.

4 recordsLinked to original sources

The information superhijack.

Infection control teams are not alone in their need to manipulate data. How best can such manipulation be achieved and what tools are available to turn information into knowledge. The workshop included discussion and demonstration of some methods currently being used by infection control teams. While the workshop did not aim to produce all the answers, participants were able to question, discuss and learn new ways that they might take their own practice in the future.

Cross Infection

Installing an appropriate information security policy.

Security of personal health care is of concern to patients, health care staff and informaticians alike. Nevertheless, their awareness of the appropriate measures for protection of such data have been found wanting. The development and implementation of an information and security policy in the health care environment must therefore take into account the attitudes of staff and their educational needs. The approach adopted in one large District General Hospital was to combine risk analysis with surveys of users attitudes to proposed measures and a participational approach to development of security procedures using an adaptation of the ETHICS soft systems methodology. As a result of several years of effort, a 'security culture' has begun to emerge in the organization. However, this can only be sustained by continual promotion of the policy and a willingness to adapt procedures to suit the operating environment.

Attitude of Health Personnel

Security of the electronic health care record--professional and ethical implications.

Many challenges face developers of secure computerised clinical systems but the technical problems are overshadowed by procedural, professional and ethical issues. The development and use of computerised systems must be controlled through compliance with standards and procedures for information security, enforced through national legislation and professional codes of conduct, if serious abuse of the data is to be avoided. Health care professionals cannot be expected to acquire working knowledge of how information systems are made secure since this is a technical and highly complex subject. However, it is essential that health care professionals understand why it is important to maintain a secure environment for the records they keep about patients and their care and how this can be organised. This is best achieved through a well structured educational programme involving all trainee and qualified health care staff, a task which should be coordinated by the national professional bodies. A management structure is needed within health care facilities that recognises the responsibility of health care professionals to keep the health care data relating to their patients secure. An arrangement is proposed that gives the most senior clinician in a health care facility the ultimate responsibility for security of health care data held in the organisation. Where appropriate, this would be delegated to a senior clinician with training and experience in information systems and their security. This 'information doctor' would, with the assistance of computer experts and health care managers, implement and monitor the organisation's information security strategy. Contracts should be developed between health care facilities and their patients, defining the limits to the use and disclosure of personal health data. Similar contracts with external agencies should also stipulate the minimum level of security to be applied to health records shared between the organisations.

Computer Security