IT security: an elusive requirement.
Explore the source record for details and available documents.
SEARCH · PubMed Health
Explore indexed PubMed citations for clinical trials, systematic reviews and public health research. Read source abstracts and follow each citation to its original PubMed record.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Explore the source record for details and available documents.
Ever since health-care information systems have been implemented, their security is being considered an important issue, especially in the light of the fact that their data are deemed to comprise extremely sensitive information. The prospect of storing health information in electronic form raises concerns about patient privacy and data security. Any attempt to introduce computerised health-care information systems should, therefore, guarantee adequate protection of the confidentiality and integrity of patient information. At the same time, the patient information also needs to be readily available to all authorised health-care providers, in order to ensure the proper treatment of the patient. The principal aim of the present paper is, however, not to make a new contribution to the subject of security per se, but rather to give an overview of current trends in the security aspects of health-care information systems. The final section of the paper will be devoted to a number of proposals for further research possibilities in the domain of health-care information systems security.
Personal and medical data processed by Healthcare Information Systems must be protected against unauthorized access, modification and withholding. Security measures should be selected to provide the required level of protection in a cost-efficient manner. This is only feasible if specific characteristics of the information system are examined on a basis of a risk analysis methodology. This paper presents the results of a risk analysis, based on the CRAMM methodology, for a healthcare organization offering a patient home-monitoring service through the transmission of vital signs, focusing on the identified security needs and the proposed countermeasures. The architectural and functional models of this service were utilized for identifying and valuating the system assets, the associated threats and vulnerabilities, as well as for assessing the impact on the patients and on the service provider, should the security of any of these assets is affected. A set of adequate organizational, administrative and technical countermeasures is described for the remote vital signs monitoring service, thus providing the healthcare organization with a data protection framework that can be utilized for the development of its own security plan.
The National Practitioner Data Bank is a database of adverse events involving physicians and other practitioners. Querying the database is mandatory for hospitals in several situations. So too, hospitals are required to report specified adverse events. Thus, hospitals need to be able to identify incidents that are reportable events, events that require them to update the databases, and any possible liability issues that may surround the hospital's reporting duties. The author argues that the regulations are unclear in addressing these issues. Likewise, he notes that practitioners should be aware of other problems with the reporting system, including the lack of sufficient Data Bank security.
The process of choosing an Internet service provider for your medical practice involves a needs assessment, a close comparison of vendor capabilities and access technologies, and an evaluation of security protocols and costs.
On Feb. 20, while most health care providers were in the midst of last-minute preparations to comply with the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule, the Department of Health and Human Services (DHHS) published the final HIPAA Security Rule.
This article reports the results of a survey of the responsible crime laboratories in the first 19 states with legislation establishing forensic DNA data banks. The survey inquired into the labs' policies and procedures regarding the collection, storage, and analysis of samples; the retention of samples and data; search protocols; access to samples and data by third parties; and related matters. The research suggests that (1) the number of samples collected from convicted offenders for DNA data banking has far surpassed the number that have been analyzed; (2) data banks have already been used in a small but growing number of cases, to locate suspects and to identify associations between unresolved cases; (3) crime labs currently plan to retain indefinitely the samples collected for their data banks; and (4) the nature and extent of security safeguards that crime labs have implemented for their data banks vary among states. The recently enacted DNA Identification Act (1994) will provide $40 million in federal matching grants to states for DNA analysis activities, so long as states comply with specified quality-assurance standards, submit to external proficiency testing, and limit access to DNA information. Although these additional funds should help to ease some sample backlogs, it remains unclear how labs will allocate the funds, as between analyzing samples for their data banks and testing evidence samples in cases without suspects. The DNA Identification Act provides penalties for the disclosure or obtaining of DNA data held by data banks that participate in CODIS, the FBI's evolving national network of DNA data banks, but individual crime labs must also develop stringent internal safeguards to prevent breaches of data-bank security.
Explore the source record for details and available documents.
Explore the source record for details and available documents.