Practical approaches to creating a security culture

被引:28
作者
Gaunt, N [1 ]
机构
[1] Plymouth Hosp NHS Trust, Plymouth PL6 8DH, Devon, England
关键词
computer; security; policy; confidentiality; patient records;
D O I
10.1016/S1386-5056(00)00115-5
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security of information in the health care environment depends not so much on technical controls as on compliance with policy by all those who use the information. Awareness of policy and observance of a code of conduct, whilst important, do not itself ensure that staff respect confidentiality. let alone follow other measures to secure records. A culture of security must be developed throughout the health care community. This demands clear policy with practical procedures that are relevant in the workplace, a long-term programme in which changes can be introduced in a managed way that is sensitive to the tensions between security and other working practises. commitment from senior management to achieve change, and strong leadership from within the health care professions. The UK National Health Service has begun such a process with the endorsement of the 'Caldicott Committee Report on the review of patient-identifiable information' and its recommendation that all health organisations appoint a senior health care professional to be responsible for confidentiality of patient information. Raising the political profile of patient confidentiality has served to change the rate of change up a gear. The response of one health care community to this initiative will be discussed and lessons drawn regarding cultural change and information security. (C) 2000 Elsevier Science Ireland Ltd. All rights reserved.
引用
收藏
页码:151 / 157
页数:7
相关论文
共 7 条
[1]  
[Anonymous], 1997, REP REV PAT ID INF
[2]   Threats to the confidentiality of medical records - No place to hide [J].
Appelbaum, PS .
JAMA-JOURNAL OF THE AMERICAN MEDICAL ASSOCIATION, 2000, 283 (06) :795-797
[3]   Privacy in clinical information systems in secondary care [J].
Denley, I ;
Smith, SW .
BRITISH MEDICAL JOURNAL, 1999, 318 (7194) :1328-1330
[4]   Assessing staff attitudes towards information security in a European healthcare establishment [J].
Furnell, SM ;
Gaunt, PN ;
Holben, RF ;
Sanders, PW ;
Stockel, CT ;
Warren, MJ .
MEDICAL INFORMATICS, 1996, 21 (02) :105-112
[5]   Installing an appropriate information security policy [J].
Gaunt, N .
INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 1998, 49 (01) :131-134
[6]  
*NHS EX, 1998, INF HLTH INF STRAT N
[7]  
WARREN MJ, 1994, INT J BIOMED COMPUT, V35, P269