Security Requirements and Solutions in Electronic Health Records: Lessons Learned from a Comparative Study

被引:27
作者
Farzandipour, Mehrdad [1 ]
Sadoughi, Farahnaz [2 ]
Ahmadi, Maryam [2 ]
Karimi, Iraj [2 ]
机构
[1] Kashan Univ Med Sci, Kashan, Iran
[2] Iran Univ Med Sci, Tehran, Iran
关键词
Security model; Security requirements; Information security; Electronic health records;
D O I
10.1007/s10916-009-9276-7
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
A growing capacity of information technologies in collection, storage and transmission of information in unprecedented amounts has produced significant problems about the availability of wide limit of the consumers of Electronic Health Records of Patients. With regard to the existence of many approaches to developing Electronic Health Records, the basic question is what kind of Model is suitable for the guarantee of the security of Electronic Health Records? The present study is a descriptive-comparative investigation conducted in Iran in 2007, along with comparisons made Electronic health records information security requirements of Australia, Canada, England and U.S.A with. The research was based on the study of texts such as articles, library's books and journals and reliable websites from 1992 to 2006. Based on the collected data, a primary Model was designed. The Delphi Technique was offered to evaluate the questionnaire and final Model was designed and proposed. Australia, Canada, England and U.S.A have requirements related to organizing information security, classifying and controlling information asset, security of human resources, environmental and physical security, Operational and communication management security, information access control security and development and Maintenance security of Electronic Health Records information systems. In the U.S.A, the above security requirements are presented in administrative, Physical and Technical safeguards. Based on the research findings, a comprehensive model of electronic health record security requirements in seven pivots is presented for Iran. This model is a collection of EHR security requirements from studied countries. The studied countries are solely subject to part of elements of this model. The suggested model is different from the ones used in other countries in some respects and is recommended for application in Iran.
引用
收藏
页码:629 / 642
页数:14
相关论文
共 26 条
[1]  
*ABC PTY LTD IT SE, 2006, INF SEC CONTR PROC M
[2]  
[Anonymous], STAT HIPAA PRIV SEC
[3]  
*ASP REF GROUP, 1999, HLTH INF MAN MAN, P5
[4]  
Behnam S., 2005, THESIS IRAN U MED SC
[5]  
BITARAF E, 2007, COMP STUDY ELECT HLT, P398
[6]  
*CAN HLTH INF, 2005, EL HLTH REC PRIV SEC
[7]  
*CAN HLTH INF, 2003, INF PAN CAN EHR SURV
[8]  
*CIHI, 2002, PRIV CONF HLTH INF C
[9]  
*COMM AUSTR, 2003, INT APPR EL HLTH REC
[10]  
*COMM DEP HLTH AG, 2002, BEN DIFF INTR NAT AP