首页> 外文会议>Biomedical Engineering International Conference >Network security vulnerabilities and personal privacy issues in healthcare information systems: A case study in a private hospital
【24h】

Network security vulnerabilities and personal privacy issues in healthcare information systems: A case study in a private hospital

机译:医疗保健信息系统中的网络安全漏洞和个人隐私问题:一家私立医院的案例研究

获取原文

摘要

Healthcare industry has become widely dependent on information technology and internet; as it moves from paper to electronic records. Despite the benefits of electronic system, good quality may not be totally achieved unless its risks to security are mitigated. Working in collaboration with a 150 bed private hospital in Turkey; this study aims to present a secure healthcare network infrastructure while presenting the security vulnerabilities in the current hospital information systems. The regulation criteria in Turkey and counterparts in USA and EU are compared according to their privacy approach and a list of items for common security controls from different industries is proposed as a best practice. The study shows that the hospital is not compliant with known healthcare standards like HIPAA or ISO 80001. Management's attitude against privacy and security shows that the responsibility is totally to IT and Biomedical Engineering Departments. As hospitals are adopting electronic transactions, consideration must be given to protect public electronic health records in terms of personal privacy aspects. Healthcare industry in Turkey should benefit from best practices in other industries and applications in other countries. This study can lead the pathway for policy makers in healthcare organizations and regulation authorities to implement a more secure environment for every citizen.
机译:医疗保健行业已广泛依赖信息技术和互联网。从纸质记录到电子记录。尽管电子系统有很多好处,但除非减轻安全隐患,否则可能无法完全获得良好的质量。与土耳其一家拥有150张床位的私立医院合作;这项研究旨在提供安全的医疗网络基础设施,同时提出当前医院信息系统中的安全漏洞。根据土耳其的法规标准以及美国和欧盟的隐私标准,对它们的法规标准进行了比较,并建议将不同行业的通用安全控制项目列表作为最佳实践。研究表明,该医院不符合HIPAA或ISO 80001等已知的医疗保健标准。管理层对隐私和安全性的态度表明,责任完全由IT和生物医学工程部门承担。由于医院采用电子交易,因此必须从个人隐私方面考虑保护公共电子健康记录。土耳其的医疗保健行业应从其他行业的最佳实践和其他国家/地区的应用中受益。这项研究可以为医疗机构和监管机构中的政策制定者提供引导途径,为每个公民实施更安全的环境。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号