首页> 美国卫生研究院文献>Journal of the American Medical Informatics Association : JAMIA >Breaching the Security of the Kaiser Permanente Internet Patient Portal: the Organizational Foundations of Information Security
【2h】

Breaching the Security of the Kaiser Permanente Internet Patient Portal: the Organizational Foundations of Information Security

机译:违反Kaiser永久互联网患者门户的安全性:信息安全的组织基础

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

This case study describes and analyzes a breach of the confidentiality and integrity of personally identified health information (e.g. appointment details, answers to patients’ questions, medical advice) for over 800 Kaiser Permanente (KP) members through KP Online, a web-enabled health care portal. The authors obtained and analyzed multiple types of qualitative data about this incident including interviews with KP staff, incident reports, root cause analyses, and media reports. Reasons at multiple levels account for the breach, including the architecture of the information system, the motivations of individual staff members, and differences among the subcultures of individual groups within as well as technical and social relations across the Kaiser IT program. None of these reasons could be classified, strictly speaking, as “security violations.” This case study, thus, suggests that, to protect sensitive patient information, health care organizations should build safe organizational contexts for complex health information systems in addition to complying with good information security practice and regulations such as the Health Insurance Portability and Accountability Act (HIPAA) of 1996.
机译:本案例研究通过网络健康KP Online为800多个Kaiser Permanente(KP)成员描述和分析了个人识别的健康信息(例如约会详细信息,患者问题的答案,医疗建议)的机密性和完整性违规行为护理门户。作者获得并分析了有关此事件的多种定性数据,包括与KP员工的访谈,事件报告,根本原因分析和媒体报告。造成这种违规的原因有多个层次,包括信息系统的体系结构,员工个人的动机,内部各个群体的亚文化之间的差异以及整个Kaiser IT计划的技术和社会关系。从严格意义上讲,这些原因都不能归类为“违反安全性”。因此,本案例研究表明,为了保护敏感的患者信息,医疗保健组织除了遵守良好的信息安全惯例和法规(例如《健康保险可移植性和责任法案》(HIPAA))外,还应为复杂的健康信息系统建立安全的组织环境。 )的1996年。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号