首页> 外文OA文献 >A model for information security management and regulatory compliance in the South African health sector
【2h】

A model for information security management and regulatory compliance in the South African health sector

机译:南非卫生部门信息安全管理和监管合规模型

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Information Security is becoming a part of the core business processes in every organization. Companies are faced with contradictory requirements to ensure open systems and accessible information while maintaining high protection standards. In addition, the contemporary management of Information Security requires a variety of approaches in different areas, ranging from technological to organizational issues and legislation. These approaches are often isolated while Security Management requires an integrated approach. Information Technology promises many benefits to healthcare organizations. It helps to make accurate information more readily available to healthcare providers and workers, researchers and patients and advanced computing and communication technology can improve the quality and lower the costs of healthcare. However, the prospect of storing health information in an electronic form raises concerns about patient privacy and security. Healthcare organizations are required to establish formal Information Security program, for example through the adoption of the ISO 17799 standard, to ensure an appropriate and consistent level of information security for computer-based patient records, both within individual healthcare organizations and throughout the entire healthcare delivery system. However, proper Information Security Management practices, alone, do not necessarily ensure regulatory compliance. South African healthcare organizations must comply with the South African National Health Act (SANHA) and the Electronic Communication Transaction Act (ECTA). It is necessary to consider compliance with the Health Insurance Portability and Accountability Act (HIPAA) to meet healthcare international industry standards. The main purpose of this project is to propose a compliance strategy, which ensures full compliance with regulatory requirements and at the same time assures customers that international industry standards are being used. This is preceded by a comparative analysis of the requirements posed by the ISO 17799 standard and the HIPAA, SANHA and ECTA regulations.
机译:信息安全正在成为每个组织的核心业务流程的一部分。公司面临着相互矛盾的要求,以确保开放的系统和可访问的信息,同时保持较高的保护标准。另外,当代的信息安全管理需要在不同领域采用多种方法,从技术到组织问题和立法。这些方法通常是隔离的,而安全管理需要集成的方法。信息技术有望为医疗机构带来许多好处。它有助于使准确的信息更易于提供给医疗保健提供者和工作者,研究人员和患者,而先进的计算和通信技术可以提高医疗质量并降低医疗成本。然而,以电子形式存储健康信息的前景引起了对患者隐私和安全性的担忧。医疗保健组织需要建立正式的信息安全计划,例如通过采用ISO 17799标准,以确保在单个医疗保健组织内部以及整个医疗保健交付过程中,针对基于计算机的患者记录的信息安全级别保持适当和一致系统。但是,仅适当的信息安全管理实践并不一定能确保合规性。南非医疗保健组织必须遵守《南非国家卫生法》(SANHA)和《电子通信交易法》(ECTA)。为了符合国际医疗保健行业标准,有必要考虑遵守《健康保险流通与责任法案》(HIPAA)。该项目的主要目的是提出一种合规策略,以确保完全符合法规要求,同时确保客户正在使用国际行业标准。在此之前,先对ISO 17799标准以及HIPAA,SANHA和ECTA法规提出的要求进行比较分析。

著录项

  • 作者

    Tuyikeze Tite;

  • 作者单位
  • 年度 2005
  • 总页数
  • 原文格式 PDF
  • 正文语种 English
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号