Furnell S M, Sanders P W
University of Plymouth, Network Research Group, Drake Circus, UK.
Stud Health Technol Inform. 1996;27:150-5.
The increasing use of and reliance upon information technology within modern healthcare establishments underlines a need for adequate security controls to protect the confidentiality, integrity and availability of systems and data. Whilst the consideration of security is now generally accepted as part of the design and implementation of new systems, many systems are already in operation in which these needs have not been adequately addressed. This paper presents a summary of the recommendations arising from the AIM SEISMED (Secure Environment for Information Systems in MEDicine) project relating to the addition and enhancement of security in existing healthcare systems. The paper is based upon material originally presented at the SEISMED Workshop "Security and Legal Aspects of Advanced Health Telematics", Brussels, 11 July 1994. The content has been revised in light of the workshop discussion and the further development of the guidelines since that time.
现代医疗机构对信息技术的使用和依赖日益增加,这凸显了实施适当安全控制措施以保护系统和数据的保密性、完整性和可用性的必要性。虽然现在人们普遍认为安全考量是新系统设计和实施的一部分,但许多已在运行的系统并未充分满足这些需求。本文概述了AIM SEISMED(医学信息系统安全环境)项目提出的有关在现有医疗系统中增加和加强安全性的建议。本文基于1994年7月11日在布鲁塞尔举行的SEISMED研讨会“先进健康远程信息学的安全与法律问题”上最初发表的材料。根据研讨会的讨论以及自那时以来指南的进一步发展,内容已作修订。