Myers D L, Culp K S, Miller R S
Medical Informatics Scott and White, Temple, Texas, USA.
Proc AMIA Symp. 1999:897-900.
Delivery of health care at Scott and White, a large integrated health care delivery system, is supported by an Electronic Medical Record (EMR) system repository of six million SGML-based documents. Control of document access is currently based on standard commercial security and confidentiality methodologies. Given the planned release in Fall 1999 of new federal security and confidentiality requirements, we have developed a web-based security process model that "wraps" existing EMR documents with HTML-compliant security attributes. Resulting logical documents are filtered regarding user queries by mapping the security attributes of the data to specific user role characteristics. A key virtue of our approach is that source EMR data do not undergo alteration by the imposition of the security process. It also places no additional work load or query pressure on the existing EMR system.
斯科特与怀特医疗集团是一个大型综合医疗服务体系,其医疗服务由一个包含600万份基于SGML文档的电子病历(EMR)系统存储库提供支持。目前,文档访问控制基于标准的商业安全和保密方法。鉴于计划于1999年秋季发布新的联邦安全和保密要求,我们开发了一种基于网络的安全流程模型,该模型用符合HTML的安全属性“包装”现有的EMR文档。通过将数据的安全属性映射到特定的用户角色特征,对生成的逻辑文档进行用户查询过滤。我们方法的一个关键优点是,源EMR数据不会因实施安全流程而被更改。它也不会给现有的EMR系统带来额外的工作量或查询压力。