Salazar-Kish J, Tate D, Hall P D, Homa K
Department of Clinical Computing, Dartmouth-Hitchcock Medical Center, Lebanon, New Hampshire, USA.
Proc AMIA Symp. 2000:749-53.
The HIPAA regulations will require that institutions ensure the prevention of unauthorized access to electronically stored or transmitted patient records. This paper discusses a process for analyzing the impact of security mechanisms on users of computerized patient records through "behind the scenes" electronic access audits. In this way, those impacts can be assessed and refined to an acceptable standard prior to implementation. Through an iterative process of design and evaluation, we develop security algorithms that will protect electronic health information from improper access, alteration or loss, while minimally affecting the flow of work of the user population as a whole.
《健康保险流通与责任法案》(HIPAA)规定要求各机构确保防止未经授权访问以电子方式存储或传输的患者记录。本文讨论了一种通过“幕后”电子访问审计来分析安全机制对计算机化患者记录用户影响的过程。通过这种方式,可以在实施之前评估这些影响并将其优化到可接受的标准。通过设计和评估的迭代过程,我们开发出安全算法,该算法将保护电子健康信息不被不当访问、篡改或丢失,同时将对整个用户群体工作流程的影响降至最低。