Collmann Jeff, Coleman Johnathan, Sostrom Kristen, Wright Willie
Telemedicine and Advanced Technology Research Center, USAMRMC, Washington, D.C., USA.
Telemed J E Health. 2004 Fall;10(3):311-20. doi: 10.1089/tmj.2004.10.311.
Organizations must continuously seek safety. When considering computerized health information systems, "safety" includes protecting the integrity, confidentiality, and availability of information assets such as patient information, key components of the technical information system, and critical personnel. "High Reliability Theory" (HRT) argues that organizations with strong leadership support, continuous training, redundant safety mechanisms, and "cultures of high reliability" can deploy and safely manage complex, risky technologies such as nuclear weapons systems or computerized health information systems. In preparation for the Health Insurance Portability and Accountability Act (HIPAA) of 1996, the Office of the Assistant Secretary of Defense (Health Affairs), the Offices of the Surgeons General of the United States Army, Navy and Air Force, and the Telemedicine and Advanced Technology Research Center (TATRC), US Army Medical Research and Materiel Command sponsored organizational, doctrinal, and technical projects that individually and collectively promote conditions for a "culture of information assurance." These efforts include sponsoring the "P3 Working Group" (P3WG), an interdisciplinary, tri-service taskforce that reviewed all relevant Department of Defense (DoD), Miliary Health System (MHS), Army, Navy and Air Force policies for compliance with the HIPAA medical privacy and data security regulations; supporting development, training, and deployment of OCTAVE(sm), a self-directed information security risk assessment process; and sponsoring development of the Risk Information Management Resource (RIMR), a Web-enabled enterprise portal about health information assurance.
各组织必须持续追求安全。在考虑计算机化健康信息系统时,“安全”包括保护信息资产的完整性、保密性和可用性,这些信息资产如患者信息、技术信息系统的关键组件以及关键人员。“高可靠性理论”(HRT)认为,拥有强有力领导支持、持续培训、冗余安全机制以及“高可靠性文化”的组织能够部署并安全管理诸如核武器系统或计算机化健康信息系统等复杂且有风险的技术。为筹备1996年的《健康保险流通与责任法案》(HIPAA),美国国防部助理部长办公室(卫生事务)、美国陆军、海军和空军军医局局长办公室以及美国陆军医学研究与物资司令部远程医学与先进技术研究中心(TATRC)发起了组织、理论和技术项目,这些项目单独或共同促进了“信息保障文化”的条件。这些努力包括赞助“P3工作组”(P3WG),这是一个跨学科、三军联合的特别工作组,负责审查国防部(DoD)、军事健康系统(MHS)、陆军、海军和空军所有相关政策,以确保符合HIPAA医疗隐私和数据安全规定;支持OCTAVE(sm)(一种自主式信息安全风险评估流程)的开发、培训和部署;以及赞助风险信息管理资源(RIMR)的开发,这是一个关于健康信息保障的基于网络的企业门户。