Collmann Jeff, Cooper Ted
Georgetown University Medical Center, Washington, DC, USA.
J Am Med Inform Assoc. 2007 Mar-Apr;14(2):239-43. doi: 10.1197/jamia.M2195. Epub 2007 Jan 9.
This case study describes and analyzes a breach of the confidentiality and integrity of personally identified health information (e.g. appointment details, answers to patients' questions, medical advice) for over 800 Kaiser Permanente (KP) members through KP Online, a web-enabled health care portal. The authors obtained and analyzed multiple types of qualitative data about this incident including interviews with KP staff, incident reports, root cause analyses, and media reports. Reasons at multiple levels account for the breach, including the architecture of the information system, the motivations of individual staff members, and differences among the subcultures of individual groups within as well as technical and social relations across the Kaiser IT program. None of these reasons could be classified, strictly speaking, as "security violations." This case study, thus, suggests that, to protect sensitive patient information, health care organizations should build safe organizational contexts for complex health information systems in addition to complying with good information security practice and regulations such as the Health Insurance Portability and Accountability Act (HIPAA) of 1996.
本案例研究描述并分析了通过凯泽永久医疗集团(KP)的在线医疗保健门户网站KP Online,800多名KP会员的个人身份健康信息(如预约详情、患者问题答案、医疗建议)的保密性和完整性遭到破坏的情况。作者获取并分析了有关该事件的多种定性数据,包括对KP工作人员的访谈、事件报告、根本原因分析以及媒体报道。多个层面的原因导致了此次违规行为,包括信息系统架构、个别工作人员的动机,以及凯泽信息技术项目中各个小组亚文化之间的差异以及技术和社会关系。严格来说,这些原因都不能归类为“安全违规”。因此,本案例研究表明,为保护敏感的患者信息,医疗保健组织除了遵守良好的信息安全实践和法规(如1996年的《健康保险流通与责任法案》(HIPAA))外,还应为复杂的健康信息系统构建安全的组织环境。