Bjornsson Bjarni Thor, Sigurdardottir Gudlaug, Stefansson Stefan Orri
Stiki ehf., Reykjavik, Iceland.
Stud Health Technol Inform. 2010;155:78-84.
The paper describes the security concerns related to Electronic Health Records (EHR) both in registration of data and integration of systems. A description of the current state of EHR systems in Iceland is provided, along with the Ministry of Health's future vision and plans. New legislation provides the opportunity for increased integration of EHRs and further collaboration between institutions. Integration of systems, along with greater availability and access to EHR data, requires increased security awareness since additional risks are introduced. The paper describes the core principles of information security as it applies to EHR systems and data. The concepts of confidentiality, integrity, availability, accountability and traceability are introduced and described. The paper discusses the legal requirements and importance of performing risk assessment for EHR data. Risk assessment methodology according to the ISO/IEC 27001 information security standard is described with examples on how it is applied to EHR systems.
本文描述了电子健康记录(EHR)在数据注册和系统集成方面的安全问题。文中介绍了冰岛电子健康记录系统的现状,以及卫生部的未来愿景和计划。新的立法为加强电子健康记录的集成以及机构间的进一步合作提供了契机。系统集成以及电子健康记录数据更高的可用性和可访问性,需要提高安全意识,因为会引入额外的风险。本文阐述了适用于电子健康记录系统和数据的信息安全核心原则。介绍并描述了保密性、完整性、可用性、问责制和可追溯性的概念。本文讨论了电子健康记录数据进行风险评估的法律要求和重要性。描述了根据ISO/IEC 27001信息安全标准的风险评估方法,并举例说明其如何应用于电子健康记录系统。