Kashan University of Medical Sciences, Kashan, Iran.
J Med Syst. 2010 Aug;34(4):629-42. doi: 10.1007/s10916-009-9276-7. Epub 2009 Apr 1.
A growing capacity of information technologies in collection, storage and transmission of information in unprecedented amounts has produced significant problems about the availability of wide limit of the consumers of Electronic Health Records of Patients. With regard to the existence of many approaches to developing Electronic Health Records, the basic question is what kind of Model is suitable for the guarantee of the security of Electronic Health Records? The present study is a descriptive-comparative investigation conducted in Iran in 2007, along with comparisons made Electronic health records information security requirements of Australia, Canada, England and U.S.A with. The research was based on the study of texts such as articles, library's books and journals and reliable websites from 1992 to 2006. Based on the collected data, a primary Model was designed. The Delphi Technique was offered to evaluate the questionnaire and final Model was designed and proposed. Australia, Canada, England and U.S.A have requirements related to organizing information security, classifying and controlling information asset, security of human resources, environmental and physical security, Operational and communication management security, information access control security and development and Maintenance security of Electronic Health Records information systems. In the U.S.A, the above security requirements are presented in administrative, Physical and Technical safeguards. Based on the research findings, a comprehensive model of electronic health record security requirements in seven pivots is presented for Iran. This model is a collection of EHR security requirements from studied countries. The studied countries are solely subject to part of elements of this model. The suggested model is different from the ones used in other countries in some respects and is recommended for application in Iran.
信息技术在信息的收集、存储和传输方面的能力不断增强,使得患者电子健康记录的消费者能够获得大量前所未有的信息,但同时也产生了一些重大问题。鉴于开发电子健康记录的方法有很多种,基本问题是哪种模式适合保证电子健康记录的安全性?本研究是 2007 年在伊朗进行的一项描述性比较研究,同时还比较了澳大利亚、加拿大、英国和美国的电子健康记录信息安全要求。研究的依据是 1992 年至 2006 年期间对文章、图书馆书籍和期刊以及可靠网站等文本的研究。根据收集的数据,设计了一个初步的模型。采用德尔菲技术对问卷进行评估,并设计和提出了最终模型。澳大利亚、加拿大、英国和美国都有与组织信息安全、信息资产分类和控制、人力资源安全、环境和物理安全、运营和通信管理安全、信息访问控制安全以及电子健康记录信息系统的开发和维护安全有关的要求。在美国,上述安全要求体现在行政、物理和技术保障中。根据研究结果,为伊朗提出了一个包含七个方面的电子健康记录安全要求的综合模型。该模型是从所研究国家的电子健康记录安全要求中收集的。研究国家仅涉及该模型的部分要素。所提出的模型在某些方面与其他国家使用的模型不同,建议在伊朗应用。