Southern Cross University, Lismore, Australia.
Int J Med Inform. 2011 Feb;80(2):e32-8. doi: 10.1016/j.ijmedinf.2010.10.006. Epub 2010 Nov 13.
To ensure that patient confidentiality is securely maintained, health ICT applications that contain sensitive personal information demand comprehensive privacy policies. Determining the adequacy of these policies to meet legal conformity together with clinical users and patient expectation is demanding in practice. Organisations and agencies looking to analyse their Privacy and Security policies can benefit from guidance provided by outside entities such as the Privacy Office of their State or Government together with law firms and ICT specialists. The advice given is not uniform and often open to different interpretations. Of greater concern is the possibility of overlooking any important aspects that later result in a data breach. Based on three case studies, this paper considers whether a more formal approach to privacy analysis could be taken that would help identify the full coverage of a Privacy Impact Analysis and determine the deficiencies with an organisation's current policies and approach. A diagrammatic model showing the relationships between Confidentiality, Privacy, Trust, Security and Safety is introduced. First the validity of this model is determined by mapping it against the real-world case studies taken from three healthcare services that depend on ICT. Then, by using software engineering methods, a formal mapping of the relationships is undertaken to identify a full set of policies needed to satisfy the model. How effective this approach may prove as a generic method for deriving a comprehensive set of policies in health ICT applications is finally discussed.
为了确保患者的保密性得到妥善维护,包含敏感个人信息的卫生信息和通信技术应用程序需要全面的隐私政策。在实践中,确定这些政策是否足以满足法律合规性以及临床用户和患者的期望是一项具有挑战性的任务。希望分析其隐私和安全政策的组织和机构可以从外部实体(如州或政府的隐私办公室)、律师事务所和信息通信技术专家那里获得指导。所提供的建议并不统一,并且经常存在不同的解释。更令人担忧的是,可能会忽略任何重要方面,而这些方面后来会导致数据泄露。本文基于三个案例研究,探讨是否可以采取更正式的隐私分析方法,以帮助确定隐私影响分析的全面覆盖范围,并确定组织当前政策和方法的不足之处。引入了一个显示保密性、隐私、信任、安全和安全之间关系的图表模型。首先,通过将其映射到依赖于信息和通信技术的三个医疗保健服务的实际案例研究来确定该模型的有效性。然后,通过使用软件工程方法,对关系进行正式映射,以确定满足模型所需的完整政策集。最后讨论了这种方法作为在卫生信息和通信技术应用程序中推导出全面的政策集的通用方法可能具有的有效性。