Suppr超能文献

设计并实现符合美国法规的审计追踪。

Design and implementation of an audit trail in compliance with US regulations.

机构信息

Purdue University Calumet, Hammond, Indiana 46323, USA.

出版信息

Clin Trials. 2011 Oct;8(5):624-33. doi: 10.1177/1740774511413943. Epub 2011 Sep 7.

Abstract

BACKGROUND

Audit trails have been used widely to ensure quality of study data and have been implemented in computerized clinical trials data systems. Increasingly, there is a need to audit access to study participant identifiable information to provide assurance that study participant privacy is protected and confidentiality is maintained. In the United States, several federal regulations specify how the audit trail function should be implemented.

PURPOSE

To describe the development and implementation of a comprehensive audit trail system that meets the regulatory requirements of assuring data quality and integrity and protecting participant privacy and that is also easy to implement and maintain.

METHODS

The audit trail system was designed and developed after we examined regulatory requirements, data access methods, prevailing application architecture, and good security practices.

RESULTS

Our comprehensive audit trail system was developed and implemented at the database level using a commercially available database management software product. It captures both data access and data changes with the correct user identifier. Documentation of access is initiated automatically in response to either data retrieval or data change at the database level.

LIMITATIONS

Currently, our system has been implemented only on one commercial database management system. Although our audit trail algorithm does not allow for logging aggregate operations, aggregation does not reveal sensitive private participant information. Careful consideration must be given to data items selected for monitoring because selection of all data items using our system can dramatically increase the requirements for computer disk space. Evaluating the criticality and sensitivity of individual data items selected can control the storage requirements for clinical trial audit trail records.

CONCLUSIONS

Our audit trail system is capable of logging data access and data change operations to satisfy regulatory requirements. Our approach is applicable to virtually any data that can be stored in a relational database.

摘要

背景

审计跟踪已广泛用于确保研究数据的质量,并已在计算机化临床试验数据系统中实施。越来越需要审核对研究参与者可识别信息的访问,以确保保护研究参与者的隐私并维护机密性。在美国,有几项联邦法规规定了应如何实施审计跟踪功能。

目的

描述一种综合审计跟踪系统的开发和实施,该系统符合确保数据质量和完整性以及保护参与者隐私的法规要求,并且易于实施和维护。

方法

在检查了法规要求、数据访问方法、流行的应用程序体系结构和良好的安全实践之后,我们设计并开发了审计跟踪系统。

结果

我们的综合审计跟踪系统是在数据库级别使用商业可用的数据库管理软件产品开发和实施的。它使用正确的用户标识符捕获数据访问和数据更改。在数据库级别响应数据检索或数据更改,自动启动访问记录。

局限性

目前,我们的系统仅在一个商业数据库管理系统上实施。虽然我们的审计跟踪算法不允许记录聚合操作,但聚合不会揭示敏感的私人参与者信息。必须仔细考虑要监视的数据项,因为使用我们的系统选择所有数据项会极大地增加对计算机磁盘空间的要求。评估所选数据项的关键性和敏感性可以控制临床试验审计跟踪记录的存储要求。

结论

我们的审计跟踪系统能够记录数据访问和数据更改操作,以满足法规要求。我们的方法适用于几乎可以存储在关系数据库中的任何数据。

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验