Yeo Kiho, Lee Keehyuck, Kim Jong-Min, Kim Tae-Hun, Choi Yong-Hoon, Jeong Woo-Jin, Hwang Hee, Baek Rong Min, Yoo Sooyoung
Center for Medical Informatics, Seoul National University Bundang Hospital, Seongnam, Korea.
Healthc Inform Res. 2012 Jun;18(2):125-35. doi: 10.4258/hir.2012.18.2.125. Epub 2012 Jun 30.
The goal of this paper is to examine the security measures that should be reviewed by medical facilities that are trying to implement mobile Electronic Medical Record (EMR) systems designed for hospitals.
The study of the security requirements for a mobile EMR system is divided into legal considerations and sectional security investigations. Legal considerations were examined with regard to remote medical services, patients' personal information and EMR, medical devices, the establishment of mobile systems, and mobile applications. For the 4 sectional security investigations, the mobile security level SL-3 from the Smartphone Security Standards of the National Intelligence Service (NIS) was used.
From a compliance perspective, legal considerations for various laws and guidelines of mobile EMR were executed according to the model of the legal considerations. To correspond to the SL-3, separation of DMZ and wireless network is needed. Mobile access servers must be located in only the smartphone DMZ. Furthermore, security measures like 24-hour security control, WIPS, VPN, MDM, and ISMS for each section are needed to establish a secure mobile EMR system.
This paper suggested a direction for applying regulatory measures to strengthen the security of a mobile EMR system in accordance with the standard security requirements presented by the Smartphone Security Guideline of the NIS. A future study on the materialization of these suggestions after their application at actual medical facilities can be used as an illustrative case to determine the degree to which theory and reality correspond with one another.
本文旨在探讨试图实施专为医院设计的移动电子病历(EMR)系统的医疗机构应审查的安全措施。
对移动EMR系统安全要求的研究分为法律考量和部门安全调查。从远程医疗服务、患者个人信息与EMR、医疗设备、移动系统的建立以及移动应用等方面审查法律考量。对于4项部门安全调查,采用了国家情报服务局(NIS)智能手机安全标准中的移动安全级别SL-3。
从合规角度来看,按照法律考量模型执行了对移动EMR各项法律法规和指南的法律考量。为符合SL-3,需要对非军事区(DMZ)和无线网络进行分离。移动访问服务器必须仅位于智能手机DMZ中。此外,需要采取诸如24小时安全控制、无线入侵防护系统(WIPS)、虚拟专用网络(VPN)、移动设备管理(MDM)以及针对每个部门的信息安全管理体系(ISMS)等安全措施,以建立一个安全的移动EMR系统。
本文根据NIS智能手机安全指南提出的标准安全要求,为应用监管措施以加强移动EMR系统的安全性提供了一个方向。未来在实际医疗机构应用这些建议后对其实现情况进行的研究,可作为一个说明性案例,用以确定理论与现实的相符程度。