Namoğlu Nihan, Ulgen Yekta
Institute of Biomedical Engineering Department, Bogazici University, Istanbul-Turkey.
Stud Health Technol Inform. 2013;190:126-8.
Healthcare industry has become widely dependent on information technology and internet as it moves from paper to electronic records. Healthcare Information System has to provide a high quality service to patients and a productive knowledge share between healthcare staff by means of patient data. With the internet being commonly used across hospitals, healthcare industry got its own share from cyber threats like other industries in the world. The challenge is allowing knowledge transfer to hospital staff while still ensuring compliance with security mandates. Working in collaboration with a private hospital in Turkey; this study aims to reveal the essential elements of a 21st century business continuity plan for hospitals while presenting the security vulnerabilities in the current hospital information systems and personal privacy auditing standards proposed by regulations and laws. We will survey the accreditation criteria in Turkey and counterparts in US and EU. We will also interview with medical staff in the hospital to understand the needs for personal privacy and the technical staff to perceive the technical requirements in terms of network security configuration and deployment. As hospitals are adopting electronic transactions, it should be considered a must to protect these electronic health records in terms of personal privacy aspects.
随着医疗行业从纸质记录转向电子记录,该行业已广泛依赖信息技术和互联网。医疗信息系统必须通过患者数据为患者提供高质量服务,并在医护人员之间实现高效的知识共享。由于互联网在医院中普遍使用,医疗行业与世界上其他行业一样,也面临着网络威胁。挑战在于在允许向医院工作人员进行知识转移的同时,仍要确保符合安全要求。本研究与土耳其的一家私立医院合作开展,旨在揭示21世纪医院业务连续性计划的基本要素,同时展示当前医院信息系统中的安全漏洞以及法规和法律提出的个人隐私审核标准。我们将调查土耳其以及美国和欧盟的认证标准。我们还将采访医院的医务人员,以了解个人隐私需求,并采访技术人员,以了解网络安全配置和部署方面的技术要求。随着医院采用电子交易,从个人隐私角度保护这些电子健康记录应被视为一项必要举措。