Mense Alexander, Hoheiser-Pförtner Franz, Schmid Martin, Wahl Harald
University of Applied Sciences Technikum Wien, Vienna, Austria.
Stud Health Technol Inform. 2013;192:548-52.
Working with health related data necessitates appropriate levels of security and privacy. Information security, meaning ensuring confidentiality, integrity, and availability, is more organizational, than technical in nature. It includes many organizational and management measures, is based on well-defined security roles, processes, and documents, and needs permanent adaption of security policies, continuously monitoring, and measures assessment. This big challenge for any organization leads to implementation of an information security management system (ISMS). In the context of establishing a regional or national electronic health record for integrated care (ICEHR), the situation is worse. Changing the medical information exchange from on-demand peer-to-peer connections to health information networks requires all organizations participating in the EHR system to have consistent security levels and to follow the same security guidelines and rules. Also, the implementation must be monitored and audited, establishing cross-organizational information security management systems (ISMS) based on international standards. This paper evaluates requirements and defines basic concepts for an ISO 27000 series-based cross-organizational ISMS in the healthcare domain and especially for the implementation of the nationwide electronic health record in Austria (ELGA).
处理与健康相关的数据需要适当的安全和隐私保护水平。信息安全,即确保保密性、完整性和可用性,本质上更多是组织层面的,而非技术层面的。它包括许多组织和管理措施,基于明确的安全角色、流程和文档,并且需要不断调整安全策略、持续监控和评估措施。这对任何组织来说都是巨大的挑战,进而促使实施信息安全管理体系(ISMS)。在建立用于综合医疗的区域或国家电子健康记录(ICEHR)的背景下,情况更为严峻。将医疗信息交换从按需点对点连接转变为健康信息网络,要求参与电子健康记录系统的所有组织具备一致的安全水平,并遵循相同的安全准则和规则。此外,必须对实施情况进行监控和审计,基于国际标准建立跨组织的信息安全管理体系(ISMS)。本文评估了相关要求,并为医疗领域基于ISO 27000系列的跨组织ISMS定义了基本概念,特别是针对奥地利全国电子健康记录(ELGA)的实施。