Williams Patricia A H
Health Research Group, School of Computer and Security Science, Edith Cowan University, Australia.
Stud Health Technol Inform. 2013;193:186-206.
It is no small task to manage the protection of healthcare data and healthcare information systems. In an environment that is demanding adaptation to change for all information collection, storage and retrieval systems, including those for of e-health and information systems, it is imperative that good information security governance is in place. This includes understanding and meeting legislative and regulatory requirements. This chapter provides three models to educate and guide organisations in this complex area, and to simplify the process of information security governance and ensure appropriate and effective measures are put in place. The approach is risk based, adapted and contextualized for healthcare. In addition, specific considerations of the impact of cloud services, secondary use of data, big data and mobile health are discussed.
管理医疗保健数据和医疗信息系统的保护并非易事。在一个要求所有信息收集、存储和检索系统(包括电子健康和信息系统)都适应变化的环境中,必须要有良好的信息安全治理。这包括理解并满足立法和监管要求。本章提供了三种模型,用于教育和指导组织应对这一复杂领域,简化信息安全治理流程,并确保采取适当且有效的措施。该方法基于风险,针对医疗保健进行了调整和情境化。此外,还讨论了云服务、数据二次使用、大数据和移动健康影响的具体考量因素。