Mohammed Ghulam Dastagir Faisal, Chandran Prakash, Mansoor Zaina, Mohaddis Momin
Trauma and Orthopaedics, London Northwest NHS Trust, London, GBR.
Trauma and Orthopaedics, Warrington and Halton NHS Foundation Trust, Warrington, GBR.
Cureus. 2021 Aug 27;13(8):e17513. doi: 10.7759/cureus.17513. eCollection 2021 Aug.
Information technology has become an integral part of health care in the United Kingdom National Health Service (NHS). All health care professionals are required to have a certain level of cyber ethics and knowledge of computers. This is assured by regular mandatory training. The government of the United Kingdom has charted out a course to strengthen cyber security and prevent any crises like Wannacry. Simple things like leaving a computer unlocked can pose a potential threat to the cyber security of the whole NHS. These cannot be addressed with money alone, as they involve complex interactions of human factors. Such seemingly simple non-compliance results often in harm to the patient or breach of confidentiality. We tried to find out the compliance among junior doctors to the Trust Information Technology (IT) Safe Usage Policy. We made interventions and interviewed junior doctors to find out the reasons for non-compliance. We re-audited in order to see if our interventions helped. We also audited compliance in another Trust independently, which showed that this problem is not specific to a particular trust. Here we suggest the changes that all Trusts can make and follow our model to audit their compliance.
在英国国家医疗服务体系(NHS)中,信息技术已成为医疗保健不可或缺的一部分。所有医疗保健专业人员都必须具备一定水平的网络道德和计算机知识。这通过定期的强制性培训得以保证。英国政府已制定了加强网络安全并预防类似“想哭”病毒这样的危机的方针。像让电脑不设密码这样简单的事情,可能会对整个NHS的网络安全构成潜在威胁。这些问题不能仅靠资金来解决,因为它们涉及人为因素的复杂相互作用。这种看似简单的违规行为往往会对患者造成伤害或导致机密信息泄露。我们试图了解初级医生对信托信息技术(IT)安全使用政策的遵守情况。我们进行了干预并采访了初级医生,以找出不遵守规定的原因。我们进行了重新审核,以查看我们的干预措施是否有帮助。我们还独立审核了另一个信托机构的合规情况,结果表明这个问题并非特定于某个信托机构。在此,我们提出所有信托机构都可以做出的改变,并遵循我们的模式来审核其合规情况。