Risk Assessment of Integrated Electronic Health Records

被引:0
|
作者
Bjornsson, Bjarni Thor [1 ]
Sigurdardottir, Gudlaug [1 ]
Stefansson, Stefan Orri [1 ]
机构
[1] Stiki Ehf, IS-105 Reykjavik, Iceland
关键词
EHR; electronic health network; ISO/IEC; 27001; Risk management; information security; system integration;
D O I
10.3233/978-1-60750-563-1-78
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
The paper describes the security concerns related to Electronic Health Records (EHR) both in registration of data and integration of systems. A description of the current state of EHR systems in Iceland is provided, along with the Ministry of Health's future vision and plans. New legislation provides the opportunity for increased integration of EHRs and further collaboration between institutions. Integration of systems, along with greater availability and access to EHR data, requires increased security awareness since additional risks are introduced. The paper describes the core principles of information security as it applies to EHR systems and data. The concepts of confidentiality, integrity, availability, accountability and traceability are introduced and described. The paper discusses the legal requirements and importance of performing risk assessment for EHR data. Risk assessment methodology according to the ISO/IEC 27001 information security standard is described with examples on how it is applied to EHR systems.
引用
收藏
页码:78 / 84
页数:7
相关论文
共 50 条
  • [1] Integrated electronic health records
    Penington, GR
    [J]. MEDICAL JOURNAL OF AUSTRALIA, 2000, 172 (07) : 350 - 350
  • [2] The Risk Assessment of the Security of Electronic Health Records Using Risk Matrix
    Alarfaj, Khalid A.
    Rahman, M. M. Hafizur
    [J]. APPLIED SCIENCES-BASEL, 2024, 14 (13):
  • [3] Misclassification in assessment of diabetogenic risk using electronic health records
    Winterstein, Almut G.
    Kubilis, Paul
    Bird, Steve
    Cooper-DeHoff, Rhonda M.
    Nichols, Greg A.
    Delaney, Joseph A.
    [J]. PHARMACOEPIDEMIOLOGY AND DRUG SAFETY, 2014, 23 (08) : 875 - 881
  • [4] Text Classification to Inform Suicide Risk Assessment in Electronic Health Records
    Bittar, Andre
    Velupillai, Sumithra
    Roberts, Angus
    Dutta, Rina
    [J]. MEDINFO 2019: HEALTH AND WELLBEING E-NETWORKS FOR ALL, 2019, 264 : 40 - 44
  • [5] Electronic Health Risk Assessment Adoption in an Integrated Healthcare System
    Buist, Diana S. M.
    Ross, Nora Knight
    Reid, Robert J.
    Grossman, David C.
    [J]. AMERICAN JOURNAL OF MANAGED CARE, 2014, 20 (01): : 62 - 69
  • [6] MEDICATION DISCREPANCIES IN INTEGRATED ELECTRONIC HEALTH RECORDS
    Linsky, Amy
    Simon, Steven R.
    [J]. JOURNAL OF GENERAL INTERNAL MEDICINE, 2012, 27 : S246 - S246
  • [7] Integrated electronic health records management system
    Di Giacomo, P.
    Ricci, Fabrizio L.
    Bocchi, Leonardo
    [J]. MEDICAL AND CARE COMPUNETICS 3, 2006, 121 : 228 - 241
  • [8] Medication discrepancies in integrated electronic health records
    Linsky, Amy
    Simon, Steven R.
    [J]. BMJ QUALITY & SAFETY, 2013, 22 (02) : 103 - 109
  • [9] Risk Prediction With Electronic Health Records
    Goldstein, Benjamin A.
    Navar, Ann Marie
    Pencina, Michael J.
    [J]. JAMA CARDIOLOGY, 2016, 1 (09) : 976 - 977
  • [10] Electronic health records within integrated care in Germany
    Jähn, K
    Gärtig-Daugs, A
    Nagel, E
    [J]. TELEMEDICINE JOURNAL AND E-HEALTH, 2005, 11 (02): : 146 - 150