Electronic Medical Records, HIPAA, and Patient Privacy

被引:2
|
作者
Li, Jingquan [1 ]
Shaw, Michael J. [2 ,3 ,4 ,5 ]
机构
[1] Texas A&M Univ Kingsville, Coll Business Adm, Accounting & Comp Informat Syst, Kingsville, TX 78363 USA
[2] Univ Illinois, Informat Technol Management, Champaign, IL 61820 USA
[3] Univ Illinois, Ctr Informat Syst & Technol Management, Champaign, IL 61820 USA
[4] Univ Illinois, Dept Business Adm, Champaign, IL 61820 USA
[5] Beckman Inst Adv Sci & Technol, Urbana, IL 61801 USA
关键词
access control; case study; electronic medical record; medical record confidentiality; privacy protection; privacy regulations;
D O I
10.4018/jisp.2008070104
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The continued growth of healthcare information systems (HCIS) promises to improve quality of care, lower costs, and streamline the entire healthcare system. But the resulting dependence on electronic medical records (EMRs) has also kindled patient concern about who has access to sensitive medical records. Healthcare organizations are obliged to protect patient records under HIPAA. The purpose of this study is to develop a formal privacy policy to protect the privacy and security of EMRs. This article describes the impact of EMRs and HIPAA on patient privacy in healthcare. It proposes access control and audit log policies to safeguard patient privacy. To illustrate the best practices in the healthcare industry, this article presents the case of the University of Texas M.D. Anderson Cancer Center. The case demonstrates that it is critical for a healthcare organization to have a privacy policy.
引用
收藏
页码:45 / 54
页数:10
相关论文
共 50 条