|
As far
as I know there are not yet any set "Security
Standards"
There
is no open sharing of patient records. What most Hosptials have is a
closed DB system such as HBOCs products (can't remember the name off of the top
of my head). These are essentially "close circuit" databases,
and are self-contained w/i the hospital. They are all proprietary systems
as well.
There
are several bills in Congress relating to Medical information and
privacy.
Some
of them are outdated and/or never passed, and/or are just sitting there - I
recommend going to the appropriate Senate of House site where they have bill
status listed:
Anyway, some to look for are:
hr-1057
hr-1941
hr-2404
hr-2878
hr-358
s-1344
s-240
s-573
s-578
s-6
s-854
You
should be albe to tell within the first page or two if this information is
relevant. It also lists the commitee memebers involved I believe, so if
there is something that you see as drastically wrong, you can get in touch with
the right person.
NONE
of these (I've read or looked over most of them) have SPECIFIC security
information. It's more like guidelines like "Only caregivers with
authentication from the patient will be allowed to view patient record
information, and the subject of the record has to approve any additions"
etc. It describes who should access what, but not HOW this will
happen. Still, it gives you a basic view of what's down the pike and what
the gov't is up to as far as their understanding of who should access
what. Personally from reading these I think that some of them are a little
too restrictive for the doctor, and give the patient TOO MUCH access to
alteration of medical records, etc. w/o adequate accountability of record
alterations mandated ("Oh yeah, I swear that my doctor gave me demerol for
my ingrown toenail - just look at my records!").
99% of
the stuff that I have seen state that security should be in place, but do not
discuss anything more than 'it should be there'. I will certainly go over
the 3Com doc.
Hope
this helps,
Alex
F
|
- Hospital INFOSEC? Jeffery Stutzman
- Re: Hospital INFOSEC? Paulosterwald
- RE: Hospital INFOSEC? Chinnery Paul
- RE: Hospital INFOSEC? Chinnery Paul
- Re: Hospital INFOSEC? Barbara Chalef
- RE: Hospital INFOSEC? Filacchione, Alex (ISSAtlanta)
- RE: Hospital INFOSEC? Neeper, Ralph
- RE: Hospital INFOSEC? Daniel Myers
