Development of information security baselines for healthcare information systems in New Zealand

被引:14
|
作者
Janczewski, L [1 ]
Shi, FXL [1 ]
机构
[1] Univ Auckland, Dept Management Sci & Informat Syst, Sch Business, Auckland 1, New Zealand
关键词
healthcare information systems; electronic medical records; information privacy; information security baselines; security model;
D O I
10.1016/S0167-4048(02)00212-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In 1996 New Zealand had introduced security standard AS/NZCS 4444 based on the British Standard BS 7799, which has recently been accepted as an international standard ISO 17799. This standard is very often referred to as the 'baseline lane approach' to the issue of managing information security. On the other hand the health information systems (HIS) are undergoing rapid development both in the number of installed systems as in the law and regulations governing HIS developments and deployment. The project was aimed at reviewing the AS/NZCS 4444 standard from the HIS requirements point of view. In this paper, we began with an overview of healthcare information systems (HIS) infrastructure in New Zealand and associated security issues around privacy and confidentiality, followed by a general review of the security baseline approach. We analyzed each clause of the AS/NZS 4444 with the information collected about technical and none technical approaches to protecting HIS, consisting of a series of multi case studies of healthcare organizations that collect, process, store and transmit electronic medical records. Finally, we proposed a new set of information security baselines based on the research to build an information security model for healthcare organizations.
引用
收藏
页码:172 / 192
页数:21
相关论文
共 50 条
  • [1] Security policy development for healthcare information systems
    Gritzalis, D
    Kokolakis, S
    ADVANCED HEALTH TELEMATICS AND TELEMEDICINE: THE MAGDEBURG EXPERT SUMMIT TEXTBOOK, 2003, 96 : 105 - 110
  • [2] Security in healthcare information systems
    Omogbadegun, Z. O.
    Information Processing in the Service of Mankind and Health, 2006, : 185 - 206
  • [3] Experiences with a new security standard for Healthcare Information Systems
    Louwerse, K
    van Ditmarsch, M
    Flikkenschild, E
    MEDICAL INFORMATICS EUROPE '99, 1999, 68 : 311 - 314
  • [4] An overview in healthcare information systems security
    Bourka, A
    Polemi, N
    Koutsouris, D
    MEDINFO 2001: PROCEEDINGS OF THE 10TH WORLD CONGRESS ON MEDICAL INFORMATICS, PTS 1 AND 2, 2001, 84 : 1242 - 1246
  • [5] The Enhancement of Security in Healthcare Information Systems
    Chia-Hui Liu
    Yu-Fang Chung
    Tzer-Shyong Chen
    Sheng-De Wang
    Journal of Medical Systems, 2012, 36 : 1673 - 1688
  • [6] The Enhancement of Security in Healthcare Information Systems
    Liu, Chia-Hui
    Chung, Yu-Fang
    Chen, Tzer-Shyong
    Wang, Sheng-De
    JOURNAL OF MEDICAL SYSTEMS, 2012, 36 (03) : 1673 - 1688
  • [7] Information Security Management Systems in the Healthcare Context
    Tyali, S.
    Pottas, D.
    PROCEEDINGS OF THE SOUTH AFRICAN INFORMATION SECURITY MULTI-CONFERENCE, 2010, : 177 - 187
  • [8] Security threats categories in healthcare information systems
    Samy, Ganthan Narayana
    Ahmad, Rabiah
    Ismail, Zuraini
    HEALTH INFORMATICS JOURNAL, 2010, 16 (03) : 201 - 209
  • [9] Development of an information security standard for healthcare organizations
    Kim, Dongsoo
    Kim, Minsoo
    Proceedings of the Sixth International Conference on Information and Management Sciences, 2007, 6 : 356 - 360
  • [10] Security aspects in healthcare information systems: A systematic mapping
    Fatima, Aqsa
    Colomo-Palacios, Ricardo
    CENTERIS 2018 - INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS / PROJMAN 2018 - INTERNATIONAL CONFERENCE ON PROJECT MANAGEMENT / HCIST 2018 - INTERNATIONAL CONFERENCE ON HEALTH AND SOCIAL CARE INFORMATION SYSTEMS AND TECHNOLOGIES, CENTERI, 2018, 138 : 12 - 19