Development of information security baselines for healthcare information systems in New Zealand

被引:15
作者
Janczewski, L [1 ]
Shi, FXL [1 ]
机构
[1] Univ Auckland, Dept Management Sci & Informat Syst, Sch Business, Auckland 1, New Zealand
关键词
healthcare information systems; electronic medical records; information privacy; information security baselines; security model;
D O I
10.1016/S0167-4048(02)00212-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In 1996 New Zealand had introduced security standard AS/NZCS 4444 based on the British Standard BS 7799, which has recently been accepted as an international standard ISO 17799. This standard is very often referred to as the 'baseline lane approach' to the issue of managing information security. On the other hand the health information systems (HIS) are undergoing rapid development both in the number of installed systems as in the law and regulations governing HIS developments and deployment. The project was aimed at reviewing the AS/NZCS 4444 standard from the HIS requirements point of view. In this paper, we began with an overview of healthcare information systems (HIS) infrastructure in New Zealand and associated security issues around privacy and confidentiality, followed by a general review of the security baseline approach. We analyzed each clause of the AS/NZS 4444 with the information collected about technical and none technical approaches to protecting HIS, consisting of a series of multi case studies of healthcare organizations that collect, process, store and transmit electronic medical records. Finally, we proposed a new set of information security baselines based on the research to build an information security model for healthcare organizations.
引用
收藏
页码:172 / 192
页数:21
相关论文
共 50 条
[31]   Understanding Nuances of Privacy and Security in the Context of Information Systems [J].
Dincelli, Ersin ;
Goel, Sanjay ;
Warkentin, Merrill .
AMCIS 2017 PROCEEDINGS, 2017,
[32]   Data governance in healthcare information systems: A systematic literature review [J].
Ngesimani, Nomputumo L. ;
Ruhode, Ephias ;
Harpur, Patricia-Ann .
SOUTH AFRICAN JOURNAL OF INFORMATION MANAGEMENT, 2022, 24 (01)
[33]   The Role of Information Systems in Healthcare: Current Research and Future Trends [J].
Fichman, Robert G. ;
Kohli, Rajiv ;
Krishnan, Ranjani .
INFORMATION SYSTEMS RESEARCH, 2011, 22 (03) :419-428
[34]   Architecturing large integrated complex information systems: an application to healthcare [J].
Pascot, Daniel ;
Bouslama, Faouzi ;
Mellouli, Sehl .
KNOWLEDGE AND INFORMATION SYSTEMS, 2011, 27 (01) :115-140
[35]   Database External Level Architecture for Use in Healthcare Information Systems [J].
Olah, P. ;
Dobru, D. ;
Ciupa, R. V. ;
Marusteri, M. ;
Bacarea, V. ;
Muji, M. .
INTERNATIONAL CONFERENCE ON ADVANCEMENTS OF MEDICINE AND HEALTH CARE THROUGH TECHNOLOGY, 2011, 36 :36-+
[36]   ARTEMIS: Towards a Secure Interoperability Infrastructure for Healthcare Information Systems [J].
Boniface, Mike ;
Wilken, Paul .
FROM GRID TO HEALTHGRID, 2005, 112 :181-189
[37]   From legacy and client/server systems to components in healthcare information systems in Finland [J].
Mykkänen, J ;
Korpela, M ;
Eerola, A ;
Porrasraaa, J ;
Ruonamaa, H ;
Sormunen, M .
MEDINFO 2001: PROCEEDINGS OF THE 10TH WORLD CONGRESS ON MEDICAL INFORMATICS, PTS 1 AND 2, 2001, 84 :745-749
[38]   Security Management in Health Care Information Systems A literature review [J].
Smaradottir, Berglind Fjola .
PROCEEDINGS 2017 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE (CSCI), 2017, :1742-1746
[39]   Improving the Security in Healthcare Information System Through Elman Neural Network Based Classifier [J].
Al-Dhafian, Buthina ;
Ahmad, Iftikhar ;
Hussain, Muhammad ;
Fazal-e-Amin ;
Imran, Muhammad .
JOURNAL OF MEDICAL IMAGING AND HEALTH INFORMATICS, 2017, 7 (06) :1429-1435
[40]   The Sri Lankan enigma: demystifying public healthcare information systems acceptance [J].
Senthilrajah, Thiviyan ;
Ahangama, Supunmali .
BMC HEALTH SERVICES RESEARCH, 2025, 25 (01)