Development of information security baselines for healthcare information systems in New Zealand

被引:15
作者
Janczewski, L [1 ]
Shi, FXL [1 ]
机构
[1] Univ Auckland, Dept Management Sci & Informat Syst, Sch Business, Auckland 1, New Zealand
关键词
healthcare information systems; electronic medical records; information privacy; information security baselines; security model;
D O I
10.1016/S0167-4048(02)00212-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In 1996 New Zealand had introduced security standard AS/NZCS 4444 based on the British Standard BS 7799, which has recently been accepted as an international standard ISO 17799. This standard is very often referred to as the 'baseline lane approach' to the issue of managing information security. On the other hand the health information systems (HIS) are undergoing rapid development both in the number of installed systems as in the law and regulations governing HIS developments and deployment. The project was aimed at reviewing the AS/NZCS 4444 standard from the HIS requirements point of view. In this paper, we began with an overview of healthcare information systems (HIS) infrastructure in New Zealand and associated security issues around privacy and confidentiality, followed by a general review of the security baseline approach. We analyzed each clause of the AS/NZS 4444 with the information collected about technical and none technical approaches to protecting HIS, consisting of a series of multi case studies of healthcare organizations that collect, process, store and transmit electronic medical records. Finally, we proposed a new set of information security baselines based on the research to build an information security model for healthcare organizations.
引用
收藏
页码:172 / 192
页数:21
相关论文
共 50 条
[41]   Cancer precision medicine today: Towards omic information in healthcare systems [J].
Maggi, Norbert ;
Gazzarata, Roberta ;
Ruggiero, Carmelina ;
Lombardo, Claudio ;
Giacomini, Mauro .
TUMORI JOURNAL, 2019, 105 (01) :38-46
[42]   Healthcare information technology and economics [J].
Payne, Thomas H. ;
Bates, David W. ;
Berner, Eta S. ;
Bernstam, Elmer V. ;
Covvey, H. Dominic ;
Frisse, Mark E. ;
Graf, Thomas ;
Greenes, Robert A. ;
Hoffer, Edward P. ;
Kuperman, Gil ;
Lehmann, Harold P. ;
Liang, Louise ;
Middleton, Blackford ;
Omenn, Gilbert S. ;
Ozbolt, Judy .
JOURNAL OF THE AMERICAN MEDICAL INFORMATICS ASSOCIATION, 2013, 20 (02) :212-217
[43]   Security Model for Sensitive Information Systems and Its Applications in Sensor Networks [J].
Lu, Tianbo ;
Guo, Xiaobo ;
Zhao, Lingling ;
Li, Yang ;
Lin, Peng ;
Fang, Binxing .
INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (05) :1-17
[44]   The security model to combine the corporate and information security [J].
Virtanen, T .
TRUSTED INFORMATION: THE NEW DECADE CHALLENGE, 2001, 65 :305-316
[46]   Value of Information Sharing in Using Healthcare Information Technology: A Systematic Review [J].
Gnanlet, Adelina ;
Choi, Min .
JOURNAL OF HEALTHCARE MANAGEMENT, 2025, 70 (02) :108-125
[47]   Success Factors in the Implementation of Healthcare Information Systems (HIS) among Developing Countries [J].
Rahman, Shafiqur ;
Islam, Aminul .
BANGLADESH JOURNAL OF MEDICAL SCIENCE, 2024, 23 (04) :957-966
[48]   Opportunities and Challenges in Healthcare Information Systems Research: Caring for Patients with Chronic Conditions [J].
Ho, Shuk Ying ;
Guo, Xitong ;
Vogel, Doug .
COMMUNICATIONS OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2019, 44 (01) :852-873
[49]   A Multimethod Approach for Healthcare Information Sharing Systems: Text Analysis and Empirical Data [J].
Malhan, Amit ;
Pavur, Robert ;
Pelton, Lou E. ;
Hajian, Ava .
INFORMATION, 2024, 15 (06)
[50]   Software Engineering Principles Applied to Large Healthcare Information Systems A Case Report [J].
Nardon, Fabiane Bizinella ;
Moura, Lincoln de A., Jr. .
MEDINFO 2007: PROCEEDINGS OF THE 12TH WORLD CONGRESS ON HEALTH (MEDICAL) INFORMATICS, PTS 1 AND 2: BUILDING SUSTAINABLE HEALTH SYSTEMS, 2007, 129 :33-+