Beyond good practice: why HIPAA only addresses part of the data security problem

被引:7
作者
Collmann, J [1 ]
Lambert, D [1 ]
Brummett, M [1 ]
DeFord, D [1 ]
Coleman, J [1 ]
Cooper, T [1 ]
McCall, K [1 ]
Seymour, D [1 ]
Alberts, C [1 ]
Dorofee, A [1 ]
机构
[1] Georgetown Univ, Med Ctr, Dept Radiol, Washington, DC 20057 USA
来源
CARS 2004: COMPUTER ASSISTED RADIOLOGY AND SURGERY, PROCEEDINGS | 2004年 / 1268卷
关键词
HIPAA; security industry good practice; risk assessment; biomedical devices; leadership;
D O I
10.1016/j.ics.2004.03.360
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Beyond Good Practice: Why HIPAA only addresses part of the data security problem presents special papers illustrating the complexities of deploying good data security practices for the protection of computerized information assets in the contemporary healthcare environment. From the perspective of the data security rules, HIPAA implements a broad approach based on standard industry good practice in information assurance. While healthcare organizations find implementing "good industry practice" difficult enough to accomplish, other issues such as the safe patching of security vulnerabilities in the software of biomedical devices, safely sharing information across enterprise boundaries, organizing information security programs in competition with other organizational missions, and managing risk in networked environments loom large and often unnoticed, especially for networks of hospitals seeking to manage information resources as an enterprise. (C) 2004 Published by Elsevier B.V.
引用
收藏
页码:113 / 118
页数:6
相关论文
共 5 条
[1]  
ALBERTS C, 2003, MANAGING INFORMATION
[2]  
[Anonymous], NORMAL ACCIDENTS
[3]  
[Anonymous], 2000, FRIENDLY FIRE ACCIDE
[4]  
Department of Health and Human Services, 1998, FED REG 142, V63, P43241
[5]  
Department of Health and Human Services, 2003, FED REGISTER, V68, P8333