Breaching the security of the Kaiser Permanente Internet patient portal: the organizational foundations of information security

被引:25
作者
Collmann, Jeff
Cooper, Ted
机构
[1] Georgetown Univ, Med Ctr, Washington, DC 20007 USA
[2] Stanford Univ, Med Ctr, Palo Alto, CA 94304 USA
关键词
D O I
10.1197/jamia.M2195
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This case study describes and analyzes a breach of the confidentiality and integrity of personally identified health information (e.g. appointment details, answers to patients' questions, medical advice) for over 800 Kaiser Permanente (KP) members through KP Online, a web-enabled health care portal. The authors obtained and analyzed multiple types of qualitative data about this incident including interviews with KP staff, incident reports, root cause analyses, and media reports. Reasons at multiple levels account for the breach, including the architecture of the information system, the motivations of individual staff members, and differences among the subcultures of individual groups within as well as technical and social relations across the Kaiser IT program. None of these reasons could be classified, strictly speaking, as "security violations." This case study, thus, suggests that, to protect sensitive patient information, health care organizations should build safe organizational contexts for complex health information systems in addition to complying with good information security practice and regulations such as the Health Insurance Portability and Accountability Act (HIPAA) of 1996.
引用
收藏
页码:239 / 243
页数:5
相关论文
共 20 条
[1]  
[Anonymous], MANAGING UNEXPECTED
[2]  
[Anonymous], 1972, STRATEGY TRANSACTION
[3]  
Argyris C., 1993, ORG LEARNING
[4]  
COLLMANN J, 1988, IM PROPER NUMBER ONE, V2
[5]  
Collmann J.R., 1988, FRINGE DWELLERS WELF
[6]  
GLUCKMAN M, 1958, 28 MANCH U
[7]  
Kapferer Bruce., 1991, A Celebration of Demons: Exorcism and the Aesthetics of Healing in Sri Lanka
[8]  
Mitchell J.Clyde., 1956, KALELA DANCE ASPECTS
[9]  
Perrow C., 1999, NORMAL ACCIDENTS
[10]  
Perrow Charles, 1999, NORMAL ACCIDENTS, P70