High level security policies for health: from theory to practice

Stud Health Technol Inform. 2004:103:416-23.

Abstract

The design and implementation of a security policy for a healthcare organisation is by no means trivial but it is, at least, feasible, taking into account the wide range of information security and privacy enhancing technologies that are currently available. Considering, however, a shared care environment with the participation of many independent healthcare organisations and the requirement for exchanging electronic healthcare records, the situation becomes much more complex since the implementation of global security policy may turn out to be an over ambitious task. This paper aims to highlight the main sources of complexity and to provide pointers for managing or/and resolving them.

MeSH terms

  • Access to Information
  • Computer Communication Networks / organization & administration
  • Computer Communication Networks / standards
  • Computer Security / standards*
  • Confidentiality / standards
  • Humans
  • Information Systems / organization & administration
  • Information Systems / standards
  • Medical Record Linkage / standards
  • Medical Records Systems, Computerized / organization & administration*
  • Medical Records Systems, Computerized / standards
  • beta-Thalassemia / therapy