Risk Assessment of Integrated Electronic Health Records

The paper describes the security concerns related to Electronic Health Records (EHR) both in registration of data and integration of systems. A description of the current state of EHR systems in Iceland is provided, along with the Ministry of Health's future vision and plans. New legislation pr...

Full description

Bibliographic Details
Main Authors: Bjornsson, Bjarni Thor, Sigurdardottir, Gudlaug, Stefansson, Stefan Orri
Language:English
Published: 2010
Subjects:
Online Access:http://hdl.handle.net/10822/1025790
http://worldcatlibraries.org/registry/gateway?version=1.0&url_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:journal&atitle=Risk+assessment+of+integrated+electronic+health+records.&title=Studies+in+health+technology+and+informatics+&volume=&issue=&date=2010&au=Bjornsson,+Bjarni+Thor;+Sigurdardottir,+Gudlaug;+Stefansson,+Stefan+Orri
Description
Summary:The paper describes the security concerns related to Electronic Health Records (EHR) both in registration of data and integration of systems. A description of the current state of EHR systems in Iceland is provided, along with the Ministry of Health's future vision and plans. New legislation provides the opportunity for increased integration of EHRs and further collaboration between institutions. Integration of systems, along with greater availability and access to EHR data, requires increased security awareness since additional risks are introduced. The paper describes the core principles of information security as it applies to EHR systems and data. The concepts of confidentiality, integrity, availability, accountability and traceability are introduced and described. The paper discusses the legal requirements and importance of performing risk assessment for EHR data. Risk assessment methodology according to the ISO/IEC 27001 information security standard is described with examples on how it is applied to EHR systems.