Network security vulnerabilities and personal privacy issues in healthcare information systems: A case study in a private hospital

Nihan Namoglu, Y. Ülgen
{"title":"Network security vulnerabilities and personal privacy issues in healthcare information systems: A case study in a private hospital","authors":"Nihan Namoglu, Y. Ülgen","doi":"10.3233/978-1-61499-276-9-126","DOIUrl":null,"url":null,"abstract":"Healthcare industry has become widely dependent on information technology and internet; as it moves from paper to electronic records. Despite the benefits of electronic system, good quality may not be totally achieved unless its risks to security are mitigated. Working in collaboration with a 150 bed private hospital in Turkey; this study aims to present a secure healthcare network infrastructure while presenting the security vulnerabilities in the current hospital information systems. The regulation criteria in Turkey and counterparts in USA and EU are compared according to their privacy approach and a list of items for common security controls from different industries is proposed as a best practice. The study shows that the hospital is not compliant with known healthcare standards like HIPAA or ISO 80001. Management's attitude against privacy and security shows that the responsibility is totally to IT and Biomedical Engineering Departments. As hospitals are adopting electronic transactions, consideration must be given to protect public electronic health records in terms of personal privacy aspects. Healthcare industry in Turkey should benefit from best practices in other industries and applications in other countries. This study can lead the pathway for policy makers in healthcare organizations and regulation authorities to implement a more secure environment for every citizen.","PeriodicalId":428610,"journal":{"name":"2014 18th National Biomedical Engineering Meeting","volume":"33 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 18th National Biomedical Engineering Meeting","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.3233/978-1-61499-276-9-126","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Healthcare industry has become widely dependent on information technology and internet; as it moves from paper to electronic records. Despite the benefits of electronic system, good quality may not be totally achieved unless its risks to security are mitigated. Working in collaboration with a 150 bed private hospital in Turkey; this study aims to present a secure healthcare network infrastructure while presenting the security vulnerabilities in the current hospital information systems. The regulation criteria in Turkey and counterparts in USA and EU are compared according to their privacy approach and a list of items for common security controls from different industries is proposed as a best practice. The study shows that the hospital is not compliant with known healthcare standards like HIPAA or ISO 80001. Management's attitude against privacy and security shows that the responsibility is totally to IT and Biomedical Engineering Departments. As hospitals are adopting electronic transactions, consideration must be given to protect public electronic health records in terms of personal privacy aspects. Healthcare industry in Turkey should benefit from best practices in other industries and applications in other countries. This study can lead the pathway for policy makers in healthcare organizations and regulation authorities to implement a more secure environment for every citizen.
医疗保健信息系统中的网络安全漏洞和个人隐私问题:一家私立医院的案例研究
医疗保健行业已广泛依赖信息技术和互联网;从纸质记录到电子记录。尽管电子系统有好处,但除非降低其安全风险,否则可能无法完全实现良好的质量。与土耳其一家拥有150张床位的私立医院合作;本研究旨在提出一个安全的医疗网络基础架构,同时提出目前医院信息系统的安全漏洞。根据各自的隐私方法,对土耳其和美国、欧盟的监管标准进行了比较,并提出了来自不同行业的通用安全控制项目列表,作为最佳实践。研究表明,该医院不符合HIPAA或ISO 80001等已知的医疗保健标准。管理层对隐私和安全的态度表明,责任完全在IT和生物医学工程部门。随着医院采用电子交易,必须考虑在个人私隐方面保护公共电子健康纪录。土耳其的医疗保健行业应受益于其他国家其他行业和应用的最佳实践。这项研究可以为医疗保健组织和监管机构的政策制定者提供途径,为每个公民实现更安全的环境。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信