PoPI Compliance through Access Control of Electronic Health Records

Tamir Tsegaye, Stephen Flowerday
{"title":"PoPI Compliance through Access Control of Electronic Health Records","authors":"Tamir Tsegaye, Stephen Flowerday","doi":"10.1145/3351108.3351130","DOIUrl":null,"url":null,"abstract":"The electronic health record (EHR) has revolutionised the manner in which healthcare is delivered by providing clinicians with electronic access to patients' complete medical history. Countries such as South Africa aim to take advantage of the EHR by implementing a national EHR system. While this has a number of benefits that are in the best interests of the patient, it also creates security and privacy risks to patients' information. Patient information has been identified as the most sensitive type of personal information. Unlike other types of personal information, it contains confidential information about the patient that cannot be changed such as the patient's medical history. Thus, the EHR needs to be protected from both unauthorised entities and misuse by authorised clinicians. This can be achieved through the regulation of the national EHR system. Although regulations state that personal information must be protected, they do not specify what processes must be followed in order to comply with them. This paper proposes a model to address this problem by indicating the components that are needed in order to assist compliance. The proposed model, which was informed by a scoping review and thematic analysis, is discussed in the context of South Africa's future national EHR system with the focus on the Protection of Personal Information (PoPI) Act.","PeriodicalId":269578,"journal":{"name":"Research Conference of the South African Institute of Computer Scientists and Information Technologists","volume":"25 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-09-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Research Conference of the South African Institute of Computer Scientists and Information Technologists","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3351108.3351130","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

The electronic health record (EHR) has revolutionised the manner in which healthcare is delivered by providing clinicians with electronic access to patients' complete medical history. Countries such as South Africa aim to take advantage of the EHR by implementing a national EHR system. While this has a number of benefits that are in the best interests of the patient, it also creates security and privacy risks to patients' information. Patient information has been identified as the most sensitive type of personal information. Unlike other types of personal information, it contains confidential information about the patient that cannot be changed such as the patient's medical history. Thus, the EHR needs to be protected from both unauthorised entities and misuse by authorised clinicians. This can be achieved through the regulation of the national EHR system. Although regulations state that personal information must be protected, they do not specify what processes must be followed in order to comply with them. This paper proposes a model to address this problem by indicating the components that are needed in order to assist compliance. The proposed model, which was informed by a scoping review and thematic analysis, is discussed in the context of South Africa's future national EHR system with the focus on the Protection of Personal Information (PoPI) Act.
通过电子健康记录访问控制实现PoPI合规性
电子健康记录(EHR)通过为临床医生提供对患者完整病史的电子访问,彻底改变了提供医疗保健的方式。南非等国家的目标是通过实施国家电子病历系统来利用电子病历。虽然这对患者来说有很多好处,但它也会给患者的信息带来安全和隐私风险。患者信息被认为是最敏感的个人信息。与其他类型的个人信息不同,它包含了患者的病史等无法更改的机密信息。因此,电子病历需要受到保护,防止未经授权的实体和被授权的临床医生滥用。这可以通过规范国家电子病历系统来实现。虽然法规规定必须保护个人信息,但并没有具体说明必须遵循哪些流程才能遵守这些规定。本文提出了一个模型来解决这个问题,它指出了为了帮助遵从性而需要的组件。通过范围审查和专题分析,本文在南非未来国家电子病历系统的背景下讨论了拟议的模型,重点是《个人信息保护法》。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信