login

A baseline security policy for distributed healthcare information systems

Computers & SecurityPublished 1 January 1997
Dimitris Gritzalis
Citations36
SJR quartileQ1
SJR score1.45
SNIP2.27

TL;DR

The need for identifying and analyzing the generic security characteristics of a healthcare information system is demonstrated and the analysis of these characteristics is based upon a decision-support roadmap, leading to the development of a baseline security policy for healthcare institutions.

Abstract

In this paper, the need for identifying and analyzing the generic security characteristics of a healthcare information system is, first, demonstrated. The analysis of these characteristics is based upon a decision-support roadmap. The results from this profiling work are then analyzed in the light of the fact that more than 1000 accidental deaths happened due to computer system failures. As a result of this analysis, a set of recommendations is drawn up, leading to the development of a baseline security policy for healthcare institutions. Such a policy should be flexible enough to reflect the local needs, expectations and user requirements, as well as strict enough to comply with international recommendations. An example of such a baseline policy is then provided. The policy refers to a given security culture and has been based upon an abstract approach to the security needs of a healthcare institution.

Keywords

Health Professions