استانداردهای امنیت اطلاعات در سیستم اطلاعات بیمارستانهای دانشگاه علوم پزشکی نیشابور

نویسندگان
1 گروه فناوری اطلاعات سلامت، دانشکده بهداشت، دانشگاه علوم پزشکی نیشابور، نیشابور، ایران
2 کمیته تحقیقات دانشجویی، دانشگاه علوم پزشکی نیشابور، نیشابور، ایران
چکیده
مقدمه

با توجه به تنوع خطراتی که اطلاعات را تهدید می‌کنند، تقویت امنیت و محرمانگی داده‌ها و اطلاعات سلامت در سازمان‌های مراقبت بهداشتی با عنایت به گستردگی سیستم‌های اطلاعات بیمارستانی در مراکز درمانی ضروری است، مطالعه حاضر با هدف بررسی امنیت سیستم اطلاعات بیمارستان‌های آموزشی-درمانی دانشکده علوم پزشکی نیشابور بر اساس استانداردهای HIPAA و ISO/IEC27001 انجام شد.

مواد و روش‌ها

پژوهش حاضر از نوع توصیفی-مقطعی بود که در سال 1400 انجام شد. جامعه پژوهش سیستم اطلاعات بیمارستانی بیمارستان‌های حکیم و 22 بهمن دانشکده علوم پزشکی نیشابور بود. ابزار گردآوری در این پژوهش چک لیست محقق ساخته بر مبنای استانداردهای HIPAA و ISO/IEC27001-2005 بود. جمع‌آوری داده‌ها، با مراجعه حضوری محققین به بیمارستان‌های مورد نظر و مشاهده و بررسی اسناد مربوط به استانداردها و پرسش از کارشناسان بخش HIS (در هر بیمارستان 4 نفر) انجام گرفت.

یافته‌ها

یافته‌های مطالعه نشان داد که استانداردهای فنی 100 درصد در بیمارستان 22 بهمن و در بیمارستان حکیم استانداردهای خط مشی امنیت اطلاعات 100 درصد و تشکیلات امنیت اطلاعات 90 درصد بالاترین حد رعایت را داشتند.

نتیجه‌گیری

علی رغم مطلوب بودن، امنیت اطلاعات در بیمارستان‌های مورد مطالعه، از آنجائیکه که روزانه اطلاعات بسیار زیادی در بیمارستان‌ها تبادل می‌شوند، عدم رعایت امنیت در حد نانو می‌تواند زیان‌های جبران‌ناپذیری را متوجه بیمارستان‌ها کند. لذا مدیران بخش‌های مدیریت اطلاعات سلامت و فن‌آوری اطلاعات بیمارستانها باید با شناسایی نقاط آسیب‌پذیر و برنامه‌ریزی مناسب جهت بهبود کاستی‌های امنیت اطلاعات بیمارستان تلاش کنند.
کلیدواژه‌ها

عنوان مقاله English

Information security standards in the information system of hospitals of Neyshabur University of Medical Sciences

نویسندگان English

Hassan Ebrahimpour Sadagheyani 1
Fatemeh Heidarpour 2
1 Department of Health Information Technology, Neyshabur University of Medical Sciences, Neyshabur, Iran
2 Students Research Committee, Neyshabur University of Medical Sciences, Neyshabur, Iran.
چکیده English

Introduction

Given the variety of risks that threaten information, it is necessary to strengthen the security and confidentiality of data and health information in health care organizations, given the breadth of hospital information systems in medical centers. The aim of this study was to investigate the security of the information system of Neyshabur University of Medical Sciences based on HIPAA and ISO / IEC27001 standards.

Method and material

The present study was a descriptive cross-sectional study that was conducted in 2021. The study population was the hospital information system of Hakim and 22 Bahman hospitals of Neyshabur University of Medical Sciences. The collection tool in this study was a researcher-made checklist based on HIPAA and ISO / IEC27001 standards. Data collection was done by visiting the researchers in person and observing and reviewing the documents related to the standards and asking questions from HIS experts (4 people in each hospital).

Results

The findings of the study showed that the technical standards of 100% in Bahman 22 Hospital and in Hakim Hospital had the highest standards of information security policy of 100% and information security organizations of 90%.

Conclusion

Despite the desirability of information security in the hospitals under study, because so much information is exchanged in hospitals on a daily basis, non-compliance with nano-level security can cause irreparable damage to hospitals. Therefore, the managers of health information management and information technology departments of hospitals should try to identify the vulnerabilities and plan to improve the shortcomings of hospital information security.

کلیدواژه‌ها English

Standard
Information Security
Hospital Information System
HIPAA
ISO/IEC27001
1. Sheikhpour R, Modiri NJIJoS, Applications I. An approach to map COBIT processes to ISO/IEC 27001 information security management controls. 2012;6(2):13-28.
2. Kankanhalli A, Teo H-H, Tan BC, Wei K-K. An integrative study of information systems security effectiveness. International journal of information management. 2003;23(2):139-54.
3. Thomson K-L, Von Solms R. Information security obedience: a definition. Computers & Security. 2005;24(1):69-75.
4. Schweizerische S. Information technology-Security techniques-Information security management systems-Requirements. ISO/IEC International Standards Organization. 2013.
5. Safa NS, Von Solms R, Furnell S. Information security policy compliance model in organizations. computers & security. 2016;56:70-82.
6. Crossler RE, Johnston AC, Lowry PB, Hu Q, Warkentin M, Baskerville R. Future directions for behavioral information security research. computers & security. 2013;32:90-101.
7. Susanto12 H, Almunawar MN, Tuan YC. Information security management system standards: A comparative study of the big five. International Journal of Electrical Computer Sciences IJECSIJENS. 2011;11(5):23-9.
8. Colwill C. Human factors in information security: The insider threat–Who can you trust these days? Information security technical report. 2009;14(4):186-96.
9. Ajami S, Ketabi S, Saghaeiannejad S, Heidari A. Requirements and areas associated with readiness assessment of electronic health records implementation. Journal of Health Administration. 2011;14(46).
10. Nasiripour AA, Rahmani H, Radfar R, Najafbeigi R. Effective elements on e-health deployment in Iran. African Journal of Business Management. 2012;6(16):5543-50.
11. Phunchongharn P, Hossain E, Niyato D, Camorlinga S. A cognitive radio system for e-health applications in a hospital environment. IEEE Wireless Communications. 2010;17(1):20-8.
12. SHARIFIAN R, NEMATOLLAHI M, MONEM H, EBRAHIMI F. evaluating the security safeguards in hospital information system according to the health insurance portability and accountability act of university hospitals in Shiraz University of Medical Sciences. 2013.
13. Torabi M, Safdari R. Electronic Medical Record. Tehran, Iran: Behineh Publication. 2004.
14. Sadoughi F, KHOUSH KM, SIAVASH B. A comparative investigation of the access levels and confidentiality of medical document in Iran and selected countries. 2007.
15. Sheikhpour R, Modiri N. An approach to map COBIT processes to ISO/IEC 27001 information security management controls. International Journal of Security and Its Applications. 2012;6(2):13-28.
16. Tofan DC. Information security standards. Journal of Mobile, Embedded and Distributed Systems. 2011;3(3):128-35.
17. Abumasoudi RS, Habibi SK, Ataei M, Esmaeili N. Evaluation of Information Management Systems in Isfahan University of Medical Science by ISO/IEC 27001 Standard. Health Information Management, 2015; 12(3): 306-316. doi: 10.22122/him.v12i3.1897
18. Wager KA, Lee FW, Glaser JP. Managing health care information systems: a practical approach for health care executives: John Wiley & Sons; 2005.
19. Hajavi A, Khoushgam M, HATAMI M. A Comparative Study on regarding Rate of the Privacy Principles in legal Issues by WHO Manual at Teaching Hospitals of Iran, Tehran and Shahid Beheshti Medical Sciences Universities; 2007. 2008.
20. Colwill CJIstr. Human factors in information security: The insider threat–Who can you trust these days? 2009;14(4):186-96.
21. Vela FG, Montes JI, Rodríguez PP, Román MS, Valverde BJJSoCP. An architecture for access control management in collaborative enterprise systems based on organization models. 2007;66(1):44-59.
22. Baskerville RJACS. Information systems security design methods: implications for information systems development. 1993;25(4):375-414.
23. Hendelman-Baavur LJMERoIA. Promises and perils of Weblogistan: Online personal journals and the Islamic Republic of Iran. 2007;11(2):77-93.
24. MEIDANI Z, ASSARI MA, MOSAVI SG, ATAEI AA. Evaluation of hospital information systems security. 2017.
25. Mohammadpour A, Ghaemi MM, Darrudi R, Sadagheyani HE. Use of Hospital Information System to Improve the Quality of Health Care from Clinical Staff Perspective. Galen Medical Journal. 2021;10:e1830-e.