HIPAA涵盖的实体中的哪些信息位置必须首先得到保护?一种多标准决策方法。

Amir Fard Bahreini PhD, MBA, MSc, CIPP/US
{"title":"HIPAA涵盖的实体中的哪些信息位置必须首先得到保护?一种多标准决策方法。","authors":"Amir Fard Bahreini PhD, MBA, MSc, CIPP/US","doi":"10.1002/jhrm.21555","DOIUrl":null,"url":null,"abstract":"<p>Creating adequate safeguards for physical and online locations (e.g., desktop computers, network servers) where protected health information (PHI) may be breached is critical for management within entities compliant with the Health Information Portability and Accountability Act (HIPAA). With the increasing complexity of cyber breaches and budgetary issues, prioritizing which locations require the most immediate attention by top management through a data-driven model is more important than ever. Using CORAS threat modeling and five methods for multi-criteria decision-making, these locations were ranked from greatest to least risk of data breaches. Statistical methods were subsequently used for consistency and robustness checks. The findings illustrate that each type of covered entity under HIPAA must prioritize a different set of locations to safeguard first: health care providers must focus on the security of network servers, other portable electronic devices, and category of others (i.e., miscellaneous locations); health plans must focus on the security of paper and films, network servers, and others; and business associates must focus on the security of category of others, network servers, and other portable electronic devices. Combined with data on the source of the breaches (external vs. internal) and type of threats (e.g., hacking, theft), these findings provide recommendations for risk identification for privacy officers across health care.</p>","PeriodicalId":39819,"journal":{"name":"Journal of healthcare risk management : the journal of the American Society for Healthcare Risk Management","volume":"43 2","pages":"27-36"},"PeriodicalIF":0.0000,"publicationDate":"2023-08-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1002/jhrm.21555","citationCount":"0","resultStr":"{\"title\":\"Which information locations in covered entities under HIPAA must be secured first? A multi-criteria decision-making approach\",\"authors\":\"Amir Fard Bahreini PhD, MBA, MSc, CIPP/US\",\"doi\":\"10.1002/jhrm.21555\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p>Creating adequate safeguards for physical and online locations (e.g., desktop computers, network servers) where protected health information (PHI) may be breached is critical for management within entities compliant with the Health Information Portability and Accountability Act (HIPAA). With the increasing complexity of cyber breaches and budgetary issues, prioritizing which locations require the most immediate attention by top management through a data-driven model is more important than ever. Using CORAS threat modeling and five methods for multi-criteria decision-making, these locations were ranked from greatest to least risk of data breaches. Statistical methods were subsequently used for consistency and robustness checks. The findings illustrate that each type of covered entity under HIPAA must prioritize a different set of locations to safeguard first: health care providers must focus on the security of network servers, other portable electronic devices, and category of others (i.e., miscellaneous locations); health plans must focus on the security of paper and films, network servers, and others; and business associates must focus on the security of category of others, network servers, and other portable electronic devices. Combined with data on the source of the breaches (external vs. internal) and type of threats (e.g., hacking, theft), these findings provide recommendations for risk identification for privacy officers across health care.</p>\",\"PeriodicalId\":39819,\"journal\":{\"name\":\"Journal of healthcare risk management : the journal of the American Society for Healthcare Risk Management\",\"volume\":\"43 2\",\"pages\":\"27-36\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-08-24\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://onlinelibrary.wiley.com/doi/epdf/10.1002/jhrm.21555\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of healthcare risk management : the journal of the American Society for Healthcare Risk Management\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://onlinelibrary.wiley.com/doi/10.1002/jhrm.21555\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"Medicine\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of healthcare risk management : the journal of the American Society for Healthcare Risk Management","FirstCategoryId":"1085","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1002/jhrm.21555","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"Medicine","Score":null,"Total":0}
引用次数: 0

摘要

为受保护的健康信息(PHI)可能被破坏的物理和在线位置(如台式计算机、网络服务器)创建足够的保护措施,对于符合《健康信息可携带性和责任法案》(HIPAA)的实体内的管理至关重要。随着网络入侵和预算问题的日益复杂,通过数据驱动的模型来确定哪些地点最需要高层管理人员立即关注,这比以往任何时候都更加重要。使用CORAS威胁建模和五种多标准决策方法,从数据泄露风险最大到最小对这些地点进行了排名。随后使用统计方法进行一致性和稳健性检查。研究结果表明,HIPAA下的每种类型的受保实体都必须优先考虑一组不同的地点,以首先进行保护:医疗保健提供者必须关注网络服务器、其他便携式电子设备和其他类别(即杂项地点)的安全;健康计划必须关注纸张和电影、网络服务器等的安全;和业务伙伴必须关注他人类别、网络服务器和其他便携式电子设备的安全。结合有关违规来源(外部与内部)和威胁类型(如黑客攻击、盗窃)的数据,这些发现为医疗保健领域的隐私官员提供了风险识别建议。
本文章由计算机程序翻译,如有差异,请以英文原文为准。

摘要图片

查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Which information locations in covered entities under HIPAA must be secured first? A multi-criteria decision-making approach

Creating adequate safeguards for physical and online locations (e.g., desktop computers, network servers) where protected health information (PHI) may be breached is critical for management within entities compliant with the Health Information Portability and Accountability Act (HIPAA). With the increasing complexity of cyber breaches and budgetary issues, prioritizing which locations require the most immediate attention by top management through a data-driven model is more important than ever. Using CORAS threat modeling and five methods for multi-criteria decision-making, these locations were ranked from greatest to least risk of data breaches. Statistical methods were subsequently used for consistency and robustness checks. The findings illustrate that each type of covered entity under HIPAA must prioritize a different set of locations to safeguard first: health care providers must focus on the security of network servers, other portable electronic devices, and category of others (i.e., miscellaneous locations); health plans must focus on the security of paper and films, network servers, and others; and business associates must focus on the security of category of others, network servers, and other portable electronic devices. Combined with data on the source of the breaches (external vs. internal) and type of threats (e.g., hacking, theft), these findings provide recommendations for risk identification for privacy officers across health care.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
1.30
自引率
0.00%
发文量
44
期刊介绍: The Journal of Healthcare Risk Management is published quarterly by the American Society for Healthcare Risk Management (ASHRM). The purpose of the journal is to publish research, trends, and new developments in the field of healthcare risk management with the ultimate goal of advancing safe and trusted patient-centered healthcare delivery and promoting proactive and innovative management of organization-wide risk. The journal focuses on insightful, peer-reviewed content that relates to patient safety, emergency preparedness, insurance, legal, leadership, and other timely healthcare risk management issues.
期刊最新文献
Haddon matrix model: Application to workplace violence in a hospital setting. Case law update. Creation of root cause analysis and action (RCA2) standard work by a multidisciplinary team to prevent harm, reduce bias, and improve safety culture. Streamlining incident reporting system: A lean approach to enhance patient and staff safety in a Middle Eastern prehospital emergency care setting. Humbled and honored.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1