透過您的圖書館登入
IP:18.223.135.102
  • 期刊

整合ISO 27001與ISO 27799應用於護理資訊之探討

摘要


依據台灣醫院協會(2012)一項「醫院因應個人資料保護法問卷調查」統計,已完成因應措施之醫療機構,僅占調查總家數之4.73%,其主要原因為對法律了解不足(72.78%)及員工對個資保護意識不足(70.41%)所致。健保局為因應電子化政府的推動,建置健保IC卡及電子病歷交換等技術,並培訓醫院資訊安全種子,提供ISO 27001:2005資訊安全管理國際標準驗證服務,至2013年2月8日全國已有93家通過驗證。本文以ISMS:ISO 27001:2005為基礎,並彙整出ISO 27001管理要項(133項)與為醫療照顧產業的特殊屬性制定的ISO 27799:2008,運用P-D-C-A循環流程及林宜隆教授所提出之PLSE Model四大構面,建立ISMS管理安全措施工作要項於護理資訊。

並列摘要


A survey on "Hospital Response to the Personal Information Protection Act" conducted by Taiwan Hospital Association shows that only 4.73% of the surveyed hospitals have implemented measures to comply with the Act. Those which have not complied with the Act were mainly constrained by unfamiliarity with the law (72.78%) and lack of awareness of personal information protection among employees (70.41%). In line with the government's promotion of e-government services, Bureau of National Health Insurance has implemented numerous measures, including use of Health Insurance IC Card, electronic medical history exchange, training of seed hospital specialists in charge of information security, and certification of ISO 27001:2005. As of Feb 8, 2013, 93 hospitals islandwide have passed the certification. Based on ISMS:ISO 27001:2005, this study first obtained key criteria in ISO 27001 (133 items in total) and ISO 27799:2008 established to specifically regulate health informatics. this study applie d P-D-C-A cycle and PLSE Model introduced by Dr. I-Long Lin to build key tasks of personal information protection for nursing institutions.

參考文獻


中央健康保險局(2012)。中央健康保險局醫療資料實體加密簡介。政府機關資訊通報。301
台灣醫院協會,2012 ,『醫院因應「個人資料保護法」問卷調查分析報告』,http://www.hatw.org.tw/mode 03_ 02.asp?num= 20120820103922
吳仁和、陳翰容、沈德村、洪誌隆、林麗敏(2013)。醫療資訊管理。台北市:智勝文化公司。
林宜隆、邱士娟、呂明達()。
法務部,2011,醫療法,法務部全國法規資料庫工作小組,全國法規資料庫,擷取自http://law.moj.gov.tw/LawClass/LawAll.aspx?PCode=L0020021

延伸閱讀