Modifying Without a Trace: General Audit Guidelines are Inadequate for Electronic Health Record Audit Mechanisms
نویسندگان
چکیده
Without adequate audit mechanisms, electronic health record (EHR) systems remain vulnerable to undetected misuse. Users could modify or delete protected health information without these actions being traceable. The objective of this paper is to assess electronic health record audit mechanisms to determine the current degree of auditing for non-repudiation and to assess whether general audit guidelines adequately address nonrepudiation. We derived 16 general auditable event types that affect non-repudiation based upon four publications. We qualitatively assess three open-source EHR systems to determine if the systems log these 16 event types. We find that the systems log an average of 12.5% of these event types. We also generated 58 black-box test cases based on specific auditable events derived from Certification Commission for Health Information Technology criteria. We find that only 4.02% of these tests pass. Additionally, 20% of tests fail in all three EHR systems. As a result, actions including the modification of patient demographics and assignment of user privileges can be executed without a trace of the user performing the action. The ambiguous nature of general auditable events may explain the inadequacy of auditing for non-repudiation. EHR system developers should focus on specific auditable events for managing protected health information instead of general events derived from guidelines.
منابع مشابه
Audit Mechanisms in Electronic Health Record Systems: Protected Health Information May Remain Vulnerable to Undetected Misuse
Inadequate audit mechanisms may result in undetected misuse of data in software-intensive systems. In the healthcare domain, electronic health record (EHR) systems should log the creating, reading, updating, or deleting of privacy-critical protected health information. The objective of this paper is to assess electronic health record audit mechanisms to determine the current degree of auditing ...
متن کاملAn electronic colonoscopy record system enables detailed quality assessment and benchmarking of an endoscopic service.
BACKGROUND Competence in colonoscopy, which is a technically difficult procedure, requires adequate exposure to it and the maintenance of a detailed logbook. Without an electronic record this is difficult to achieve. By implementing an electronic medical record system we aimed to perform a detailed quality assessment audit of colonoscopy, to benchmark our results and generate accurate logbooks ...
متن کاملThe Type of Audit Firms Mergers in Iran: Formal or Real
Although increased mergers of audit firms in the Iranian audit market has attracted the attention of profession, regulatory bodies and researchers, little evidence is available on the motivations, barriers, processes, types, consequences and reasons for failures of audit firm’s mergers. Therefore, the present study is an attempt to open the black box of mergers of audit firms through in-depth i...
متن کاملDrugs for dementia: the first year. An audit of prescribing practice.
In March 1998 the Department of Health and Social Services issued prescribing guidelines for the use of drugs for dementia. A criterion based audit of 202 consecutive cases was undertaken over one year which showed that the prescribing guidelines in general were being followed. A small number of patients, 3, were prescribed the drugs outside the guidelines and most failures, 10, were due to poo...
متن کاملGuidelines for medical audit: seven principles.
The government, general managers, and professional bodies all agree that medical audit should be implemented throughout the United Kingdom. Nevertheless, it is not yet decided either nationally or locally how audit should be defined and what its implications will be. In an analysis to find ways of measuring the design and effectiveness of hospital audit, therefore, seven main measures emerged t...
متن کامل