Information Security Management and Regulatory Compliance in the South African Health Sector

نویسندگان

  • Tite Tuyikeze
  • Dalenca Pottas
چکیده

Information security is becoming a part of core business processes in every organization. Companies are faced with contradictory requirements to ensure open systems and accessible information while maintaining high protection standards. In addition, contemporary management of organizations’ information security requires various approaches in different areas, ranging from technology to organizational issues and legislation. These approaches are often isolated while security management requires an integrated approach. Information Technology promises many benefits to healthcare organizations. By helping to make accurate information more readily available to health care providers and workers, researchers and patients, advanced computing and communication technology can improve the quality and lower the cost of health care. However, the prospect of storing health information in an electronic form raises concerns about patient privacy and security. To ensure an appropriate and consistent level of information security for computer-based patient records, both within individual healthcare organizations and throughout the entire healthcare delivery system, healthcare organizations are required to establish formal information security programs, for example through the adoption of the ISO 17799 standard. However, proper information security management practices alone, do not necessarily ensure regulatory compliance. South African health care organizations have to comply with the South African National Health Act (SANHA) and the Electronic Communication Transaction Act (ECTA). It is arguably necessary to consider compliance with the Health Insurance Portability and Accountability Act (HIPAA) in order to meet international industry standards. The main purpose of this paper is to propose a compliance strategy, which ensures full compliance with regulatory requirements while at the same time guarantees customers that international industry standards are being used. This is preceded by a comparative analysis of the requirements posed by the ISO 17799 standard and the HIPAA, SANHA and ECTA regulations.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Towards Regulatory Compliance - A model for the South African Financial Sector

The information age brought along with it, significant advances, challenges and changes, thus resulting in the businesses becoming more complex significant advances such as using the cyber world as a market place, with the aid of new technology. Clearly, the trend of exploiting the cyber market has benefited the financial industry. However, whereas Information Technology is of critical importan...

متن کامل

HIPAA Compliance: An Institutional Theory Perspective

One would think that the enactment of the HIPAA and associated mandates on data security and privacy has brought a major shift in the information security management practices across the US healthcare sector. Unfortunately, recent industry reports indicate substantially low level of regulatory compliance, thus raising security concerns to US health IT infrastructure. This research develops a re...

متن کامل

Information Security Requirements for Implementing Electronic Health Records in Iran

Background and Goal: ICT development in recent years has created excellent developments in human social and economic life. One of the most important opportunities to use information technology is in the medical field, that the result would be electronic health record (EHR).The purpose of this research is to investigate the effects information securi...

متن کامل

Information Security Requirements for Implementing Electronic Health Records in Iran

Background and Goal: ICT development in recent years has created excellent developments in human social and economic life. One of the most important opportunities to use information technology is in the medical field, that the result would be electronic health record (EHR).The purpose of this research is to investigate the effects information securi...

متن کامل

Identifying the Challenges of the Blockchain Technology Maturity Model in Health-Oriented Organizations

Introduction: Blockchain is a widely used technology in the health area; however, it also comes with challenges. By identifying these challenges, the road to blockchain maturity can be made smoother in this field. This study aimed to identify the challenges of the blockchain technology maturity model in health-oriented organizations. Method: In this phenomenological qualitative study, experts i...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2005