ASTM E2147 Standard Specification for Audit and Disclosure Logs for Use in Health Information Systems
Данный раздел/документ содержится в продуктах:
- Техэксперт: Машиностроительный комплекс
- Картотека зарубежных и международных стандартов
- SNV SN EN ISO 13606-5 Health informatics - Electronic health record communication - Part 5: Interface specification
- ISO 12967-1 Health informatics — Service architecture — Part 1: Enterprise viewpoint - First Edition
- ISO TR 19231 Health informatics - Survey of mHealth projects in low and middle income countries (LMIC) - First Edition
- ISO 12967-1 Health informatics — Service architecture — Part 1: Enterprise viewpoint - First Edition
- 35
- SNV SN EN ISO 13606-5 Health informatics - Electronic health record communication - Part 5: Interface specification
- ISO 12967-1 Health informatics — Service architecture — Part 1: Enterprise viewpoint - First Edition
- ISO TR 19231 Health informatics - Survey of mHealth projects in low and middle income countries (LMIC) - First Edition
- ISO 12967-1 Health informatics — Service architecture — Part 1: Enterprise viewpoint - First Edition
- 35.240
- SNV SN EN ISO 13606-5 Health informatics - Electronic health record communication - Part 5: Interface specification
- ISO 12967-1 Health informatics — Service architecture — Part 1: Enterprise viewpoint - First Edition
- ISO TR 19231 Health informatics - Survey of mHealth projects in low and middle income countries (LMIC) - First Edition
- ISO 12967-1 Health informatics — Service architecture — Part 1: Enterprise viewpoint - First Edition
- 35.240.80
- SNV SN EN ISO 13606-5 Health informatics - Electronic health record communication - Part 5: Interface specification
- ISO 12967-1 Health informatics — Service architecture — Part 1: Enterprise viewpoint - First Edition
- ISO TR 19231 Health informatics - Survey of mHealth projects in low and middle income countries (LMIC) - First Edition
- ISO 12967-1 Health informatics — Service architecture — Part 1: Enterprise viewpoint - First Edition
- SNV SN EN ISO 13606-5 Health informatics - Electronic health record communication - Part 5: Interface specification
- SNV SN EN ISO 13606-5 Health informatics - Electronic health record communication - Part 5: Interface specification
- SNV SN EN ISO 13606-5 Health informatics - Electronic health record communication - Part 5: Interface specification
- ISO 12967-1 Health informatics — Service architecture — Part 1: Enterprise viewpoint - First Edition
- ISO TR 19231 Health informatics - Survey of mHealth projects in low and middle income countries (LMIC) - First Edition
- ISO TR 19231 Health informatics - Survey of mHealth projects in low and middle income countries (LMIC) - First Edition
- ISO TR 14639-2 Health informatics - Capacity-based eHealth architecture roadmap - Part 2: Architectural components and maturity model - First Edition
- ISO HL7 27932 Data Exchange Standards - HL7 Clinical Document Architecture, Release 2 - First Edition
- ASTM E1578 Standard Guide for Laboratory Information Management Systems (LIMS)
- ASTM E2066 Standard Guide for Validation of Laboratory Information Management Systems
- ASTM E2473 Standard Practice for the Occupational/Environmental Health View of the Electronic Health Record
- SNV SN EN ISO 13606-5 Health informatics - Electronic health record communication - Part 5: Interface specification
- Картотека зарубежных и международных стандартов
ASTM International
Standard Specification for Audit and Disclosure Logs for Use in Health Information Systems
N E2147
Annotation
This specification is for the development and implementation of security audit/disclosure logs for health information. It specifies how to design an access audit log to record all access to patient identifiable information maintained in computer systems and includes principles for developing policies, procedures, and functions of health information logs to document all disclosure of health information to external users for use in manual and computer systems. The process of information disclosure and auditing should conform, where relevant, with the Privacy Act of 1974 (1).2
The first purpose of this specification is to define the nature, role, and function of system access audit logs and their use in health information systems as a technical and procedural tool to help provide security oversight. In concert with organizational confidentiality and security policies and procedures, permanent audit logs can clearly identify all system application users who access patient identifiable information, record the nature of the patient information accessed, and maintain a permanent record of actions taken by the user. By providing a precise method for an organization to monitor and review who has accessed patient data, audit logs have the potential for more effective security oversight than traditional paper record environments. This specification will identify functionality needed for audit log management, the data to be recorded, and the use of audit logs as security and management tools by organizational managers.
In the absence of computerized logs, audit log principles can be implemented manually in the paper patient record environment with respect to permanently monitoring paper patient record access. Where the paper patient record and the computer-based patient record coexist in parallel, security oversight and access management should address both environments.



