ASTM E1986 - 09(2013) Standard Guide for Information Access Privileges to Health Information (Withdrawn 2017).pdf
《ASTM E1986 - 09(2013) Standard Guide for Information Access Privileges to Health Information (Withdrawn 2017).pdf》由会员分享,可在线阅读,更多相关《ASTM E1986 - 09(2013) Standard Guide for Information Access Privileges to Health Information (Withdrawn 2017).pdf(13页珍藏版)》请在麦多课文档分享上搜索。
1、Designation: E1986 09 (Reapproved 2013) An American National StandardStandard Guide forInformation Access Privileges to Health Information1This standard is issued under the fixed designation E1986; the number immediately following the designation indicates the year oforiginal adoption or, in the cas
2、e of revision, the year of last revision. A number in parentheses indicates the year of last reapproval. Asuperscript epsilon () indicates an editorial change since the last revision or reapproval.1. Scope*1.1 This guide covers the process of granting and maintain-ing access privileges to health inf
3、ormation. It directly ad-dresses the maintenance of confidentiality of personal,provider, and organizational data in the healthcare domain. Itaddresses a wide range of data and data elements not alltraditionally defined as healthcare data, but all elemental in theprovision of data management, data s
4、ervices, and administra-tive and clinical healthcare services. In addition, this guideaddresses specific requirements for granting access privilegesto patient-specific health information during health emergen-cies.1.2 This guide is based on long-term existing and estab-lished professional practices
5、in the management of healthcareadministrative and clinical data. Healthcare data, and specifi-cally healthcare records (also referred to as medical records orpatient records), are generally managed under similar profes-sional practices throughout the United States, essentially re-gardless of specifi
6、c variations in local, regional, state, andfederal laws regarding rules and requirements for data andrecord management.1.3 This guide applies to all individuals, groups,organizations, data-users, data-managers, and public and pri-vate firms, companies, agencies, departments, bureaus, service-provide
7、rs, and similar entities that collect individual, group,and organizational data related to health care.1.4 This guide applies to all collection, use, management,maintenance, disclosure, and access of all individual, group,and organizational data related to health care.1.5 This guide does not attempt
8、 to address specific legisla-tive and regulatory issues regarding individual, group, andorganizational rights to protection of privacy.1.6 This guide covers all methods of collection and use ofdata whether paper-based, written, printed, typed, dictated,transcribed, forms-based, photocopied, scanned,
9、 facsimile,telefax, magnetic media, image, video, motion picture, stillpicture, film, microfilm, animation, 3D, audio, digital media,optical media, synthetic media, or computer-based.1.7 This guide does not directly define explicit disease-specific and evaluation/treatment-specific data control orac
10、cess, or both. As defined under this guide, the confidentialprotection of elemental data elements in relation to which dataelements fall into restrictive or specifically controlledcategories, or both, is set by policies, professional practice, andlaws, legislation and regulations.2. Referenced Docum
11、ents2.1 ASTM Standards:2E1869 Guide for Confidentiality, Privacy, Access, and DataSecurity Principles for Health Information Including Elec-tronic Health RecordsE2595 Guide for Privilege Management Infrastructure3. Terminology3.1 Definitions:3.1.1 accessthe provision of an opportunity to approach,in
12、spect, review, retrieve, store, communicate with, or make useof health information system resources (for example, hardware,software, systems, or structure) or patient identifiable data andinformation, or both. (E1869)3.1.2 access controlthe prevention of unauthorized use ofa resource, including the
13、prevention of use of a resource in anunauthorized manner.3.1.2.1 DiscussionAccess control counters the threat ofunauthorized access to, disclosure of, or modification of data.(ISO 7498-2)3.1.3 accountabilitythe property that ensures that theactions of an entity can be traced. (ISO 7498-2)3.1.4 audit
14、 traildata collected and potentially used tofacilitate a security audit. (ISO 7498-2)3.1.5 authenticationthe corroboration that an entity is theone claimed. (ISO 7498-2)1This guide is under the jurisdiction of ASTM Committee E31 on HealthcareInformatics and is the direct responsibility of Subcommitt
15、ee E31.25 on HealthcareData Management, Security, Confidentiality, and Privacy.Current edition approved March 1, 2013. Published March 2013. Originallyapproved in 1998. Last previous edition approved in 2009 as E1986 09. DOI:10.1520/E1986-09R13.2For referenced ASTM standards, visit the ASTM website,
16、 www.astm.org, orcontact ASTM Customer Service at serviceastm.org. For Annual Book of ASTMStandards volume information, refer to the standards Document Summary page onthe ASTM website.*A Summary of Changes section appears at the end of this standardCopyright ASTM International, 100 Barr Harbor Drive
17、, PO Box C700, West Conshohocken, PA 19428-2959. United StatesNOTICE: This standard has either been superseded and replaced by a new version or withdrawn.Contact ASTM International (www.astm.org) for the latest information13.1.6 authorizethe granting to a user the right of access tospecified data an
18、d information, a program, a terminal, or aprocess. (E1869)3.1.7 authorization(1) The granting of rights, which in-cludes the granting of access based on access rights. (2) Themechanism for obtaining consent for the use and disclosure ofhealth information. (ISO 7498-2, CPRI, AHIMA)3.1.8 confidentials
19、tatus accorded to data or informationindicating that it is sensitive for some reason and needs to beprotected against theft, disclosure, or improper use, or both,and must be disseminated only to authorized individuals ororganizations with an approved need to know. Private infor-mation which is entru
20、sted to another with the confidence thatunauthorized disclosure that will be prejudicial to the indi-vidual will not occur. (E1869)3.1.9 confidentialitythe property that information is notmade available or disclosed to unauthorized individuals,entities, or processes. (ISO 7498-2)3.1.10 databasea col
21、lection of data organized for rapidsearch and retrieval. (Websters, 1993)3.1.11 data elementthe combination of one or more dataentities that forms a unit or piece of information, such as thesocial security number, a diagnosis, an address, or a medica-tion.3.1.12 data entitya discrete form of data su
22、ch as a numberor word.3.1.13 disclosure (health care)the release of informationto third parties within or outside the healthcare providerorganization from an individuals record with or without theconsent of the individual to whom the record pertains.3.1.13.1 DiscussionUnder this guide the definition
23、 isslightly modified to read: the release of information to anindividual, group or organization from an individuals healthinformation with or without the authorization of the individualto whom the health information pertains. (CPRI)3.1.14 emergencya sudden demand for action. Conditionthat poses an i
24、mmediate threat to the health of the patient.3.1.15 healthcare datadata which are input, stored, pro-cessed or output by the automated information system whichsupport the business functions of the healthcare establishment.These data may relate to person identifiable records or may bepart of an admin
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
5000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ASTM E1986 09 2013 Standard Guide for Information Access Privileges to Health Withdrawn 2017

链接地址:http://www.mydoc123.com/p-287061.html