EN ISO 27789-2013 en Health informatics - Audit trails for electronic health records《健康信息学 电子健康档案审计跟踪》.pdf
《EN ISO 27789-2013 en Health informatics - Audit trails for electronic health records《健康信息学 电子健康档案审计跟踪》.pdf》由会员分享,可在线阅读,更多相关《EN ISO 27789-2013 en Health informatics - Audit trails for electronic health records《健康信息学 电子健康档案审计跟踪》.pdf(56页珍藏版)》请在麦多课文档分享上搜索。
1、raising standards worldwideNO COPYING WITHOUT BSI PERMISSION EXCEPT AS PERMITTED BY COPYRIGHT LAWBSI Standards PublicationBS EN ISO 27789:2013Health informatics Audittrails for electronic healthrecords (ISO 27789:2013)BS EN ISO 27789:2013 BRITISH STANDARDNational forewordThis British Standard is the
2、 UK implementation of EN ISO27789:2013.The UK participation in its preparation was entrusted to TechnicalCommittee IST/35, Health informatics.A list of organizations represented on this committee can beobtained on request to its secretary.This publication does not purport to include all the necessar
3、yprovisions of a contract. Users are responsible for its correctapplication. The British Standards Institution 2013. Published by BSI StandardsLimited 2013ISBN 978 0 580 57559 4ICS 35.240.80Compliance with a British Standard cannot confer immunity fromlegal obligations.This British Standard was publ
4、ished under the authority of theStandards Policy and Strategy Committee on 30 April 2013.Amendments issued since publicationDate Text affectedEUROPEAN STANDARD NORME EUROPENNE EUROPISCHE NORM EN ISO 27789 March 2013 ICS 35.240.80 English Version Health informatics - Audit trails for electronic healt
5、h records (ISO 27789:2013) Informatique de sant - Historique dexpertise des dossiers de sant informatiss (ISO 27789:2013) Medizinische Informatik - Audit-Trails fr elektronische Gesundheitsakten (ISO 27789:2013) This European Standard was approved by CEN on 16 February 2013. CEN members are bound to
6、 comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for giving this European Standard the status of a national standard without any alteration. Up-to-date lists and bibliographical references concerning such national standards may be obtained on application to the CEN-CE
7、NELEC Management Centre or to any CEN member. This European Standard exists in three official versions (English, French, German). A version in any other language made by translation under the responsibility of a CEN member into its own language and notified to the CEN-CENELEC Management Centre has t
8、he same status as the official versions. CEN members are the national standards bodies of Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, Former Yugoslav Republic of Macedonia, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxem
9、bourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey and United Kingdom. EUROPEAN COMMITTEE FOR STANDARDIZATION COMIT EUROPEN DE NORMALISATION EUROPISCHES KOMITEE FR NORMUNG Management Centre: Avenue Marnix 17, B-1000 Brussels 2013 CEN
10、All rights of exploitation in any form and by any means reserved worldwide for CEN national Members. Ref. No. EN ISO 27789:2013: EBS EN ISO 27789:2013EN ISO 27789:2013 (E) 3 Foreword This document (EN ISO 27789:2013) has been prepared by Technical Committee ISO/TC 215 “Health informatics“ in collabo
11、ration with Technical Committee CEN/TC 251 “Health informatics” the secretariat of which is held by NEN. This European Standard shall be given the status of a national standard, either by publication of an identical text or by endorsement, at the latest by September 2013, and conflicting national st
12、andards shall be withdrawn at the latest by September 2013. Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. CEN and/or CENELEC shall not be held responsible for identifying any or all such patent rights. According to the CEN-CENEL
13、EC Internal Regulations, the national standards organizations of the following countries are bound to implement this European Standard: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, Former Yugoslav Republic of Macedonia, France, Germany, Greece, Hungary, Ice
14、land, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey and the United Kingdom. Endorsement notice The text of ISO 27789:2013 has been approved by CEN as EN ISO 27789:2013 without any modificat
15、ion. BS EN ISO 27789:2013ISO 27789:2013(E) ISO 2013 All rights reserved iiiContents PageForeword ivIntroduction v1 Scope . 12 Normative references 13 Terms and definitions . 14 Symbols and abbreviated terms . 45 Requirements and uses of audit data . 55.1 Ethical and formal requirements 55.2 Uses of
16、audit data 66 Trigger events 76.1 General . 76.2 Details of the event types and their contents . 77 Audit record details . 87.1 The general record format 87.2 Trigger event identification . 97.3 User identification . 117.4 Access point identification . 147.5 Audit source identification 157.6 Partici
17、pant object identification . 178 Audit records for individual events .238.1 Access events . 238.2 Query events 249 Secure management of audit data .269.1 Security considerations 269.2 Securing the availability of the audit system . 279.3 Retention requirements . 279.4 Securing the confidentiality an
18、d integrity of audit trails 279.5 Access to audit data . 27Annex A (informative) Audit scenarios .28Annex B (informative) Audit log services .35Bibliography .44BS EN ISO 27789:2013ISO 27789:2013(E)ForewordISO (the International Organization for Standardization) is a worldwide federation of national
19、standards bodies (ISO member bodies). The work of preparing International Standards is normally carried out through ISO technical committees. Each member body interested in a subject for which a technical committee has been established has the right to be represented on that committee. International
20、 organizations, governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.International Standards are drafted in accordance with the rules gi
21、ven in the ISO/IEC Directives, Part 2.The main task of technical committees is to prepare International Standards. Draft International Standards adopted by the technical committees are circulated to the member bodies for voting. Publication as an International Standard requires approval by at least
22、75 % of the member bodies casting a vote.Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. ISO shall not be held responsible for identifying any or all such patent rights.ISO 27789 was prepared by Technical Committee ISO/TC 215, Hea
23、lth informatics.iv ISO 2013 All rights reservedBS EN ISO 27789:2013ISO 27789:2013(E)Introduction0.1 GeneralPersonal health information is regarded by many as among the most confidential of all types of personal information and protecting its confidentiality is essential if the privacy of subjects of
24、 care is to be maintained. In order to protect the consistency of health information, it is also important that its entire life cycle be fully auditable. Health records should be created, processed and managed in ways that guarantee the integrity and confidentiality of their contents and that suppor
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ENISO277892013ENHEALTHINFORMATICSAUDITTRAILSFORELECTRONICHEALTHRECORDS 健康 信息学 电子 档案 审计 跟踪 PDF

链接地址:http://www.mydoc123.com/p-726945.html