NEMA HN 1-2013 Manufacturer Disclosure Statement for Medical Device Security.pdf
《NEMA HN 1-2013 Manufacturer Disclosure Statement for Medical Device Security.pdf》由会员分享,可在线阅读,更多相关《NEMA HN 1-2013 Manufacturer Disclosure Statement for Medical Device Security.pdf(33页珍藏版)》请在麦多课文档分享上搜索。
1、 HIMSS/NEMA HN 1-2013 Manufacturer Disclosure Statement for Medical Device Security HIMSS/NEMA Standard HN 1-2013 Manufacturer Disclosure Statement for Medical Device Security Published by National Electrical Manufacturers Association 1300 North 17th Street, Suite 900 Rosslyn, Virginia 22209 www.nem
2、a.org Copyright 2013 by the National Electrical Manufacturers Association and the Healthcare Information and Management Systems Society. All rights including translation into other languages, reserved under the Universal Copyright Convention, the Berne Convention for the Protection of Literary and A
3、rtistic Works, and the International and Pan American Copyright Conventions. Copyright 2013 by the National Electrical Manufacturers Association and the Healthcare Information and Management Systems Society. NOTICE AND DISCLAIMER The information in this publication was considered technically sound b
4、y the consensus of persons engaged in the development and approval of the document at the time it was developed. Consensus does not necessarily mean that there is unanimous agreement among every person participating in the development of this document. The National Electrical Manufacturers Associati
5、on (NEMA) standards and guideline publications, of which the document contained herein is one, are developed through a voluntary consensus standards development process. This process brings together volunteers and/or seeks out the views of persons who have an interest in the topic covered by this pu
6、blication. While NEMA administers the process and establishes rules to promote fairness in the development of consensus, it does not write the document and it does not independently test, evaluate, or verify the accuracy or completeness of any information or the soundness of any judgments contained
7、in its standards and guideline publications. NEMA disclaims liability for any personal injury, property, or other damages of any nature whatsoever, whether special, indirect, consequential, or compensatory, directly or indirectly resulting from the publication, use of, application, or reliance on th
8、is document. NEMA disclaims and makes no guaranty or warranty, expressed or implied, as to the accuracy or completeness of any information published herein, and disclaims and makes no warranty that the information in this document will fulfill any of your particular purposes or needs. NEMA does not
9、undertake to guarantee the performance of any individual manufacturer or sellers products or services by virtue of this standard or guide. In publishing and making this document available, NEMA is not undertaking to render professional or other services for or on behalf of any person or entity, nor
10、is NEMA undertaking to perform any duty owed by any person or entity to someone else. Anyone using this document should rely on his or her own independent judgment or, as appropriate, seek the advice of a competent professional in determining the exercise of reasonable care in any given circumstance
11、s. Information and other standards on the topic covered by this publication may be available from other sources, which the user may wish to consult for additional views or information not covered by this publication. NEITHER THE HEALTHCARE INFORMATION AND MANAGEMENT SYSTEMS SOCIETY (HIMSS) NOR NEMA
12、HAVE POWER, NOR DO THEY UNDERTAKE TO POLICE OR ENFORCE COMPLIANCE WITH THE CONTENTS OF THIS DOCUMENT. NEITHER HIMSS NOR NEMA CERTIFY, TEST, OR INSPECT PRODUCTS, DESIGNS, OR INSTALLATIONS FOR SAFETY OR HEALTH PURPOSES. ANY CERTIFICATION OR OTHER STATEMENT OF COMPLIANCE WITH ANY HEALTH OR SAFETY RELAT
13、ED INFORMATION IN THIS DOCUMENT SHALL NOT BE ATTRIBUTABLE TO HIMSS OR NEMA AND IS SOLELY THE RESPONSIBILITY OF THE CERTIFIER OR MAKER OF THE STATEMENT. HN 1-2013 Page i Copyright 2013 by the National Electrical Manufacturers Association and the Healthcare Information and Management Systems Society.
14、CONTENTS FOREWORD . ii CHANGES FROM PREVIOUS (2008) MDS2 REVISION . iv Section 1 GENERAL 1 1.1 SCOPE.1 1.1.1 The Role of Healthcare Providers in the Security Management Process 1 1.1.2 The Role of Medical Device Manufacturers in the Security Management Process .1 1.2 REFERENCES 1 1.3 DEFINITIONS 2 1
15、.4 ACRONYMS4 Section 2 INSTRUCTIONS FOR OBTAINING, USING, AND COMPLETING MDS2 FORM .5 2.1 OBTAINING THE MDS2 FORM (PROVIDERS) .5 2.2 USING THE MDS2 FORM (PROVIDERS) 5 2.2.1 Device Description 5 2.2.2 Explanatory notes .5 2.2.3 Security Capabilities 5 2.3 COMPLETING THE MDS2 FORM (MANUFACTURERS)5 2.3
16、.1 General .5 2.3.2 MDS2 Form Completion Guidance .5 Section 3 MDS2 FORM . 15 Annex COMPARISON OF PREVIOUS (2008) AND CURRENT (2013) MDS2 (Informative) 23 HN 1-2013 Page ii Copyright 2013 by the National Electrical Manufacturers Association and the Healthcare Information and Management Systems Socie
17、ty. FOREWORD This document consists of the Manufacturer Disclosure Statement for Medical Device Security (MDS2) form and related instructions how to complete the form. The intent of the MDS2 form is to supply healthcare providers with important information to assist them in assessing the vulnerabili
18、ty and risks associated with protecting private data transmitted or maintained by medical devices and systems. Because security risk assessment spans an entire organization, this document focuses on only those elements of the security risk assessment process associated with medical devices that main
19、tain or transmit private data. A standardized form 1) allows manufacturers to quickly respond to a potentially large volume of information requests from providers regarding the security- related features of the medical devices they manufacture; and 2) facilitates the providers review of the large vo
20、lume of security-related information supplied by the manufacturers. The manufacturer-completed MDS2 should: (1) Be useful to healthcare provider organizations worldwide. The information presented should be useful for any healthcare delivery organization that aspires to have an effective information
21、security risk management program. (2) Include device-specific information addressing the technical security-related attributes of the individual device model. (3) Provide a simple, flexible way of collecting the technical, device-specific elements of the common/typical information needed by provider
22、 organizations (device users/operators) to begin medical device information security (i.e., confidentiality, integrity, availability) risk assessments. HIMSS and NEMA grant permission to make copies and use this form. PLEASE BE ADVISEDThe MDS2 form is not intended to nor should it be used as the sol
23、e basis for medical device procurement. Writing procurement specifications requires a deeper and more extensive knowledge of security (including the individual facilitys/providers situation) and the healthcare mission. Using the information provided by the manufacturer in the MDS2 form together with
24、 information collected about the care delivery environment (e.g., through tools such as ACCE, American College of Clinical Engineering/ECRIs Guide for Information Security for Biomedical Technology), the providers multidisciplinary risk assessment team can review assembled information and make infor
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- NEMAHN12013MANUFACTURERDISCLOSURESTATEMENTFORMEDICALDEVICESECURITYPDF

链接地址:http://www.mydoc123.com/p-994211.html