Analysis of information security management systems at 5 domestic hospitals with more than 500 beds

The information security management systems (ISMS) of 5 hospitals with more than 500 beds were evaluated with regards to the level of information security, management, and physical and technical aspects so that we might make recommendations on information security and security countermeasures which...

Full description

Saved in:
Bibliographic Details
Published inHealthcare informatics research Vol. 16; no. 2; pp. 89 - 99
Main Authors Park, Woo-Sung, Seo, Sun-Won, Son, Seung-Sik, Lee, Mee-Jeong, Kim, Shin-Hyo, Choi, Eun-Mi, Bang, Ji-Eon, Kim, Yea-Eun, Kim, Ok-Nam
Format Journal Article
LanguageEnglish
Published Korea (South) Korean Society of Medical Informatics 01.06.2010
The Korean Society of Medical Informatics
대한의료정보학회
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:The information security management systems (ISMS) of 5 hospitals with more than 500 beds were evaluated with regards to the level of information security, management, and physical and technical aspects so that we might make recommendations on information security and security countermeasures which meet both international standards and the needs of individual hospitals. The ISMS check-list derived from international/domestic standards was distributed to each hospital to complete and the staff of each hospital was interviewed. Information Security Indicator and Information Security Values were used to estimate the present security levels and evaluate the application of each hospital's current system. With regard to the moderate clause of the ISMS, the hospitals were determined to be in compliance. The most vulnerable clause was asset management, in particular, information asset classification guidelines. The clauses of information security incident management and business continuity management were deemed necessary for the establishment of successful ISMS. The level of current ISMS in the hospitals evaluated was determined to be insufficient. Establishment of adequate ISMS is necessary to ensure patient privacy and the safe use of medical records for various purposes. Implementation of ISMS which meet international standards with a long-term and comprehensive perspective is of prime importance. To reflect the requirements of the varied interests of medical staff, consumers, and institutions, the establishment of political support is essential to create suitable hospital ISMS.
Bibliography:ObjectType-Article-1
SourceType-Scholarly Journals-1
ObjectType-Feature-2
content type line 23
G704-001070.2010.16.2.004
ISSN:2093-3681
2093-369X
DOI:10.4258/hir.2010.16.2.89