首页> 外文期刊>BMC Medical Informatics and Decision Making >Analysis of the quality of hospital information systems audit trails
【24h】

Analysis of the quality of hospital information systems audit trails

机译:医院信息系统审计追踪质量分析

获取原文
           

摘要

Background Audit Trails (AT) are fundamental to information security in order to guarantee access traceability but can also be used to improve Health information System’s (HIS) quality namely to assess how they are used or misused. This paper aims at analysing the existence and quality of AT, describing scenarios in hospitals and making some recommendations to improve the quality of information. Methods The responsibles of HIS for eight Portuguese hospitals were contacted in order to arrange an interview about the importance of AT and to collect audit trail data from their HIS. Five institutions agreed to participate in this study; four of them accepted to be interviewed, and four sent AT data. The interviews were performed in 2011 and audit trail data sent in 2011 and 2012. Each AT was evaluated and compared in relation to data quality standards, namely for completeness, comprehensibility, traceability among others. Only one of the AT had enough information for us to apply a consistency evaluation by modelling user behaviour. Results The interviewees in these hospitals only knew a few AT (average of 1 AT per hospital in an estimate of 21 existing HIS), although they all recognize some advantages of analysing AT. Four hospitals sent a total of 7 AT – 2 from Radiology Information System (RIS), 2 from Picture Archiving and Communication System (PACS), 3 from Patient Records. Three of the AT were understandable and three of the AT were complete. The AT from the patient records are better structured and more complete than the RIS/PACS. Conclusions Existing AT do not have enough quality to guarantee traceability or be used in HIS improvement. Its quality reflects the importance given to them by the CIO of healthcare institutions. Existing standards (e.g. ASTM:E2147, ISO/TS 18308:2004, ISO/IEC 27001:2006) are still not broadly used in Portugal.
机译:后台审计跟踪(AT)对于确保访问可追溯性是信息安全的基础,但也可以用于提高健康信息系统(HIS)的质量,即评估其使用或滥用方式。本文旨在分析AT的存在和质量,描述医院中的情况,并提出一些建议以提高信息质量。方法与葡萄牙八家医院的HIS负责人联系,以安排有关AT重要性的访谈,并从其HIS收集审计跟踪数据。五个机构同意参加这项研究;他们中的四人接受了采访,四人发送了AT数据。在2011年进行了访谈,并在2011年和2012年发送了审计跟踪数据。对每个AT进行了评估并与数据质量标准(即完整性,可理解性和可追溯性)进行了比较。只有一个AT有足够的信息供我们通过对用户行为进行建模来应用一致性评估。结果这些医院的受访者只知道少数几个AT(平均每个医院1个AT,估计已有21个HIS),尽管他们都意识到分析AT的一些优势。四家医院总共从放射信息系统(RIS)发送了7个AT – 2,从图片存档和通信系统(PACS)发送了2个,从患者记录发送了3个。其中三个AT是可以理解的,而三个AT是完整的。与RIS / PACS相比,病历中的AT具有更好的结构和更完善的功能。结论现有AT的质量不足以保证可追溯性或不能用于HIS改进。它的质量反映了医疗机构CIO对他们的重视。现有标准(例如ASTM:E2147,ISO / TS 18308:2004,ISO / IEC 27001:2006)仍未在葡萄牙广泛使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号