Related Experiment Videos
Organizing safety: conditions for successful information assurance programs.
Jeff Collmann1, Johnathan Coleman, Kristen Sostrom
1Telemedicine and Advanced Technology Research Center, USAMRMC, Washington, D.C., USA. collmanj@georgetown.edu
Summary
Organizations can achieve high reliability in computerized health information systems by fostering a culture of safety, supported by leadership and continuous training. This approach ensures the integrity, confidentiality, and availability of sensitive patient data.
Area of Science:
- Health Information Management
- Information Security
- Organizational Theory
Background:
- Computerized health information systems require robust safety measures to protect data integrity, confidentiality, and availability.
- High Reliability Theory (HRT) provides a framework for managing complex technologies by emphasizing leadership, training, and safety cultures.
- The Health Insurance Portability and Accountability Act (HIPAA) mandated stringent privacy and security regulations for health information.
Purpose of the Study:
- To explore the application of High Reliability Theory to enhance safety in computerized health information systems.
- To outline initiatives undertaken to promote a "culture of information assurance" within the military health system.
- To ensure compliance with HIPAA regulations for medical privacy and data security.
Main Methods:
- Sponsorship of organizational, doctrinal, and technical projects to foster information assurance.
- Formation of the "P3 Working Group" (P3WG) to review Department of Defense (DoD) and Military Health System (MHS) policies for HIPAA compliance.
- Support for the development and deployment of the OCTAVE(sm) risk assessment process and the Risk Information Management Resource (RIMR) portal.
Main Results:
- Development of interdisciplinary taskforces to ensure policy compliance with HIPAA.
- Implementation of self-directed information security risk assessment tools.
- Creation of a web-enabled enterprise portal for health information assurance resources.
Conclusions:
- A culture of high reliability, supported by strategic initiatives and tools, is crucial for safe management of computerized health information systems.
- Proactive measures and adherence to regulations like HIPAA are essential for protecting patient information.
- Continuous training and robust safety mechanisms are key to maintaining information assurance in healthcare organizations.