National Academy of Sciences | 150 Year Anniversary

Questions? Call 800-624-6242

| Items in cart [0]

The National Academies Press

HARDBACK
price:$32.95
add to cart

Rights & Permissions

topleft topright

For the Record: Protecting Electronic Health Information (1997)
Computer Science and Telecommunications Board (CSTB)

Citation Manager

. "4 Technical Approaches to Protecting Electronic Health Information." For the Record: Protecting Electronic Health Information. Washington, DC: The National Academies Press, 1997.

Please select a format:

BibTeX EndNote RefMan


Page
115
bottomleft bottomright

The following HTML text is provided to enhance online readability. Many aspects of typography translate only awkwardly to HTML. Please use the page image as the authoritative form to ensure accuracy.


TABLE 4.2 Summary of Security Tools and Practices Observed During Site Visits

 

Site

Security Feature

A

B

C

D

E

F

Authentication

 

 

 

 

 

 

Individual user IDs and passwords

 

 

Token-based authentication (e.g., token plus password)

 

 

 

 

 

 

Change passwords often

 

 

 

 

 

 

No unencrypted passwords

 

 

 

 

 

 

Uniform user IDs across organization

 

 

 

 

Incentives to reduce key sharing

 

 

Access Control

 

 

 

 

 

 

Need to know, right to know

 

 

 

 

 

Access control list technology and management

 

 

 

 

 

 

Role-based access profiles

 

 

 

 

 

Access overrides for emergencies

 

 

 

 

 

 

Audit Trails

 

 

 

 

 

 

Audit trails and self-audit

 

 

 

 

 

Software-based audit analysis

 

 

 

 

 

 

Physical Security

 

 

 

 

 

 

Terminal security

 

 

 

 

 

 

Security perimeter, network layout

 

 

 

 

Network physical security

 

 

 

 

 

Server physical security

 

Secure destruction of obsolete data or equipment

 

 

 

 

 

 

Control of Links

 

 

 

 

 

 

Firewall

 

 

Dial-in protections

 

 

 

 

 

Page
115