Standard Specification for Audit and Disclosure Logs for Use in Health Information Systems

ABSTRACT
This specification describes the security requirements involved in the development and implementation of audit and disclosure logs used in health information systems. It specifies how to design an access audit log to record all access to patient identifiable information maintained in computer systems, and includes principles for developing policies, procedures, and functions of health information logs to document all disclosure of confidential health care information to external users for use in manual and computer systems. This specification provides for two main purposes, namely: to define the nature, role, and function of system access audit logs and their use in health information systems as a technical and procedural tool to help provide security oversight; and to identify principles for establishing a permanent record of disclosure of health information to external users and the data to be recorded in maintaining it.
SCOPE
1.1 This specification is for the development and implementation of security audit/disclosure logs for health information. It specifies how to design an access audit log to record all access to patient identifiable information maintained in computer systems and includes principles for developing policies, procedures, and functions of health information logs to document all disclosure of health information to external users for use in manual and computer systems. The process of information disclosure and auditing should conform, where relevant, with the Privacy Act of 1974 (1).
1.2 The first purpose of this specification is to define the nature, role, and function of system access audit logs and their use in health information systems as a technical and procedural tool to help provide security oversight. In concert with organizational confidentiality and security policies and procedures, permanent audit logs can clearly identify all system application users who access patient identifiable information, record the nature of the patient information accessed, and maintain a permanent record of actions taken by the user. By providing a precise method for an organization to monitor and review who has accessed patient data, audit logs have the potential for more effective security oversight than traditional paper record environments. This specification will identify functionality needed for audit log management, the data to be recorded, and the use of audit logs as security and management tools by organizational managers.
1.3 In the absence of computerized logs, audit log principles can be implemented manually in the paper patient record environment with respect to permanently monitoring paper patient record access. Where the paper patient record and the computer-based patient record coexist in parallel, security oversight and access management should address both environments.
1.4 The second purpose of this specification is to identify principles for establishing a permanent record of disclosure of health information to external users and the data to be recorded in maintaining it. Security management of health information requires a comprehensive framework that incorporates mandates and criteria for disclosing patient health information found in federal and state laws, rules and regulations and ethical statements of professional conduct. Accountability for such a framework should be established through a set of standard principles that are applicable to all health care settings and health information systems.
1.5 Logs used to audit and oversee health information access and disclosure are the responsibility of each health care organization, data intermediary, data warehouse, clinical data repository, third party payer, agency, organization or corporation that maintains or provides, or has access to individually-identifiable data. Such logs are specified in and support policy on information access monitoring and are tied to disciplinary sanctions that satisfy legal, regulatory, accre...

General Information

Status
Historical
Publication Date
09-Nov-2001
Current Stage
Ref Project

Relations

Buy Standard

Technical specification
ASTM E2147-01 - Standard Specification for Audit and Disclosure Logs for Use in Health Information Systems
English language
5 pages
sale 15% off
Preview
sale 15% off
Preview

Standards Content (Sample)

NOTICE: This standard has either been superseded and replaced by a new version or withdrawn.
Contact ASTM International (www.astm.org) for the latest information
An American National Standard
Designation: E 2147 – 01
Standard Specification for
Audit and Disclosure Logs for Use in Health Information
1
Systems
This standard is issued under the fixed designation E 2147; the number immediately following the designation indicates the year of
original adoption or, in the case of revision, the year of last revision. A number in parentheses indicates the year of last reapproval. A
superscript epsilon (e) indicates an editorial change since the last revision or reapproval.
1. Scope computer-based patient record coexist in parallel, security
oversight and access management should address both envi-
1.1 This specification is for the development and implemen-
ronments.
tation of security audit/disclosure logs for health information.
1.4 The second purpose of this specification is to identify
It specifies how to design an access audit log to record all
principles for establishing a permanent record of disclosure of
access to patient identifiable information maintained in com-
health information to external users and the data to be recorded
puter systems and includes principles for developing policies,
in maintaining it. Security management of health information
procedures, and functions of health information logs to docu-
requires a comprehensive framework that incorporates man-
ment all disclosure of health information to external users for
dates and criteria for disclosing patient health information
use in manual and computer systems. The process of informa-
found in federal and state laws, rules and regulations and
tion disclosure and auditing should conform, where relevant,
2
ethical statements of professional conduct. Accountability for
with the Privacy Act of 1974 (1).
such a framework should be established through a set of
1.2 The first purpose of this specification is to define the
standardprinciplesthatareapplicabletoallhealthcaresettings
nature, role, and function of system access audit logs and their
and health information systems.
use in health information systems as a technical and procedural
1.5 Logs used to audit and oversee health information
tool to help provide security oversight. In concert with orga-
access and disclosure are the responsibility of each health care
nizational confidentiality and security policies and procedures,
organization, data intermediary, data warehouse, clinical data
permanentauditlogscanclearlyidentifyallsystemapplication
repository, third party payer, agency, organization or corpora-
users who access patient identifiable information, record the
tion that maintains or provides, or has access to individually-
nature of the patient information accessed, and maintain a
identifiable data. Such logs are specified in and support policy
permanent record of actions taken by the user. By providing a
on information access monitoring and are tied to disciplinary
precise method for an organization to monitor and review who
sanctions that satisfy legal, regulatory, accreditation and insti-
hasaccessedpatientdata,auditlogshavethepotentialformore
tutional mandates.
effective security oversight than traditional paper record envi-
1.6 Organizations need to prescribe access requirements for
ronments. This specification will identify functionality needed
aggregate data and to approve query tools that allow auditing
for audit log management, the data to be recorded, and the use
capability, or design data repositories that limit inclusion of
of audit logs as security and management tools by organiza-
datathatprovidepotentialkeystoidentifiabledata.Inferencing
tional managers.
patient identifiable data through analysis of aggregate data that
1.3 Intheabsenceofcomputerizedlogs,auditlogprinciples
contains limited identifying data elements such as birth date,
can be implemented manually in the paper patient record
birth location, and family name, is possible using software that
environment with respect to permanently monitoring paper
matches data elements across data bases. This allows a
patient record access. Where the paper patient record and the
consistent approach to linking records into longitudinal cases
for research purposes. Audit trails can be designed to work
1
with applications which use these techniques if the query
This specification is under the jurisdiction of ASTM Committee E31 on
Healthcare Informatics and is the direct responsibility of Subcommittee E31.25 on
functions are part of a defined retrieval application but often
Healthcare Data Management, Security, Confidentiality, and Privacy.
standard query tools are not easily audited. This specification
Current edition approved Nov. 10, 2001. Published February 2002.
2 applies to the disclosure or transfer of health information
The boldface numbers in parentheses refer to the list of references at the end of
this standard. (records) individually or in bat
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.