Health informatics - Electronic health record communication - Part 4: Security

This part of this multipart standard on Electronic Health Record Communication describes a methodology for specifying the privileges necessary to access EHR data. This methodology forms part of the overall EHR communications architecture defined in Part 1 of this standard.
This standard seeks to address those requirements uniquely pertaining to EHR communications and to represent and communicate EHR-specific information that will inform an access decision. It also refers to general security requirements that apply to EHR communications and points at technical solutions and standards that specify details on services meeting these security needs.
NOTE   Security requirements for EHR systems not related to the communication of EHRs are outside the scope of this standard.

Medizinische Informatik - Kommunikation von Patientendaten in elektronischer Form - Teil 4: Sicherheit

Informatique de la santé - Communication des dossiers de santé informatisés - Partie 4 : Sécurité

Cette partie de la présente norme en plusieurs parties relative à la Communication des Dossiers Informatisés de Santé décrit une méthodologie permettant de spécifier les privilèges que nécessite un accès aux données de DIS. Cette méthodologie forme une partie de l’architecture globale relative aux communications de DIS définie dans la Partie 1 de la présente norme.
La présente norme tente d’aborder les exigences se rapportant uniquement aux communications de DIS, de représenter et de communiquer les informations spécifiques aux DIS qui permettront d’instruire une décision d’accès. Elle fait également référence aux exigences générales en matière de sécurité s’appliquant aux communications de DIS et indique des normes et des solutions techniques spécifiant des détails relatifs aux services répondant à ces besoins en matière de sécurité.
NOTE   Les exigences en matière de sécurité concernant les systèmes de DIS non relatives à la communication de DIS ne relèvent pas du domaine d’application de la présente norme.

Zdravstvena informatika - Komunikacija z elektronskimi zapisi na področju zdravstva - 4. del: Varnost

General Information

Status
Withdrawn
Publication Date
27-Mar-2007
Withdrawal Date
02-Jul-2019
Current Stage
9960 - Withdrawal effective - Withdrawal
Completion Date
03-Jul-2019

Relations

Buy Standard

Standard
EN 13606-4:2008
English language
48 pages
sale 10% off
Preview
sale 10% off
Preview
e-Library read for
1 day

Standards Content (Sample)

2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.Health Informatics - Electronic health record communication - Part 4: SecuritySRGURþMXInformatique de la santé - Communication des dossiers informatisés de santé - Partie 4 : SécuritéMedizinische Informatik - Kommunikation von Patientendaten in elektronischer Form - Teil 4: SicherheitTa slovenski standard je istoveten z:EN 13606-4:2007SIST EN 13606-4:2008en35.240.80ICS:SIST ENV 13606-4:20031DGRPHãþDSLOVENSKI
STANDARDSIST EN 13606-4:200801-maj-2008







EUROPEAN STANDARDNORME EUROPÉENNEEUROPÄISCHE NORMEN 13606-4March 2007ICS 35.240.80Supersedes ENV 13606-4:2000
English VersionHealth informatics - Electronic health record communication -Part 4: SecurityInformatique de santé - Dossiers de santé informatiséscommunicants - Partie 4 : Exigences de sécurité et règlesde distributionMedizinische Informatik - Kommunikation vonPatientendaten in elektronischer Form - Teil 4: SicherheitThis European Standard was approved by CEN on 10 February 2007.CEN members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for giving this EuropeanStandard the status of a national standard without any alteration. Up-to-date lists and bibliographical references concerning such nationalstandards may be obtained on application to the CEN Management Centre or to any CEN member.This European Standard exists in three official versions (English, French, German). A version in any other language made by translationunder the responsibility of a CEN member into its own language and notified to the CEN Management Centre has the same status as theofficial versions.CEN members are the national standards bodies of Austria, Belgium, Bulgaria, Cyprus, Czech Republic, Denmark, Estonia, Finland,France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal,Romania, Slovakia, Slovenia, Spain, Sweden, Switzerland and United Kingdom.EUROPEAN COMMITTEE FOR STANDARDIZATIONCOMITÉ EUROPÉEN DE NORMALISATIONEUROPÄISCHES KOMITEE FÜR NORMUNGManagement Centre: rue de Stassart, 36
B-1050 Brussels© 2007 CENAll rights of exploitation in any form and by any means reservedworldwide for CEN national Members.Ref. No. EN 13606-4:2007: E



EN 13606-4:2007 (E) 2 Contents Page Foreword.3 Introduction.4 1 Scope.19 2 Normative references.19 3 Terms and definitions.19 4 Symbols and abbreviations.21 5 Conformance.22 6 Record Component Sensitivity and Functional Roles (Normative).23 6.1 RECORD_COMPONENT sensitivity.23 6.2 Functional Roles.23 6.3 Mapping of Functional Role to RECORD_COMPONENT Sensitivity.24 7 Representing access policy information within an EHR_EXTRACT.25 7.1 General.25 7.2 Archetype of the Access policy COMPOSITION.26 7.3 ADL representation of the archetype of the access policy COMPOSITION.28 7.4 UML representation of the archetype of the access policy COMPOSITION.33 8 Representation of audit log information.35 8.1 EHR_AUDIT_LOG_EXTRACT model.35 Annex A (informative)
Illustrative access control example.38 Annex B (informativ
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.