Volume 2, Issue 3 (Fall 2015)                   jhbmi 2015, 2(3): 184-194 | Back to browse issues page

XML Persian Abstract Print


Download citation:
BibTeX | RIS | EndNote | Medlars | ProCite | Reference Manager | RefWorks
Send citation to:

Moghaddasi H, Ghaemi M M. A Comparative Study of Three Standards of Data Security in Health Systems . jhbmi 2015; 2 (3) :184-194
URL: http://jhbmi.ir/article-1-96-en.html
Ph.D. in Medical Informatics, Shahid Beheshti University of Medical Sciences, School of Paramedical, Tehran, Iran.
Abstract:   (11905 Views)

Introduction: The increasing influence of ICT on health and changing information systems to electrical form makes using the information, data transmission, and also preparation printouts of information so easy that the importance of internal and external disclosure policy, data security, and confidentiality standards in these systems have been doubled.

Method: At the beginning of research, all the combinations of key words were searched, then the history and importance of the health data security standards were studied. So the most prevalent and reliable standards were selected to perform the full text. For the next step the researchers extracted the properties which were used to be compared with the selected standards and finally the comparison was discussed.

Results: PCI-DSS, HIPAA, and ISO-27799:2008 properties were classified in 8 groups and 25 subgroups.  ISO-27799:2008 was attended to all properties in Encryption group, but HIPAA was just attended to Encryption in storage, and asymmetric key, and PCI-DSS was considered on Encryption in storage, using Hash algorithm and use of asymmetric key. Operation system security was considered only in HIPAA. Only PCI-DSS standard considered RFID and DNS security and cell phone security, and PCI-DSS as well as ISO-27799:2008 considered wireless networks security.

Conclusion: One can use the standard that is stronger in context. So, it is recommended to use PCI-DSS for cell phone or PDA systems, and ISO-27799:2008 or PCI-DSS for wireless networks. It is better for security in operation systems to use HIPAA. Combined standard with all these three standards aspects can be used as the safest approach.

Full-Text [PDF 624 kb]   (5552 Downloads)    
Type of Study: Narrative review articles | Subject: Special
Received: 2015/07/16 | Accepted: 2015/09/21

Add your comments about this article : Your username or Email:
CAPTCHA

Send email to the article author


Rights and permissions
Creative Commons License This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.

© 2024 CC BY-NC 4.0 | Journal of Health and Biomedical Informatics

Designed & Developed by : Yektaweb