A tale of two standards: strengthening HIPAA security regulations using the PCI-DSS

被引:2
|
作者
Gaynor, Mark [1 ]
Bass, Catherine [1 ]
Duepner, Bryan [1 ]
机构
[1] St Louis Univ, St Louis, MO 63104 USA
关键词
HIPAA; PCI-DSS; standards; security; patient information; compliance;
D O I
10.1057/hs.2014.17
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
This paper both illustrates the inadequacy of current Health Insurance Portability and Accountability Act (HIPAA) regulations in protecting health-care information and proposes a more cohesive strategy to protect such information based on the organizational model that undergirds the Payment Card Industry Data Security Standards (PCI-DSS). The evidence indicates that the industry consortium model used to develop the PCI-DSS works rapidly and effectively. The success of these standards suggests that their strengths provide a favorable base from which to develop a robust set of standards to enhance information security within health care. A national organization consisting of industry representatives that is devoted to creating a more comprehensive and less vague set of security standards is required to protect health- care information more effectively than is possible under the current HIPAA approach.
引用
收藏
页码:111 / 123
页数:13
相关论文
共 5 条