• AS 4400-1995

    Withdrawn A Withdrawn Standard is one, which is removed from sale, and its unique number can no longer be used. The Standard can be withdrawn and not replaced, or it can be withdrawn and replaced by a Standard with a different number.

    Personal privacy protection in health care information systems

    Available format(s):  Hardcopy, PDF 1 User, PDF 3 Users, PDF 5 Users, PDF 9 Users

    Withdrawn date:  30-06-2017

    Language(s):  English

    Published date:  01-01-1995

    Publisher:  Standards Australia

    Add To Cart

    Abstract - (Show below) - (Hide below)

    Sets out the requirements for the protection of personal information held in health care information systems from breaches of integrity and confidentiality. It applies to all forms of health information, whether held in computerised systems or hard copy records, in both private and public sector organizations.

    Scope - (Show below) - (Hide below)

    This Standard establishes requirements for the protection of personal information in health care information systems. The Standard has been developed to apply to all forms of health information, including that held in computerized systems or hard copy records.The Standard recognizes that many organizations with personal information in health care information systems operate under the requirements of legislation or codes of practice or guidelines that have a legal basis. For these organizations these arrangements will take precedence over the requirements of the corresponding sections of this Standard.The Standard recognizes the requirement for properly authorized and conducted health research, quality assurance and clinical audit, and accepts that there needs to be a balance between the requirements of personal information privacy and the health benefits achievable through such recognized activities.The Standard outlines what a reasonable individual, whether health care provider or patient, might expect in relation to the protection of personal information by way of protection of data and systems security. Importantly, the Standard recognizes the balance required between the protection of personal privacy and the genuine, controlled and legitimate use of this information in providing and improving health care systems.The Standard also serves as a benchmark which may be used to audit performance and to determine whether a holder of personal information may be able to trust a third party with that information, based on their compliance with this Standard, in whole or in part.ApplicationEach organization is expected to develop its own information policy or code of practice, appropriate to its own operating environment, based on this Standard.Where an organization does not comply fully with the requirements of this Standard, it shall record in its policy the extent of noncompliance and the alternative measures taken to protect personal information. The policy, including noncompliance should be reviewed and approved by an appropriate independent body.The appropriate independent body which approves an organization's information policy should have the power to grant exemptions to particular requirements of this Standard, provided that such exemptions are recorded in the organization's information policy.An appropriate independent body which grants exemptions should adopt guidelines on when an exemption may be granted. Decisions to grant exemptions should be publicly available.

    General Product Information - (Show below) - (Hide below)

    Committee IT-014
    Document Type Standard
    Publisher Standards Australia
    Status Withdrawn
    Supersedes

    History - (Show below) - (Hide below)

    First published as AS 4400-1995.

    Standards Referenced By This Book - (Show below) - (Hide below)

    ISO/TS 27527:2010 Health informatics Provider identification
    PD CR 13694:1999 Health informatics. Safety and security related software quality standards for healthcare (SSQS)
    DD ISO/TS 27527:2010 Health informatics. Provider identification
    DD ISO/TS 22220:2011 Health informatics. Identification of subjects of health care
    ISO/TS 22220:2011 Health informatics — Identification of subjects of health care

    Standards Referencing This Book - (Show below) - (Hide below)

    AS 4590-1999 Interchange of client information
    AS 5017-2002 Health Care Client Identification
    AS 4700.2-2004 Implementation of Health Level Seven (HL7) Version 2.3.1 - Pathology orders and results
    AS/NZS 4700.3:1999 Implementation of Health Level Seven (HL7) Version 2.3 Electronic messages for exchange of information on drug prescription
    AS/NZS 3905.14:1998 Quality system guidelines - Guide to AS/NZS ISO 9001, 9002 and 9003 for health services
    AS 4485.1-1997 Security for health care facilities - General requirements 1
    AS 4485.2-1997 Security for health care facilities - Procedures guide
    • Access your standards online with a subscription

      Features

      • Simple online access to standards, technical information and regulations
      • Critical updates of standards and customisable alerts and notifications
      • Multi - user online standards collection: secure, flexibile and cost effective