A New Security Framework for HIPAA-Compliant Health Information Systems

Security in health care information systems is among the highest priority research topics. Introduction of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) increased the pressure on health care organizations for implementing security. Two existing frameworks, which affect the proposed security standards, are introduced. It is important to understand the development of standards and how they can be useful, in order to successfully implement them. In this paper, we propose a techno-managerial framework that can aid planners of security systems as deployed within health care environment. Having a security framework will enable organizations to implement security standards more easily and quickly. As a result, we–the patients–will start seeing an increasing number of new health care services supported by the information technologies.