A new approach to risk management in the health-care domain

نویسندگان

  • Elmé Smith
  • Jan H. P. Eloff
چکیده

This paper is devoted to the presentation of a risk-management methodology (RiMaHCoF) that is specifically tailored for the health-care environment. The proposed methodology includes five successive stages in all, namely initiation, domain analysis, risk assessment, risk analysis and domain monitoring. This paper focuses on the risk analysis stage. The RiMaHCoF (" Risk Management in Health Care – using Cognitive Fuzzy techniques ") methodology enhances risk management in the specific domain of health care in the sense that it deems the patient's health-care information, processed and stored in a typical health-care institution, to be of utmost importance to such institution. The methodology further enhances risk management in this domain in that it incorporates cognitive fuzzy-logic techniques − as opposed to quantitative techniques such as annual loss exposure (ALE) calculation − to assess and analyse the information-technology risks. In this way, it is ensured that full cognisance is taken of the intuitive nature of human observation when assessing the possible IT risks to be incurred in a health-care institution. In addition, the methodology takes into account the vagueness of the decision making process with respect to securing patient information. The cognitive fuzzy approach to the assessment and analysis of information technology risks in health care does not only identify the high-risk areas within a typical health-care institution, but also helps to manage risks by facilitating the decision-making process with respect to securing patient information. 3 1. INTRODUCTION Information technology is currently being employed in health-care environments across the globe, resulting in significant improvements in the efficiency and quality of all services rendered in this realm [1-6]. The prospect of storing health-care information in electronic form does, however, raise concerns about the risks that could be incurred. The occurrence of a risk, such as the exposure of highly confidential and sensitive health-care information to outsiders, could compromise not only the patient's privacy, but also quite literally his/her wellbeing. It is, therefore, imperative to be able to identify possible risks in good time and to implement the necessary security controls in order to protect the patient in the health-care institution. Broadly speaking, risk management can be defined as that process which can be used to identify and implement security controls that will, at best, prevent risks from occurring and, at worst, minimise their effect if they were to occur [7-9]. A number of powerful techniques (such as CRAMM) could be employed to facilitate the …

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Explanation of the Management Challenges of Health System Reform in Health Care Domain city QOM: A Qualitative Study (Iran)

Background and Objectives: Assessment, identification, and presentation of management challenges of running programs can help policymakers and administrators to overcome these deficiencies and achieve the objectives of the plan. This study was conducted with the aim of explanation of the management challenges and solutions for its elimination in the health sector of health system reform plan Qo...

متن کامل

An Approach to Management of Health Care and Medical Diagnosis Using of a Hybrid Disease Diagnosis System

Introduction: In order to simplify the information exchange within the medical diagnosis process, a collaborative software agent’s framework is presented. The purpose of the framework is to allow the automated information exchange between different medicine specialists. Methods: This study presented architecture of a hybrid disease diagnosis system. The architecture employed a learning...

متن کامل

Multi-Criteria Risk-Benefit Analysis of Health Care Management

Abstract Purpose of this paper: The objectives of this paper are two folds: (1) utilizing hierarchical fuzzy technique for order preference by similarity to ideal solution (TOPSIS) approach to evaluate the most suitable RFID-based systems decision, and (2) to highlight key risks and benefits of radio frequency identification technology in healthcare industry. Design/methodology/approach: R...

متن کامل

Risks and Opportunities of Reforms Putting Primary Care in the Driver’s Seat; Comment on “Governance, Government, and the Search for New Provider Models”

Recognizing the advantages of primary care as a means of improving the entire health system, this text comments on reforms of publicly funded primary health centers, and the rapid development of private forprofit providers in Sweden. Many goals and expectations are connected to such reforms, which equally require critical analyses of scarce resources, professional trust/motivation and business ...

متن کامل

Sport Entrepreneurship: A Recent Approach in Entrepreneurship and Sport Management

Innovation, creativity and change are the key elements and unavoidable factors in sport. The importance of this issue encourages us to study sport from the point of view of entrepreneurship. During the recent years, spreading the sport management and development of entrepreneurship have created a new frame work in sport in a way that a new approach has been appeared regarding sport management a...

متن کامل

Governance, Government, and the Search for New Provider Models

A central problem in designing effective models of provider governance in health systems has been to ensure an appropriate balance between the concerns of public sector and/or government decision-makers, on the one hand, and of non-governmental health services actors in civil society and private life, on the other. In tax-funded European health systems up to the 1980s, the state and other publi...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • South African Computer Journal

دوره 27  شماره 

صفحات  -

تاریخ انتشار 2001