Informatics
You’re right to double-check! I’ll go through everything again and ensure no details are left out. Below is a comprehensive set of flashcards covering both major and minor points from Medical Informatics Sessions 11 & 12.
Session 11: Privacy in Health Information Systems
1⃣ General Concepts
1⃣ Q: What are the three main principles of health information security?
A: Privacy, security, and confidentiality.
2⃣ Q: How does ISO 18308:2011 define an Electronic Health Record (EHR)?
A: A repository of patient health data that is computer-processable, securely stored, and accessible by authorized users.
3⃣ Q: What does ISO 27799 define as personal health information (PHI)?
A: Any information related to a person’s physical/mental health or healthcare provision, including patient demographics and billing data.
2⃣ Privacy, Security, and Confidentiality
4⃣ Q: Define privacy in the healthcare setting.
A: The right of individuals to control access to their personal health information.
5⃣ Q: What is security in health informatics?
A: Protection measures that safeguard health data from unauthorized access, modification, or breaches.
6⃣ Q: How does confidentiality differ from security?
A: Confidentiality limits the disclosure of private information, ensuring it is used only for its intended purpose.
3⃣ Standards and Regulations
7⃣ Q: What is HIPAA, and what does it regulate?
A: The Health Insurance Portability and Accountability Act (HIPAA) regulates privacy, security, and breach notification of PHI.
8⃣ Q: Name two international organizations responsible for health informatics standards.
A: ISO (ISO/TC215) and CEN (CEN/TC251).
9⃣ Q: What are the 10 security domains by the International Information Systems Security Consortium?
A: Security management, access control, cryptography, operations security, physical security, etc.
4⃣ Security Management & Risk Assessment
🔟 Q: What is the Seven-Step Approach to Security Management?
A:
• Step 1: Lead culture & select team
• Step 2: Document process
• Step 3: Perform security risk analysis
• Step 4: Develop action plan
• Step 5: Manage risks
• Step 6: Attest for compliance
• Step 7: Monitor security
1⃣1⃣ Q: What is a security breach in health informatics?
A: Unauthorized disclosure or misuse of PHI that compromises privacy or security.
1⃣2⃣ Q: How can PHI be secured?
A: Through encryption, access controls, physical security, and secure EHR systems.
5⃣ Security Risk Analysis & Mitigation
1⃣3⃣ Q: What are examples of security risks for EHRs?
A:
• Office-based EHRs: Natural disasters, cyber-attacks, outdated software.
• Cloud-based EHRs: Internet dependence, data storage outside the U.S.
1⃣4⃣ Q: How can risks be mitigated in healthcare IT security?
A:
• Data encryption
• Strong authentication protocols
• Regular security audits
• Staff training
6⃣ HIPAA Regulations
1⃣5⃣ Q: What does HIPAA’s Privacy Rule protect?
A: Most individually identifiable health information in electronic, paper, or oral form.
1⃣6⃣ Q: What does HIPAA’s Security Rule regulate?
A: National standards for securing electronic PHI (ePHI).
1⃣7⃣ Q: What is the HIPAA Breach Notification Rule?
A: Requires healthcare providers to notify affected individuals and authorities when a PHI breach occurs.
1⃣8⃣ Q: What entities must comply with HIPAA regulations?
A:
• Covered Entities (CEs): Providers, insurers, clearinghouses.
• Business Associates (BAs): Third-party vendors handling PHI.
7⃣ Data Sharing & De-Identification
1⃣9⃣ Q: When can patient data be shared without authorization?
A:
• Treatment and payment purposes
• Public health and safety concerns
• Research (if de-identified)
2⃣0⃣ Q: What is de-identified PHI?
A: Health information that has had all identifiers removed so it cannot be linked to an individual.
Session 12: Mobile Health Technologies
1⃣ History of Mobile Health Tech
2⃣1⃣ Q: What was the first PDA in the 1990s, and why did it fail?
A: The Apple Newton; it was too big, slow, had insufficient memory, and was expensive.
2⃣2⃣ Q: What was the first successful PDA for medical use?
A: The Palm Pilot 1000, released in 1996.
2⃣3⃣ Q: What role did BlackBerry play in medical informatics?
A: It was widely used for email and medical software programs.
2⃣ Types of mHealth Technology
2⃣4⃣ Q: What are the three main types of mHealth technology?
A: Apps, sensors, and devices.
2⃣5⃣ Q: What are the advantages of sensor-based mHealth solutions?
A: Automatic data capture and reduced reliance on patient self-reporting.
2⃣6⃣ Q: How do devices integrate mHealth technologies?
A: By combining app and sensor functions for real-time biometric data transmission.
3⃣ Institutional Integration & Functions
2⃣7⃣ Q: What are the levels of institutional integration in mHealth?
A: Stand-alone, expert-certified, FDA-approved, or insurance-approved.
2⃣8⃣ Q: What are the key functions of mHealth technologies?
A: Inform, advise, communicate, measure, monitor, and motivate.
2⃣9⃣ Q: How can mHealth technologies help in patient motivation?
A: By encouraging better health decisions through tracking and alerts.
4⃣ Medical Software & Smartphone Use
3⃣0⃣ Q: What are common types of medical software for mobile platforms?
A: Drug lookup tools, medical calculators, patient record apps, and disease diagnosis guides.
3⃣1⃣ Q: Name a widely used free medical software program for clinicians.
A: Epocrates.
3⃣2⃣ Q: What are key features of Android and iOS in medical informatics?
A:
• Android: Open-source app development.
• iOS: Integrated Apple ecosystem for medical programs.
5⃣ Limitations of Mobile Health Technology
3⃣3⃣ Q: What are common limitations of mHealth technology?
A:
• Slow input (small keyboards, styluses)
• Small screen sizes
• Security risks
• Expense of data plans
3⃣4⃣ Q: How can security issues in mHealth be addressed?
A: Encryption, authentication measures, and anti-virus programs.
This expanded version covers all major and minor details from both sessions. Let me know if you’d like me to refine anything further!