15.11.2013 Views

Standards and Guidelines for Electronic Medical Record Systems in ...

Standards and Guidelines for Electronic Medical Record Systems in ...

Standards and Guidelines for Electronic Medical Record Systems in ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

A locally stored backup log should be ma<strong>in</strong>ta<strong>in</strong>ed with the follow<strong>in</strong>g <strong>in</strong><strong>for</strong>mation as m<strong>in</strong>imum:<br />

i. name of media used;<br />

ii. Type of backup (e.g. full backup/<strong>in</strong>cremental, differential, etc.);<br />

iii. date the backup was per<strong>for</strong>med;<br />

iv. verification status (completed/failed);<br />

v. who per<strong>for</strong>med the backup (automated or by specific staff); <strong>and</strong><br />

vi. Location where the backup media is stored, date it was placed there, <strong>and</strong> who placed it<br />

there.<br />

(NB: See Annex F <strong>for</strong> a sample Backup Log)<br />

Backup procedures should allow <strong>for</strong> daily backups, as well as, <strong>in</strong>clude the possibility <strong>for</strong> per<strong>for</strong>m<strong>in</strong>g<br />

day-to-day restorations or full data recovery.<br />

The backup process should be automated wherever possible <strong>in</strong> order to ensure consistency.<br />

Off-site backup media should be given the same level of physical <strong>and</strong> environmental protection that<br />

is required <strong>for</strong> the primary site as def<strong>in</strong>ed <strong>in</strong> this document. This <strong>in</strong>cludes security dur<strong>in</strong>g the<br />

transportation of media <strong>and</strong> documentation between the facility <strong>and</strong> the off-site location.<br />

A documented procedure should be <strong>in</strong> place that outl<strong>in</strong>es the off-site backup process. At a m<strong>in</strong>imum<br />

this should <strong>in</strong>clude a list of who is authorized to send data off-site, to where, <strong>and</strong> who is authorized<br />

to recall data.<br />

Computer Virus <strong>and</strong> Spyware Control<br />

1. All computer systems must have virus detection software <strong>in</strong>stalled <strong>and</strong> updated<br />

regularly.<br />

2. Antivirus software should be configured to scan all removable media when <strong>in</strong>serted<br />

<strong>in</strong>to the system <strong>for</strong> viruses.<br />

Computer viruses are a significant threat to the <strong>in</strong>tegrity <strong>and</strong> confidentiality of data on computer<br />

systems. A facility operat<strong>in</strong>g an EMR system should have a written procedure on how to update the<br />

antivirus def<strong>in</strong>ition files, either automatically through the <strong>in</strong>ternet or periodically us<strong>in</strong>g remotely<br />

downloaded files. A full virus scan should be per<strong>for</strong>med rout<strong>in</strong>ely <strong>and</strong> each time virus def<strong>in</strong>ition<br />

files are updated.<br />

<strong>St<strong>and</strong>ards</strong> <strong>and</strong> <strong>Guidel<strong>in</strong>es</strong> <strong>for</strong> <strong>Electronic</strong> <strong>Medical</strong> <strong>Record</strong>s <strong>Systems</strong> <strong>in</strong> Kenya 71

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!