Showing posts with label safety. Show all posts
Showing posts with label safety. Show all posts

Tuesday, March 20, 2007

Best Buy - Standards

I've been heads down the last couple of weeks preparing for my risk workshops at the University of Waterloo. In my research I've found that the best site from which to buy standards is the ANSI (American National Standards Institute) eStandards Store. I was able to buy Security Standards ISO 17799 and ISO27001 for $30 USD each (the price on the Standards Council of Canada Website was $199.98 CDN and $131.75 CDN respectively). Other risk management standards I think are useful and will be integrated into the eHealth Risk/Opportunity Report card are:

ANSI/AAMI HE74:2001 - Human Factors Design Process for Medical Devices
IEC62198 - Project Risk Management - Application Guidelines
IEEE1490 - IEEE Guide - Adoption of PMI Standard - A Guide to the Project Management Body of Knowledge

There are also two relevant standards being developed by ISO TC215 WG4. They are at a very early stage of development. You might be able get them if you know someone on the committee ;-) They are:

Health Informatics - Application of risk management to the manufacture of health software; and

Health Informatics - Guidance on risk evaluation and management in the deployment and use of health software.

Saturday, March 3, 2007

Do No Harm!

In thinking about eHealth risk I am first drawn to Hippocrates' admonition to "do no harm". What harm can befall a person because of eHealth? The possibilities are limited and closely interrelated. The ones that come to mind are:
  1. Harm to a person's physical and mental well-being - this is the classic "safety" issue. We can cause personal physical or mental damage to people because we don't build or use our eHealth systems properly.
  2. Harm to a person's financial well-being - personal health information can be used to steal a person's identity, making them vulnerable to financial attack by identity thieves.
  3. Harm to a person's reputation - which can impact physical, mental and financial well-being. Release of personal information can impact a person's social standing, cause varying levels of embarrassment, and result in stigmatization.
I've strained my brain and I am challenged to add to this list. Of course, this is from a human being point of view. Organizations, many of which have the status of "natural humans" in law can also be subject to such harms, though the physical and mental well-being issue only applies in a very limited sense (an event so serious may occur that the organization might go out of business, or die).

At this stage I'm more interested in the human impacts, because addressing human health, be it physical, mental, financial or reputational, is the whole point of implementing eHealth systems in the first place.

Comments are welcome.