Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
Last revision Both sides next revision
physical_security [2016/02/19 14:53]
jillian_nadette_de_leon
physical_security [2016/06/15 15:34]
jillian_nadette_de_leon
Line 1: Line 1:
 ##PHYSICAL SECURITY ##PHYSICAL SECURITY
-  *Pre-deployment site assessment shall be conducted and the computers to be installed shall be fixed in one place and not portable.\\ 
-  *The area for data collection and processing shall be separate from the server room.\\ 
-  *The IT room shall only be accessible to authorized personnel and to personnel involved during quality assurance monitoring and HICC for monitoring.\\ 
  
 **COMPUTER ACCESS**\\ **COMPUTER ACCESS**\\
-  * Computer access ​shall be limited ​to authorized personnel only. Role-based system access shall be implemented ​and there shall only be one account ​per userHaving multiple ​accounts are not allowed.\\ +  * Pre-deployment site assessment ​shall be conducted and computers to be installed shall be non-portable and fixed in one place. Computers shall be accessible ​to authorized personnel only and role-based system access shall be implemented. Each user shall have one account ​onlyMultiple ​accounts ​per user are not allowed. A person requesting for access to a computer shall fill-out a request form. \\ 
-  * A person requesting for access to a computer shall fill-out a request form.\\ +  * Anti-glare filters on computer monitors shall be installed. This will not only help reduce glare, but also prevent anyone from seeing what is on the screen unless directly in front of the computer.\\ 
-  * Only applications for the hospital information system shall be installed in the computer system. Other applications,​ most especially social media applications are strictly not allowed.\\ + 
-  * In case of computer loss, the accounts in the computer system shall be reset and deactivated until it is retrieved or reported.\\+//​Applications.// ​Only applications for the hospital information system shall be installed in the computer system. Other applications,​ most especially social media applications are strictly not allowed.  
  
 **SERVERS**\\ **SERVERS**\\
-  ​*The server room shall be a separate room from the IT office and a designated person shall be tasked to handle the servers.\\ +  *The health facility shall provide a designated area for the housing of servers/data centers. ​It shall be a separate ​area from the data collection and processing as well as from the IT office. The server room shall be marked as "​Restricted"​ and shall only be accessible to authorized personnel. If the health facility cannot allot a space for the server room, at the minimum, a data cabinet shall be installed ​and restrictions in terms of access shall be provided.\\ 
-  ​* The health facility/​hospital ​shall provide a designated area for the housing of servers ​or data centers. ​This area is to be marked as "​Restricted"​ and shall only be accessible to authorized personnel. If the health facility/​hospital ​cannot allot a space for the server room, at the minimum, a data cabinet shall be installed.\\ + 
-  * For smaller health facilities/clinics, they may use cloud computing while hospitals use servers.\\+//IT Room.// The IT room shall only be accessible to authorized personnel and to personnel involved during quality assurance monitoring. A designated IT personnel shall be tasked to handle the servers.\\
  
 **OTHER DEVICES**\\ **OTHER DEVICES**\\
-   * Capturing of patient data using camera phones and bringing of electronic devices such as cellular/​smart phones, laptops, tablets, cameras inside the medical records area is strictly not allowed. \\ +   * Facility-registered electronic devices shall not be brought outside the premises ​of the health facility ​except under circumstances such as disasters and vaccinations ​or unless otherwise approved by the head of the facility. USB devices shall be limited to office use but as may be practical, shall not be used.\\ 
-   * Facility-registered electronic devices shall not be brought outside the hospital ​premises except under circumstances such as disasters and vaccinations.\\ +   * Mobile devices used for job responsibilities are subject to audits even if an employee owns it.\\ 
-   ​* ​USB devices shall be limited to office use but as may be practical, shall not be used. \\+ 
 +  * Capturing of patient data using camera phones and bringing of electronic devices such as cellular phones, laptops, tablets, and cameras inside the medical records area is strictly not allowed.\\
  
 **POINTS TO CONSIDER** **POINTS TO CONSIDER**