**This is an old revision of the document!**

PHYSICAL SECURITY

  • The location of the computer must be fixed in one place and not portable.
  • Workstation for data collection and processing shall be in a separate area from the server room.
  • Pre-deployment site assessment shall be conducted.

COMPUTER ACCESS

  • Only authorized personnel will have access to stations/computers and there shall be role-based system access.
  • There shall be no multiple accounts per user. One user is to one account policy.
  • A person requesting for access to a computer shall fill-out a request form.
  • Applications installed in the computer must only be the ones necessary for the hospital information system. Other applications, most especially social media applications are strictly not allowed.

SERVERS

  • A designated area in the hospital shall be used for housing servers or data centers. This area shall be marked as restricted and shall be of limited access to personnel.
  • The IT office shall be a separate room from the server room.
  • If hospital/health facility cannot allot a place for a server room, at the minimum, a data cabinet shall be installed in lieu of the server room.
  • Clinics may use cloud computing while hospitals may use servers and put up server rooms.
  • Only one person shall be in-charge of handling the servers.

OTHER DEVICES

  • USB devices can only be used by limited offices. If possible, they should be prohibited.
  • Any facility-registered electronic devices (USB,Cellular/Smart phones, laptops, cameras, etc) shall be confined and cannot be taken outside the hospital premises and should only be dedicated for hospital use. Exceptions include disaster, vaccination, among others.
  • Bringing of electronic devices (cellular/smart phones, laptops, tablets, etc) inside the medical records area is strictly prohibited.
  • Devices not intended for handling patient information is not allowed to be used.
  • Capturing patient data via camera phones/cameras shall not be permitted.

OTHERS

  • In case of machine/computer loss, the accounts in the computer system shall be deactivated until it is retrieved or reported. However, it would be best if the credentials in the system shall be reset.

POINTS TO CONSIDER

  • State provisions regarding setting-up of infrastructure where physical servers or data center of hospital information system shall be located. Applicability of the existing administrative order containing provisions on IHOMP shall be considered. Implementation of an off-site back-up shall be done if the aforementioned AO shall be affected by this proposed set of rules.

See Also