**This is an old revision of the document!**

PHYSICAL SECURITY

COMPUTER ACCESS

  • Pre-deployment site assessment shall be conducted and computers to be installed shall be non-portable and fixed in one place. Computers shall be accessible to authorized personnel only and role-based system access shall be implemented. Each user shall have one account only. Multiple accounts per user are not allowed. A person requesting for access to a computer shall fill-out a request form.
  • Anti-glare filters on computer monitors shall be installed. This will not only help reduce glare, but also prevent anyone from seeing what is on the screen unless directly in front of the computer.

Applications. Only applications for the hospital information system shall be installed in the computer system. Other applications, most especially social media applications are strictly not allowed.

SERVERS

  • The health facility shall provide a designated area for the housing of servers/data centers. It shall be a separate area from the data collection and processing as well as from the IT office. The server room shall be marked as “Restricted” and shall only be accessible to authorized personnel. If the health facility cannot allot a space for the server room, at the minimum, a data cabinet shall be installed and restrictions in terms of access shall be provided.

IT Room. The IT room shall only be accessible to authorized personnel and to personnel involved during quality assurance monitoring. A designated IT personnel shall be tasked to handle the servers.

OTHER DEVICES

  • Facility-registered electronic devices shall not be brought outside the premises of the health facility except under circumstances such as disasters and vaccinations or unless otherwise approved by the head of the facility. USB devices shall be limited to office use but as may be practical, shall not be used.
  • Mobile devices used for job responsibilities are subject to audits even if an employee owns it.
  • Capturing of patient data using camera phones and bringing of electronic devices such as cellular phones, laptops, tablets, and cameras inside the medical records area is strictly not allowed.

POINTS TO CONSIDER

  • State provisions regarding setting-up of infrastructure where physical servers or data center of hospital information system shall be located. Applicability of the existing administrative order containing provisions on IHOMP shall be considered. Implementation of an off-site back-up shall be done if the aforementioned AO shall be affected by this proposed set of rules.

(We have to discuss whether we really want to specify in the IRR that setting up of infrastructure is required. I think it is sufficient to just specify the conditions that must be complied with. Part of this has already been developed by Kit's group.-IP)

See Also