Applying data protection part of ISO 27001 to patient and user data produced by medical devices – Case: disease specific quality registers

dc.contributor.authorTorkkeli, Aapo
dc.contributor.departmentfi=Tulevaisuuden teknologioiden laitos|en=Department of Future Technologies|
dc.contributor.facultyfi=Luonnontieteiden ja tekniikan tiedekunta|en=Faculty of Science and Engineering|
dc.contributor.studysubjectfi=Tietotekniikka|en=Information and Communication Technology|
dc.date.accessioned2020-05-14T21:01:21Z
dc.date.available2020-05-14T21:01:21Z
dc.date.issued2020-05-07
dc.description.abstractData protection may be considered a subset of information security, consisting of the rules that define who may have access to what data and under what conditions. Rules concerning the handling of personally identifiable information have also become a major topic of discussion with regulation such as the GDPR by the European Union. To improve data protection of personally identifiable information, initiatives such as MyData and IHAN have been developed. In the field of information security, standards such as ISO 27001 exist to improve and unify information security in organizations. This thesis studies the requirements that the data protection initiatives MyData and IHANimpose on organizations processing personally identifiable information, as well as the requirements imposed by the ISO 27001 standard. The requirements of MyData and IHAN are compared to the ISO 27001 standard, along with a case study that looks at the requirements of both in the context of patient data stored and processed in disease specific quality registers. A gap analysis of the ISO 27001 - security controls is performed to evaluate the current situation against the standards requirements. Suggestions for measures to meet the different potential requirements of MyData and IHAN are also given, along with discussion of their relevance to disease specific quality registers. Considerations of legal aspects of the protection of patient data related to these are however omitted.
dc.format.extent98
dc.identifier.olddbid166435
dc.identifier.oldhandle10024/149569
dc.identifier.urihttps://www.utupub.fi/handle/11111/11618
dc.identifier.urnURN:NBN:fi-fe2020051435521
dc.language.isoeng
dc.rightsfi=Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.|en=This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.|
dc.rights.accessrightsavoin
dc.source.identifierhttps://www.utupub.fi/handle/10024/149569
dc.subjectdata protection, information security, ISO 27001, MyData, IHAN, medical information systems
dc.titleApplying data protection part of ISO 27001 to patient and user data produced by medical devices – Case: disease specific quality registers
dc.type.ontasotfi=Diplomityö|en=Master's thesis|

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
Torkkeli_Aapo_opinnayte.pdf
Size:
426.24 KB
Format:
Adobe Portable Document Format