æ£è ããŒã¿ãå®å¿ããŠä¿è· â å®å šå¯Ÿçãèªååãããªã¹ã¯ãç£èŠããç£æ»äººã®èŠæ±ãæºããããšã³ãããŒãšã³ãã® HIPAA ã³ã³ãã©ã€ã¢ã³ã¹ã

å»çæ©é¢ã¯ãçŸåããæãæ©å¯æ§ã®é«ãããŒã¿ã§ãã
ä¿è·å»çæ å ± (PHI) â ããæã峿 ŒãªèŠå¶ãã¬ãŒã ã¯ãŒã¯ã®1ã€ã«åºã¥ããŠæ±ã£ãŠããŸããHIPAA éåã¯ãéåã«ããŽãªããã幎éæå€§190äžãã«ã®çœ°éãç§ããããå»çããŒã¿äŸµå®³ã®å¹³åã³ã¹ãã¯1090äžãã«ãšãå šæ¥çã§æãé«é¡ã§ããã»ãšãã©ã®å»çæäŸè ããã«ã¹ããã¯äŒæ¥ã¯ãæåã®ã¹ãã¬ããã·ãŒãããã©ãã©ã®ã»ãã¥ãªãã£ããŒã«ããããŠåçãªè åšã®ç¶æ³ãæããããªã幎次ãªã¹ã¯è©äŸ¡ã«ãã£ãŠã³ã³ãã©ã€ã¢ã³ã¹ã管çããŠããŸãã
æ°åã®ãã³ããŒãšã®äºæ¥ææºå¥çŽ (BAA) ã¯è¿œè·¡ããããåŸæ¥å¡ãã¬ãŒãã³ã°ã®äžåã¯èŠéãããã圹å²ã責任ãå€åããŠãã¢ã¯ã»ã¹å¶åŸ¡ã¯éçãªãŸãŸã§ããOCR ã®ç£æ»äººãæ¥ãå Žåãçµç¹ã¯ããã¿ã³ãã¯ãªãã¯ããã ãã§å©çšå¯èœã§ããã¹ã蚌æ ã®åéã«æ°é±éãè²»ãããŸãã
次ã®ãããžã§ã¯ãã®ããã®å®è£ ãã«ãŒããªã³ãããã£ãšèŠã€ãã
MicrocosmWorksã¯ããã¹ãŠã®ePHIã«å¯Ÿããä¿ç®¡æã«AES-256æå·åã転éæã«TLS 1.3ãå®è£ ããŠãããããã«ã¯ããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ãèªåã»ãã·ã§ã³ã¿ã€ã ã¢ãŠãããã¹ãŠã®ã·ã¹ãã ã³ã³ããŒãã³ãã«ãããåºæã®ãŠãŒã¶ãŒèå¥ãçµã¿åããããŠããŸãããã©ãããã©ãŒã ã«ã¯ãHIPAA Security Ruleã®æè¡çä¿è·æªçœ®èŠä»¶ãæºããããã«ãæå·åããã·ã¥ã«ããæŽåæ§å¶åŸ¡ãšèªåããã¯ã¢ããæ€èšŒãå«ãŸããŠããŸãã
MicrocosmWorksã®ãã«ãŒããªã³ãã¯ãePHIãžã®ãã¹ãŠã®ã¢ã¯ã»ã¹ã倿Žãããã³è»¢éããŠãŒã¶ãŒIDãã¿ã€ã ã¹ã¿ã³ããã¢ã¯ã·ã§ã³ã¿ã€ããããã³ã¢ã¯ã»ã¹ãããããŒã¿èŠçŽ ãšãšãã«ãã£ããã£ããäžå€ã®ç£æ»ãã®ã³ã°ãå®è£ ããŠããŸãããããã®ãã°ã¯ãèšå®å¯èœãªä¿ææéïŒHIPAAèŠä»¶ã«åºã¥ãæäœ6幎éïŒãæã€æ¹ãã鲿¢æ©èœä»ãã®è¿œèšå°çšã¹ãã¬ãŒãžã«ä¿åããã䟵害調æ»ããã³OCRç£æ»å¯Ÿå¿ã®ããã«æ€çŽ¢å¯èœã§ãã
ã¯ããMicrocosmWorksã¯ããã¹ãŠã®Business Associateããã®BAAå®è¡ã¹ããŒã¿ã¹ã幎éãªã¹ã¯è©äŸ¡ã®ææ¥ãããã³äžè«ãæ¥è ãã§ãŒã³ã远跡ãããã³ããŒç®¡çã¢ãžã¥ãŒã«ãæ§ç¯ããŠããŸãããã®ãã©ãããã©ãŒã ã¯ãèªåæŽæ°ãªãã€ã³ããŒãéä¿¡ããePHIã«ã¢ã¯ã»ã¹ããæ°èŠãã³ããŒã®BAAã®ã®ã£ãããç¹å®ãããµãŒãããŒãã£ãªã¹ã¯ã®ç¶æ³ãå³åº§ã«å¯èŠåã§ããã³ã³ãã©ã€ã¢ã³ã¹ããã·ã¥ããŒããç¶æããŸãã
MicrocosmWorksã¯ãã€ã³ã·ãã³ããé倧床å¥ã«åé¡ãã圱é¿ãåããåäººã®æ°ãèšç®ãã500人以äžã«åœ±é¿ãäžããéåã«çŸ©åä»ããããŠããéãã«ãæ£è ãHHS OCRãã¡ãã£ã¢åãã®äºåãã©ãŒãããæžã¿éç¥æžãçæãããèªååãããé忀åºããã³å¯Ÿå¿ã¯ãŒã¯ãããŒãæ§ç¯ããŸãããã®ãã©ãããã©ãŒã ã¯ã60æ¥éã®éç¥æéã远跡ããå€ãã®å ŽåããçãæéãèšããŠããå·åºæã®éç¥èŠä»¶ã管çããŸãã
MicrocosmWorksã®$25ïœ$45/æã®ã¬ãŒãã«åºã¥ããšã貎瀟ã®ç¹å®ã®ã¯ãŒã¯ãããŒã«åãããã«ã¹ã¿ã ã®HIPAAã³ã³ãã©ã€ã¢ã³ã¹ã·ã¹ãã ãéçºããã«ã¯ãéåžž$40,000ïœ$90,000ã®è²»çšãããããŸããããã¯ã貎瀟ã®EHRããã©ã¯ãã£ã¹ç®¡çã·ã¹ãã ãšçµ±åããªãå¯èœæ§ã®ããSaaSã³ã³ãã©ã€ã¢ã³ã¹ããŒã«ã«å¹Žé$8,000ïœ$25,000ãããã®ãšæ¯èŒããå Žåã§ããã«ã¹ã¿ã ãã©ãããã©ãŒã ã¯2ïœ4å¹Žã§æè³ãååã§ããããæ·±ãçµ±åãšå®å šãªããŒã¿æææš©ãæäŸããŸãã
å°éããŒã ãã客æ§ã®ããžãã¹ã®ããã«ãã®ãœãªã¥ãŒã·ã§ã³ãæ§ç¯ããæ¹æ³ã«ã€ããŠãåãåãããã ããã
ãåãåããMicrocosmWorks ã¯ãPHI ã®æå·åãšè©³çްãªã¢ã¯ã»ã¹å¶åŸ¡ãããç¶ç¶çãªãªã¹ã¯è©äŸ¡ãã€ã³ã·ãã³ã察å¿ã®èª¿æŽãç£æ»å¯Ÿå¿ã¬ããŒããŸã§ãå»çããŒã¿ä¿è·ã®å šã©ã€ããµã€ã¯ã«ãèªååãããšã³ãããŒãšã³ãã® HIPAA ã³ã³ãã©ã€ã¢ã³ã¹ã·ã¹ãã ãæäŸããŸãããã®ãã©ãããã©ãŒã ã¯ã3ã€ã®ãã¹ãŠã®
HIPAA å®å šå¯Ÿçã«ããŽãª â 管ççãç©ççãæè¡ç â ãããªã¢ã«ã¿ã€ã ã®ã³ã³ãã©ã€ã¢ã³ã¹ã¹ã³ã¢ãªã³ã°ãåããç¶ç¶çã«ç£èŠãããå¶åŸ¡ãšããŠå®è£ ããŸããBAA ã©ã€ããµã€ã¯ã«ç®¡çã¯ãå¥çŽç· çµããçµäºãŸã§ããããããã³ããŒãšã®é¢ä¿ã远跡ããèªåæŽæ°ã¢ã©ãŒããšã³ã³ãã©ã€ã¢ã³ã¹æ€èšŒãæäŸããŸããçµ±åãããåŸæ¥å¡ãã¬ãŒãã³ã°ã¢ãžã¥ãŒã«ã¯ãå®äºè¿œè·¡æ©èœä»ãã®åœ¹å²ããŒã¹ã® HIPAA æè²ãæäŸããã€ã³ã·ãã³ã察å¿ãšã³ãžã³ã¯ãHHSãã¡ãã£ã¢ãããã³å人ãžã®éç¥ãã«ããŒããèªååãããã¯ãŒã¯ãããŒã«ããã60æ¥éã®æ å ±æŒæŽ©éç¥æéãéµå®ãããããšãä¿èšŒããŸãã
ãã®ã·ã¹ãã ã¯ãHIPAA æºæ ã®ã¯ã©ãŠããã€ãã£ãã¢ããªã±ãŒã·ã§ã³ãšããŠèšèšãããŠãããAWS GovCloud ãŸãã¯å°çšã® HIPAA èªå®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãããã€ãããä¿åæããã³è»¢éæã®æå·åãåºæ¬èŠä»¶ãšããŠããŸããäžå€®ã®ã³ã³ãã©ã€ã¢ã³ã¹ãšã³ãžã³ã¯ãEHR ã·ã¹ãã ãã¯ã©ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ãID ãããã€ããŒãããã³ãšã³ããã€ã³ããšãŒãžã§ã³ããããã¬ã¡ããªãŒãç¶ç¶çã«åéãã45 CFR Parts 160 ããã³ 164 ã«ãããã³ã°ãããå æ¬ç㪠HIPAA å¶åŸ¡ã©ã€ãã©ãªã«å¯ŸããŠããŒã¿ãè©äŸ¡ããŸãã
ç¬ç«ãã PHI ããŒã¿ç®¡çã¬ã€ã€ãŒã¯ãæå·åããŒç®¡çãã¢ã¯ã»ã¹ç£æ»ãã°èšé²ãããã³èªåããŒã¿åé¡ãæäŸããããŒã¿ã«ã¬ã€ã€ãŒã¯ã管çè ãã³ã³ãã©ã€ã¢ã³ã¹æ åœè ãç£æ»äººã«å¯Ÿãã圹å²ã«å¿ããããã·ã¥ããŒããšã¬ããŒãã€ã³ã¿ãŒãã§ãŒã¹ãæäŸããŸãã
管çãšèšå®å¯èœãªã¹ã±ãžã¥ãŒã«ã§ã®èªåããŒããŒã·ã§ã³
ã€ãã³ã â 誰ããäœãããã€ãã©ãã§ããªãè¡ã£ãã â æ¹ãã鲿¢ã®å®å šæ§
PHI ãåŠçãããã¹ãŠã®ã·ã¹ãã ã«ãããå¶åŸ¡ã®æå¹æ§ãç¶ç¶çã«è©äŸ¡
æéåãã¢ã©ãŒããã³ã³ãã©ã€ã¢ã³ã¹æ€èšŒãããã³çµäºã¯ãŒã¯ãããŒ
ä¿å šãããã³ HHSãå·åžæ³é·å®ãã¡ãã£ã¢ã
圱é¿ãåããå人ãžã®å€ãã£ã³ãã«éç¥
| ã¬ã€ã€ãŒ | ãã¯ãããžãŒ |
|---|---|
| ããã¯ãšã³ã | Java (Spring Boot), Python, Apache Kafka, REST APIs |
| AI / ML | spaCy (PHI æ€åº), TensorFlow (ç°åžžæ€åº), Drools (ã«ãŒã«) |
| ããã³ããšã³ã | Angular, TypeScript, Material UI, Apache ECharts |
| ããŒã¿ããŒã¹ | PostgreSQL (æå·åæžã¿), Amazon DynamoDB, S3 (SSE-KMS), Redis |
| ã€ã³ãã©ã¹ãã©ã¯ã㣠| AWS GovCloud, Kubernetes (EKS), Terraform, AWS KMS, CloudTrail, GuardDuty |
| ææš | æ¹å | 詳现 |
|---|---|---|
| ç£æ»å¯Ÿå¿æºå | æºåæéã95%åæž | ç¶ç¶çãªèšŒæ åéã«ãããæ°é±éã«ãããæåã®ç£æ»æºåãäžèŠã«ãªããŸã |
| PHI ã¢ã¯ã»ã¹å¯èŠæ§ | 100%ã«ã㌠| ä¿è·å»çæ å ±ãžã®ãã¹ãŠã®ã¢ã¯ã»ã¹ãèšé²ãããã¬ãã¥ãŒå¯èœã«ãªããŸã |
| ãªã¹ã¯è©äŸ¡ã®å®æœé »åºŠ | ç¶ç¶ç | 幎1åã®æç¹ç㪠SRA ãç¶ç¶çãªé©å¿è©äŸ¡ã«çœ®ãæããŸã |
| æ å ±æŒæŽ©å¯Ÿå¿æé | 75%é«éå | èªååããããã¬ã€ããã¯ããæ€åºããéç¥ãŸã§ããŒã ãå°ããŸã |
| ãã¬ãŒãã³ã°ã³ã³ãã©ã€ã¢ã³ã¹ | 99%å®äº | èªåå²ãåœãŠãšãšã¹ã«ã¬ãŒã·ã§ã³ã«ãããåŸæ¥å¡ã® HIPAA ãã¬ãŒãã³ã°ã確å®ã«å®æœãããŸã |
1. 1-3é±ç®: HIPAA ã®ã£ããè©äŸ¡ãPHI ããŒã¿ã€ã³ãã³ããªãããã³ã€ã³ãã©ã¹ãã©ã¯ãã£ã»ãã¥ãªãã£ããŒã¹ã©ã€ã³ç£æ»
2. 4-6é±ç®: EHR ã·ã¹ãã å šäœã§ã®æå·åå±éãã¢ã¯ã»ã¹å¶åŸ¡å®è£ ãããã³ç£æ»ãã°èšé²ã®æå¹å
3. 7-9é±ç®: ãªã¹ã¯è©äŸ¡ã¢ãžã¥ãŒã«èšå®ãBAA ã€ã³ãã³ããªç§»è¡ãããã³ãã³ããŒã³ã³ãã©ã€ã¢ã³ã¹æ€èšŒ
4. 10-11é±ç®: ã€ã³ã·ãã³ã察å¿ãã¬ã€ããã¯éçºãæ å ±æŒæŽ©éç¥ã¯ãŒã¯ãããŒãã¹ããããã³åŸæ¥å¡ãã¬ãŒãã³ã°å±é
5. 12-14é±ç®: ããã·ã¥ããŒãå±éãã³ã³ãã©ã€ã¢ã³ã¹ã¹ã³ã¢ãªã³ã°èª¿æŽãæš¡æ¬ç£æ»å®æœãããã³æ¬çªç°å¢ãžã®åŒãæž¡ã
決ããŠä¿¡çšãããåžžã«æ€èšŒãã â å¢çããŒã¹ã®ã»ãã¥ãªãã£ãããã¹ãŠã®ãŠãŒã¶ãŒãšããã€ã¹ã«å¯ŸããIDäžå¿ã®ãç¶ç¶çã«æ€èšŒãããã¢ã¯ã»ã¹ã«çœ®ãæããŸãã