Organization of Health Related Data Using Computer
Session 1: Organization of Health Related Data Using Computer
Packages
Learning Tasks
By the end of this session students are expected to be able to:
What is Data Storage
Data storage is the recording (storing) of information (data) in a storage medium.
Numerate four (4) storage media
List four (4) electronic Data storage formats
HMIS NOTES
B.Boy
List five (5) storage devices
Numerate Three (3) common type’s data storage
Explanation of each type of Storage
o The term "hard drive" is actually short for "hard disk drive."
o The term "hard disk" refers to the actual disks inside the drive.
o The hard drive is a non-volatile memory hardware device that permanently stores and
retrieves data on a computer.
Non-volatile memory is a term used to describe any memory or storage that is saved
regardless if the power to the computer is on or off.
The best example of non-volatile memory and storage is a computer hard drive, flash
memory, and ROM.
HMIS NOTES
B.Boy
o A hard drive is a secondary storage device that consists of one or more platters to which
data is written using a magnetic head, all inside of an air-sealed casing.
o A typical hard drive is only slightly larger than a human hand and can hold over 100
GB of data.
o A USB flash drive is a device used for data storage that includes a flash memory and an
integrated Universal Serial Bus (USB) interface.
o Most USB flash drives are removable and rewritable.
o Physically, they are small, durable and reliable.
o The larger their storage space, the faster they tend to operate.
o USB flash drives are mechanically very robust because there are no moving parts.
o They derive the power to operate from the device to which they are connected (typically
a computer) via the USB port.
o A USB flash drive may also be known as a flash drive or USB drive.
o A memory card is a type of storage device that is used for storing media and data files.
o It provides a permanent and non-volatile medium to store data and files from the
attached device.
Define the Term Memory Card
Memory cards are commonly used in small, portable devices, such as cameras and phones.
List five (5) most popular forms of memory cards are:
HMIS NOTES
B.Boy
In the healthcare system, data are store in the electronic systems, and these systems are
called electronic health records (EHR) and electronic medical records (EMR)
Define the following Terms
o An electronic health record (EHR) is a digital version of a patient’s paper chart.
o It contains a patient’s medical history, diagnoses, medications, treatment plans,
immunization dates, allergies, radiology images, and laboratory and test results in
electronic format.
o It is health information that is created and managed by authorized providers in a digital
format capable of being shared with other providers across more than one health care
organization.
o Electronic medical records (EMRs) are a digital version of the paper charts in the clinician’s
office.
o EMR contain medical information used by clinicians mostly for diagnosis and treatment..
o An EMR contains the medical and treatment history of the patients in one practice.
o Information in EMRs cannot easily be shared out of the medical practice.
o The patient’s record can easily be printed out and shared with other members of the care
team.
HMIS NOTES
B.Boy
ELECTRONIC FILLING
Filling
A filing system is a plan or method of arranging documents in a prescribed order.
The purpose of filing documents is to enable a quick retrieval of complete information
Whenever it is required.
Requirements of a good filing system
o Simplicity-The filing method must be easy to understand and simple to operate.
o Easy access-Documents should be easily identified and located to enable speedy pulling and
filing.
o Security-Documents should be safely kept and well preserved.
o Tracer system-The whereabouts of documents removed from the storage must be known.
Methods of Filing in Medical Records
There are four common methods of filing patient records used in health facilities
o Alphabetical
o Chronological
o Geographical
o Numerical
HMIS NOTES
B.Boy
Explanation of each method
Alphabetical Filing System
Chronological Filing System
Chronological filing means filing in time order.
each group in date order. Example of chronological filing system is, those patients who are
expected to be admitted on 14th February 2010, Abdallah/14, Bakari/14, Charles/14. The 14 is
a filing position in filing waiting list.
Geographical Filing System
Geographical filing is based on geographical units like countries, regions, and town.
and customers is needed.
method used in combination with other method of filing.
HMIS NOTES
B.Boy
o Temeke district: 00-00-01/Temeke, 00-00-02/Temeke, 00-00-03/Temeke. (Filing is done in
shelves identified for Temeke district).
o Kinondoni district: 00-00-04/Kinondoni, 00-00-05/Kinondoni. (Filing is done in shelves
identified for Kinondoni district).
Numerical Filing System
Numerical and alphabetical filing systems are the most commonly used.
Explanation on Numbering Filling
Numbering System in Patient Medical Records
medical records according to these numbers.
Types of Numbering Systems
o In serial numbering the patient receives a new number each time he or she is admitted or
treated as a new out-patient case.
o This means that if a patient is admitted three times he or she gets three different numbers and
his medical records are filed in three different places.
o This system is based on the principle that the patient (not the disease episode and a patient) is
the unit and that all notes on one individual patient are kept in one file.
o When serial numbering is used the series of numbers should continue.
HMIS NOTES
B.Boy
o It is quite common in Tanzania to begin new series each year or even each month and to
distinguish the series by a letter and by the last two calendar year digits or the digits for month
and calendar year (Example: F 2345/78, M 6789/4/78).
Patient Records Filing Procedures
Filing Procedure for Patient Records
o Critical checking, if there is missing documents from the clinics/departments
o Arrange documents in a systematically order, for example from registration sheet to
discharge summary Sorting of patients’ file
o Arrange files in a sequence order, from the smallest number to the largest one.
o It facilitates speed in filing
o Insert files in the shelf according to the patient registration number or the alphabetic order of
their names
HMIS NOTES
B.Boy
THE TYPES OF FILING
Explain the types of Filling
o Paper based system
Filing of all documents that should be part of the complete health records are added to
the discharge record, preferably prior to completion.
As with the addition of any document to the record, care should be taken to verify the
resident name prior to inserting the document in the record.
o Hybrid system
The facility policies and procedures should determine which parts of the record will be
paper based and which parts are stored in a data repository.
This policy should also determine whether or not additional documents should be
added as paper based documents or scanned into the data repository.
If documents are added to the electronic portion of the record after this has been
completed, these should be added as addendums.
o Electronic record
The facility policies and procedures should allow for the capture of additional
material for the electronic record through a system of scanning to the file.
If the record has been determined to be complete and additional paperwork is
discovered, these documents should be added as addendums.
The electronic system should be able to separate the active from the inactive record
within the data base
HMIS NOTES
B.Boy
APPLICATION OF SECURITY TO DATA
Computer Security
Security is the protection of assets. It deals with the protection of unauthorized actions by users
of a computer system.
OR
Computer Security Is protecting computers and information they contain against unwanted
access, damage, modification or destruction.
Restricted access to the server computer room is present in a form of Physical Security
Main objectives of computer security are
The three main aspects of Security are:
Some differences between traditional security and information security
HMIS NOTES
B.Boy
What features should a computer security system provide?
Confidentiality
The prevention of unauthorized disclosure of information.
Confidentiality is keeping information secret or private.
Confidentiality might be important for military, business or personal reasons.
Integrity
Integrity is the unauthorised writing or modification of information.
Integrity means that there is an external consistency in the system – everything is as it is
expected to be.
Data integrity means that the data stored on a computer is the same as the source documents.
Availability
Information should be accessible and useable upon appropriate demand by an authorised user.
Availability is the prevention of unauthorised withholding of information.
Denial of service attacks are a common form of attack.
Non-repudiation
Non-repudiation is the prevention of either the sender or the receiver denying a transmitted
message.
A system must be able to prove that certain messages were sent and received.
Non-repudiation is often implemented by using digital signatures.
Authentication
Proving that you are who you say you are, where you say you are, at the time you say it is.
HMIS NOTES
B.Boy
Authentication may be obtained by the provision of a password or a scan of your retina.
Access Controls
The limitation and control of access through identification and authentication.
A system needs to be able to identify and authenticate users for access to data, applications and
hardware.
In a large system there may be a complex structure determining which users and applications
have access to which objects.
Accountability
The system managers are accountable to scrutiny from outside.
Audit trails must be selectively kept and protected so that actions affecting security can be
traced back to the responsible party
Security systems
A security system is not just a computer package. It also requires security conscious personnel
who respect the procedures and their role in the system.
Conversely, a good security system should not rely on personnel having security expertise.
Risk Analysis
The disadvantages of a security system are that they are time-consuming, costly, often clumsy,
and impede management and smooth running of the organisation.
Risk analysis is the study of the cost of a particular system against the benefits of the system.
HMIS NOTES
B.Boy
Ways of improve electronic patient data security/ The steps to enforce proper use of
password to keep electronic data secure.
o Do a security risk assessment
Information security risk assessment is an on-going process of discovering, correcting
and preventing security problems.
The risk assessment is an integral part of a risk management process designed to
provide appropriate levels of security for information systems.
Security risk assessments must be performed annually to meet the criteria of the
meaningful use of an HER
o Encrypt data
Encryption is the process of encoding a message or information in such a way that
only authorized parties can access it and those who are not authorized cannot.
Patient data should be encrypted whenever possible
Antivirus programs and firewalls to defend the privacy and security of data should be
installed in the system
Use password to protect data from being accessed with unauthorized persons
o Control system access
Access control is a key component of patient data security.
List two main types of access control
Physical access control limits access to buildings, rooms and physical IT assets where
patient data are stored.
Logical access limits connections to computer networks, system files and health data.
HMIS NOTES
B.Boy
o Authenticate users
Authentication is the process of recognizing a user’s identity.
Authentication process can be described in two distinct phases: identification and
actual authentication.
Identification phase provides a user identity to the security system and this identity is
provided in the form of a user ID.
An actual user can be mapped to other abstract user object in the system, and
therefore be granted rights and permissions to the user and user must give evidence to
prove his identity to the system.
The process of determining claimed user identity by checking user-provided evidence
is called authentication and the evidence which is provided by the user during process
of authentication is called a credential.
o Use and scan audit logs
An audit log is a document that records an event in an information (IT) technology
system.
It is a security-relevant chronological record, set of records, destination and source of
records that provide documentary evidence of the sequence of activities that have
affected at any time a specific operation, procedure, or event.
It documents what resources were accessed; audit log entries usually include
destination and source addresses, timestamp and user login information.
EHRs have audit logs that record which user did what in the EHR and when.
Most of hospitals that practices EHR were using their audit logs or another feature
designed to prevent people from tampering with the logs to erase the signs of an
intruder.
EHR practices need software that automatically scans their audit logs to detect
anomalies that might indicate a cyber-attack, such as an unfamiliar user or a known
user logging on at an unusual time of the day.
HMIS NOTES
B.Boy
o Back up data off site
An offsite backup is a backup process or facility that stores backup data or
applications external to the organization or core IT environment.
It is similar to a standard backup process, but uses a facility or storage media that is
not physically located within the organization's core infrastructure.
The institution that practices EHR should have off site backup, both for security
purposes and also for the case of natural disasters.
HMIS NOTES
B.Boy
CYBER SECURITY
Terminologies
Cyber Space (Area)
It’s the term means computer network connected together and connect to the host.
Cyber Crime
It’s the term that referrers to the attack of the computer that its connected to a network system.
Masquerade attack
PASSWORD SECURITY (AUTHENTICATION)
A Security Token
Is a physical or digital device that provide two factor authentication for a user to prove their
identity in a login process
Traditional known as Password
Types of Security Token
HMIS NOTES
B.Boy
Explanation of the Types of Security Token
One Factor Authentications (1FA)
Use of Random Numbers hence expires after a period of Time.
Two Factor Authentications (2FA)
Use of Numbers and Letters (Alphabets)
Three Factor Authentications (3FA)
Use of Numbers, Letters (Alphabets) and Human recognitions i.e Face recognition, Finger
prints.
BIOMETRIC SECURITY
Definition
Is the use of Software to automatically Recognize people based on their behavioural or
biological characteristics.
Types of Biometric Security Devices
DNA Matching
Eye Iris Recognition
Face Recognition
Hand Geometry Recognition
Typing Recognition
Voice Speaker Identification
HMIS NOTES
B.Boy
List five (5) common cyber-attacks which can be used to damage network
An ideal password authentication scheme has to withstand a number of attacks.
Describe five of these attacks.
Denial of Service Attacks
o An attacker can update false verification information of a legal user for the
next login phase. Afterwards, the legal user will not be able to login
successfully anymore.
Forgery Attacks (Impersonation Attacks)
o An attacker attempts to modify intercepted communications to masquerade the
legal user and login to the system.
Forward Secrecy
o It has to be ensured that the previously generated passwords in the system are
secure even if the system’s secret key has been revealed in public by accident
or is stolen.
Server spoofing attacks
o Mutual authentication can help withstand the server spoofing attack where an
attacker pretends to be the server to manipulate sensitive data of the legal
users. Mutual authentication means the user and the server can authenticate
each other. Not only can the server verify the legal users, but the users can
also verify the legal server.
Parallel Session Attacks
o Without knowing a user’s password, an attacker can masquerade as the legal
user by creating a valid login message out of some eavesdropped
communication between the user and the server.
Password Guessing Attacks
HMIS NOTES
B.Boy
o Most passwords have such low entropy that they are vulnerable to password
guessing attacks, where an attacker intercepts authentication messages and
stores them locally and then uses a guessed password and seeks verify the
correctness of their guess using these authentication messages.
Replay Attacks
o Having intercepted previous communications, an attacker can replay the
intercepted messages to impersonate the legal user to login to the system.
SR8. Smart Card Loss Attacks When the smart card is lost or stolen,
unauthorized
List five (5) computer security challenges
operation.
What are main security threats to computer system?
HMIS NOTES
B.Boy
METHODS OF SUMMARIZING DATA/ WAYS OF DATA PRESENTATION
o The process of placing classified data into tabular form is known as tabulation
o A table is a symmetric arrangement of statistical data in rows and columns
o Rows are horizontal arrangements whereas columns are vertical arrangements
Table 1: Number of patients admitted at Mount Meru hospital in the year 2011
NUMBER OF PATIENTS
AGE
Below 35 1,280
35-55 1,160
Above 55 300
Total 2,740
HMIS NOTES
B.Boy
Line graph
o A line graph is a graphical tool used to present and compare two variables.
o One variable is represented at X axis and other at Y axis.
o The points given are plotted and are joined together by straight lines.
Figure 1: Annual sales of a particular organization
o A simple bar chart is used to represents data involving only one variable classified on
spatial, quantitative or temporal basis
Figure 2: Hospital Patients by unit
Hospital Patients by Unit
5000
4000
patients per year
Number of
3000
2000
1000
0
Emergency
Cardiac
Intensive
Surgery
Maternity
Care
Care
HMIS NOTES
B.Boy
o A two or more sets of inter-related data are represented.
o Multiple bar diagram facilities comparison between more than one phenomena.
Figure 3: The number of Male and Female Cataract at Mwembetogwa ward
THE NUMBER OF MALE & FEMALE CATARACT
SCREENING AT MWEMBETOGWA WARD FROM 1991-1995
14000
12000
10000
NO. Clients
8000 Male
6000 Female
4000
2000
0
1991 1992 1993 1994 1995
Years
HMIS NOTES
B.Boy
o Sub-divided or component bar chart is used to represent data in which the total
magnitude is divided into different or components
Figure 4: The Diabetic Tablets produced from 1991-1994
THE DIABETIC TABLETS IN 100 gms/BOX PRODUCED FROM 1991-
1994
120
100
Quantity in 100 gms
80
Glimepiride
Glyburide
60
Glipizide
Chlorpromide
40
20
0
1991 1992 1993 1994
Years
HMIS NOTES
B.Boy
o Sub-divided bar chart may be drawn on percentage basis
o This type of chart is useful to make comparison in components holding the difference of
total constant
Figure 5: Inpatient cases at Medical ward-MNH 1991-1994
INPATIENT CASES IN HUNDRED AT MEDICAL WARD-MNH
FROM 1991-1994
100%
90%
Number of Cases in %
80%
70%
60% MTA
50% HIV/AIDS
40% Malaria
30%
20%
10%
0%
1991 1992 1993 1994
Years
HMIS NOTES
B.Boy
o Pie chart is named so, due to its similarity with pie and its slices.
o Pie chart is a circular chart which is divided into sectors.
o Each sector corresponds to different values of a data.
o In pie charts, the percentage of each number is calculated and then obtained
percentages are plotted at pie chart.
Figure 6: Hospital Patients by Unit
Hospital Patients by Unit
Cardiac
Care
12%
Emergenc
Surgery y
53% 25%
Intensive
Care
Maternity 4%
6%
HMIS NOTES
B.Boy
o A bar graph that displays the data from a frequency distribution
o Horizontal Scale (x-axis) is labeled using CLASS BOUNDARIES or MIDPOINTS
o Vertical Scale (y-axis) is labeled using frequency
o Bars are contiguous (No gaps)
Figure 7: Time to complete blood transfusion
Time to Complete Blood Transfusion
30
Fr 25
eq
ue 20
nc
y 15 Frequenc y
10
5
0
235.5 260.5 285.5 310.5 335.5 360.5
Minutes
HMIS NOTES
B.Boy
o It presented by using Line graph rather than a bar graph.
o It uses class midpoints rather than class boundaries on x-axis
Figure 8: Frequency polygon for Blood pressure data
Frequency Polygon for B.P.
18
16
14
12
Frequency
10
8
6
4
2
0
92.5 106.5 120.5 134.5 148.5 162.5 176.5 190.5 204.5 218.5
Systolic Pressure
HMIS NOTES
B.Boy
o Line graph (rather than a bar graph)
o Uses class boundaries on x-axis
o Uses cumulative frequencies (total as you go) rather than individual class frequencies
o Used to visually represent how many values are below a specified upper class boundary
Figure 9: Blood Pressure of fifty subjects
Blood Pressures of 50 Subjects
60
Cummulative Frequency
50
40
30
20
10
0
99.5 127.5 155.5 183.5 211.5
Systolic Pressure
HMIS NOTES
B.Boy
Evaluation Questions
Is the means of storing soft data information in given format like Music, Video, Document or
Pictures in a device which could be a flash disk or rather a hard disk drive
Or Data storage is the collective methods and technologies that capture and retain digital
information on electromagnetic, optical or silicon-based storage media.
Data security is the practice of protecting digital information from unauthorized access,
corruption, or theft throughout its entire lifecycle
.
Discrete and continuous data
Statistical data
HMIS NOTES
B.Boy
management process at pharmacy information system.
o Do a security risk assessment
Information security risk assessment is an on-going process of discovering, correcting
and preventing security problems.
The risk assessment is an integral part of a risk management process designed to
provide appropriate levels of security for information systems.
Security risk assessments must be performed annually to meet the criteria of the
meaningful use of an HER
o Encrypt data
Encryption is the process of encoding a message or information in such a way that
only authorized parties can access it and those who are not authorized cannot.
Patient data should be encrypted whenever possible
Antivirus programs and firewalls to defend the privacy and security of data should be
installed in the system
Use password to protect data from being accessed with unauthorized persons
o Control system access
Access control is a key component of patient data security.
There are two main types of access control: physical and logical.
Physical access control limits access to buildings, rooms and physical IT assets where
patient data are stored.
Logical access limits connections to computer networks, system files and health data.
o Authenticate users
Authentication is the process of recognizing a user’s identity.
Authentication process can be described in two distinct phases: identification and
actual authentication.
HMIS NOTES
B.Boy
Identification phase provides a user identity to the security system and this identity is
provided in the form of a user ID.
An actual user can be mapped to other abstract user object in the system, and
therefore be granted rights and permissions to the user and user must give evidence to
prove his identity to the system.
The process of determining claimed user identity by checking user-provided evidence
is called authentication and the evidence which is provided by the user during process
of authentication is called a credential.
o Use and scan audit logs
An audit log is a document that records an event in an information (IT) technology
system.
It is a security-relevant chronological record, set of records, destination and source of
records that provide documentary evidence of the sequence of activities that have
affected at any time a specific operation, procedure, or event.
It documents what resources were accessed; audit log entries usually include
destination and source addresses, timestamp and user login information.
EHRs have audit logs that record which user did what in the EHR and when.
Most of hospitals that practices EHR were using their audit logs or another feature
designed to prevent people from tampering with the logs to erase the signs of an
intruder.
EHR practices need software that automatically scans their audit logs to detect
anomalies that might indicate a cyber-attack, such as an unfamiliar user or a known
user logging on at an unusual time of the day.
o Back up data off site
An offsite backup is a backup process or facility that stores backup data or
applications external to the organization or core IT environment.
It is similar to a standard backup process, but uses a facility or storage media that is
not physically located within the organization's core infrastructure.
HMIS NOTES
B.Boy
hospital setup.
o The term "hard drive" is actually short for "hard disk drive."
o The term "hard disk" refers to the actual disks inside the drive.
o The hard drive is a non-volatile memory hardware device that permanently stores and
retrieves data on a computer.
Non-volatile memory is a term used to describe any memory or storage that is saved
regardless if the power to the computer is on or off.
The best example of non-volatile memory and storage is a computer hard drive, flash
memory, and ROM.
o A hard drive is a secondary storage device that consists of one or more platters to which
data is written using a magnetic head, all inside of an air-sealed casing.
o A typical hard drive is only slightly larger than a human hand and can hold over 100
GB of data.
o A USB flash drive is a device used for data storage that includes a flash memory and an
integrated Universal Serial Bus (USB) interface.
o Most USB flash drives are removable and rewritable.
o Physically, they are small, durable and reliable.
o The larger their storage space, the faster they tend to operate.
o USB flash drives are mechanically very robust because there are no moving parts.
o They derive the power to operate from the device to which they are connected (typically
a computer) via the USB port.
o A USB flash drive may also be known as a flash drive or USB drive.
o A memory card is a type of storage device that is used for storing media and data files.
o It provides a permanent and non-volatile medium to store data and files from the
attached device.
HMIS NOTES
B.Boy
in health care industry.
Merits
Demerits
data, which can provide a misleading view of the data.
in aiding a presentation less useful
HMIS NOTES
B.Boy
Unataka kutumiwa notes hizi kupitia WhatsApp?Kwa notes zilizopangiliwa vizuri kwa kusoma offline au PDF, bonyeza kitufe hapa chini. Ujumbe wenye Level, Semester, Module na Topic utaandaliwa moja kwa moja.TUMIWA NOTES WHATSAPP