Security Evaluation and Assurance of Electronic Health Records

被引:0
作者
Weber-Jahnke, Jens H.
机构
来源
ADVANCES IN INFORMATION TECHNOLOGY AND COMMUNICATION IN HEALTH | 2009年 / 143卷
关键词
EHR; relative conformance; security assurance; requirements engineering;
D O I
10.3233/978-1-58603-979-0-290
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Electronic Health Records (EHRs) maintain information of sensitive nature. Security requirements in this context are typically multilateral, encompassing the viewpoints of multiple stakeholders. Two main research questions arise from a security assurance point of view, namely how to demonstrate the internal correctness of EHRs and how to demonstrate their conformance in relation to multilateral security regulations. The above notions of correctness and conformance directly relate to the general concept of system verification, which asks the question "are we building the system right?" This should not be confused with the concept of system validation, which asks the question "are we building the right system?" Much of the research in the medical informatics community has been concerned with the latter aspect (validation). However, trustworthy security requires assurances that standards are followed and specifications are met. The objective of this paper is to contribute to filling this gap. We give an introduction to fundamentals of security assurance, summarize current assurance standards, and report on experiences with using security assurance methodology applied to the EHR domain, specifically focusing on case studies in the Canadian context.
引用
收藏
页码:290 / 296
页数:7
相关论文
共 13 条
[1]  
Allas A., 2006, Canada Health Infoway : EHRS Blueprint
[2]  
*BC MIN HLTH, 2007, REQ PROP EL MED REC
[3]  
Bishop M, 2003, Computer security: art and science
[4]  
Gregoire J., 2007, 3 INT WORKSH SOFTW E
[5]  
Herrmann D.S., 2003, USING COMMON CRITERI
[6]  
*HLTH CAN INF, 2005, AUD PRES EXP PAN REV
[7]  
*HLTH CAN INF, 2005, EL HLTH REC EHR PRIV
[8]  
Howard M., 2006, The security development lifecycle
[9]  
IBRAHIM L, 2004, CMMI SAFETY SECURITY
[10]  
Lau F., 2006, Healthcare Quarterly, V10, P112