HIPAA's effect on web site privacy policies

被引:26
作者
Anton, Annie I. [1 ]
Earp, Julia B.
Vail, Matthew W.
Jain, Neha
Gheen, Carrie M.
Frink, Jack M.
机构
[1] N Carolina State Univ, Coll Engn, Raleigh, NC 27695 USA
[2] N Carolina State Univ, Coll Management, Raleigh, NC 27695 USA
基金
美国国家科学基金会;
关键词
13;
D O I
10.1109/MSP.2007.7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A study was conducted to examine the effects of the 1996 Health Information and Portability Accountability Act's (HIPAA) enactment on a collection of privacy policy documents for a nine organizations over four-year period. Online documents of nine healthcare institutions such as GlaxoSmithKline and HealthCentral were analyzed using goal-driven requirements engineering and text readability metrics. The privacy statements of each healthcare institutions were analyzed prior to HIPAA's enactment. Various goals of the PGMT goal repository such as G867, G642, G1166, and G1167 were identified and classified as privacy protection or vulnerabilities goals. Flesch Reading Ease Score (FRES) and Flesch Kincaid Grade Level (FGL)score methods were used to quantify readability of documents. It was observed that pre-HIPAA study took 183 person hours to extract goals from 23 privacy documents in comparison of 34 person hours for 24 post-HIPAA documents.
引用
收藏
页码:45 / 52
页数:8
相关论文
共 13 条
[1]  
Anton A.I., 2002, P 10 ANN IEEE JOINT, P605
[2]   Financial privacy policies and the need for standardization [J].
Anton, AI ;
Earp, JB ;
He, QF ;
Stufflebeam, W ;
Bolchini, D ;
Jensen, C .
IEEE SECURITY & PRIVACY, 2004, 2 (02) :36-45
[3]   Inside JetBlue's privacy policy violations [J].
Antón, AI ;
He, QF ;
Baumer, DL .
IEEE SECURITY & PRIVACY, 2004, 2 (06) :12-18
[4]   A requirements taxonomy for reducing Web site privacy vulnerabilities [J].
Antón, AI ;
Earp, JB .
REQUIREMENTS ENGINEERING, 2004, 9 (03) :169-185
[5]  
BAUMER D, 2000, ACM COMPUTERS SOC, V30, P40, DOI [10.1145/572260, DOI 10.1145/572260]
[6]  
Cranor L., 2002, The platform for privacy preferences 1.0 (p3p1.0) specification. Technical report
[7]  
*FED TRAD COMM, 1998, PRIV ONL REP C
[8]  
Flesch R.F., 1949, Art of readable writing
[9]  
Fox S., 2003, INTERNET HLTH RESOUR
[10]  
GOLDMAN J, 2000, PRIVACY REPORT PRIVA