首页> 外文会议>ICSE workshop on software engineering in health care 2010 >Towards Improved Security Criteria for Certification of Electronic Health Record Systems
【24h】

Towards Improved Security Criteria for Certification of Electronic Health Record Systems

机译:迈向电子病历系统认证的改进安全标准

获取原文
获取原文并翻译 | 示例

摘要

The Certification Commission for Health Information Technology (CCHIT) is an electronic health record certification organization in the United States. In 2009, CCHIT's comprehensive criteria were augmented with security criteria that define additional functional security requirements. The goal of this research is to illustrate the importance of requiring misuse cases in certification standards, such as CCHIT, by demonstrating the implementation bugs in an open source healthcare IT application. We performed an initial evaluation of an open source electronic health record system, OpenEMR, using an automated static analysis tool and a penetration testing tool. We were able to discover implementation bugs latent in the application, ranging from cross-site scripting to insecure cryptographic algorithms. Our findings stress the importance that certification security criteria should focus on implementation bugs as well as design flaws. Based upon our findings, we recommend that CCHIT be augmented with a set of misuse cases that check for specific threats against EMR systems and thereby improve this aspect of the certification process.
机译:健康信息技术认证委员会(CCHIT)是美国的电子健康记录认证组织。 2009年,CCHIT的综合标准增加了定义其他功能安全要求的安全标准。这项研究的目的是通过演示开源医疗保健IT应用程序中的实现错误,来说明在认证标准(例如CCHIT)中要求滥用案例的重要性。我们使用自动化的静态分析工具和渗透测试工具对开源电子健康记录系统OpenEMR进行了初步评估。我们能够发现应用程序中潜在的实现错误,范围从跨站点脚本到不安全的密码算法。我们的研究结果强调了认证安全性标准应着重于实施错误以及设计缺陷的重要性。根据我们的发现,我们建议在CCHIT中增加一系列滥用案例,以检查针对EMR系统的特定威胁,从而改善认证过程的这一方面。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号