首页> 外文会议>IFIP WG 11.11 international conference on trust management >Improving the Exchange of Lessons Learned in Security Incident Reports: Case Studies in the Privacy of Electronic Patient Records
【24h】

Improving the Exchange of Lessons Learned in Security Incident Reports: Case Studies in the Privacy of Electronic Patient Records

机译:改进安全事件报告中的经验教训交流:电子病历隐私中的案例研究

获取原文

摘要

The increasing use of Electronic Health Records has been mirrored by a similar rise in the number of security incidents where confidential information has inadvertently been disclosed to third parties. These problems have been compounded by an apparent inability to learn from previous violations; similar security incidents have been observed across Europe, North America and Asia. This paper presents the results of an empirical study that evaluates the utility and usability of conventional text-based security incident reports with a graphical formalism based on the Goal Structuring Notation. The two methods were compared in term of the users' ability to identify a number of lessons learned from investigations into previous incidents involving the disclosure of healthcare records. These lessons included both the causes of the incident but also the participants' ability to understand the reasons why particular recommendations were proposed as ways of avoiding future violations. Even using a relatively small sample, we were able to obtain statistically significant differences between the two approaches. The study showed that the graphical approach resulted in higher accuracy in terms of number of correct answers generated by participants. However, subjective feedback raised further questions about the usability of both approaches as the readers of security incident reports try to interpret the lessons that can increase the security of patient data.
机译:电子病历的使用不断增加,也反映了安全事件数量的类似增加,在这种情况下,机密信息被无意间泄露给了第三方。这些问题由于显然无法从以前的违法行为中吸取教训而变得更加复杂。在欧洲,北美和亚洲也观察到类似的安全事件。本文介绍了一项实证研究的结果,该研究使用基于目标结构表示法的图形化形式来评估常规的基于文本的安全事件报告的实用性和可用性。比较了两种方法的用户识别用户能力的能力,这些能力是从对涉及医疗记录披露的先前事件进行调查中吸取的教训。这些课程既包括事件的原因,也包括参与者理解提出特定建议的原因的能力,这些建议是避免将来发生违规行为的方法。即使使用相对较小的样本,我们也能够获得两种方法之间的统计学显着差异。研究表明,图形化方法可以提高参与者产生的正确答案的准确性。但是,由于安全事件报告的读者试图解释可以提高患者数据安全性的课程,因此主观反馈对这两种方法的可用性提出了进一步的疑问。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号