首页> 外文会议>International Conference on Healthcare Informatics >Using Access Control to Mitigate Insider Threats to Healthcare Systems
【24h】

Using Access Control to Mitigate Insider Threats to Healthcare Systems

机译:使用访问控制来减轻对医疗保健系统的内幕威胁

获取原文
获取外文期刊封面目录资料

摘要

Rapid and reliable sharing of patient information across healthcare systems is a major technological factor in improving healthcare. Although such sharing would lower costs, applicable laws and regulations, e.g., HIPAA in the United States, impose security and privacy guarantees that necessitate appropriate access control mechanisms to protect healthcare data. Many currently used access control models in healthcare systems are inadequate, as demonstrated by the constant successful attacks on these systems. As protecting healthcare information and systems from malicious or inadvertent attacks by authorized insiders is crucial, this paper investigates insider threats and develops an approach to protect such information from unauthorized or improper use, disclosure, alteration, and destruction by healthcare personnel. A threat model is designed and constructed for access control in healthcare systems, and used to assess the effectiveness of common access control models such as Role-Based Access Control and Attribute-Based Access Control.
机译:在医疗保健系统上快速可靠地分享患者信息是改善医疗保健的主要技术因素。虽然此类共享将降低成本,适用的法律法规,例如,美国的HIPAA,施加安全和隐私保障,这需要适当的访问控制机制来保护医疗保健数据。医疗保健系统中的许多目前使用的访问控制模型不足,正如这些系统对这些系统的不断的成功攻击所证明的。由于授权内部人保护医疗信息和来自恶意或无意攻击的医疗信息和系统至关重要,本文调查了内部威胁,并制定了通过医疗保健人员免受未经授权或不当使用,披露,改变和破坏来保护此类信息的方法。威胁模型是为医疗系统中的访问控制而设计和构建,并用于评估公共访问控制模型的有效性,例如基于角色的访问控制和基于属性的访问控制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号