首页> 外文会议>IEEE International Conference on E-health Networking, Application Services >Risk Analysis Based Security Compliance Assessment and Management for Sensitive Health Data Environment
【24h】

Risk Analysis Based Security Compliance Assessment and Management for Sensitive Health Data Environment

机译:基于风险分析的安全合规性评估和管理敏感健康数据环境

获取原文
获取外文期刊封面目录资料

摘要

The digitisation of personal health information (PHI) through electronic health record (EHR) has become widespread due to their efficiency in terms of cost, storage, processing, and the subsequent quality of delivering patient care. However, security concerns remain one of its major setback. In order to handle EHR, institutions need to comply with their local government security regulations. These regulations control to which extent health data can be processed, transmitted, and stored as well as define how misuses are addressed. This paper proposes Φcomp, a solution for monitoring, assessing, and evaluating the compliance of health applications with respect to defined security regulations. Φcomp is able to assess the level of security risk of an application at runtime and automatically perform the required mitigation actions to recover a compliant environment. Φcomp was implemented in an industrial context and evaluated on a medical appointment application. The results of the experiments showed that it manages the security compliance of third party applications with low performance overhead and attenuate unacceptable levels of risk to restore compliance.
机译:通过电子健康记录(EHR)个人健康信息(PHI)的数字化由于其在成本,储存,加工以及提供患者护理的后续质量方面而普遍存在。但是,安全问题仍然是其主要挫折之一。为了处理EHR,机构需要遵守当地的政府安全法规。这些规则控制可以处理,传输和存储,以及定义如何解决缺陷的方式。本文提出了φCOMP,一种监测,评估和评估卫生应用符合定义安全规定的解决方案。 φcomp能够在运行时评估应用程序的安全风险级别,并自动执行所需的缓解操作以恢复兼容的环境。 φcomp在工业背景下实施,并在医疗申请中进行评估。实验结果表明,它管理第三方应用的安全遵守性能低,性能低,并衰减不可接受的风险恢复合规性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号