首页> 外文期刊>ACM Transactions on Management Information Systems >Security and Privacy Requirements for Cloud Computing in Healthcare: Elicitation and Prioritization from a Patient Perspective
【24h】

Security and Privacy Requirements for Cloud Computing in Healthcare: Elicitation and Prioritization from a Patient Perspective

机译:医疗保健中云计算的安全和隐私要求:患者视角的诱导和优先次序

获取原文
获取原文并翻译 | 示例

摘要

Cloud computing promises essential improvements in healthcare delivery performance. However, its wide adoption in healthcare is yet to be seen, one main reason being patients' concerns for security and privacy of their sensitive medical records. These concerns can be addressed through corresponding security and privacy requirements within the system engineering process. Despite a plethora of related research, security and privacy requirements for cloud systems and services have seldomly been investigated methodically so far, whereas their individual priorities to increase the system success probability have been neglected. Against this background, this study applies a systematic requirements engineering process: First, based on a systematic literature review, an extensive initial set of security and privacy requirements is elicited. Second, an online survey based on the best-worst scaling method is designed, conducted, and evaluated to determine priorities of security and privacy requirements. Our results show that confidentiality and integrity of medical data are ranked at the top of the hierarchy of prioritized requirements, followed by control of data use and modification, patients' anonymity, and patients' control of access rights. Availability, fine-grained access control, revocation of access rights, flexible access, clinicians' anonymity, as well as usability, scalability, and efficiency of the system complete the ranking. The level of agreement among patients is rather small, but statistically significant at the 0.01 level. The main contribution of the present research comprises the study method and results highlighting the role of strong security and privacy and excluding any trade-offs with system usability. Enabling a richer understanding of patients' security and privacy requirements for adopting cloud computing in healthcare, these are of particular importance to researchers and practitioners interested in supporting the process of security and privacy engineering for health-cloud solutions. It further represents a supplement that can support time-intensive negotiation meetings between the requirements engineers and patients.
机译:云计算承诺在医疗保健交付性能方面的基本改进。然而,它的广泛采用尚未得到看待,患者对其敏感的医疗记录的安全和隐私的关注。这些问题可以通过系统工程过程中的相应安全性和隐私要求来解决这些问题。尽管迄今为止,云系统和服务的安全性和隐私要求已经很少地调查,但是,到目前为止,他们的个人优先事项已经忽略了增加了系统成功概率。在此背景下,本研究适用于系统需求工程过程:首先,基于系统文献综述,阐述了广泛的初始安全和隐私要求。其次,设计,进行了基于最糟糕的缩放方法的在线调查,并进行了评估,以确定安全和隐私要求的优先事项。我们的研究结果表明,医疗数据的机密性和完整性在优先考虑的等级等级的顶部排名,然后控制数据使用和修改,患者的匿名性和患者控制权的访问权。可用性,细粒度的访问控制,撤销访问权限,灵活的访问,临床医生的匿名,以及系统的可用性,可扩展性和效率完成排名。患者之间的一致性程度相当小,但在0.01水平上具有统计学意义。本研究的主要贡献包括研究方法和结果,突出了强大的安全和隐私的作用,并不包括任何具有系统可用性的权衡。能够更加丰富地了解患者的安全性和隐私要求,以便在医疗保健中采用云计算,这些对有兴趣支持健康云解决方案的安全和隐私工程进程的研究人员和从业者特别重要。它进一步代表了可以支持需求工程师和患者之间的时间密集谈判会议的补充。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号