首页> 外文期刊>Decision support systems >Optimal information security investment in a Healthcare Information Exchange: An economic analysis
【24h】

Optimal information security investment in a Healthcare Information Exchange: An economic analysis

机译:在医疗保健信息交换中的最佳信息安全投资:经济分析

获取原文
获取原文并翻译 | 示例
           

摘要

The complexity of the problem, the increasing security breaches, and the regulatory and financial consequences of breached patient data highlight the fact that security of electronic patient information in Healthcare Information Exchanges (HIEs) is an organizational imperative and a research priority. This study applies classical economic decision analysis techniques and models the HIE based on its network characteristics to offer key insights into the issue of determining the optimal level of information security investment We find that for an organization in a HIE, only security events with the potential loss reaching some critical value are worth protecting, and organizations would only spend a fraction of the intrinsic security risk on protection measures. Even when business benefit from security investment exists, organizations in a HIE tend to invest based on risk reduction alone. The implications of such decisions made at the node level and the resulting built-in moral hazard at the HIE level is discussed.
机译:问题的复杂性,不断增加的安全漏洞以及泄露的患者数据的法规和财务后果突出表明了以下事实:医疗信息交换(HIE)中的电子患者信息安全是组织的当务之急,也是研究的重点。这项研究运用经典的经济决策分析技术,并基于HIE的网络特征对HIE进行建模,从而为确定最佳信息安全投资水平的问题提供关键见解。我们发现,对于HIE中的组织而言,只有具有潜在损失的安全事件达到某个临界值值得保护,并且组织仅将固有安全风险的一小部分用于保护措施。即使存在从安全投资中获得业务收益的情况,HIE中的组织也倾向于仅基于降低风险进行投资。讨论了在节点级别做出此类决策的含义以及在HIE级别上导致的内置道德风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号