...
首页> 外文期刊>Journal of medical Internet research >An Evaluation of Personal Health Information Remnants in Second-Hand Personal Computer Disk Drives
【24h】

An Evaluation of Personal Health Information Remnants in Second-Hand Personal Computer Disk Drives

机译:二手个人计算机磁盘驱动器中个人健康信息残留的评估

获取原文

摘要

Background: The public is concerned about the privacy of their health information, especially as more of it is collected, stored, and exchanged electronically. But we do not know the extent of leakage of personal health information (PHI) from data custodians. One form of data leakage is through computer equipment that is sold, donated, lost, or stolen from health care facilities or individuals who work at these facilities. Previous studies have shown that it is possible to get sensitive personal information (PI) from second-hand disk drives. However, there have been no studies investigating the leakage of PHI in this way.Objectives: The aim of the study was to determine the extent to which PHI can be obtained from second-hand computer disk drives.Methods: A list of Canadian vendors selling second-hand computer equipment was constructed, and we systematically went through the shuffled list and attempted to purchase used disk drives from the vendors. Sixty functional disk drives were purchased and analyzed for data remnants containing PHI using computer forensic tools.Results: It was possible to recover PI from 65% (95% CI: 52%-76%) of the drives. In total, 10% (95% CI: 5%-20%) had PHI on people other than the owner(s) of the drive, and 8% (95% CI: 7%-24%) had PHI on the owner(s) of the drive. Some of the PHI included very sensitive mental health information on a large number of people.Conclusions: There is a strong need for health care data custodians to either encrypt all computers that can hold PHI on their clients or patients, including those used by employees and subcontractors in their homes, or to ensure that their computers are destroyed rather than finding a second life in the used computer market.
机译:背景:公众关注其健康信息的隐私,尤其是随着越来越多的信息以电子方式收集,存储和交换。但是我们不知道数据保管者泄漏个人健康信息(PHI)的程度。数据泄漏的一种形式是通过医疗设备或在这些设备上工作的个人出售,捐赠,丢失或失窃的计算机设备。先前的研究表明,可以从二手磁盘驱动器中获取敏感的个人信息(PI)。然而,目前还没有研究以这种方式泄漏PHI的研究。目的:研究的目的是确定从二手计算机磁盘驱动器中获得PHI的程度。方法:加拿大销售卖方的清单建造了二手计算机设备,然后我们有条不紊地浏览了清单,尝试从供应商那里购买二手磁盘驱动器。购买了60个功能性磁盘驱动器,并使用计算机取证工具分析了包含PHI的数据残留。结果:可以从驱动器的65%(95%CI:52%-76%)中恢复PI。共有10%(95%CI:5%-20%)的驱动器所有者以外的人拥有PHI,并且8%(95%CI:7%-24%)的所有者拥有PHI驱动器。某些PHI包含了对许多人非常敏感的心理健康信息。结论:卫生保健数据保管人强烈需要对可以在其客户或患者身上保存PHI的所有计算机进行加密,包括员工和患者使用的计算机。分包商,或确保销毁其计算机,而不是在二手计算机市场中找到第二生命。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号