首页> 外文OA文献 >Improving the exchange of lessons learned in security incident reports: case studies in the privacy of electronic patient records
【2h】

Improving the exchange of lessons learned in security incident reports: case studies in the privacy of electronic patient records

机译:改进安全事故报告中的经验教训交流:电子病历中隐私的案例研究

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The increasing use of Electronic Health Records has been mirrored by a similar rise in the number of security incidents where confidential information has inadvertently been disclosed to third parties. These problems have been compounded by an apparent inability to learn from previous violations; similar security incidents have been observed across Europe, North America and Asia. This has resulted in the loss of confidence and trust of the public towards the organisations’ ability to protect the patients’ private information. The Generic Security Template (G.S.T.) has been proposed to communicate security lessons learned from previous security incidents. This paper conducts a series of empirical studies to evaluate the usability of the G.S.T. The first study compares the G.S.T. with the conventional text-based security incident reports. The two methods were compared in term of the users’ ability to identify a number of lessons learned from investigations into previous incidents involving the disclosure of healthcare records. The study showed that the graphical approach resulted in higher accuracy in terms of number of correct answers generated by participants. However, subjective feedback raised further questions about the usability of the G.S.T. as the readers of security incident reports try to interpret the lessons that can increase the security of patient data. The second study further evaluates the usability of the G.S.T. using the Cognitive Dimensions and identifies some aspects that need to be improved.
机译:电子病历的使用不断增加,也反映了安全事件数量的类似增长,在这种情况下,机密信息被无意间泄露给了第三方。这些问题由于显然无法从以前的违规行为中学习而变得更加复杂。在欧洲,北美和亚洲也观察到类似的安全事件。这导致公众对组织保护患者私人信息的能力失去信心和信任。已建议使用通用安全模板(G.S.T.)来传达从以前的安全事件中学到的安全经验。本文进行了一系列的实证研究,以评估G.S.T.第一项研究比较了G.S.T.与传统的基于文本的安全事件报告。比较了这两种方法的用户识别用户能力的能力,这些能力是从对涉及医疗记录披露的先前事件进行调查中吸取的教训。研究表明,图形化方法可以提高参与者产生的正确答案的准确性。但是,主观反馈对G.S.T.的可用性提出了进一步的问题。当安全事故报告的读者试图解释可以提高患者数据安全性的课程时。第二项研究进一步评估了G.S.T.使用认知维度并确定一些需要改进的方面。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号