A technique for strengthening weak passwords in electronic medical record systems

  • Authors:
  • Samuel Tusubira Kalyango;Gilbert Maiga

  • Affiliations:
  • School of Computing and Informatics Technology, Makerere University, Kampala, Uganda;School of Computing and Informatics Technology, Makerere University, Kampala, Uganda

  • Venue:
  • FHIES'11 Proceedings of the First international conference on Foundations of Health Informatics Engineering and Systems
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

The internet has accelerated access to and sharing of electronic medical records (EMR). EMRs are meant to be confidential and only accessed or shared with authorization from the owner. A combination of UserID and a Password is the most widely used mechanism to assure user authentication and access to EMRs. However, these mechanisms have been greatly compromised by guessing and hacking of weak passwords leading to increased cases of medical identity theft, cyber terrorism and information systems attacks. This has resulted in false financial claims, debts due to unauthorized disclosure of the private and confidential EMRs leading to huge losses for the victims. This study developed a technique to strengthen weak passwords that integrates UserIDs, weaker password, salts, challenge responses and random variables to derive a stronger password for authentication. A system prototype to test the technique was built, tested and validated by users.