Access control hygiene and the empathy gap in medical IT

  • Authors:
  • Yifei Wang;Sean Smith;Andrew Gettinger

  • Affiliations:
  • Department of Computer Science, Dartmouth College;Department of Computer Science, Dartmouth College;Department of Computer Science, Dartmouth College

  • Venue:
  • HealthSec'12 Proceedings of the 3rd USENIX conference on Health Security and Privacy
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

In theory, access control is a solved problem. In practice, large real-world enterprises still report trouble: de facto policy becomes unmanageable; users circumvent controls. These issues can be particularly critical in medical IT, such as emerging EMR and EHR, where access control errors can have serious repercussions. In this paper, we investigate how real-world EMR users think about access control when they are making policy decisions in the abstract-and when they are actually using the system in treatment scenarios. Mismatches suggest places ("empathy gaps") where new policy tools may be needed.