Towards the security and privacy analysis of patient portals

  • Authors:
  • Janos L. Mathe;Sean Duncavage;Jan Werner;Bradley A. Malin;Akos Ledeczi;Janos Sztipanovits

  • Affiliations:
  • Institute for Software Integrated Systems, Vanderbilt University, Nashville, TN;Institute for Software Integrated Systems, Vanderbilt University, Nashville, TN;Institute for Software Integrated Systems, Vanderbilt University, Nashville, TN;Department of Biomedical Informatics, Vanderbilt University, Nashville, TN;Institute for Software Integrated Systems, Vanderbilt University, Nashville, TN;Institute for Software Integrated Systems, Vanderbilt University, Nashville, TN

  • Venue:
  • ACM SIGBED Review - Special issues on the NSF team for research in ubiquitous secure technology (TRUST) project reports
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Clinical information systems (CIS) significantly influence the quality and efficiency of health care delivery. However, CIS are complex environments that integrate information technologies, human stakeholders, and patient-specific data. Given the sensitivity of patient data, federal regulations require healthcare providers to adopt policy, as well as technology, protections for patient data. Ad hoc system design and implementation of CIS can cause unforeseen and unintended privacy and security breaches. The introduction of model-based design techniques combined with the development of high-level modeling abstractions and analysis methods provide a mechanism to investigate these concerns by conceptually simplifying CIS without losing expressive power. This work introduces the Model-based Design Environment for Clinical Information Systems (MODECIS) - a graphical design environment that assists CIS architects in formalizing CIS systems as well-defined services. MODECIS leverages Service-Oriented Architectures to create realistic system models at an abstract level. By modeling CIS using abstractions, we enable the analysis of legacy architectures, as well as the design and simulation of, future CIS. We present the feasibility of MODECIS via modeling certain functions, such as the authentication process of the MyHealth@Vanderbilt patient portal.