PubMed Health⌕ Search

SEARCH · PubMed Health

Results for “secured computing”

Explore indexed PubMed citations for clinical trials, systematic reviews and public health research. Read source abstracts and follow each citation to its original PubMed record.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 1,063 records · Page 59Linked to original sources

HIPAA compliance deadlines are fast approaching!

The 1996 Health Insurance Portability and Accountability Act is a broad and complex law that sets out requirements in areas ranging from uniform data management to the privacy and security of health care information. No home care or hospice provider will be compliant with HIPAA without changes in their operation. The author reviews the entities affected by HIPAA, provides the timetable for the law's implementation, and sorts through the wide-ranging security and privacy standards home care providers will have to incorporate into their operations.

Computer Security↗

Formal policies for flexible EHR security.

State of the Art methodologies for establishing requirements and solutions to securing applications are based on narrative descriptions about the use of available system, sometimes also dedicated to system components. Even nowadays new developments to ruling application security services by the use of predicate logic suffer from being administered manually. Therefore, security and privacy requirements cannot be properly met resulting in restrictions and fears for allowing the use of sensitive data and functions. Because of the sensitivity of personal health information and especially of genetic data with its wider implications beyond the original subject of care, weaknesses in guaranteeing fine-grained security and privacy rules lead to less acceptance or even the avoidance of essential information transfer and use. To overcome the problem, security and privacy have to become properties of the architectural components of the respective health information system. Embedding security into the systems architecture allows for negotiating and enforcing any security and privacy services related to principals, their roles, their relationships, further contextual information as well as other regulations summarized in formally modeled policies. The paper introduces the evolving paradigm of the model-driven architecture, first time also comprehensively deployed for security and privacy services in bio-genetic and health information systems.

Authorship↗

Managing educational resource in medicine: system design and integration.

The objective of this paper is to describe our experience in developing a tool based on web technologies, for storing, managing and providing medical courses written by professors in the medical university of Rennes. The increasing number of documents sent by professors leaded us to build a specific resource management system. We created a relational database, containing all meta information about each available document. Professors provide their courses in various formats. We use natural language parsing techniques to extract information from the text, and provide a proper semantic indexation which will be used by a medical-specific search engine. Then the content of our database is dynamically displayed on a web interface. A user's directory identifies teachers and students, controls the access, tracks the students' navigation and allows an on-line discussion forum. This portal contains 524 courses and we had more than 3,000,000 connections on it last year. We are now integrating its content using the semantic web approach in a larger project: the French Virtual Medical University.

Computer Security↗

Intrusion detection using rough set classification.

Recently machine learning-based intrusion detection approaches have been subjected to extensive researches because they can detect both misuse and anomaly. In this paper, rough set classification (RSC), a modern learning algorithm, is used to rank the features extracted for detecting intrusions and generate intrusion detection models. Feature ranking is a very critical step when building the model. RSC performs feature ranking before generating rules, and converts the feature ranking to minimal hitting set problem addressed by using genetic algorithm (GA). This is done in classical approaches using Support Vector Machine (SVM) by executing many iterations, each of which removes one useless feature. Compared with those methods, our method can avoid many iterations. In addition, a hybrid genetic algorithm is proposed to increase the convergence speed and decrease the training time of RSC. The models generated by RSC take the form of "IF-THEN" rules, which have the advantage of explication. Tests and comparison of RSC with SVM on DARPA benchmark data showed that for Probe and DoS attacks both RSC and SVM yielded highly accurate results (greater than 99% accuracy on testing set).

Algorithms↗

HIPAA compliant auditing system for medical images.

As an official regulation for healthcare privacy and security, Health Insurance Portability and Accountability Act (HIPAA) mandates health institutions to protect health information against unauthorized use or disclosure. One such method proposed by HIPAA Security Standards is audit trail, which records and examines health information access activities. HIPAA mandates healthcare providers to have the ability to generate audit trails on data access activities for any specific patient. Although current medical imaging systems generate activity logs, there is a lack of formal methodology to interpret these large volumes of log data and generate HIPAA compliant auditing trails. This paper outlines the design of a HIPAA compliant auditing system (HCAS) for medical images in imaging systems such as PACS and discusses the development of a security monitoring (SM) toolkit based on some of the partial components in HCAS.

Computer Security↗

Health care management and information systems security: awareness, training or education?

In this paper, a methodology for determining the training needs of personnel classes within health care establishments (HCEs) with respect to information systems security is discussed. This methodology, in way of an example, is applied to a particular class of HCE personnel, namely managers, whose training needs are derived. Further, the ISHTAR training course on information systems security for HCE managers is evaluated against these requirements and improvements to it are proposed.

Computer Security↗

Privacy vs usability: a qualitative exploration of patients' experiences with secure Internet communication with their general practitioner.

BACKGROUND: Direct electronic communication between patients and physicians has the potential to empower patients and improve health care services. Communication by regular email is, however, considered a security threat in many countries and is not recommended. Systems which offer secure communication have now emerged. Unlike regular email, secure systems require that users authenticate themselves. However, the authentication steps per se may become barriers that reduce use. OBJECTIVES: The objective was to study the experiences of patients who were using a secure electronic communication system. The focus of the study was the users' privacy versus the usability of the system. METHODS: Qualitative interviews were conducted with 15 patients who used a secure communication system (MedAxess) to exchange personal health information with their primary care physician. RESULTS: Six main themes were identified from the interviews: (1) supporting simple questions, (2) security issues, (3) aspects of written communication, (4) trust in the physician, (5) simplicity of MedAxess, and (6) trouble using the system. By using the system, about half of the patients (8/15) experienced easier access to their physician, with whom they tended to solve minor health problems and elaborate on more complex illness experiences. Two thirds of the respondents (10/15) found that their physician quickly responded to their MedAxess requests. As a result of the security barriers, the users felt that the system was secure. However, due to the same barriers, the patients considered the log-in procedure cumbersome, which had considerable negative impact on the actual use of the system. CONCLUSIONS: Despite a perceived need for secure electronic patient-physician communication systems, security barriers may diminish their overall usefulness. A dual approach is necessary to improve this situation: patients need to be better informed about security issues, and, at the same time, their experiences of using secure systems must be studied and used to improve user interfaces.

Communication↗

Business process design. Securing computerized health information files.

1. With technological advances, nurses in the workplace are challenged to continue the protection of confidential health records. 2. The security of health records can be viewed in three distinct categories: securing files from outside intrusion, maintaining the internal data security, and providing for recovery from disasterous events. 3. Common techniques for securing data include authenication, electronic firewalls, and data encryption.

Commerce↗

Image integrity verification in medical information systems.

In nowadays it is a major objective to protect healthcare information against unauthorized access. Comparing conventional and electronic management of medical images the later one demands much more complex security measures. We propose a new scenario for watermark data buildup and embedding which is independent from the applied watermarking technology. In our proposed method the embedded watermark data is dependant on image and patient information too. The proposed watermark buildup method provides watermark information where it is small in size and represents a unique digest of the image and image related data. The embedded data can be considered unique with high probability even if the same algorithm was used in different medical information systems. Described procedures ensure new, more secure links between image and related data, offering further perspectives in smartcard implementations.

Authorship↗

Purposes of health identification cards in belgium.

Although other alternatives might exist, identification cards have been chosen as an acceptable and adequate tool to be used to identify patients and health professionals.They are planned for a digital signature and for access to electronic health records as well as for health information exchange and for databases querying. Local applications might exist independently, but the Federal State has now developed BeHealth, a platform for health professionals, social security personnel as well as the great public to facilitate a common access to some health data. Security conditions have been defined and are described.

Belgium↗