Evaluation framework for automatic privacy auditing tools for hospital data breach detections: A case study.

Abstract:

OBJECTIVE:We aim to 1) design an evaluation framework to examine the accuracy of automatic privacy auditing tools, 2) apply the evaluation method at a hospital to validate the performance of an auditing tool that uses a machine learning algorithm to automate user access auditing, and 3) recommend further improvements in auditing for the hospital. MATERIALS AND METHODS:Using the black box method of user acceptance testing, we have designed an evaluation framework consisting of appropriate and inappropriate behaviour scenarios to examine the privacy auditing tools. The scenarios were designed from clinical and non-clinical hospital staff perspective, taking expert opinions from the privacy officers and considering examples from the Information and Privacy Commission (IPC) and were tested using Mackenzie Richmond Hill Hospital's data. RESULTS:The case study using this evaluation framework found that on average 98.09 % of total accesses of the hospital were identified as appropriate and the tool was unable to explain the remaining 1.91 % of accesses. In addition, a statistically significant (P < 0.05) increasing trend on categorizing appropriate accesses by the tool have been observed. Furthermore, an analysis of unexplained accesses revealed the contributing factors and found issues related to hospital workflows and data quality (information was missing about staff roles and departments). CONCLUSION:Given that adoption of these machine learning tools is increasing in hospitals, this research provides an evaluation framework and an empirical evidence on the effectiveness of automated privacy auditing and detecting anomalies for dynamic hospital workflows.

journal_name

Int J Med Inform

authors

Yesmin T,Carter MW

doi

10.1016/j.ijmedinf.2020.104123

subject

Has Abstract

pub_date

2020-06-01 00:00:00

pages

104123

eissn

1386-5056

issn

1872-8243

pii

S1386-5056(19)31402-9

journal_volume

138

pub_type

杂志文章
  • A smart wearable device for monitoring and self-management of diabetic foot: A proof of concept study.

    abstract:BACKGROUND AND OBJECTIVE:Diabetic foot is one of the important complications of diabetes, which is occurred due to the destructive parameters in different anatomical sites of feet. Management and monitoring of these parameters are very important to decrease or prevent foot ulcers. We aimed to develop a smart wearable d...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2020.104343

    authors: Moulaei K,Malek M,Sheikhtaheri A

    更新日期:2021-02-01 00:00:00

  • The application of a computerized problem-oriented medical record system and its impact on patient care.

    abstract::The present computer system is the first of its kind based on problem-oriented medical record (POMR) design developed and operated in a hospital in Hong Kong. It went live in May 1996 with two workstations installed in the medical record office (MRO). Doctors have no direct access to it. They dictate medical notes on ...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/s1386-5056(99)00019-2

    authors: Ho LM,McGhee SM,Hedley AJ,Leong JC

    更新日期:1999-07-01 00:00:00

  • Achieving the integrated and smart health and wellbeing paradigm: a call for policy research and action on governance and business models.

    abstract::To assure sustainability of our health systems and improve quality, implementing integrated wellness, health and social care service models have been proposed. They will need the enabling power of Health ICT facilitated systems and applications. Such solutions support the efficient coordination of service provision ac...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2012.05.008

    authors: Stroetmann KA

    更新日期:2013-04-01 00:00:00

  • Policy for cryptography in healthcare--a view from the NHS.

    abstract::Effective security arrangements, which both protect and assure those information assets of healthcare providers, doctors and patients, are fundamental requirements in a modern electronic healthcare culture. At the heart of healthcare information systems in future will be those infrastructure components and services, w...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/s1386-5056(00)00109-x

    authors: Donaldson A

    更新日期:2000-11-01 00:00:00

  • Web-based learning in undergraduate medical education: development and assessment of an online course on experimental surgery.

    abstract::In order to increase the number of practical and discussion classes offered to students in the traditional-curriculum scenario, while decreasing the lecture-based ones and to create an online community to share knowledge on surgery, we developed and assessed the first online course for undergraduate medical students o...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2004.06.002

    authors: Bernardo V,Ramos MP,Plapler H,De Figueiredo LF,Nader HB,Anção MS,Von Dietrich CP,Sigulem D

    更新日期:2004-09-01 00:00:00

  • Complexity and the science of implementation in health IT--knowledge gaps and future visions.

    abstract:OBJECTIVES:The intent of this paper is in the examination of health IT implementation processes - the barriers to and facilitators of successful implementation, identification of a beginning set of implementation best practices, the identification of gaps in the health IT implementation body of knowledge, and recommend...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2013.10.009

    authors: Abbott PA,Foster J,Marin Hde F,Dykes PC

    更新日期:2014-07-01 00:00:00

  • The introduction of a diagnostic decision support system (DXplain™) into the workflow of a teaching hospital service can decrease the cost of service for diagnostically challenging Diagnostic Related Groups (DRGs).

    abstract:BACKGROUND:In an era of short inpatient stays, residents may overlook relevant elements of the differential diagnosis as they try to evaluate and treat patients. However, if a resident's first principal diagnosis is wrong, the patient's appropriate evaluation and treatment may take longer, cost more, and lead to worse ...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章,评审

    doi:10.1016/j.ijmedinf.2010.09.004

    authors: Elkin PL,Liebow M,Bauer BA,Chaliki S,Wahner-Roedler D,Bundrick J,Lee M,Brown SH,Froehling D,Bailey K,Famiglietti K,Kim R,Hoffer E,Feldman M,Barnett GO

    更新日期:2010-11-01 00:00:00

  • Towards implementing SNOMED CT in nursing practice: A scoping review.

    abstract:BACKGROUND:Currently, it is rare for nursing data to be available in data repositories due to the quality of nursing data collected in clinical practice. To improve the quality of nursing data, the American Nurses Association recommends the use of Systematized Nomenclature of Medicine Clinical Terms (SNOMED CT) for cod...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章,评审

    doi:10.1016/j.ijmedinf.2019.104035

    authors: Kim J,Macieira TGR,Meyer SL,Ansell Maggie M,Bjarnadottir Raga RI,Smith MB,Citty SW,Schentrup DM,Nealis RM,Keenan GM

    更新日期:2020-02-01 00:00:00

  • Text preprocessing for improving hypoglycemia detection from clinical notes - A case study of patients with diabetes.

    abstract:BACKGROUND AND OBJECTIVE:Hypoglycemia is a common safety event when attempting to optimize glycemic control in diabetes (DM). While electronic medical records provide a natural ground for detecting and analyzing hypoglycemia, ICD codes used in the databases may be invalid, insensitive or non-specific in detecting new h...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2019.06.020

    authors: Zhou L,Siddiqui T,Seliger SL,Blumenthal JB,Kang Y,Doerfler R,Fink JC

    更新日期:2019-09-01 00:00:00

  • Patient expectations and experiences of remote monitoring for chronic diseases: Systematic review and thematic synthesis of qualitative studies.

    abstract:OBJECTIVES:To describe the range of patients' beliefs, attitudes, expectations, and experiences of remote monitoring for chronic conditions across different healthcare contexts and populations. DESIGN:We searched MEDLINE, Embase, PsychINFO, and CINAHL, Google Scholar, and reference lists of related studies through to ...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2019.01.013

    authors: Walker RC,Tong A,Howard K,Palmer SC

    更新日期:2019-04-01 00:00:00

  • Diagnostic accuracy of chest X-rays acquired using a digital camera for low-cost teleradiology.

    abstract::Store-and-forward telemedicine, using e-mail to send clinical data and digital images, offers a low-cost alternative for physicians in developing countries to obtain second opinions from specialists. To explore the potential usefulness of this technique, 91 chest X-ray images were photographed using a digital camera a...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2003.10.002

    authors: Szot A,Jacobson FL,Munn S,Jazayeri D,Nardell E,Harrison D,Drosten R,Ohno-Machado L,Smeaton LM,Fraser HS

    更新日期:2004-02-01 00:00:00

  • More than just a question of technology: factors related to hospitals' adoption and implementation of health information exchange.

    abstract:INTRODUCTION:The provisions of the American Recovery & Reinvestment Act increased the likelihood of more widespread health information exchange (HIE), the electronic transfer of patient-level information between organizations, by essentially mandating the use of electronic health record systems. While important, the sp...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2010.09.003

    authors: Vest JR

    更新日期:2010-12-01 00:00:00

  • Social media and flu: Media Twitter accounts as agenda setters.

    abstract:OBJECTIVES:This paper has two objectives. First, it categorizes the Twitter handles tweeted flu related information based on the amount of replies and mentions within the Twitter network. The collected Twitter accounts are categorized as media, health related individuals, organizations, government, individuals with no ...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2016.04.009

    authors: Yun GW,Morin D,Park S,Joa CY,Labbe B,Lim J,Lee S,Hyun D

    更新日期:2016-07-01 00:00:00

  • Usability of quality measures for online health information: Can commonly used technical quality criteria be reliably assessed?

    abstract:PURPOSE:Many criteria have been developed to rate the quality of online health information. To effectively evaluate quality, consumers must use quality criteria that can be reliably assessed. However, few instruments have been validated for inter-rater agreement. Therefore, we assessed the degree to which two raters co...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2005.02.002

    authors: Bernstam EV,Sagaram S,Walji M,Johnson CW,Meric-Bernstam F

    更新日期:2005-08-01 00:00:00

  • Evaluation of mobile phone and Internet intervention on waist circumference and blood pressure in post-menopausal women with abdominal obesity.

    abstract:PURPOSE:The present study evaluated whether an intervention using a short message service (SMS) by personal cellular phone and Internet would reduce cardiovascular risk factors in post-menopausal women with abdominal obesity over 12 weeks. METHODS:This is a quasi-experimental design with pre and post tests. Participan...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2011.12.011

    authors: Park MJ,Kim HS

    更新日期:2012-06-01 00:00:00

  • Adding insight: a qualitative cross-site study of physician order entry.

    abstract::The research questions, strategies, and results of a 7-year qualitative study of computerized physician order entry implementation (CPOE) at successful sites are reviewed over time. The iterative nature of qualitative inquiry stimulates a consecutive stream of research foci, which, with each iteration, add further ins...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章,多中心研究

    doi:10.1016/j.ijmedinf.2005.05.005

    authors: Ash JS,Sittig DF,Seshadri V,Dykstra RH,Carpenter JD,Stavri PZ

    更新日期:2005-08-01 00:00:00

  • Organizational issues in health informatics: a model approach.

    abstract::In this paper, we present a model that describes the stages of the implementation of an information system in a health care organization. The model offers no explanation of the implementation process but rather describes in a cyclic order the domains that are relevant when implementing a system. The model offers thus ...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/s1386-5056(98)00142-7

    authors: Aarts J,Peel V,Wright G

    更新日期:1998-10-01 00:00:00

  • Measuring mobile patient safety information system success: an empirical study.

    abstract:OBJECTIVE:The Health Risk Reminders and Surveillance (HRRS) system was designed to deliver critical abnormal test results of severely ill patients from Laboratory, Radiology, and Pathology departments to physicians within 5 min using cell phone text messages. This paper explores the success of the HRRS system. METHOD:...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2008.03.003

    authors: Jen WY,Chao CC

    更新日期:2008-10-01 00:00:00

  • Patients' perceptions of a home telecare system.

    abstract:GOAL:To identify any major factors that could affect patients' perceptions of a Home Telecare Management System (HTMS) and use the findings to contribute to development of a theoretical framework for patient acceptance of HTMS. MATERIALS AND METHODS:Ten Focus Group Interviews (FGIs) were conducted with patients suffer...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2007.10.006

    authors: Rahimpour M,Lovell NH,Celler BG,McCormick J

    更新日期:2008-07-01 00:00:00

  • Assessing team effectiveness and affective learning in a datathon.

    abstract:BACKGROUND:Datathons are increasingly organized in the healthcare field. The goal is to assemble people with different backgrounds to work together as a team and engage in clinically relevant research or develop algorithms using health-related datasets. Criteria to assess the return of investment on such events have tr...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2018.01.005

    authors: Piza FMT,Celi LA,Deliberato RO,Bulgarelli L,de Carvalho FRT,Filho RR,de La Hoz MAA,Kesselheim JC

    更新日期:2018-04-01 00:00:00

  • How to ensure data security of an epidemiological follow-up: quality assessment of an anonymous record linkage procedure.

    abstract::A computerised record hash coding and linkage procedure is proposed to allow the chaining of medical information within the framework of epidemiological follow-up. Before their extraction, files are rendered anonymous using a one-way hash coding based on the standard hash algorithm (SHA) function, in order to respect ...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/s1386-5056(98)00019-7

    authors: Quantin C,Bouzelat H,Allaert FA,Benhamiche AM,Faivre J,Dusserre L

    更新日期:1998-03-01 00:00:00

  • Variation in the use of online clinical evidence: a qualitative analysis.

    abstract:OBJECTIVE:To investigate factors influencing variations in clinicians' use of an online evidence retrieval system. SETTING:Public hospitals in New South Wales, Australia. METHOD:Web log analysis demonstrated considerable variation in rates of evidence use by clinicians at different hospitals. Focus groups and intervi...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/s1386-5056(02)00046-1

    authors: Gosling AS,Westbrook JI,Coiera EW

    更新日期:2003-01-01 00:00:00

  • Organizational routines, innovation, and flexibility: the application of narrative networks to dynamic workflow.

    abstract:OBJECTIVE:The purpose of this paper is to demonstrate how current visual representations of organizational and technological processes do not fully account for the variability present in everyday practices. We further demonstrate how narrative networks can augment these representations to indicate potential areas for s...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2011.01.005

    authors: Hayes GR,Lee CP,Dourish P

    更新日期:2011-08-01 00:00:00

  • A case study evaluation of a Critical Care Information System adoption using the socio-technical and fit approach.

    abstract:BACKGROUND:Clinical information systems have long been used in intensive care units but reports on their adoption and benefits are limited. This study evaluated a Critical Care Information System implementation. METHODS:A case study summative evaluation was conducted, employing observation, interview, and document ana...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2015.03.001

    authors: Yusof MM

    更新日期:2015-07-01 00:00:00

  • The use of a medical dictionary for regulatory activities terminology (MedDRA) in prescription-event monitoring in Japan (J-PEM).

    abstract::The Medical Dictionary for Regulatory Activities Terminology (MedDRA) version 2.1 (V2.1) was released in March 1999 accompanied by the MedDRA/J V2.1J specifically for Japanese users. In prescription-event monitoring in Japan (J-PEM), we have employed the MedDRA/J for data entry, signal generation and event listing. In...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/s1386-5056(00)00062-9

    authors: Yokotsuka M,Aoyama M,Kubota K

    更新日期:2000-07-01 00:00:00

  • Physician satisfaction with transition from CPOE to paper-based prescription.

    abstract:INTRODUCTION:In January 2015, Rouen University Hospital's information system experienced serious issues. It was necessary to rapidly switch from the computerized provider order entry (CPOE) system towards a paper-based order entry (PBOE) system. This was an opportunity to evaluate prescriber opinion on the two provider...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2017.04.007

    authors: Griffon N,Schuers M,Joulakian M,Bubenheim M,Leroy JP,Darmoni SJ

    更新日期:2017-07-01 00:00:00

  • Design and evaluation of a mobile application for monitoring patients with Alzheimer's disease: A day center case study.

    abstract:BACKGROUND AND OBJECTIVE:This paper presents Alzheed, a mobile application for monitoring patients with Alzheimer's disease at day centers as well as a set of design recommendations for the development of healthcare mobile applications. The Alzheed project was conducted at Day Center "Dorita de Ojeda" that is focused o...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2019.103972

    authors: Chávez A,Borrego G,Gutierrez-Garcia JO,Rodríguez LF

    更新日期:2019-11-01 00:00:00

  • Accuracy of using natural language processing methods for identifying healthcare-associated infections.

    abstract:OBJECTIVE:There is a growing interest in using natural language processing (NLP) for healthcare-associated infections (HAIs) monitoring. A French project consortium, SYNODOS, developed a NLP solution for detecting medical events in electronic medical records for epidemiological purposes. The objective of this study was...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2018.06.002

    authors: Tvardik N,Kergourlay I,Bittar A,Segond F,Darmoni S,Metzger MH

    更新日期:2018-09-01 00:00:00

  • Assessing graduate programs for healthcare information management/technology (HIM/T) executives.

    abstract::This paper describes a methodology to assess health/medical informatics graduate-level education curricula. The authors used the Certified Professional in Healthcare Information Management Systems (CPHIMS) exam objectives published by the Healthcare Information and Management Systems Society (HIMSS) as the basis for t...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2003.12.002

    authors: Moore RA,Berner ES

    更新日期:2004-03-18 00:00:00

  • Design and implementation of an ICU incident registry.

    abstract::Due to its complexity intensive care is vulnerable to errors. On the ICU adults of the AMC (Amsterdam, The Netherlands) the available registries used for error reporting did not give insight in the occurrence of unwanted events, and did not lead to preventive measures. Therefore, a new registry has been developed on t...

    journal_title:International journal of medical informatics

    pub_type: 杂志文章

    doi:10.1016/j.ijmedinf.2006.08.003

    authors: van der Veer S,Cornet R,de Jonge E

    更新日期:2007-02-01 00:00:00