Security framework for cloud based Electronic Health Record (EHR) system

Raghavendra Ganiga, Radhika M. Pai, M. M. Manohara Pai, Rajesh Kumar Sinha

Research output: Contribution to journalArticle

Abstract

Health records are an integral aspect of any Hospital Management System. With newer innovations in technology, there has been a shift in the way of recording health information. Medical records which used to be managed using various paper charts have now become easier to organize and maintain, thereby increasing the efficiency of medical staff. The Electronic Health Records (EHR) System is becoming a high-tech medical management technology developed for the economic or emerging economic countries like India. In a national health system, the EHR integrates the Electronic Medical Records (EMR) in all collaborating hospitals through different networks. EHR gives healthcare professionals a way to share and manage patient data quickly and effectively. Due to the mass storage of confidential patient data, healthcare organizations are considered as one of the most targeted sectors by intruders. This paper proposes a security framework for EHR system, which takes into consideration the integrity, availability, and confidentiality of health records. The threats posed to the EHR system are modeled by STRIDE modeling tool, and the amount of risk is calculated using DREAD. The paper also suggests the security mechanism and countermeasures based on security standards, which can be utilized in an EHR environment. The paper shows that the utilization of the proposed methods effectively addresses security concerns such as breach of sensitive medical information.

Original languageEnglish
Pages (from-to)455-466
Number of pages12
JournalInternational Journal of Electrical and Computer Engineering
Volume10
Issue number1
DOIs
Publication statusPublished - 01-01-2020

Fingerprint

Health
Electronic medical equipment
Economics
Innovation
Availability

All Science Journal Classification (ASJC) codes

  • Computer Science(all)
  • Electrical and Electronic Engineering

Cite this

@article{b491fd80879d43fcba0256ad1481058f,
title = "Security framework for cloud based Electronic Health Record (EHR) system",
abstract = "Health records are an integral aspect of any Hospital Management System. With newer innovations in technology, there has been a shift in the way of recording health information. Medical records which used to be managed using various paper charts have now become easier to organize and maintain, thereby increasing the efficiency of medical staff. The Electronic Health Records (EHR) System is becoming a high-tech medical management technology developed for the economic or emerging economic countries like India. In a national health system, the EHR integrates the Electronic Medical Records (EMR) in all collaborating hospitals through different networks. EHR gives healthcare professionals a way to share and manage patient data quickly and effectively. Due to the mass storage of confidential patient data, healthcare organizations are considered as one of the most targeted sectors by intruders. This paper proposes a security framework for EHR system, which takes into consideration the integrity, availability, and confidentiality of health records. The threats posed to the EHR system are modeled by STRIDE modeling tool, and the amount of risk is calculated using DREAD. The paper also suggests the security mechanism and countermeasures based on security standards, which can be utilized in an EHR environment. The paper shows that the utilization of the proposed methods effectively addresses security concerns such as breach of sensitive medical information.",
author = "Raghavendra Ganiga and Pai, {Radhika M.} and {Manohara Pai}, {M. M.} and Sinha, {Rajesh Kumar}",
year = "2020",
month = "1",
day = "1",
doi = "10.11591/ijece.v10i1.pp455-466",
language = "English",
volume = "10",
pages = "455--466",
journal = "International Journal of Electrical and Computer Engineering",
issn = "2088-8708",
publisher = "Institute of Advanced Engineering and Science (IAES)",
number = "1",

}

Security framework for cloud based Electronic Health Record (EHR) system. / Ganiga, Raghavendra; Pai, Radhika M.; Manohara Pai, M. M.; Sinha, Rajesh Kumar.

In: International Journal of Electrical and Computer Engineering, Vol. 10, No. 1, 01.01.2020, p. 455-466.

Research output: Contribution to journalArticle

TY - JOUR

T1 - Security framework for cloud based Electronic Health Record (EHR) system

AU - Ganiga, Raghavendra

AU - Pai, Radhika M.

AU - Manohara Pai, M. M.

AU - Sinha, Rajesh Kumar

PY - 2020/1/1

Y1 - 2020/1/1

N2 - Health records are an integral aspect of any Hospital Management System. With newer innovations in technology, there has been a shift in the way of recording health information. Medical records which used to be managed using various paper charts have now become easier to organize and maintain, thereby increasing the efficiency of medical staff. The Electronic Health Records (EHR) System is becoming a high-tech medical management technology developed for the economic or emerging economic countries like India. In a national health system, the EHR integrates the Electronic Medical Records (EMR) in all collaborating hospitals through different networks. EHR gives healthcare professionals a way to share and manage patient data quickly and effectively. Due to the mass storage of confidential patient data, healthcare organizations are considered as one of the most targeted sectors by intruders. This paper proposes a security framework for EHR system, which takes into consideration the integrity, availability, and confidentiality of health records. The threats posed to the EHR system are modeled by STRIDE modeling tool, and the amount of risk is calculated using DREAD. The paper also suggests the security mechanism and countermeasures based on security standards, which can be utilized in an EHR environment. The paper shows that the utilization of the proposed methods effectively addresses security concerns such as breach of sensitive medical information.

AB - Health records are an integral aspect of any Hospital Management System. With newer innovations in technology, there has been a shift in the way of recording health information. Medical records which used to be managed using various paper charts have now become easier to organize and maintain, thereby increasing the efficiency of medical staff. The Electronic Health Records (EHR) System is becoming a high-tech medical management technology developed for the economic or emerging economic countries like India. In a national health system, the EHR integrates the Electronic Medical Records (EMR) in all collaborating hospitals through different networks. EHR gives healthcare professionals a way to share and manage patient data quickly and effectively. Due to the mass storage of confidential patient data, healthcare organizations are considered as one of the most targeted sectors by intruders. This paper proposes a security framework for EHR system, which takes into consideration the integrity, availability, and confidentiality of health records. The threats posed to the EHR system are modeled by STRIDE modeling tool, and the amount of risk is calculated using DREAD. The paper also suggests the security mechanism and countermeasures based on security standards, which can be utilized in an EHR environment. The paper shows that the utilization of the proposed methods effectively addresses security concerns such as breach of sensitive medical information.

UR - http://www.scopus.com/inward/record.url?scp=85073339575&partnerID=8YFLogxK

UR - http://www.scopus.com/inward/citedby.url?scp=85073339575&partnerID=8YFLogxK

U2 - 10.11591/ijece.v10i1.pp455-466

DO - 10.11591/ijece.v10i1.pp455-466

M3 - Article

AN - SCOPUS:85073339575

VL - 10

SP - 455

EP - 466

JO - International Journal of Electrical and Computer Engineering

JF - International Journal of Electrical and Computer Engineering

SN - 2088-8708

IS - 1

ER -