课题基金 / 基金详情

Automated Detection of Anomalous Accesses to Electronic Health Records

Automated Detection of Anomalous Accesses to Electronic Health Records
自动检测电子健康记录的异常访问
批准号:
7766720
负责人:
Bradley A. Malin
金额:
$24.41万
依托单位:
依托单位国家:
美国
项目类别:
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-30 至 2013-09-29
关键词:
Academic Medical CentersAdministratorAdoptedAdoptionArchitectureBasic ScienceBehaviorBusinessesCaringCessation of lifeClinicalCollectionCommitCommunitiesCommunity HealthcareComplementComplexComputer SecurityComputer softwareComputersDataData ProtectionDetectionDevelopmentDocumentationElectronic Health RecordElectronicsEngineeringEnsureEnvironmentEventFaceFeedbackFoundationsGoalsHealth Insurance Portability and Accountability ActHealthcareHospitalsIndividualInformaticsInformation SystemsInformation TechnologyInterdisciplinary StudyInvestigationInvestmentsKnowledgeLeadLearningLegalManualsMeasuresMedicalMedical InformaticsMedical RecordsMedical centerMethodologyMethodsMiningMissionModelingMonitorNatureNeonatalNoiseNursesOperative Surgical ProceduresOrganizational ModelsPaperPatient Access to RecordsPatientsPatternPhysiciansPilot ProjectsPoliciesPrimary Health CarePrincipal InvestigatorPrivacyProbabilityProcessProviderRecordsRegulationResearchResearch InfrastructureResearch Project GrantsRightsRoleRunningSafetySamplingScienceScientistSecureSecurityServicesSocial NetworkSocial ObligationsSocietiesSoftware EngineeringSoftware ToolsSpecific qualifier valueSpottingsSurveillance ModelingSystemTechniquesTechnologyTimeTrustUniversitiesValidationWorkauthoritybasebiomedical informaticscomputer sciencecostdata miningdesignelectronic recording systemexpectationexperiencefollow-upforginghealth information technologyhealth organizationinterestmedical schoolsmemberneglectnew technologynovelorganizational structurepatient privacypoint of carepreventpsychologicrepositoryresponsesoftware developmenttool

项目摘要

项目成果

Bradley A. Malin的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
DESCRIPTION (provided by applicant): The decreasing cost of information technologies has rapidly enabled the collection, storage, and application of highly sensitive personal information in healthcare environments, which until recently, were dependent on paper documentation, face-to-face interactions, and physical protections for all matters trust-related. As these environments migrate to the electronic setting, it is imperative, as well as our legal and social obligation, to protect the privacy of patients" electronic health records (EHRs) from threats that are external, as well as internal, to healthcare organizations (HCOs). For the most part, the medical informatics and computer science communities have focused on the external threat, which has led to the development of sophisticated information and computer security mechanisms. However, the internal threat has been neglected, mainly due to the dynamic nature of complex HCOs, such as large distributed medical centers. One of the most significant challenges of data protection in HCOs is that we cannot limit service providers' access to the records in mission critical settings. Consider when a hospital patient requires treatment and a care provider's access to their EHR is delayed or denied, the patient may suffer considerable harm or death. Federal regulations, such as the Security Rule of the Health Insurance Portability and Accountability Act, require HCOs to stockpile access logs, but there are no clear mechanisms for auditing beyond simple manual spot checks, which are limited in scope. Thus, the overarching goal of this project to develop automated methods to data mine EHR access logs to detect when potentially privacy-violating accesses have been committed, so that the appropriate authorities may be alerted to follow-up with an investigation. Our primary goal is to develop informatics tools to monitor how users (e.g., physicians) access the records of subjects (e.g., patients) in the system and flag potentially privacy-compromising actions (e.g., an unauthorized "peek"). The proposed tools will integrate HCO knowledge and access log repositories to represent the system as a dynamic social network of teams and business processes that are applied to score the "safety" of each recorded access. The specific objectives of the proposed project are (1) to develop a scientific foundation for automatically learning and modeling the normal business operations of HCOs from EHR access logs, (2) to automatically detect EHR accesses that are suspicious in the context of learned HCO operations, (3) to evaluate our approach with expert feedback, and (4) to implement our approaches in an extendable software tool that is rapidly reconfigurable to any EHR system. In support of these goals, we will evaluate real world access logs from the EHR system of the Vanderbilt University Medical Center, which is a detailed repository with data covering tens of thousands of users and over a million patients. We believe that auditing tools for EHR systems, such as those developed through this research, are crucial to the continued adoption of health information technologies without sacrificing patients' privacy rights.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Ethics Core (FABRIC)
  • 批准号:
    10662376
  • 项目类别:
  • 资助金额:
    $121.72万
  • 财政年份:
    2023
  • 负责人:
    Bradley A. Malin
  • 依托单位:
Ethics Core (FABRIC)
A Risk Management Framework for Identifiability in Genomics Research
  • 批准号:
    8695427
  • 项目类别:
  • 资助金额:
    $34.3万
  • 财政年份:
    2012
  • 负责人:
    Bradley A. Malin
  • 依托单位:
A Risk Management Framework for Identifiability in Genomics Research
海外基金