Automated Detection of Anomalous Accesses to Electronic Health Records
Automated Detection of Anomalous Accesses to Electronic Health Records
批准号:
7938889
负责人:
Bradley A. Malin
金额:
$24.21万
依托单位:
依托单位国家:
美国
项目类别:
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-30 至 2013-09-29
关键词:
Academic Medical CentersAdministratorAdoptedAdoptionArchitectureBasic ScienceBehaviorBusinessesCaringCessation of lifeClinicalCollectionCommitCommunitiesCommunity HealthcareComplementComplexComputer SecurityComputer softwareComputersDataData ProtectionDetectionDevelopmentDocumentationElectronic Health RecordElectronicsEngineeringEnsureEnvironmentEventFaceFeedbackFoundationsGoalsHealth Insurance Portability and Accountability ActHealthcareHospitalsIndividualInformaticsInformation SystemsInformation TechnologyInterdisciplinary StudyInvestigationInvestmentsKnowledgeLeadLearningLegalManualsMeasuresMedicalMedical InformaticsMedical RecordsMedical centerMethodologyMethodsMiningMissionModelingMonitorNatureNeonatalNoiseNursesOrganizational ModelsPaperPatient Access to RecordsPatientsPatternPhysiciansPilot ProjectsPoliciesPrimary Health CarePrincipal InvestigatorPrivacyProbabilityProcessProviderRecordsRegulationResearchResearch InfrastructureResearch Project GrantsRightsRoleRunningSafetySamplingScienceScientistSecureSecurityServicesSocial NetworkSocial ObligationsSocietiesSoftware EngineeringSoftware ToolsSpecific qualifier valueSpottingsSurveillance ModelingSystemTechniquesTechnologyTimeTrustUniversitiesValidationWorkauthoritybasebiomedical informaticscomputer sciencecostdata miningdesignelectronic recording systemexpectationexperiencefollow-upforginghealth information technologyhealth organizationinterestmedical schoolsmemberneglectnew technologynoveloperationorganizational structurepatient privacypoint of carepreventpsychologicrepositoryresponsesoftware developmenttool
中文摘要
描述(由申请人提供):
信息技术成本的不断下降,使得医疗环境中高度敏感的个人信息的收集、存储和应用成为可能,直到最近,医疗环境还依赖于纸质文档、面对面的交互以及对所有与信任相关的事项的物理保护。随着这些环境迁移到电子环境,保护患者电子健康记录(EHR)的隐私免受医疗保健组织(HCO)外部和内部的威胁是当务之急,也是我们的法律的和社会义务。在大多数情况下,医学信息学和计算机科学界都把重点放在外部威胁上,这导致了复杂的信息和计算机安全机制的发展。然而,内部威胁被忽视,主要是由于复杂的HCO的动态性质,如大型分布式医疗中心。HCO中数据保护的最重大挑战之一是,我们无法限制服务提供商在使命关键设置中访问记录。考虑到当医院的病人需要治疗,而医护人员对他们的EHR的访问被延迟或拒绝时,病人可能会遭受相当大的伤害或死亡。联邦法规,如《健康保险流通和责任法案》的安全规则,要求HCO储存访问日志,但除了范围有限的简单手动抽查外,没有明确的审计机制。因此,该项目的总体目标是开发自动化方法来挖掘EHR访问日志,以检测何时可能发生侵犯隐私的访问,以便提醒有关当局进行后续调查。我们的主要目标是开发信息学工具来监控用户(例如,医生)访问受试者的记录(例如,患者)并标记潜在的隐私损害动作(例如,未经授权的“偷看”)。拟议的工具将整合HCO知识和访问日志存储库,将系统表示为一个动态的团队和业务流程社交网络,用于对每个记录的访问的“安全性”进行评分。拟议项目的具体目标是:(1)为从EHR访问日志中自动学习和建模HCO的正常业务操作开发科学基础,(2)自动检测在学习HCO操作的背景下可疑的EHR访问,(3)通过专家反馈评估我们的方法,以及(4)在可扩展的软件工具中实现我们的方法,该软件工具可快速重新配置为任何EHR系统。为了支持这些目标,我们将评估来自范德比尔特大学医学中心EHR系统的真实的世界访问日志,该系统是一个详细的存储库,数据覆盖数万名用户和超过一百万名患者。我们认为,EHR系统的审计工具,例如通过这项研究开发的工具,对于在不牺牲患者隐私权的情况下继续采用健康信息技术至关重要。
英文摘要
DESCRIPTION (provided by applicant):
The decreasing cost of information technologies has rapidly enabled the collection, storage, and application of highly sensitive personal information in healthcare environments, which until recently, were dependent on paper documentation, face-to-face interactions, and physical protections for all matters trust-related. As these environments migrate to the electronic setting, it is imperative, as well as our legal and social obligation, to protect the privacy of patients" electronic health records (EHRs) from threats that are external, as well as internal, to healthcare organizations (HCOs). For the most part, the medical informatics and computer science communities have focused on the external threat, which has led to the development of sophisticated information and computer security mechanisms. However, the internal threat has been neglected, mainly due to the dynamic nature of complex HCOs, such as large distributed medical centers. One of the most significant challenges of data protection in HCOs is that we cannot limit service providers' access to the records in mission critical settings. Consider when a hospital patient requires treatment and a care provider's access to their EHR is delayed or denied, the patient may suffer considerable harm or death. Federal regulations, such as the Security Rule of the Health Insurance Portability and Accountability Act, require HCOs to stockpile access logs, but there are no clear mechanisms for auditing beyond simple manual spot checks, which are limited in scope. Thus, the overarching goal of this project to develop automated methods to data mine EHR access logs to detect when potentially privacy-violating accesses have been committed, so that the appropriate authorities may be alerted to follow-up with an investigation. Our primary goal is to develop informatics tools to monitor how users (e.g., physicians) access the records of subjects (e.g., patients) in the system and flag potentially privacy-compromising actions (e.g., an unauthorized "peek"). The proposed tools will integrate HCO knowledge and access log repositories to represent the system as a dynamic social network of teams and business processes that are applied to score the "safety" of each recorded access. The specific objectives of the proposed project are (1) to develop a scientific foundation for automatically learning and modeling the normal business operations of HCOs from EHR access logs, (2) to automatically detect EHR accesses that are suspicious in the context of learned HCO operations, (3) to evaluate our approach with expert feedback, and (4) to implement our approaches in an extendable software tool that is rapidly reconfigurable to any EHR system. In support of these goals, we will evaluate real world access logs from the EHR system of the Vanderbilt University Medical Center, which is a detailed repository with data covering tens of thousands of users and over a million patients. We believe that auditing tools for EHR systems, such as those developed through this research, are crucial to the continued adoption of health information technologies without sacrificing patients' privacy rights.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Ethics Core (FABRIC)
-
批准号:10662376
-
项目类别:
-
资助金额:$121.72万
-
财政年份:2023
-
负责人:Bradley A. Malin
-
依托单位:
Ethics Core (FABRIC)
-
批准号:10473062
-
项目类别:
-
资助金额:$54.3万
-
财政年份:2022
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:8695427
-
项目类别:
-
资助金额:$34.3万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:9301793
-
项目类别:
-
资助金额:$33.25万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:9193769
-
项目类别:
-
资助金额:$26.84万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:8548389
-
项目类别:
-
资助金额:$33.43万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:9754854
-
项目类别:
-
资助金额:$24.06万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:9360125
-
项目类别:
-
资助金额:$24.96万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:8915734
-
项目类别:
-
资助金额:$0.88万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:8341447
-
项目类别:
-
资助金额:$39.52万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
Automated Detection of Anomalous Accesses to Electronic Health Records
-
批准号:8882547
-
项目类别:
-
资助金额:$0.01万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Automated Detection of Anomalous Accesses to Electronic Health Records
-
批准号:7766720
-
项目类别:
-
资助金额:$24.41万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Technologies to Enable Privacy in Biomedical Databanks
-
批准号:7736656
-
项目类别:
-
资助金额:$28.7万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Automated Detection of Anomalous Accesses to Electronic Health Records
-
批准号:8323988
-
项目类别:
-
资助金额:$23.12万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Technologies to Enable Privacy in Biomedical Databanks
-
批准号:7921434
-
项目类别:
-
资助金额:$27.24万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Technologies to Enable Privacy in Biomedical Databanks
-
批准号:8323989
-
项目类别:
-
资助金额:$25.51万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Automated Detection of Anomalous Accesses to Electronic Health Records
-
批准号:9143798
-
项目类别:
-
资助金额:$34.15万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Technologies to Enable Privacy in Biomedical Databanks
-
批准号:9302038
-
项目类别:
-
资助金额:$26.06万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Technologies to Enable Privacy in Biomedical Databanks
-
批准号:8140679
-
项目类别:
-
资助金额:$0.19万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Automated Detection of Anomalous Accesses to Electronic Health Records
-
批准号:8139876
-
项目类别:
-
资助金额:$23.59万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
海外基金