Automated Detection of Anomalous Accesses to Electronic Health Records
Automated Detection of Anomalous Accesses to Electronic Health Records
批准号:
7766720
负责人:
Bradley A. Malin
金额:
$24.41万
依托单位:
依托单位国家:
美国
项目类别:
财政年份:
2009
资助国家:
美国
项目状态:
已结题
起止时间:
2009-09-30 至 2013-09-29
关键词:
Academic Medical CentersAdministratorAdoptedAdoptionArchitectureBasic ScienceBehaviorBusinessesCaringCessation of lifeClinicalCollectionCommitCommunitiesCommunity HealthcareComplementComplexComputer SecurityComputer softwareComputersDataData ProtectionDetectionDevelopmentDocumentationElectronic Health RecordElectronicsEngineeringEnsureEnvironmentEventFaceFeedbackFoundationsGoalsHealth Insurance Portability and Accountability ActHealthcareHospitalsIndividualInformaticsInformation SystemsInformation TechnologyInterdisciplinary StudyInvestigationInvestmentsKnowledgeLeadLearningLegalManualsMeasuresMedicalMedical InformaticsMedical RecordsMedical centerMethodologyMethodsMiningMissionModelingMonitorNatureNeonatalNoiseNursesOperative Surgical ProceduresOrganizational ModelsPaperPatient Access to RecordsPatientsPatternPhysiciansPilot ProjectsPoliciesPrimary Health CarePrincipal InvestigatorPrivacyProbabilityProcessProviderRecordsRegulationResearchResearch InfrastructureResearch Project GrantsRightsRoleRunningSafetySamplingScienceScientistSecureSecurityServicesSocial NetworkSocial ObligationsSocietiesSoftware EngineeringSoftware ToolsSpecific qualifier valueSpottingsSurveillance ModelingSystemTechniquesTechnologyTimeTrustUniversitiesValidationWorkauthoritybasebiomedical informaticscomputer sciencecostdata miningdesignelectronic recording systemexpectationexperiencefollow-upforginghealth information technologyhealth organizationinterestmedical schoolsmemberneglectnew technologynovelorganizational structurepatient privacypoint of carepreventpsychologicrepositoryresponsesoftware developmenttool
中文摘要
描述(由申请人提供):
信息技术成本的下降使高度敏感的个人信息在医疗保健环境中的收集、存储和应用迅速成为可能,直到最近,医疗保健环境还依赖于纸质文档、面对面的互动和对所有与信任相关的事项的实物保护。随着这些环境向电子环境迁移,保护患者的电子健康记录(EHR)的隐私免受医疗保健组织(HCO)的外部和内部威胁是当务之急,也是我们的法律和社会义务。在很大程度上,医学信息学和计算机科学界关注的是外部威胁,这导致了复杂的信息和计算机安全机制的发展。然而,内部威胁被忽视了,主要是因为复杂的HCO的动态性质,例如大型分布式医疗中心。HCOS中数据保护的最大挑战之一是,我们不能限制服务提供商在关键任务设置中访问记录。考虑到当医院的病人需要治疗,而护理提供者延迟或拒绝接触他们的电子病历时,病人可能会遭受相当大的伤害或死亡。联邦法规,如《健康保险可携带性和责任法案》的《安全规则》,要求HCO储存访问日志,但除了范围有限的简单人工抽查外,没有明确的审计机制。因此,该项目的首要目标是开发自动方法来对电子病历访问日志进行数据挖掘,以检测何时发生了可能侵犯隐私的访问,以便可以提醒有关当局进行后续调查。我们的主要目标是开发信息学工具,以监控用户(例如,医生)如何访问系统中受试者(例如,患者)的记录,并标记可能危及隐私的行为(例如,未经授权的“窥视”)。拟议的工具将整合HCO知识和访问日志库,以将系统表示为团队和业务流程的动态社交网络,应用这些网络来对每个记录的访问的“安全性”进行评分。拟议项目的具体目标是:(1)开发一个科学基础,用于从EHR访问日志中自动学习和建模HCO的正常业务操作;(2)在学习到的HHR操作的背景下自动检测可疑的EHR访问;(3)通过专家反馈评估我们的方法;以及(4)在可扩展的软件工具中实现我们的方法,该工具可以快速重新配置到任何EHR系统。为了支持这些目标,我们将评估范德比尔特大学医疗中心EHR系统的真实访问日志,该系统是一个详细的存储库,数据覆盖数万名用户和100多万名患者。我们认为,电子病历系统的审计工具,如通过这项研究开发的工具,对于在不牺牲患者隐私权的情况下继续采用医疗信息技术至关重要。
英文摘要
DESCRIPTION (provided by applicant):
The decreasing cost of information technologies has rapidly enabled the collection, storage, and application of highly sensitive personal information in healthcare environments, which until recently, were dependent on paper documentation, face-to-face interactions, and physical protections for all matters trust-related. As these environments migrate to the electronic setting, it is imperative, as well as our legal and social obligation, to protect the privacy of patients" electronic health records (EHRs) from threats that are external, as well as internal, to healthcare organizations (HCOs). For the most part, the medical informatics and computer science communities have focused on the external threat, which has led to the development of sophisticated information and computer security mechanisms. However, the internal threat has been neglected, mainly due to the dynamic nature of complex HCOs, such as large distributed medical centers. One of the most significant challenges of data protection in HCOs is that we cannot limit service providers' access to the records in mission critical settings. Consider when a hospital patient requires treatment and a care provider's access to their EHR is delayed or denied, the patient may suffer considerable harm or death. Federal regulations, such as the Security Rule of the Health Insurance Portability and Accountability Act, require HCOs to stockpile access logs, but there are no clear mechanisms for auditing beyond simple manual spot checks, which are limited in scope. Thus, the overarching goal of this project to develop automated methods to data mine EHR access logs to detect when potentially privacy-violating accesses have been committed, so that the appropriate authorities may be alerted to follow-up with an investigation. Our primary goal is to develop informatics tools to monitor how users (e.g., physicians) access the records of subjects (e.g., patients) in the system and flag potentially privacy-compromising actions (e.g., an unauthorized "peek"). The proposed tools will integrate HCO knowledge and access log repositories to represent the system as a dynamic social network of teams and business processes that are applied to score the "safety" of each recorded access. The specific objectives of the proposed project are (1) to develop a scientific foundation for automatically learning and modeling the normal business operations of HCOs from EHR access logs, (2) to automatically detect EHR accesses that are suspicious in the context of learned HCO operations, (3) to evaluate our approach with expert feedback, and (4) to implement our approaches in an extendable software tool that is rapidly reconfigurable to any EHR system. In support of these goals, we will evaluate real world access logs from the EHR system of the Vanderbilt University Medical Center, which is a detailed repository with data covering tens of thousands of users and over a million patients. We believe that auditing tools for EHR systems, such as those developed through this research, are crucial to the continued adoption of health information technologies without sacrificing patients' privacy rights.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Ethics Core (FABRIC)
-
批准号:10662376
-
项目类别:
-
资助金额:$121.72万
-
财政年份:2023
-
负责人:Bradley A. Malin
-
依托单位:
Ethics Core (FABRIC)
-
批准号:10473062
-
项目类别:
-
资助金额:$54.3万
-
财政年份:2022
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:8695427
-
项目类别:
-
资助金额:$34.3万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:9301793
-
项目类别:
-
资助金额:$33.25万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:9193769
-
项目类别:
-
资助金额:$26.84万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:8548389
-
项目类别:
-
资助金额:$33.43万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:9754854
-
项目类别:
-
资助金额:$24.06万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:9360125
-
项目类别:
-
资助金额:$24.96万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:8341447
-
项目类别:
-
资助金额:$39.52万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
A Risk Management Framework for Identifiability in Genomics Research
-
批准号:8915734
-
项目类别:
-
资助金额:$0.88万
-
财政年份:2012
-
负责人:Bradley A. Malin
-
依托单位:
Automated Detection of Anomalous Accesses to Electronic Health Records
-
批准号:8882547
-
项目类别:
-
资助金额:$0.01万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Technologies to Enable Privacy in Biomedical Databanks
-
批准号:7921434
-
项目类别:
-
资助金额:$27.24万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Automated Detection of Anomalous Accesses to Electronic Health Records
-
批准号:8323988
-
项目类别:
-
资助金额:$23.12万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Technologies to Enable Privacy in Biomedical Databanks
-
批准号:7736656
-
项目类别:
-
资助金额:$28.7万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Automated Detection of Anomalous Accesses to Electronic Health Records
-
批准号:7938889
-
项目类别:
-
资助金额:$24.21万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Technologies to Enable Privacy in Biomedical Databanks
-
批准号:8323989
-
项目类别:
-
资助金额:$25.51万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Automated Detection of Anomalous Accesses to Electronic Health Records
-
批准号:9143798
-
项目类别:
-
资助金额:$34.15万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Technologies to Enable Privacy in Biomedical Databanks
-
批准号:9302038
-
项目类别:
-
资助金额:$26.06万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Technologies to Enable Privacy in Biomedical Databanks
-
批准号:8140679
-
项目类别:
-
资助金额:$0.19万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
Automated Detection of Anomalous Accesses to Electronic Health Records
-
批准号:8139876
-
项目类别:
-
资助金额:$23.59万
-
财政年份:2009
-
负责人:Bradley A. Malin
-
依托单位:
海外基金