Research Toward the Practical Application of a Risk Evaluation Framework: Security Analysis of the Clinical Area within the German Electronic Health Information System

Proceedings of International Bled eCon­ference (Bled 2011), Bled, Slovenia, June 12-15, 2011, pp. 156-168

Posted: 29 Sep 2012

See all articles by Ali Sunyaev

Ali Sunyaev

University of Cologne; Karlsruhe Institute of Technology

Johannes Pflug

University of Vienna

Date Written: 2011

Abstract

The following study provides a risk analysis of the forthcoming nationwide healthcare information system in Germany. Based on the information security audit methodology of the Federal Office for Information Security (BSI), we evaluated the introduction of the new system in hospitals with respect to security. Conceptually, the study focuses explicitly on an organizational level; specifically the use of healthcare telematics components such as electronic health card and health professional card. A dual approach of both security process and risk analysis thereby established an adequate level of information security. For this purpose, an appropriate framework specifically designed for the clinical area is first developed and explained in detail. Based on these perceptions it is possible to precisely check the workflows “patient admission” and “prescription of medicine” for inherent organizational threats. The aim of this paper is to propose appropriate steps to mitigate potential risks before German healthcare telematics comes into use.

Keywords: electronic health card, eHealth, organizational risk analysis, information security management

Suggested Citation

Sunyaev, Ali and Pflug, Johannes, Research Toward the Practical Application of a Risk Evaluation Framework: Security Analysis of the Clinical Area within the German Electronic Health Information System (2011). Proceedings of International Bled eCon­ference (Bled 2011), Bled, Slovenia, June 12-15, 2011, pp. 156-168, Available at SSRN: https://ssrn.com/abstract=2152951

Ali Sunyaev (Contact Author)

University of Cologne ( email )

Albertus-Magnus-Platz
Cologne, 50923
Germany

HOME PAGE: http://www.isq.uni-koeln.de

Karlsruhe Institute of Technology ( email )

Kaiserstraße 12
Karlsruhe, Baden Württemberg 76131
Germany

Johannes Pflug

University of Vienna ( email )

Bruenner Strasse 72
Vienna, Vienna 1090
Austria

Do you have negative results from your research you’d like to share?

Paper statistics

Abstract Views
287
PlumX Metrics