Research Output
Monitoring information security risks within health care
  This paper presents an overview of possible risks to the security of health care data. These
risks were detected with a novel approach to information security. It is based on the
philosophy that information security risk monitoring should include human and societal
factors, and that collaboration between organisations and experts is essential to gain
knowledge about potential risks. The methodology uses a mixed methods approach
including a quantitative analysis of historical security incident data and expert elicitation
through a Delphi study. The result is an overview of the possible socio-technical risks that
a panel of experts expect to materialise in health care organisations in the near future.
These risks include (amongst others): staff leaving data assets unattended on the premises
and these assets consequently go missing, staff sharing passwords to access patient data
and staff sending email containing personal patient data to the wrong addressee thus
disclosing data to unauthorised persons. The expert panel recognized risks from current
discussion topics such as outsourcing, but these risks are still considered to appear less
frequently than the more traditional information security risks. Furthermore, the panel did
not estimate a high frequency of occurrence of socio-technical information security risks
caused by new technologies such as cloud computing or RFID.

  • Type:

    Article

  • Date:

    29 April 2013

  • Publication Status:

    Published

  • Publisher

    Elsevier

  • DOI:

    10.1016/j.cose.2013.04.005

  • Cross Ref:

    S0167404813000813

  • ISSN:

    0167-4048

  • Library of Congress:

    QA75 Electronic computers. Computer science

  • Dewey Decimal Classification:

    005.8 Data security

Citation

van Deursen, N., Buchanan, W. J., & Duff, A. (2013). Monitoring information security risks within health care. Computers and Security, 37, 31-45. https://doi.org/10.1016/j.cose.2013.04.005

Authors

Keywords

Delphi method; Health care; Information security; Patient privacy; Risk management; Sociotechnical information security;

Monthly Views:

Available Documents