期刊
INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS
卷 76, 期 9, 页码 677-687出版社
ELSEVIER IRELAND LTD
DOI: 10.1016/j.ijmedinf.2006.06.002
关键词
instant messaging; mobility; healthcare; information security; risk analysis
Introduction: Instant messaging (IM) is suited for immediate communication because messages are delivered almost in real time. Results from studies of IM use in enterprise work settings make us believe that IM based services may prove useful also within the healthcare sector. However, today's public instant messaging services do not have the level of information security required for adoption of IM in healthcare. We proposed MedlMob, our own architecture for a secure enterprise IM service for use in healthcare. MedlMob supports IM clients on mobile devices in addition to desktop based clients. Methods: Security threats were identified in a risk analysis of the MedIMob architecture. The risk analysis process consists of context identification, threat identification, analysis of consequences and likelihood, risk evaluation, and proposals for risk treatment. Results: The risk analysis revealed a number of potential threats to the information security of a service like this. Many of the identified threats are general when dealing with mobile devices and sensitive data; others are threats which are more specific to our service and architecture. Individual threats identified in the risks analysis are discussed and possible counter measures presented. Discussion: The risk analysis showed that most of the proposed risk treatment measures must be implemented to obtain an acceptable risk level; among others blocking much of the additional functionality of the smartphone. To conclude on the usefulness of this IM service, it will be evaluated in a trial study of the human-computer interaction. Further work also includes an improved design of the proposed MedIMob architecture.(c) 2006 Elsevier Ireland Ltd. All rights reserved.
作者
我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。
推荐
暂无数据