Web Application Security - Term Paper

(2) Encryption and Trusted Base. HCOs are struggling with rapid changes in the systems they need to secure. Early HCO computing systems used mainframe computers that could be accessed from terminals located in a hospital facility. This trusted base was relatively easy to secure until the Internet offered remote access, but standard enterprise protections such as firewalls were accepted as being sufficiently effective. Now the situation is increasingly complicated by technology changes such as: Bring Your Own Device (BYOD) arrangements in which HCO employees put sensitive data on their own cell phones and tablets, the use of cloud services in which Electronic Health Records (EHRs) are held by third parties, participation in HIE systems that move data between a changing collection of HCOs, and the deployment of patient portals, which provide a new attack surface for access to the EHR. Encryption is a powerful tool for addressing challenges with trusted base. For instance, if the data stored on a lost laptop or maintained by a compromised cloud service is encrypted, the threat of a privacy compromise is greatly reduced. Research is needed to make such strategies efficient and convenient enough to enable their universal deployment, particularly to protect data at rest (that is, in storage). These problems and the required solutions also apply to secondary use data for medical research or public health. Another area of concern is the rise of Advanced Persistent Threats (APTs), which entail sophisticated attacks, possibly supported by foreign governments. While these attacks do not currently target EHRs, they are creating significant levels of collateral damage to EHR systems, especially when such systems are attached to certain types of targets like government and university networks.

(3) Automated Policy. A key challenge faced by many HCOs is the need to share EHRs securely though HIEs such as those being set up by many states and regions, and the need to share them though rapidly evolving partnerships with various business associates. Current techniques are too informal and manual to provide the desired efficiency and convenience. For instance, if it is necessary to get an attorney to review each interstate data exchange, then a high level of exchange of EHR data will lead to a high level of expense (and delayed access). Enabling computers to settle policy decisions automatically can lead to reduced costs, improved care (though timely information exchange), and better support for secondary use of data. Research is needed to determine reliable ways to express policies. We also require strategies to integrate and enforce formally expressed policies into common HCO and HIE information architectures. Such advances will touch on other important areas like legal and medical ontologies and will inform the development of legal codes and consent management in the future.

Term Paper: Web Application Security Challenges - …

Web security term paper, Custom paper Academic Service

Research Papers Web Services Security

Essay about Web Application Security - 1495 Words

(6) Data Segmentation and De-Identification. It is widely recognized by both HCOs and government regulators that patients feel that some types of health data are especially sensitive. Examples include records related to mental health, drug abuse, genetics, sexually transmitted diseases, and more. When health data is shared, there is a desire to transmit this information only when it is necessary. For example, a provider who needs immunization records may not need to see mental health notes. Interest in how to perform this kind of data segmentation has intensified with the growth of HCOs and the introduction of HIEs. However, there is little understanding of exactly how this type of segmentation can deliver meaningful privacy with acceptable impact on the safety and quality of care. Vendor products that claim to segment data may mislead patients and caregivers if they are poorly designed. A technology closely related to data segmentation is de-identification, wherein records are transformed so it is difficult to determine whether a given record is associated with a given individual. The data segmentation problem needs some of the rigor that has been applied to the de-identification problem. In particular, we require ways to measure the tradeoffs between privacy, safety, and quality. These measures should be used to determine tradeoffs for specific segmentation technologies. The de-identification problem itself also faces new challenges such as how to protect privacy of genomic data. New techniques are emerging in this area, but new research is required to determine information flows and privacy risks and to design sufficiently efficient protective measures.

