|
|
| Research article summary (published 21 Aug 2006): |
Risk analysis of information security in a mobile instant messaging and presence system for healthcare.
Full Abstract
INTRODUCTION:
Instant messaging (IM) is suited for immediate communication because messages are delivered almost in real time. Results from studies of IM use in enterprise work settings make us believe that IM based services may prove useful also within the healthcare sector. However, today's public instant messaging services do not have the level of information security required for adoption of IM in healthcare. We proposed MedIMob, our own architecture for a secure enterprise IM service for use in healthcare. MedIMob supports IM clients on mobile devices in addition to desktop based clients.
METHODS:
Security threats were identified in a risk analysis of the MedIMob architecture. The risk analysis process consists of context identification, threat identification, analysis of consequences and likelihood, risk evaluation, and proposals for risk treatment.
RESULTS:
The risk analysis revealed a number of potential threats to the information security of a service like this. Many of the identified threats are general when dealing with mobile devices and sensitive data; others are threats which are more specific to our service and architecture. Individual threats identified in the risks analysis are discussed and possible counter measures presented.
DISCUSSION:
The risk analysis showed that most of the proposed risk treatment measures must be implemented to obtain an acceptable risk level; among others blocking much of the additional functionality of the smartphone. To conclude on the usefulness of this IM service, it will be evaluated in a trial study of the human-computer interaction. Further work also includes an improved design of the proposed MedIMob architecture.2006 Elsevier Ireland Ltd
Learn Faster Today Improve your study skills
Author information
Author/s: Bønes, Erlend (E); Hasvold, Per (P); Henriksen, Eva (E); Strandenaes, Thomas (T);
Affiliation: Norwegian Centre for Telemedicine, University Hospital of North Norway, P.O. Box 35, NO-9038 Tromsø, Norway.
Journal and publication information
Publication Type: Journal Article
Journal: International journal of medical informatics (Int J Med Inform), published in Ireland. (Language: eng)
Reference: 2007-Sep; vol 76 (issue 9) : pp 677-87
Dates: Created 2007/07/30; Completed 2007/11/13;
PMID: 16931132, status: MEDLINE (last retrieval date: 12/26/2008)
Sourced from the National Library of Medicine. Abstract text and other information may be subject to copyright.
External Links for this article (including full text providers, if available):
Click Electronic Full-text Provider Links to see options for finding the electronic full text links to this article. Note there may be a subscription or fee required for access to the full text. See our FAQ for information on finding FREE full text articles.
This article may also be located in paper journal collections available in many libraries. Use the Journal and Publication Information above to find the full article.
MeSH headings (categories)
This article was linked to the MESH Headings shown below.
Related articles
These are the highest related articles currently in the database:
- Email consultations in health care: 2--acceptability and safe application.
19 Aug 2004 - Gateway solutions for SPAM.
29 Apr 2003 - Emerging technologies. Tools considered fanciful just a few years ago have matured and are ready to break forth.
30 Dec 2003 - A systematic review of practice standards and research ethics in technology-based home health care intervention programs for older adults.
29 Nov 2005 - Evaluation of a new device for the transmission of electrocardiograms by email.
30 Dec 2007 - [Telemedicine and general practice--future or present. Telemedicine, a way to strengthen the gatekeeper role?]
2 Nov 2002 - PET_Mail: a low-key, high-tech PET community.
29 Jun 2003 - Patient-physician e-mail: passion or fashion?
29 Jun 2003 - Use of health-related online sites.
30 Dec 2002 - Soft networks for bridging the gap between research and practice: illuminative evaluation of CHAIN.
13 May 2004
Related Article Map
Legend:
- FREE Full text Article.
- Abstract only.
- Title only. More help.
See a large map of 100+ related articles.