School of Computing

Grounding information security in healthcare

Ana Ferreira, Luis Antunes, David Chadwick, and Ricardo Correi

International Journal of Medical Informatics, 79(4):182-196, April 2010 [doi].

Abstract

Abstract Purpose The objective of this paper is to show that grounded theory (GT), together with mixed methods, can be used to involve healthcare professionals in the design and definition of access control policies to EMR systems. Methods The mixed methods applied for this research included, in this sequence, focus groups (main qualitative method that used grounded theory for the data analysis) and structured questionnaires (secondary quantitative method). Results Results showed that the presented methodology can be used to involve healthcare professionals in the definition of access control policies to EMR systems and explore these issues in a diversified and integrated way. The methodology allowed for the generation of great amounts of data in the beginning of the study and in a short time span. Results from the applied methodology revealed a first glimpse of the theories to be generated and integrated, with future research, into the access control policies. Conclusions The methodological research described in this paper is very rarely, if ever, applied in developing security tools such as access control. Nevertheless, it can be an effective way of involving healthcare professionals in the definition of access control policies and in making information security more grounded into their workflows and daily practices.

Download publication 357 kbytes (PDF)

Bibtex Record

@article{3029,
author = {Ana Ferreira and Luis Antunes and David Chadwick and Ricardo Correi},
title = {Grounding Information Security in Healthcare},
month = {April},
year = {2010},
pages = {182-196},
keywords = {determinacy analysis, Craig interpolants},
note = {},
doi = {10.1016/j.ijmedinf.2010.01.009},
url = {http://www.cs.kent.ac.uk/pubs/2010/3029},
    publication_type = {article},
    submission_id = {282_1280840829},
    journal = {International Journal of Medical Informatics},
    volume = {79},
    number = {4},
}

School of Computing, University of Kent, Canterbury, Kent, CT2 7NF

Enquiries: +44 (0)1227 824180 or contact us.

Last Updated: 21/03/2014