13
IRUS Total
Downloads
  Altmetric

Comprehensive user requirements engineering methodology for secure and interoperable health data exchange

File Description SizeFormat 
s12911-018-0664-0.pdfPublished version1.87 MBAdobe PDFView/Open
Title: Comprehensive user requirements engineering methodology for secure and interoperable health data exchange
Authors: Natsiavas, P
Rasmussen, J
Voss-Knude, M
Votis, K
Coppolino, L
Campegiani, P
Cano, I
Mari, D
Faiella, G
Clemente, F
Nalin, M
Grivas, E
Stan, O
Gelenbe, E
Dumortier, J
Petersen, J
Tzovaras, D
Romano, L
Komnios, I
Koutkias, V
Item Type: Journal Article
Abstract: Background Increased digitalization of healthcare comes along with the cost of cybercrime proliferation. This results to patients’ and healthcare providers' skepticism to adopt Health Information Technologies (HIT). In Europe, this shortcoming hampers efficient cross-border health data exchange, which requires a holistic, secure and interoperable framework. This study aimed to provide the foundations for designing a secure and interoperable toolkit for cross-border health data exchange within the European Union (EU), conducted in the scope of the KONFIDO project. Particularly, we present our user requirements engineering methodology and the obtained results, driving the technical design of the KONFIDO toolkit. Methods Our methodology relied on four pillars: (a) a gap analysis study, reviewing a range of relevant projects/initiatives, technologies as well as cybersecurity strategies for HIT interoperability and cybersecurity; (b) the definition of user scenarios with major focus on cross-border health data exchange in the three pilot countries of the project; (c) a user requirements elicitation phase containing a threat analysis of the business processes entailed in the user scenarios, and (d) surveying and discussing with key stakeholders, aiming to validate the obtained outcomes and identify barriers and facilitators for HIT adoption linked with cybersecurity and interoperability. Results According to the gap analysis outcomes, full adherence with information security standards is currently not universally met. Sustainability plans shall be defined for adapting existing/evolving frameworks to the state-of-the-art. Overall, lack of integration in a holistic security approach was clearly identified. For each user scenario, we concluded with a comprehensive workflow, highlighting challenges and open issues for their application in our pilot sites. The threat analysis resulted in a set of 30 user goals in total, documented in detail. Finally, indicative barriers of HIT acceptance include lack of awareness regarding HIT risks and legislations, lack of a security-oriented culture and management commitment, as well as usability constraints, while important facilitators concern the adoption of standards and current efforts for a common EU legislation framework. Conclusions Our study provides important insights to address secure and interoperable health data exchange, while our methodological framework constitutes a paradigm for investigating diverse cybersecurity-related risks in the health sector.
Issue Date: 16-Oct-2018
Date of Acceptance: 28-Sep-2018
URI: http://hdl.handle.net/10044/1/65174
DOI: https://dx.doi.org/10.1186/s12911-018-0664-0
ISSN: 1472-6947
Publisher: BioMed Central
Journal / Book Title: BMC Medical Informatics and Decision Making
Volume: 18
Copyright Statement: © The Author(s). 2018 Open Access This article is distributed under the terms of the Creative Commons Attribution 4.0 International License (http://creativecommons.org/licenses/by/4.0/), which permits unrestricted use, distribution, and reproduction in any medium, provided you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons license, and indicate if changes were made. The Creative Commons Public Domain Dedication waiver (http://creativecommons.org/publicdomain/zero/1.0/) applies to the data made available in this article, unless otherwise stated.
Keywords: Science & Technology
Life Sciences & Biomedicine
Medical Informatics
Cybersecurity
Interoperability
Health information technologies (HIT)
Digital health
Cross-border health data exchange
User requirements engineering
Gap analysis
Barriers and facilitators for HIT acceptance
0806 Information Systems
1103 Clinical Sciences
0909 Geomatic Engineering
Publication Status: Published
Article Number: ARTN 85
Online Publication Date: 2018-10-16
Appears in Collections:Electrical and Electronic Engineering
Faculty of Engineering