Authors:
Ana Ferreira
1
;
Pedro Farinha
2
;
Cátia Santos-Pereira
2
;
Ricardo Correia
2
;
Pedro P. Rodrigues
2
;
Altamiro Costa-Pereira
2
and
Verónica Orvalho
3
Affiliations:
1
University of Luxembourg, Faculty of Medicine and University of Porto, Luxembourg
;
2
Faculty of Medicine and University of Porto, Portugal
;
3
Faculty of Science and University of Porto, Portugal
Keyword(s):
Security Usability, Human Interaction Log Analysis, Electronic Health Records, Access Control Override.
Related
Ontology
Subjects/Areas/Topics:
Accessibility and Usability
;
Adaptive and Adaptable User Interfaces
;
Enterprise Information Systems
;
HCI on Enterprise Information Systems
;
Human Factors
;
Human-Computer Interaction
;
Physiological Computing Systems
Abstract:
Patients’ privacy is critical in healthcare but users of Electronic Health Records (EHR) frequently circumvent existing security rules to perform their daily work. Users are so-called the weakest link in security but they are, many times, part of the solution when they are involved in systems’ design. In the healthcare domain, the focus is to treat patients (many times with scarce technological, time and human resources) and not to secure their information. Therefore, security must not interfere with this process but be present, nevertheless. Security usability issues must also be met with interdisciplinary knowledge from human-computer-interaction, social sciences and psychology. The main goal of this paper is to raise security and usability awareness with the analysis of users’ interaction logs of a BreakTheGlass (BTG) feature. This feature is used to restrict access to patient reports to a group of healthcare professionals within an EHR but also permit access control override in e
mergency and/or unexpected situations. The analysis of BTG user interaction logs allows, in a short time span and transparently to the user, revealing security and usability problems. This log analysis permits a better choice of methodologies to further apply in the investigation and resolution of the encountered problems.
(More)