• DocumentCode
    3089358
  • Title

    Proposing regulatory-driven automated test suites for electronic health record systems

  • Author

    Morrison, Patrick ; Holmgreen, Casper ; Massey, Aaron K. ; Williams, Laurie

  • Author_Institution
    Dept. of Comput. Sci., North Carolina State Univ., Raleigh, NC, USA
  • fYear
    2013
  • fDate
    20-21 May 2013
  • Firstpage
    46
  • Lastpage
    49
  • Abstract
    In regulated domains such as finance and health care, failure to comply with regulation can lead to financial, civil and criminal penalties. While systems vary from organization to organization, regulations apply across organizations. We propose the use of Behavior-Driven-Development (BDD) scenarios as the basis of an automated compliance test suite for standards such as regulation and interoperability. Such test suites could become a shared asset for use by all systems subject to these regulations and standards. Each system, then, need only create their own system-specific test driver code to automate their compliance checks. The goal of this research is to enable organizations to compare their systems to regulation in a repeatable and traceable way through the use of BDD. To evaluate our proposal, we developed an abbreviated HIPAA test suite and applied it to three open-source electronic health record systems. The scenarios covered all security behavior defined by the selected regulation. The system-specific test driver code covered all security behavior defined in the scenarios, and identified where the tested system lacked such behavior.
  • Keywords
    automatic testing; conformance testing; health care; medical information systems; open systems; program testing; security of data; BDD scenarios; HIPAA test suite; automated compliance test suite; behavior-driven-development; civil penalties; compliance checks; criminal penalties; financial penalties; health care; interoperability; open-source electronic health record systems; organization; regulations; regulatory-driven automated test suites; security behavior; system-specific test driver code; Boolean functions; Certification; Data structures; NIST; Behavior-Driven-Development Healthcare IT; Regulatory Compliance; Security; Software Engineering; Software Testing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Engineering in Health Care (SEHC), 2013 5th International Workshop on
  • Conference_Location
    San Francisco, CA
  • Type

    conf

  • DOI
    10.1109/SEHC.2013.6602477
  • Filename
    6602477