• DocumentCode
    3282955
  • Title

    Information Security Risk Assessment in Healthcare: The Experience of an Italian Paediatric Hospital

  • Author

    Bava, Michele ; Cacciari, Domenico ; Sossa, Edoardo ; Zotti, Daniel ; Zangrando, Riccardo

  • Author_Institution
    Clinical Eng. & IT Dept., Inst. of Maternal & Child Health IRCCS "Burlo Garofolo", Trieste, Italy
  • fYear
    2009
  • fDate
    23-25 July 2009
  • Firstpage
    321
  • Lastpage
    326
  • Abstract
    The match of research activity and paediatric healthcare services offered by the IRCCS ldquoBurlo Garofolordquo, produces a complex situation especially regarding IT security. World-wide IT security issues in the recent years have had an exponential development of problems to face. Meanwhile, risks and threats are therefore growing and so all the problems tied up to the vulnerabilitiespsila management generating risks for the hospital security. These remarks arenpsilat involving only the continuous fitting to the application of the current Italian regulation, but the search of tools (technological and organizational) that may guarantee security in an effective way. This study shows how the hospital IT dept. is providing the adjustment of technologies and procedures to increase IT security needs and giving access to data, information and knowledge to authorized personnel. To face these challenges the hospital IT dept. proposed both internally developed open-source technical solutions and information security risk assessment methods.
  • Keywords
    health care; medical information systems; message authentication; risk management; IRCCS Burlo Garofolo; IT security; Italian paediatric hospital; Italian regulation; healthcare; hospital IT department; hospital security; information security risk assessment; open-source technical solutions; wireless authentication; Cryptography; Data security; Hospitals; Information management; Information security; Legislation; Medical services; Pediatrics; Protection; Risk management; IT Security; Risk Analysis; Risk Management; Wireless Authentication;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence, Communication Systems and Networks, 2009. CICSYN '09. First International Conference on
  • Conference_Location
    Indore
  • Print_ISBN
    978-0-7695-3743-6
  • Type

    conf

  • DOI
    10.1109/CICSYN.2009.14
  • Filename
    5231949