为医疗信息化设计可落地的全球网络安全框架
A Global Cybersecurity Standardization Framework for Healthcare Informatics
- 从20项关键活动出发,分5类并用专家法与算法排序
- 数据保护类($ackslashcomplement_3$)最优先,技术安全类最后实施
- 适合政策制定者和医疗信息专业人员参考落地
后疫情时代医疗数字化加速,医疗物联网与可穿戴设备持续生成云端数据,借助人工智能可用于疾病诊断、预测甚至治疗。然而,受保护健康信息(PHI)的安全风险日益严峻,现有法规既不全面也难实施。本研究首先识别出20项保障隐私与安全的关键活动,将其归纳为五类:$ackslashcomplement_1$(政策与合规管理)、$ackslashcomplement_2$(员工培训与意识)、$ackslashcomplement_3$(数据保护与隐私控制)、$ackslashcomplement_4$(监控与响应)、$ackslashcomplement_5$(技术与基础设施安全),并基于密度聚类(DBSCAN)完成分类,利用TOPSIS方法进行优先级排序。结果表明,$ackslashcomplement_3$应优先实施,其次为$ackslashcomplement_1$和$ackslashcomplement_2$,最后是$ackslashcomplement_4$与$ackslashcomplement_5$。该优先级框架对医疗政策制定者与信息专业人员具有实践指导意义。
原文摘要 · Abstract (English)
Healthcare has witnessed an increased digitalization in the post-COVID world. Technologies such as the medical internet of things and wearable devices are generating a plethora of data available on the cloud anytime from anywhere. This data can be analyzed using advanced artificial intelligence techniques for diagnosis, prognosis, or even treatment of disease. This advancement comes with a major risk to protecting and securing protected health information (PHI). The prevailing regulations for preserving PHI are neither comprehensive nor easy to implement. The study first identifies twenty activities crucial for privacy and security, then categorizes them into five homogeneous categories namely: $\complement_1$ (Policy and Compliance Management), $\complement_2$ (Employee Training and Awareness), $\complement_3$ (Data Protection and Privacy Control), $\complement_4$ (Monitoring and Response), and $\complement_5$ (Technology and Infrastructure Security) and prioritizes these categories to provide a framework for the implementation of privacy and security in a wise manner. The framework utilized the Delphi Method to identify activities, criteria for categorization, and prioritization. Categorization is based on the Density-Based Spatial Clustering of Applications with Noise (DBSCAN), and prioritization is performed using a Technique for Order of Preference by Similarity to the Ideal Solution (TOPSIS). The outcomes conclude that $\complement_3$ activities should be given first preference in implementation and followed by $\complement_1$ and $\complement_2$ activities. Finally, $\complement_4$ and $\complement_5$ should be implemented. The prioritized view of identified clustered healthcare activities related to security and privacy, are useful for healthcare policymakers and healthcare informatics professionals.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。