Show simple item record

dc.contributor.authorWairimu, Samuel
dc.contributor.authorFritsch, Lothar
dc.date.accessioned2023-02-01T14:03:03Z
dc.date.available2023-02-01T14:03:03Z
dc.date.created2022-08-25T12:30:10Z
dc.date.issued2022-08-23
dc.identifier.isbn978-1-4503-9670-7
dc.identifier.urihttps://hdl.handle.net/11250/3047778
dc.description.abstractWhat harms and consequences do patients experience after a medical data breach? This article aims at the improvement of privacy impact analysis for data breaches that involve personal medical data. The article has two major findings. First, scientific literature does not mention consequences and harms to the data subjects when discussing data breaches in the healthcare sector. For conceptualizing actual documented harm, we had to search court rulings and popular press articles instead. We present the findings of our search for empirically founded harms in the first part of the article. Second, we present a modified PRIAM assessment method with the goal of better assessment of harms and consequences of such data breaches for the patient/employee data subject in healthcare. We split the risk assessment into parallel categories of assessment rather than calculating a single risk score. In addition, we quantify the original PRIAM categories into a calculus for risk assessment. The article presents our modified PRIAM which is the result of these modifications. Our overall contribution is the collection of actual harms and consequences of e-health data breaches that complement the overly theoretical discussion in publications. With our operationalization of PRIAM and by providing a catalog of real harms examples, we focus privacy impact assessment on actual harms to persons.en_US
dc.language.isoengen_US
dc.publisherAssociation for Computing Machinery (ACM)en_US
dc.relation.ispartofARES 2022: The 17th International Conference on Availability, Reliability and Security
dc.relation.urihttps://dl.acm.org/doi/abs/10.1145/3538969.3544462
dc.rightsNavngivelse 4.0 Internasjonal*
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/deed.no*
dc.subjectPrivacyen_US
dc.subjectData breachen_US
dc.subjectPersonal health informationen_US
dc.subjectConsequencesen_US
dc.subjectRisk assessmenten_US
dc.subjectHarmsen_US
dc.subjectPrivacy impacten_US
dc.titleModelling privacy harms of compromised personal medical data - beyond data breachen_US
dc.typeConference objecten_US
dc.description.versionpublishedVersionen_US
dc.rights.holder© 2022 Copyright held by the owner/author(s)en_US
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1
dc.identifier.doihttps://doi.org/10.1145/3538969.3544462
dc.identifier.cristin2045990
dc.source.pagenumber1-9en_US
dc.subject.nsiVDP::Matematikk og naturvitenskap: 400en_US
dc.subject.nsiVDP::Mathematics and natural scienses: 400en_US


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record

Navngivelse 4.0 Internasjonal
Except where otherwise noted, this item's license is described as Navngivelse 4.0 Internasjonal