Risk analysis of information security in a mobile instant messaging and presence system for healthcare

نویسندگان

  • Erlend Bønes
  • Per Hasvold
  • Eva Henriksen
  • Thomas Strandenæs
چکیده

INTRODUCTION Instant messaging (IM) is suited for immediate communication because messages are delivered almost in real time. Results from studies of IM use in enterprise work settings make us believe that IM based services may prove useful also within the healthcare sector. However, today's public instant messaging services do not have the level of information security required for adoption of IM in healthcare. We proposed MedIMob, our own architecture for a secure enterprise IM service for use in healthcare. MedIMob supports IM clients on mobile devices in addition to desktop based clients. METHODS Security threats were identified in a risk analysis of the MedIMob architecture. The risk analysis process consists of context identification, threat identification, analysis of consequences and likelihood, risk evaluation, and proposals for risk treatment. RESULTS The risk analysis revealed a number of potential threats to the information security of a service like this. Many of the identified threats are general when dealing with mobile devices and sensitive data; others are threats which are more specific to our service and architecture. Individual threats identified in the risks analysis are discussed and possible counter measures presented. DISCUSSION The risk analysis showed that most of the proposed risk treatment measures must be implemented to obtain an acceptable risk level; among others blocking much of the additional functionality of the smartphone. To conclude on the usefulness of this IM service, it will be evaluated in a trial study of the human-computer interaction. Further work also includes an improved design of the proposed MedIMob architecture.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Exploring the Potential of a Mobile Messaging Application for Self-Initiated Language Learning

With the rapid expansion of deploying mobile instant messaging applications such as Telegram for the purpose of language learning, it is quite apparent that language research in this regard is lagging behind the trend. This study addressed the matter by exploring how language learners utilize a Telegram group for the purpose of language learning. In this regard, the activities of a Telegram lan...

متن کامل

Expert and Non-Expert Attitudes towards (Secure) Instant Messaging

In this paper, we present results from an online survey with 1,510 participants and an interview study with 31 participants on (secure) mobile instant messaging. Our goal was to uncover how much of a role security and privacy played in people’s decisions to use a mobile instant messenger. In the interview study, we recruited a balanced sample of ITsecurity experts and non-experts, as well as an...

متن کامل

Epidemic Dissemination of Presence Information in Mobile Instant Messaging Systems

This paper presents an approach for exchanging presence information between users of an instant messaging system in a mobile ad hoc network. As major feature, presence information is transferred when mobile users get in direct contact, similar to the spread of an infections disease. By exploiting node mobility, presence information is epidemically distributed throughout the network, effectively...

متن کامل

Using Mobile Health to Improve Genetic and Heart Diseases Prediction

Introduction: Mobile personal health are a rapidly growing area of health information technology. Mobile personal health users are able to manage their own health data and communicate with doctors in order to improve healthcare quality and efficiency. In recent years, information and communication technologies improvements, along with mobile Internet, offering anywhere and anytime connectivity,...

متن کامل

Presence, Location, and Instant Messaging in a Context-Aware Application Framework

A mobile user's presence and location information often forms important input for those applications and services that must anticipate on the user's context. Additionally, the ability to let a mobile device determine its location in an indoor environment at a fine-grained level supports the creation of a new range of personalized mobile Internet applications. The framework described here joins ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • International journal of medical informatics

دوره 76 9  شماره 

صفحات  -

تاریخ انتشار 2007