Skip to main navigation Skip to search Skip to main content

An activity theory approach to leak detection and mitigation in patient health information (Phi)

  • University of Texas at San Antonio

Research output: Contribution to journalArticlepeer-review

12 Scopus citations

Abstract

The migration to electronic health records (EHR) in the healthcare industry has raised issues with respect to security and privacy. One issue that has become a concern for healthcare providers, insurance companies, and pharmacies is patient health information (PHI) leaks because PHI leaks can lead to violation of privacy laws, which protect the privacy of individuals’ identifiable health information, potentially resulting in a healthcare crisis. This study explores the issue of PHI leaks from an access control viewpoint. We utilize access control policies and PHI leak scenarios derived from semi structured interviews with four healthcare practitioners and use the lens of activity theory to articulate the design of an access control model for detecting and mitigating PHI leaks. Subsequently, we follow up with a prototype as a proof of concept.

Original languageEnglish
Pages (from-to)1007-1036
Number of pages30
JournalJournal of the Association for Information Systems
Volume22
Issue number4
DOIs
StatePublished - 2021

Keywords

  • Access Control Model
  • Activity Theory
  • Crisis Management
  • Design Science
  • Patient Health Information (PHI)
  • PHI Leak Detection and Mitigation

Fingerprint

Dive into the research topics of 'An activity theory approach to leak detection and mitigation in patient health information (Phi)'. Together they form a unique fingerprint.

Cite this