Using a Policy Spaces Auditor to check for Temporal Inconsistencies in Healthcare Audit Log Files

Published in: Innovation in Engineering, Technology and Education for Competitiveness and Prosperity: Proceedings of the 11th Latin American and Caribbean Conference for Engineering and Technology
Date of Conference: August 14-16, 2013
Location of Conference: Cancun, Mexico
Authors: Tyrone Grandison
Sean Thorpe
Technical Paper: #24

Abstract:

In English:
The core tenet of the healthcare field is that care delivery comes first and nothing should interfere with it. Consequently, theaccess control mechanisms, used in healthcare to regulate and restrict the disclosure of data, are often bypassed,especially in emergency cases. This concept is called ‘break the glass’ (BtG) and is common in healthcare organizations.Though useful and necessary in emergency situations, from a security perspective, it is an important system flaw. Malicious users can exploit the system by breaking the glass to gain unauthorized privileges and accesses.Also, as the proportion of system accesses that are BtG increases, it becomes easier for an attacker to hide in the crowd of the audit log. In this paper, we build upon existing work that defined policy spaces to help manage the impact of the break the glass phenomenon in healthcare systems. We present a system that enables the inference and discovery of facts that require further scrutiny. This significantly reduces the burden on the person investigating potentially suspicious activity in the audit logs of healthcare information systems.