Related Experiment Videos
An integrated secure design of a medical database system
G Pangalos1, M Khair, L Bozios
1Computers Division, Faculty of Technology, Aristotelian University, Thessaloniki 540 06, Greece.
Summary
This study introduces a secure design for hospital databases, combining two security policy types to protect medical data. The method effectively prevents unauthorized access without hindering system usability.
Area of Science:
- Health Informatics
- Database Security
- Information Security Policy
Background:
- Hospital environments handle sensitive medical data, necessitating robust security measures.
- Existing database security policies have limitations when used in isolation.
- Integrating different security approaches can offer enhanced protection.
Purpose of the Study:
- To propose an integrated secure design methodology for hospital databases.
- To combine discretionary and mandatory database security policies for improved medical data protection.
- To evaluate the effectiveness of the proposed methodology in a real-world hospital setting.
Main Methods:
- Development of an integrated secure design methodology based on discretionary and mandatory security policies.
- Experimental implementation of the methodology in a major Greek hospital.
- Evaluation of the system's effectiveness in limiting unauthorized access and maintaining system capabilities.
Main Results:
- The integrated methodology successfully combined the strengths of discretionary and mandatory security policies.
- Experimental implementation demonstrated effective limitation of unauthorized access to the medical database.
- The system maintained operational capabilities without significant restrictions.
Conclusions:
- The integrated secure design methodology enhances medical database security in hospital environments.
- Combining discretionary and mandatory policies offers a superior approach to protecting sensitive patient information.
- The implemented system provides effective security without compromising system functionality.