Safeguarding Healthcare: A Comprehensive Threat Analysis of Clinical Decision Support Systems

  • Aleksandra Ursula Charlotte Hamel
  • , Bogdan Cristian Zarcu
  • , Andras Gergely Csenteri
  • , Tamara Pfliegler
  • , Sajjad Khan
  • , Davor Svetinovic

    Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

    1 Scopus citations

    Abstract

    Using digital data gathering and analytics in healthcare brings benefits and risks to patients and practitioners. Smart Health Information Systems, such as Clinical Decision Support Systems (CDSSs), consolidate data from various sources, utilizing artificial intelligence for decision support. However, machine learning models in CDSSs are vulnerable to various attacks, leading to incorrect predictions with severe consequences. This paper systematically investigates security and privacy threats related to CDSSs. First, we leverage the data flow and sequence diagrams to identify the critical use cases that might lead to security or privacy breaches. Second, we identify and classify threats imminent to the CDSSs using Security Cards and STRIDE. Lastly, the persona non-grata who pose a significant threat to the integrity of the CDSSs are identified. Implementing our method can assist teams in addressing security threats to CDSSs by considering their unique vulnerabilities. This research contributes to developing comprehensive security strategies for CDSSs.

    Original languageBritish English
    Title of host publication2023 IEEE International Conference on Dependable, Autonomic and Secure Computing, International Conference on Pervasive Intelligence and Computing, International Conference on Cloud and Big Data Computing, International Conference on Cyber Science and Technology Congress, DASC/PiCom/CBDCom/CyberSciTech 2023
    PublisherInstitute of Electrical and Electronics Engineers Inc.
    Pages478-485
    Number of pages8
    ISBN (Electronic)9798350304602
    DOIs
    StatePublished - 2023
    Event2023 IEEE International Conference on Dependable, Autonomic and Secure Computing, 2023 International Conference on Pervasive Intelligence and Computing, 2023 International Conference on Cloud and Big Data Computing, 2023 International Conference on Cyber Science and Technology Congress, DASC/PiCom/CBDCom/CyberSciTech 2023 - Abu Dhabi, United Arab Emirates
    Duration: 14 Nov 202317 Nov 2023

    Publication series

    Name2023 IEEE International Conference on Dependable, Autonomic and Secure Computing, International Conference on Pervasive Intelligence and Computing, International Conference on Cloud and Big Data Computing, International Conference on Cyber Science and Technology Congress, DASC/PiCom/CBDCom/CyberSciTech 2023

    Conference

    Conference2023 IEEE International Conference on Dependable, Autonomic and Secure Computing, 2023 International Conference on Pervasive Intelligence and Computing, 2023 International Conference on Cloud and Big Data Computing, 2023 International Conference on Cyber Science and Technology Congress, DASC/PiCom/CBDCom/CyberSciTech 2023
    Country/TerritoryUnited Arab Emirates
    CityAbu Dhabi
    Period14/11/2317/11/23

    Keywords

    • clinical decision support system
    • healthcare
    • persona non-grata
    • privacy
    • security
    • STRIDE
    • threat modeling

    Fingerprint

    Dive into the research topics of 'Safeguarding Healthcare: A Comprehensive Threat Analysis of Clinical Decision Support Systems'. Together they form a unique fingerprint.

    Cite this