HI-risk: A Method to Analyse Health Information Risk Intelligence

Buchanan, W., Deursen, N. (2016). HI-risk: A Method to Analyse Health Information Risk Intelligence. In: (Ed.) IEEE 15th International Conference on e-Health Networking, Applications & Services, , () ( ed.). (pp. ). Munich, Germany: . IEEE.



This paper describes the Health Information risk (HI-risk) method for identifying socio-technical information security risks in healthcare. It is argued that information security risk approaches should consider risks from a socio-technical point of view, including technical, social and environmental subsystems. The environment often remains unexplored, but many lessons can be learned from the social and information sciences, in particular from macro-scale information society studies. HI-risk identifies risks in the environment by incorporating security intelligence from related entities and experts in the field. The results of a risk forecast made by the HI-risk method suggest the feasibility of this approach in healthcare and beyond. It is concluded that sharing socio-technical information security intelligence may positively contribute to the security of information in interrelated organisations and society at large.
