SlideShare a Scribd company logo
What is an EHR?What is an EHR?
The EHR is a longitudinal
electronic record of a patient
health information generated by
one or more encounters in any
care delivery setting.
Advantages of EHRAdvantages of EHR
Cost can be reduced
Quality of care can be improved
Record can be kept easily
Mobility
Why Security of EHR Is Needed ?Why Security of EHR Is Needed ?
INSIDER ATTACKS
An Insider attack occurs when
employees with legitimate
access to their organization
information systems use these
systems to sabotage their
organization IT infrastructure
or commit fraud.
SOFTWARE SECURITY
REQUIREMENTS
SOFTWARE SECURITY
REQUIREMENTS
Use cases
Misuse cases
It specifies a negative use case i.e. behavior
that is not allowed in the proposed system.
It is a description of the possible
sequences of interactions between the
system and it’s external actors.
Certification of EHR SystemsCertification of EHR Systems
Its certification began in 2006
It is primarily conducted by the
Certification Commission of
Healthcare IT (CCHIT)
Why EHR Systems Are
Attacked ?
For Health
Records
For Service
For Identity And
Billing Information
Exploits Done On
Targeted
Applications
Exploits Done On
Targeted
Applications
Implementation Bugs
Design Flaws
They are code level software
problems.
They are high-level problems
associated with the architecture
and design of the system.
Implementation Bugs Session
Hijacking
Cross-Site
Scripting
Phishing
SQL
Injections
PDF Exploits
Denial of
Service: File
Uploads
Authorization
Failure
SQL InjectionsSQL Injections
In this, an attacker exploits
a lack of input validation to
force unintended system
behavior by inserting
reserved words or
characters into input fields
that will alter the logical
structure of a SQL
statement.
Performed on
Admin Login - Amskrupajal.org
www.giantstudios.com/buy-soft/adminlogin.asp
www.quickwrench.net/
Cross-Site
Scripting
Cross-Site
Scripting
It’s a computer
security vulnerability
that enables malicious
attackers to inject
client side script into
web-page viewed by
other users.
Electronic health records
Denial of Service:
File Uploads
Denial of Service:
File Uploads
In this the attacker
changes the state of
web server to slow or
unresponsive.
PhishingPhishing
It is an attempt to
acquire sensitive
information such as
user names, passwords
etc. by masking as a
trustworthy entity.
Lack of
Authorization
control
Lack of
Authorization
control
In this the patient’s
confidential health
records and personal
identification
information can be
viewed by the
attacker.
ConclusionConclusion
The EHR will soon have ….
Better privacy and security
protections …
Information will be available
when we need it …
BibliographyBibliography
1) Research paper
2) http://www.ncrr.nih.gov/publications/informatics/ehr.pdf
3) http://www.hhs.gov/health/healthnetwork/background/
4) Wikipedia.
5)http://mhcc.maryland.gov/electronichealth/mhitr/EHR
%20Links /challenges_to_ehr.pdf
7) www.drivencompany.com/nist.cfm
8) http://go4webapps.com/2010/04/24/webscarab-web-
security-application-testing-tool/
THANK YOU
Submitted by:
Shivani Tyagi
Anurag Deb

More Related Content

PDF
A Review Report on Security Threats on Database
PPTX
Priviledged Identity Management
PDF
Trivadis TechEvent 2017 The future of mobility Daniel von Büren
PDF
Top ten database_threats
DOCX
Sec440: Server Malware Protection Policy
DOCX
Security raw
DOCX
CYB 610 Effective Communication - snaptutorial.com
A Review Report on Security Threats on Database
Priviledged Identity Management
Trivadis TechEvent 2017 The future of mobility Daniel von Büren
Top ten database_threats
Sec440: Server Malware Protection Policy
Security raw
CYB 610 Effective Communication - snaptutorial.com

What's hot (19)

PDF
Cyb 610 Education Organization-snaptutorial.com
DOCX
CYB 610 Exceptional Education - snaptutorial.com
DOCX
Cyb 610Education Specialist / snaptutorial.com
PDF
Csec 610 Believe Possibilities / snaptutorial.com
PDF
Get Ahead of your Next Security Breach
PDF
200711 002
PDF
Cyb 610 Believe Possibilities / snaptutorial.com
DOCX
CSEC 610 Education Specialist / snaptutorial.com
PDF
Csec 610 Education Organization-snaptutorial.com
PDF
Cst 610 Believe Possibilities / snaptutorial.com
DOCX
CSEC 610 Effective Communication - snaptutorial.com
PPTX
Secure Code Warrior - Poor authorization and authentication
DOCX
CST 610 RANK Educational Specialist--cst610rank.com
PDF
CST 610 RANK Become Exceptional--cst610rank.com
DOCX
CST 610 RANK Inspiring Innovation--cst610rank.com
PDF
CST 610 RANK Introduction Education--cst610rank.com
PDF
CST 610 RANK Remember Education--cst610rank.com
DOCX
CST 610 Effective Communication - snaptutorial.com
DOCX
CSEC 610 Effective Communication/tutorialrank.com
Cyb 610 Education Organization-snaptutorial.com
CYB 610 Exceptional Education - snaptutorial.com
Cyb 610Education Specialist / snaptutorial.com
Csec 610 Believe Possibilities / snaptutorial.com
Get Ahead of your Next Security Breach
200711 002
Cyb 610 Believe Possibilities / snaptutorial.com
CSEC 610 Education Specialist / snaptutorial.com
Csec 610 Education Organization-snaptutorial.com
Cst 610 Believe Possibilities / snaptutorial.com
CSEC 610 Effective Communication - snaptutorial.com
Secure Code Warrior - Poor authorization and authentication
CST 610 RANK Educational Specialist--cst610rank.com
CST 610 RANK Become Exceptional--cst610rank.com
CST 610 RANK Inspiring Innovation--cst610rank.com
CST 610 RANK Introduction Education--cst610rank.com
CST 610 RANK Remember Education--cst610rank.com
CST 610 Effective Communication - snaptutorial.com
CSEC 610 Effective Communication/tutorialrank.com
Ad

Viewers also liked (19)

PPTX
Interface between ris his & pacs
PPTX
LABORATORY INFORMATION SYSTEM RADIOLOGY INFORMATION SYSTEM
PPTX
HospitalSoftwareShop - Laboratory Information System LIS
PPT
Components And Workflow Of A Digital Radiology Department
PDF
Laboratory Information Management System
PDF
Sage - Clinical Laboratory Management System
PPT
Why PACS is Modern Medicine?
PDF
iCloud WebPACS for Radiology
PPT
Laboratory Information Management System (LIMS)
PPTX
RIS, PACS, DICOM - Hospital Garrahan
PPTX
Health information systems (his)
PPTX
Health Information Systems
PPT
Planning & orag.imaging services
PPTX
Health management information system
PPTX
Hospital Information Management System 24092010
PPT
Hospital information system
PPTX
Intorduction to Health information system presentation
PPTX
Hospital Management System
PPTX
[PPT] Hospital management system - Quanta-his
Interface between ris his & pacs
LABORATORY INFORMATION SYSTEM RADIOLOGY INFORMATION SYSTEM
HospitalSoftwareShop - Laboratory Information System LIS
Components And Workflow Of A Digital Radiology Department
Laboratory Information Management System
Sage - Clinical Laboratory Management System
Why PACS is Modern Medicine?
iCloud WebPACS for Radiology
Laboratory Information Management System (LIMS)
RIS, PACS, DICOM - Hospital Garrahan
Health information systems (his)
Health Information Systems
Planning & orag.imaging services
Health management information system
Hospital Information Management System 24092010
Hospital information system
Intorduction to Health information system presentation
Hospital Management System
[PPT] Hospital management system - Quanta-his
Ad

Similar to Electronic health records (20)

PPTX
PDF
Application security testing an integrated approach
PDF
Web application sec_3
PDF
Vulnerabilities In Industrial Control System
PPTX
CyberSecurityppt. pptx
PPTX
Security Testing Training With Examples
PDF
OWASP Top 10 Project
PPTX
Web and Mobile Application Security
PPTX
Secure practices with dot net services.pptx
PPT
Application Security
PPTX
What is penetration testing and why is it important for a business to invest ...
PPTX
Web_Appication_Security_Training_For_Developers.pptx
PDF
C01461422
PDF
Study of Web Application Attacks & Their Countermeasures
PPTX
Appsec2013 assurance tagging-robert martin
PPTX
2.1 Web Vulnerabilities.pptx
PPS
Application Security Review 5 Dec 09 Final
PPTX
Data base security and injection
PPTX
Core defense mechanisms against security attacks on web applications
PPT
It For Dummies Kamens 081107
Application security testing an integrated approach
Web application sec_3
Vulnerabilities In Industrial Control System
CyberSecurityppt. pptx
Security Testing Training With Examples
OWASP Top 10 Project
Web and Mobile Application Security
Secure practices with dot net services.pptx
Application Security
What is penetration testing and why is it important for a business to invest ...
Web_Appication_Security_Training_For_Developers.pptx
C01461422
Study of Web Application Attacks & Their Countermeasures
Appsec2013 assurance tagging-robert martin
2.1 Web Vulnerabilities.pptx
Application Security Review 5 Dec 09 Final
Data base security and injection
Core defense mechanisms against security attacks on web applications
It For Dummies Kamens 081107

More from Anurag Deb (8)

DOCX
Git github
DOCX
Open Script (OATS)
DOCX
Tutorials on Macro
PDF
letter of appreciation 2
PDF
letter of appreciation 1
PDF
Article on The Electronic Health Record
PDF
Let me design
DOCX
Virtual Memory In Contemporary Microprocessors And 64-Bit Microprocessors Arc...
Git github
Open Script (OATS)
Tutorials on Macro
letter of appreciation 2
letter of appreciation 1
Article on The Electronic Health Record
Let me design
Virtual Memory In Contemporary Microprocessors And 64-Bit Microprocessors Arc...

Recently uploaded (20)

PDF
CT Anatomy for Radiotherapy.pdf eryuioooop
PPT
CHAPTER FIVE. '' Association in epidemiological studies and potential errors
PPTX
History and examination of abdomen, & pelvis .pptx
PPTX
ca esophagus molecula biology detailaed molecular biology of tumors of esophagus
PPTX
15.MENINGITIS AND ENCEPHALITIS-elias.pptx
PDF
Handout_ NURS 220 Topic 10-Abnormal Pregnancy.pdf
PPTX
post stroke aphasia rehabilitation physician
DOC
Adobe Premiere Pro CC Crack With Serial Key Full Free Download 2025
PPTX
Electromyography (EMG) in Physiotherapy: Principles, Procedure & Clinical App...
PPTX
Acid Base Disorders educational power point.pptx
PPT
Copy-Histopathology Practical by CMDA ESUTH CHAPTER(0) - Copy.ppt
PPTX
Respiratory drugs, drugs acting on the respi system
PPTX
Uterus anatomy embryology, and clinical aspects
PPTX
POLYCYSTIC OVARIAN SYNDROME.pptx by Dr( med) Charles Amoateng
PPTX
CME 2 Acute Chest Pain preentation for education
PPTX
Chapter-1-The-Human-Body-Orientation-Edited-55-slides.pptx
PDF
Therapeutic Potential of Citrus Flavonoids in Metabolic Inflammation and Ins...
PDF
NEET PG 2025 | 200 High-Yield Recall Topics Across All Subjects
PPTX
surgery guide for USMLE step 2-part 1.pptx
PPTX
Gastroschisis- Clinical Overview 18112311
CT Anatomy for Radiotherapy.pdf eryuioooop
CHAPTER FIVE. '' Association in epidemiological studies and potential errors
History and examination of abdomen, & pelvis .pptx
ca esophagus molecula biology detailaed molecular biology of tumors of esophagus
15.MENINGITIS AND ENCEPHALITIS-elias.pptx
Handout_ NURS 220 Topic 10-Abnormal Pregnancy.pdf
post stroke aphasia rehabilitation physician
Adobe Premiere Pro CC Crack With Serial Key Full Free Download 2025
Electromyography (EMG) in Physiotherapy: Principles, Procedure & Clinical App...
Acid Base Disorders educational power point.pptx
Copy-Histopathology Practical by CMDA ESUTH CHAPTER(0) - Copy.ppt
Respiratory drugs, drugs acting on the respi system
Uterus anatomy embryology, and clinical aspects
POLYCYSTIC OVARIAN SYNDROME.pptx by Dr( med) Charles Amoateng
CME 2 Acute Chest Pain preentation for education
Chapter-1-The-Human-Body-Orientation-Edited-55-slides.pptx
Therapeutic Potential of Citrus Flavonoids in Metabolic Inflammation and Ins...
NEET PG 2025 | 200 High-Yield Recall Topics Across All Subjects
surgery guide for USMLE step 2-part 1.pptx
Gastroschisis- Clinical Overview 18112311

Electronic health records