Analyzing privacy requirements: A case study of healthcare in Saudi Arabia.

Inform Health Soc Care

c College of Computer Science & Information Systems, Jazan University, Jazan , Saudi Arabia.

Published: October 2016

Developing legally compliant systems is a challenging software engineering problem, especially in systems that are governed by law, such as healthcare information systems. This challenge comes from the ambiguities and domain-specific definitions that are found in governmental rules. Therefore, there is a significant business need to automatically analyze privacy texts, extract rules and subsequently enforce them throughout the supply chain. The existing works that analyze health regulations use the U.S. Health Insurance Portability and Accountability Act as a case study. In this article, we applied the Breaux and Antón approach to the text of the Saudi Arabian healthcare privacy regulations; in Saudi Arabia, privacy is among the top dilemmas for public and private healthcare practitioners. As a result, we extracted and analyzed 2 rights, 4 obligations, 22 constraints, and 6 rules. Our analysis can assist requirements engineers, standards organizations, compliance officers and stakeholders by ensuring that their systems conform to Saudi policy. In addition, this article discusses the threats to the study validity and suggests open problems for future research.

Download full-text PDF

Source
http://dx.doi.org/10.3109/17538157.2014.965301DOI Listing

Publication Analysis

Top Keywords

case study
8
saudi arabia
8
analyzing privacy
4
privacy requirements
4
requirements case
4
healthcare
4
study healthcare
4
saudi
4
healthcare saudi
4
arabia developing
4

Similar Publications

Want AI Summaries of new PubMed Abstracts delivered to your In-box?

Enter search terms and have AI summaries delivered each week - change queries or unsubscribe any time!