DocumentCode :
3089358
Title :
Proposing regulatory-driven automated test suites for electronic health record systems
Author :
Morrison, Patrick ; Holmgreen, Casper ; Massey, Aaron K. ; Williams, Laurie
Author_Institution :
Dept. of Comput. Sci., North Carolina State Univ., Raleigh, NC, USA
fYear :
2013
fDate :
20-21 May 2013
Firstpage :
46
Lastpage :
49
Abstract :
In regulated domains such as finance and health care, failure to comply with regulation can lead to financial, civil and criminal penalties. While systems vary from organization to organization, regulations apply across organizations. We propose the use of Behavior-Driven-Development (BDD) scenarios as the basis of an automated compliance test suite for standards such as regulation and interoperability. Such test suites could become a shared asset for use by all systems subject to these regulations and standards. Each system, then, need only create their own system-specific test driver code to automate their compliance checks. The goal of this research is to enable organizations to compare their systems to regulation in a repeatable and traceable way through the use of BDD. To evaluate our proposal, we developed an abbreviated HIPAA test suite and applied it to three open-source electronic health record systems. The scenarios covered all security behavior defined by the selected regulation. The system-specific test driver code covered all security behavior defined in the scenarios, and identified where the tested system lacked such behavior.
Keywords :
automatic testing; conformance testing; health care; medical information systems; open systems; program testing; security of data; BDD scenarios; HIPAA test suite; automated compliance test suite; behavior-driven-development; civil penalties; compliance checks; criminal penalties; financial penalties; health care; interoperability; open-source electronic health record systems; organization; regulations; regulatory-driven automated test suites; security behavior; system-specific test driver code; Boolean functions; Certification; Data structures; NIST; Behavior-Driven-Development Healthcare IT; Regulatory Compliance; Security; Software Engineering; Software Testing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software Engineering in Health Care (SEHC), 2013 5th International Workshop on
Conference_Location :
San Francisco, CA
Type :
conf
DOI :
10.1109/SEHC.2013.6602477
Filename :
6602477
Link To Document :
بازگشت