{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,23]],"date-time":"2026-02-23T18:59:30Z","timestamp":1771873170828,"version":"3.50.1"},"reference-count":42,"publisher":"Springer Science and Business Media LLC","issue":"5-6","license":[{"start":{"date-parts":[[2017,2,15]],"date-time":"2017-02-15T00:00:00Z","timestamp":1487116800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Ann. Telecommun."],"published-print":{"date-parts":[[2017,6]]},"DOI":"10.1007\/s12243-017-0568-5","type":"journal-article","created":{"date-parts":[[2017,2,15]],"date-time":"2017-02-15T16:13:54Z","timestamp":1487175234000},"page":"347-357","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["IT governance and risk mitigation approach for private cloud adoption: case study of provincial healthcare provider"],"prefix":"10.1007","volume":"72","author":[{"given":"Ayo","family":"Gbadeyan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6235-8858","authenticated-orcid":false,"given":"Sergey","family":"Butakov","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shaun","family":"Aghili","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,2,15]]},"reference":[{"key":"568_CR1","doi-asserted-by":"crossref","unstructured":"Ahuja et al (2012) A survey of the state of cloud computing in healthcare. Netw Commun Technol 12\u201319","DOI":"10.5539\/nct.v1n2p12"},{"key":"568_CR2","unstructured":"Alberta Health (2014) Alberta Health Annual Report 2013\u201314. Retrieved from Alberta Health: http:\/\/www.health.alberta.ca\/documents\/Annual-Report-14.pdf"},{"key":"568_CR3","unstructured":"Alberta Health (2017) Alberta Health. Retrieved from Alberta Health: http:\/\/www.health.alberta.ca\/about-us.html"},{"key":"568_CR4","unstructured":"Association of Healthcare Internal Auditors (AHIA) & Grant Thornton LLP (2013) Third-party Relationships and Your Confidential Data. Retrieved from Association of Healthcare Internal Auditors (AHIA): http:\/\/www.ahia.org\/news\/white-papers\/third-party-relationships-and-your-confidential-data-\/"},{"key":"568_CR5","unstructured":"Badger et al (2012) NIST Special Publication 800-146. Retrieved from NIST: http:\/\/csrc.nist.gov\/publications\/nistpubs\/800-146\/sp800-146.pdf"},{"key":"568_CR6","series-title":"Twentieth Americas Conference on Information Systems(AMCIS)","first-page":"1825","volume-title":"A comparison of IT governance & control frameworks in cloud computing","author":"JD Becker","year":"2014","unstructured":"Becker JD, Bailey E (2014) A comparison of IT governance & control frameworks in cloud computing, Twentieth Americas Conference on Information Systems(AMCIS). Association for Information Systems (AIS), Savanah, pp 1825\u20131840"},{"key":"568_CR7","unstructured":"Canada Health Infoway (2012) Emerging Technology Series: Cloud Computing in Health White Paper. Retrieved from Canada Health Infoway: https:\/\/www.infoway-inforoute.ca\/index.php\/resources\/technical-documents\/emerging-technology\/doc_download\/659-cloud-computing-in-health-white-paper-full"},{"key":"568_CR8","unstructured":"Canadian Healthcare Technology (2014) Alberta Privacy Commissioner Investigates Big Breach. Retrieved from Canadian Healthcare Technology: http:\/\/www.canhealth.com\/2014\/02\/alberta-privacy-commissioner-investigates-big-breach\/"},{"key":"568_CR9","unstructured":"Chan et al. (2012) Enterprise Risk Management for Cloud Computing. Retrieved from Committee of Sponsoring Organizations of the Treadway Commission (COSO): http:\/\/www.coso.org\/documents\/Cloud%20Computing%20Thought%20Paper.pdf"},{"key":"568_CR10","doi-asserted-by":"crossref","unstructured":"Chaput SR, Ringwood K (2010) Cloud compliance: a framework for using cloud computing in a regulated world. In Cloud Computing, pp. 241\u2013255","DOI":"10.1007\/978-1-84996-241-4_14"},{"key":"568_CR11","unstructured":"Cloud Security Alliance (2013) The Notorious Nine: Cloud Computing Top Threats in 2013. Retrieved from Cloud Security Alliance(CSA): https:\/\/downloads.cloudsecurityalliance.org\/initiatives\/top_threats\/The_Notorious_Nine_Cloud_Computing_Top_Threats_in_2013.pdf"},{"key":"568_CR12","unstructured":"CSA (2011) Security Guidance for Critical Areas of Focus in Cloud Computing v3.0. Retrieved from Cloud Security Alliance (CSA): https:\/\/cloudsecurityalliance.org\/download\/security-guidance-for-critical-areas-of-focus-in-cloud-computing-v3\/"},{"key":"568_CR13","unstructured":"CSA (2013) \"Cloud Computing Vulnerability Incidents\u201d Document and Appendices. Retrieved from Cloud Security Alliance: https:\/\/cloudsecurityalliance.org\/download\/cloud-computing-vulnerability-incidents-a-statistical-overview\/"},{"key":"568_CR14","unstructured":"CSA and ISACA (2012) Cloud Computing Market Maturity: Study Results. Retrieved from ISACA: http:\/\/www.isaca.org\/Knowledge-Center\/Research\/ResearchDeliverables\/Pages\/2012-Cloud-Computing-Market-Maturity-Study-Results.aspx"},{"key":"568_CR15","unstructured":"CSCC (2012) Impact of Cloud Computing on Healthcare. Retrieved from Cloud Standards Customer Council(CSCC): http:\/\/www.cloud-council.org\/cscchealthcare110512.pdf"},{"key":"568_CR16","unstructured":"ENISA (2009) Cloud Computing Risk Assessment. Retrieved from ENISA European Union Agency for Network and Information Security: http:\/\/www.enisa.europa.eu\/activities\/risk-management\/files\/deliverables\/cloud-computing-risk-assessment"},{"key":"568_CR17","first-page":"6","volume":"2","author":"V Gatewood","year":"2013","unstructured":"Gatewood V (2013) Aspirations to reality: filling the cloud computing performance gap. ISACA 2:6\u20139","journal-title":"ISACA"},{"key":"568_CR18","unstructured":"Government of Alberta: Health and Wellness (2012) Alberta Netcare. Retrieved from Alberta Health: http:\/\/www.albertanetcare.ca\/documents\/ABNetcarePortal_PIA.pdf"},{"key":"568_CR19","unstructured":"Hines C (2015) What the Anthem Breach Means for Healthcare Security. Retrieved from Cloud Security Alliance: https:\/\/blog.cloudsecurityalliance.org\/2015\/02\/06\/anthem-breach-means-healthcare-security\/"},{"key":"568_CR20","unstructured":"Hitachi (2012) How to Improve Healthcare with Cloud Computing. Retrieved from Hitachi Data Systems: http:\/\/docs.media.bitpipe.com\/io_10x\/io_108673\/item_650544\/cloud%20computing%20wp.pdf"},{"key":"568_CR21","unstructured":"IPC\/Ontario (2004) A Guide to the Personal Health Information and Protection Act. Retrieved from Information and Privacy Commissioner\/Ontario: https:\/\/www.ipc.on.ca\/images\/resources\/hguide-e.pdf"},{"key":"568_CR22","unstructured":"ISACA (2012) An ISACA Cloud Computing Vision Series: Guiding Principles for Cloud Adoption and Use. Retrieved from ISACA: http:\/\/www.isaca.org\/Knowledge-Center\/Research\/Documents\/Guiding-Principles-Cloud_whp_Eng_0212.pdf"},{"key":"568_CR23","unstructured":"ISACA (2013a) Cloud Governance: Questions Boards of Directors Need to Ask; An ISACA Cloud Vision Series White Paper. Retrieved from ISACA: http:\/\/www.isaca.org\/Knowledge-Center\/Research\/ResearchDeliverables\/Pages\/Cloud-Governance-Questions-Boards-of-Directors-Need-to-Ask.aspx"},{"key":"568_CR24","unstructured":"ISACA (2013b) COBIT 5 for Risk"},{"key":"568_CR25","unstructured":"ISACA (2014) Controls and Assurance in the Cloud: Using COBIT 5. Retrieved from ISACA: http:\/\/www.isaca.org\/Knowledge-Center\/Research\/ResearchDeliverables\/Pages\/Controls-and-Assurance-in-the-Cloud-Using-COBIT-5.aspx"},{"key":"568_CR26","doi-asserted-by":"crossref","unstructured":"Kuo AM-H (2011) Opportunities and challenges of cloud computing to improve health care services. J Med Internet Res:1\u201321","DOI":"10.2196\/jmir.1867"},{"key":"568_CR27","first-page":"17","volume":"1","author":"L Marks","year":"2013","unstructured":"Marks L (2013) Governance implementation\u2014COBIT 5 and ISO. ISACA 1:17\u201323 Retrieved from http:\/\/www.isaca.org\/Journal\/archives\/2013\/Volume-1\/Documents\/13v1-Governance-Implementation.pdf","journal-title":"ISACA"},{"key":"568_CR28","unstructured":"McCann E (2012) Forecast looks clear for cloud computing. Retrieved from Healthcare IT News: http:\/\/www.healthcareitnews.com\/news\/forecasts-look-clear-cloud-computing"},{"key":"568_CR29","doi-asserted-by":"crossref","unstructured":"Meis R, Heisel M (2016) Supporting privacy impact assessments using problem-based privacy analysis. In Software Technologies, pp 79\u201398","DOI":"10.1007\/978-3-319-30142-6_5"},{"key":"568_CR30","doi-asserted-by":"crossref","unstructured":"Mell P, Grance T (2011) SP 800-145, The NIST Definition of Cloud. Retrieved from National Institute of Standards and Technology (NIST): http:\/\/csrc.nist.gov\/publications\/nistpubs\/800-145\/SP800-145.pdf","DOI":"10.6028\/NIST.SP.800-145"},{"key":"568_CR31","unstructured":"NIST (2012) NIST SPECIAL PUBLICATIONS. Retrieved from National Institute of Standards and Technology (NIST): http:\/\/csrc.nist.gov\/publications\/nistpubs\/800-30-rev1\/sp800_30_r1.pdf"},{"key":"568_CR32","unstructured":"OIPC (2010) Privacy Impact Assesssment Requirement. Retrieved from Office of the Information and Privacy Commissioner(OIPC) of Alberta: http:\/\/www.oipc.ab.ca\/Content_Files\/Files\/PIAs\/PIA_Requirements_2010.pdf"},{"key":"568_CR33","unstructured":"OPC (2011) Privacy Impact Assessment. Retrieved from Office of the Privacy Commissioner of Canada: https:\/\/www.priv.gc.ca\/resource\/fs-fi\/02_05_d_33_e.asp"},{"key":"568_CR34","doi-asserted-by":"crossref","unstructured":"Rodrigues JJ, de la Torre I, Fern\u00e1ndez G, L\u00f3pez-Coronado M (2013) Analysis of the security and privacy requirements of cloud-based electronic health records systems. J Med Internet Res, 15(8)","DOI":"10.2196\/jmir.2494"},{"key":"568_CR35","unstructured":"Rossi B (2015) How Anthem was breached \u2013 and how you can prevent it happening to you - See more at: http:\/\/www.information-age.com\/technology\/security\/123458996\/how-anthem-was-breached-and-how-you-can-prevent-it-happening-you#sthash.jGqewgq2.dpuf . Retrieved from Information Age: http:\/\/www.information-age.com\/technology\/security\/123458996\/how-anthem-was-breached-and-how-you-can-prevent-it-happening-you"},{"key":"568_CR36","unstructured":"Schrutt M (2013) IDC and TELUS Enterprise Cloud Study, 2013: Capitalizing on Cloud's Window od Opportunity for Business Value. Retrieved from TELUS: http:\/\/resources-business.telus.com\/cms\/files\/files\/000\/000\/583\/original\/IDC_TELUS_Cloud_Study_June_3_FINAL.pdf"},{"key":"568_CR37","unstructured":"ServiceMesh (2013) Enterprice Cloud Governance: Requirements and Best Practices. Retrieved from CSC: https:\/\/assets1.csc.com\/cloud\/downloads\/8217_21_Cloud_Governance_White_Paper_v7_Web.pdf"},{"key":"568_CR38","doi-asserted-by":"crossref","unstructured":"Tancock D, Pearson S, & Charlesworth A (2013) A privacy impact assessment tool. In Privacy and Security for Cloud Computing. Springer.","DOI":"10.1007\/978-1-4471-4189-1_3"},{"key":"568_CR39","series-title":"5th IEEE Conference on Cloud Computing Technology and Science","first-page":"177","volume-title":"Privacy risks, security accountability in the cloud","author":"Theoharidou","year":"2013","unstructured":"Theoharidou et al (2013) Privacy risks, security accountability in the cloud, 5th IEEE Conference on Cloud Computing Technology and Science. IEEE Press, United Kingdom, pp 177\u2013184"},{"key":"568_CR40","unstructured":"Wan et al. (2010) Six questions every health industry executive should ask about cloud computing. Retrieved from Accenture: http:\/\/newsroom.accenture.com\/images\/20020\/HealthcareCloud.pdf"},{"key":"568_CR41","unstructured":"Zeng K, Cavoukian A (2010) Modelling cloud computing architecture without compromising privacy: a privacy by design approach. Retrieved from Privacy by Design: https:\/\/www.privacybydesign.ca\/content\/uploads\/2010\/07\/pbd-NEC-cloud.pdf"},{"key":"568_CR42","series-title":"IEEE 3rd International Conference on Cloud Computing","first-page":"268","volume-title":"Security models and requirements for healthcare application clouds","author":"R Zhang","year":"2010","unstructured":"Zhang R, Lui L (2010) Security models and requirements for healthcare application clouds, IEEE 3rd International Conference on Cloud Computing. IEEE, Miami, Florida, pp 268\u2013275"}],"container-title":["Annals of Telecommunications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s12243-017-0568-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s12243-017-0568-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s12243-017-0568-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,24]],"date-time":"2022-07-24T05:51:35Z","timestamp":1658641895000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s12243-017-0568-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,2,15]]},"references-count":42,"journal-issue":{"issue":"5-6","published-print":{"date-parts":[[2017,6]]}},"alternative-id":["568"],"URL":"https:\/\/doi.org\/10.1007\/s12243-017-0568-5","relation":{},"ISSN":["0003-4347","1958-9395"],"issn-type":[{"value":"0003-4347","type":"print"},{"value":"1958-9395","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,2,15]]}}}