{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:36:44Z","timestamp":1781105804031,"version":"3.54.1"},"reference-count":0,"publisher":"IGI Global Scientific Publishing","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017,1]]},"abstract":"<jats:p>Healthcare business is responsible of keeping patient data safe and secure by following the rules of the federal Health Insurance Portability and Accountability Act of 1996, (HIPAA). Agile software organizations that deal with healthcare software system face a number of challenges to demonstrate that their process activities conform to the rules of HIPAA. Such organizations must establish a software process life cycle and develop procedures, tools, and methodologies that can manage the HIPAA requirements during the different stages of system development, and also must provide evidences of HIPAA conformity. This paper proposes an auditing model for HIPAA security and privacy rules in XP environments. The design of the proposed model is based on an evaluation theory which takes as its input the work of Lopez ATAM, and the standards of common criteria (CC) concepts. The proposed auditing model has been assessed based on four case studies. The auditing result shows that the proposed model is capable of capturing the auditing evidences in most of the selected case studies.<\/jats:p>","DOI":"10.4018\/ijisss.2017010101","type":"journal-article","created":{"date-parts":[[2016,9,12]],"date-time":"2016-09-12T07:31:53Z","timestamp":1473665513000},"page":"1-21","source":"Crossref","is-referenced-by-count":3,"title":["HIPAA Security and Privacy Rules Auditing in Extreme Programming Environments"],"prefix":"10.4018","volume":"9","author":[{"given":"Mahmood","family":"Alsaadi","sequence":"first","affiliation":[{"name":"Department of Computer Science, Princess Sumaya University for Technology, Amman, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Malik","family":"Qasaimeh","sequence":"additional","affiliation":[{"name":"Department of Software Engineering, Princess Sumaya University for Technology, Amman, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sara","family":"Tedmori","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Princess Sumaya University for Technology, Amman, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Khaled","family":"Almakadmeh","sequence":"additional","affiliation":[{"name":"Department of Software Engineering, Hashemite University, Zarqa, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","container-title":["International Journal of Information Systems in the Service Sector"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=165416","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,5]],"date-time":"2022-05-05T17:51:23Z","timestamp":1651773083000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/IJISSS.2017010101"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2017,1]]},"references-count":0,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.4018\/ijisss.2017010101","relation":{},"ISSN":["1935-5688","1935-5696"],"issn-type":[{"value":"1935-5688","type":"print"},{"value":"1935-5696","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,1]]}}}