{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:38:36Z","timestamp":1781105916648,"version":"3.54.1"},"reference-count":18,"publisher":"IGI Global Scientific Publishing","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012,4,1]]},"abstract":"<p>Inadequate audit mechanisms may result in undetected misuse of data in software-intensive systems. In the healthcare domain, electronic health record (EHR) systems should log the creating, reading, updating, or deleting of privacy-critical protected health information. The objective of this paper is to assess electronic health record audit mechanisms to determine the current degree of auditing for non-repudiation and to assess whether general audit guidelines adequately address non-repudiation. The authors analyzed the audit mechanisms of two open source EHR systems, OpenEMR and Tolven eCHR, and one proprietary EHR system. The authors base the qualitative assessment on a set of 16 general auditable events and 58 black-box test cases for specific auditable events. The authors find that OpenEMR satisfies 62.5% of the general criteria and passes 63.8% of the black-box test cases. Tolven eCHR and the proprietary EHR system each satisfy less than 19% of the general criteria and pass less than 11% of the black-box test cases.<\/p>","DOI":"10.4018\/jcmam.2012040102","type":"journal-article","created":{"date-parts":[[2012,11,19]],"date-time":"2012-11-19T13:30:01Z","timestamp":1353331801000},"page":"23-42","source":"Crossref","is-referenced-by-count":2,"title":["Audit Mechanisms in Electronic Health Record Systems"],"prefix":"10.4018","volume":"3","author":[{"given":"Jason","family":"King","sequence":"first","affiliation":[{"name":"North Carolina State University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ben","family":"Smith","sequence":"additional","affiliation":[{"name":"North Carolina State University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Laurie","family":"Williams","sequence":"additional","affiliation":[{"name":"North Carolina State University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jcmam.2012040102-0","doi-asserted-by":"crossref","unstructured":"B\u00f6ck, B., Huemer, D., & Tjoa, A. M. (2010). Towards more trustable log files for digital forensics by means of 'trusted computing.' In Proceedings of the 24th IEEE International Conference on Advanced Information Networking and Applications, Perth, Australia (pp. 1020-1027).","DOI":"10.1109\/AINA.2010.26"},{"key":"jcmam.2012040102-1","unstructured":"Certified, C. C. H. I. T. (2011). Ambulatory EHR. Retrieved from https:\/\/www.cchit.org\/cchit-certified"},{"key":"jcmam.2012040102-2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2009.70"},{"key":"jcmam.2012040102-3","doi-asserted-by":"publisher","DOI":"10.1109\/MP.2005.1594001"},{"key":"jcmam.2012040102-4","unstructured":"EHR Incentives & Certifications. (2011) Meaningful use definition & objectives. Retrieved April 9, 2012, from http:\/\/www.healthit.gov\/providers-professionals\/meaningful-use-definition-objectives"},{"key":"jcmam.2012040102-5","unstructured":"Health Insurance Portability and Accountability Act, United States Department of Health & Human Services \u00a7 Technical Safeguards, 164.312(b) Stat. (2007)."},{"key":"jcmam.2012040102-6","year":"2008","journal-title":"IEEE standard for information technology: Hardcopy device and system security"},{"key":"jcmam.2012040102-7","author":"K.Kent","year":"2006","journal-title":"Guide to computer security log management"},{"key":"jcmam.2012040102-8","doi-asserted-by":"crossref","unstructured":"King, J., Smith, B., & Williams, L. (2012). Modifying without a trace: General audit guidelines are inadequate for electronic health record audit mechanisms. In Proceedings of the ACM SIGHIT International Health Informatics Symposium, Miami, FL (pp. 305-314).","DOI":"10.1145\/2110363.2110399"},{"key":"jcmam.2012040102-9","doi-asserted-by":"crossref","DOI":"10.21236\/ADA482452","author":"A. P.Moore","year":"2008","journal-title":"The \u201cbig picture\u201d of insider IT sabotage across U.S. critical infrastructures"},{"key":"jcmam.2012040102-10","unstructured":"MySQL. (2011). 5.2.3: The general query log. Retrieved September 18, 2011, from http:\/\/dev.mysql.com\/doc\/refman\/5.1\/en\/query-log.html"},{"key":"jcmam.2012040102-11","year":"2004","journal-title":"Revolutionizing health care through information technology"},{"key":"jcmam.2012040102-12","year":"2006","journal-title":"Final report and recommendation"},{"key":"jcmam.2012040102-13","doi-asserted-by":"crossref","unstructured":"Robinson, P., Cook, N., & Shrivastava, S. (2005). Implementing fair non-repudiable interactions with Web services. In Proceedings of the 9th IEEE International Enterprise Computing Conference (pp. 195-206).","DOI":"10.1109\/EDOC.2005.16"},{"key":"jcmam.2012040102-14","unstructured":"SANS Consensus Project. (2007). Information system audit logging requirements. Retrieved from http:\/\/www.sans.org\/security-resources\/policies\/info_sys_audit.pdf"},{"key":"jcmam.2012040102-15","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2009.180"},{"key":"jcmam.2012040102-16","unstructured":"Smith, B. (2011). CCHIT black-box security test plan. Retrieved from http:\/\/securitytestpatterns.org\/doku.php?id=old:cchit_black_box_security_test_plan#audit_test_scripts"},{"key":"jcmam.2012040102-17","doi-asserted-by":"publisher","DOI":"10.1145\/1985793.1986019"}],"container-title":["International Journal of Computational Models and Algorithms in Medicine"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=72874","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T10:48:36Z","timestamp":1654080516000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jcmam.2012040102"}},"subtitle":["Protected Health Information May Remain Vulnerable to Undetected Misuse"],"short-title":[],"issued":{"date-parts":[[2012,4,1]]},"references-count":18,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2012,4]]}},"URL":"https:\/\/doi.org\/10.4018\/jcmam.2012040102","relation":{},"ISSN":["1947-3133","1947-3141"],"issn-type":[{"value":"1947-3133","type":"print"},{"value":"1947-3141","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,4,1]]}}}