Towards Norm Classification: An Initial Analysis of HIPAA Breaches

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Scopus citations

Abstract

Regulatory policies, like the US Health Insurance Portability and Accountability Act (HIPAA), impose the social norms mediated by software-intensive systems. Breaches, modeled as norm violations, can help elicit security and privacy requirements to prevent future system failures. This paper reports our initial analysis of 38 HIPAA breaches with the objective of classifying them into the different norm types: commitments, authorizations, or prohibitions. The results show only limited distinguishing power of textual features, and reveal the fundamental interchangeability of commitments and prohibitions.

Original languageEnglish
Title of host publicationProceedings - 29th IEEE International Requirements Engineering Conference Workshops, REW 2021
EditorsTao Yue, Mehdi Mirakhorli
PublisherIEEE Computer Society
Pages415-420
Number of pages6
ISBN (Electronic)9781665418980
DOIs
StatePublished - Sep 2021
Event29th IEEE International Requirements Engineering Conference Workshops, REW 2021 - Virtual, Notre Dame, United States
Duration: Sep 20 2021Sep 24 2021

Publication series

NameProceedings of the IEEE International Conference on Requirements Engineering
Volume2021-September
ISSN (Print)1090-705X
ISSN (Electronic)2332-6441

Conference

Conference29th IEEE International Requirements Engineering Conference Workshops, REW 2021
Country/TerritoryUnited States
CityVirtual, Notre Dame
Period09/20/2109/24/21

Keywords

  • security and privacy breaches
  • social norms

Fingerprint

Dive into the research topics of 'Towards Norm Classification: An Initial Analysis of HIPAA Breaches'. Together they form a unique fingerprint.

Cite this