WER2007 - 10th Workshop on Requirements Engineering, Toronto - Canada


A Requirements Management Framework for Privacy Compliance

Sepideh Ghanavati; Daniel Amyot; Liam Peyton

PDF Scholar

Abstract

Compliance with privacy legislation is a primary concern for health care institutions that are building information systems support for their business processes. This paper describes a requirements management framework that enables health information custodians (HIC) to document and track compliance with privacy legislation. A metamodel is defined for our framework to define compliance tracking links between separate User Requirements Notation models of the HIC and privacy legislation. Using examples from a case study at a major teaching hospital, we show how this framework can be used to manage change and ensure compliance when privacy legislation is amended or the business processes evolved.

requirements management



WER Editions