William J. Gordon

dblp:47/937 · DBLP profile ↗
← Back
9ranked-venue papers
5as first author
5since 2021 · last 2025
0000-0002-6975-3225ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 9 · 5 first-author · 5 since 2021
YearPublicationVenuePosition
2025 A standards-based approach to digital health research: implementing the people heart study
abstract
OBJECTIVE: To assess whether HL7 Fast Healthcare Interoperability Resources (FHIR) can underpin a fully standards-based, end-to-end digital research architecture, demonstrate it in a live study, and quantify its benefits for interoperability and development efficiency. MATERIALS AND METHODS: We designed a generalizable standards-based architecture to accelerate digital health research relying on FHIR as the sole transactional model throughout a participant research lifecycle starting from API-based study discovery to results. It was instantiated for People Heart Study, a real-world digital health cardiovascular-risk assessment study with its protocol transformed into FHIR resources (eligibility, consent, tasks, and results). Evaluation examined workflow coverage, validator conformance across independent servers, and points requiring custom extensions or app logic. RESULTS: The architecture was implemented using cloud managed FHIR stores including an illustrative public research discovery API for first-/third-party apps. A participant-facing iOS app was published on the App Store. Our evaluation reveals that 6 of 10 research app workflows could be executed entirely from FHIR artifacts; 2 were partially standards-driven and 2 remained limited requiring custom development. All FHIR resources passed structural, semantic validation with minimal custom extension usage and terminology integrity issues. DISCUSSION: Our approach addresses persistent challenges in digital health research by enhancing data interoperability, minimizing redundant development, and supporting the full research lifecycle. The architecture aligns with national priorities and complements healthcare standardization efforts. CONCLUSION: By leveraging FHIR, our architecture enables generalizability, interoperability, and reuse across diverse digital health research contexts, transforming study design into data modeling rather than software development, and fostering a more inclusive and agile digital health ecosystem.
Raheel Sayeed, David A. Kreda, Joshua C. Mandel, Bryan Larson, William J. Gordon, Kenneth D. Mandl, Isaac S. Kohane
J. Am. Medical Informatics Assoc.5
2022 A SMART on FHIR Application to Improve Suicide Risk Prediction and Management
William J. Gordon, Kate Bentley, Amy Fitzpatrick, Brian Kaney, Ronald Kessler, Matthew K. Nock, Ben Y. Reis, Mark Schechter, Vicki Strateman, Dewar Tan, Sarah Young, Jordan W. Smoller
AMIA1
2022 I2b2-etl: Python application for importing electronic health data into the informatics for integrating biology and the bedside platform
abstract
MOTIVATION: The i2b2 platform is used at major academic health institutions and research consortia for querying for electronic health data. However, a major obstacle for wider utilization of the platform is the complexity of data loading that entails a steep curve of learning the platform's complex data schemas. To address this problem, we have developed the i2b2-etl package that simplifies the data loading process, which will facilitate wider deployment and utilization of the platform. RESULTS: We have implemented i2b2-etl as a Python application that imports ontology and patient data using simplified input file schemas and provides inbuilt record number de-identification and data validation. We describe a real-world deployment of i2b2-etl for a population-management initiative at MassGeneral Brigham. AVAILABILITY AND IMPLEMENTATION: i2b2-etl is a free, open-source application implemented in Python available under the Mozilla 2 license. The application can be downloaded as compiled docker images. A live demo is available at https://i2b2clinical.org/demo-i2b2etl/ (username: demo, password: Etl@2021). SUPPLEMENTARY INFORMATION: Supplementary data are available at Bioinformatics online.
Kavishwar B. Wagholikar, Layne Ainsworth, David Zelle, Kira Chaney, Michael Mendis, Jeffrey G. Klann, Alexander J. Blood, Angela Miller, Rupendra Chulyadyo, Michael Oates, William J. Gordon, Samuel J. Aronson, Benjamin M. Scirica, Shawn N. Murphy
Bioinform.11
2021 Patient-led data sharing for clinical bioinformatics research: USCDI and beyond
abstract
The 21st Century Cures Act, passed in 2016, and the Final Rules it called for create a roadmap for enabling patient access to their electronic health information. The set of data to be made available, as determined by the Office of the National Coordinator for Health IT through the US Core Data for Interoperability expansion process, will impact the value creation of this improved data liquidity. In this commentary, we look at the potential for significant value creation from USCDI in the context of clinical bioinformatics research and advocate for the research community's involvement in the USCDI process to propel this value creation forward. We also describe 1 mechanism-using existing required APIs for full data export capabilities-that could pragmatically enable this value creation at minimal additional technical lift beyond the current regulatory requirements.
William J. Gordon, Daniel Gottlieb 0001, David A. Kreda, Joshua C. Mandel, Kenneth D. Mandl, Isaac S. Kohane
J. Am. Medical Informatics Assoc.1
2021 Telemedicine, privacy, and information security in the age of COVID-19
abstract
The spread of COVID-19 has resulted in unprecedented circumstances that have necessitated a shift toward adopting infrastructure for telemedicine, due in large part to the inaccessibility of traditional care services and high exposure risks of in-person healthcare visits. With the increased strain and demand on traditional medical resources, telemedicine has emerged as an essential component of clinical care delivery and many healthcare organizations are reporting substantial increases in telemedicine use. For example, 1 medical center in New York City saw an increase in urgent care virtual visits from a pre-COVID-19 average of 102 daily to 802 post-COVID-19 expansion (March 2, 2020–April 14, 2020).1 Despite the numerous barriers to telemedicine, such as educating staff, cost, reimbursement, access to broadband, and patient digital literacy, telemedicine has flourished during the pandemic, forcing implementations that may have taken years without such a catalyst. As we continue this shift to telemedicine, new issues and risks unravel that need to be addressed, particularly in regard to information security and privacy, and ongoing work is needed to ensure that our technology infrastructure provides an environment for safe and effective care delivery. In the US, the Department of Health and Human Services recently lifted several restrictions on communication apps, (eg, allowing the use of popular video conferencing applications, like Apple FaceTime, Facebook Messenger video chat, Google Hangouts, Zoom, and Skype) and increasing the range of services that are billable using telehealth.2 These actions reduced barriers that previously prevented the use of telemedicine services for individuals. Despite these advancements, the substantial information security and privacy concerns surrounding telemedicine cannot be overlooked. For example, Zoom, currently 1 of the most popular video conferencing platforms, has had a 10-fold increase in usage over just a few months including increased use in healthcare, leading to several important privacy considerations, such as intruders joining video conferences or inadequate encryption of communications, leading to the possibility of eavesdropping. Additionally, governmental agencies have warned of increased risk of cyberattacks towards the healthcare sector and organizations doing research on COVID-19.3 Ransomware attacks—a type of cybersecurity threat that involves encrypting data and demanding payment in return for unencryption—have continued unabated during the pandemic, with many targeting hospitals.4 A recent ransomware attack in Germany led to a patient’s death, perhaps the first death in healthcare directly attributable to a cyberattack. Other recent ransomware attacks have included the Illinois Public Health website and a medical testing facility in the UK.3 Successful cyberattacks negatively impact hospital operations, delay access to clinical services, and lead to significant economic loss, all of which would be devastating to organizations already under extraordinary economic and clinical strain. Protection against these threats to secure telemedicine platforms is complex, and requires a multi-disciplinary, multi-stakeholder approach. Awareness is an important first step, and can take the form of education, employee training, and simulated cyberattacks (eg, sending fake phishing emails and providing training for those who click) toward establishing a culture of security. Recent research in hospitals shows that among several personal characteristics and organizational conditions, employees’ workload had the strongest impact on the rate of clicking on phishing links.5 While extensive emailing of announcements may be needed to keep employees up to date during the pandemic, it could unnecessarily add to workload, putting them at higher risk of clicking on phishing emails. Moreover, best-practice security behaviors must be followed—encrypting data, keeping software updated, running antivirus software, using 2-factor authentication, and following local cybersecurity regulations or recommendations. While healthcare organizations and ambulatory practices may initially need to use consumer video conferencing tools, they should transition to an enterprise (healthcare specific) video conferencing product. Enterprise grade software versions may include key security features such as encryption and may offer additional configuration settings that can be standardized for the entire organization, such as requiring a waiting room with every teleconference. Overall, healthcare organizations need to enhance (if not revolutionize) their cybersecurity infrastructure by developing stronger prevention and detection protocols, both administrative and technological. Executives need to be willing to invest fully in cybersecurity throughout the organization. Emerging fields, such as artificial intelligence, the internet of things, and blockchain can also be employed as prevention and detection tools to combat cyber threats more effectively. To leverage these technologies, healthcare organizations need to partner with telemedicine and cybersecurity vendors to understand how to best implement and use their infrastructure and products. While prevention and detection capabilities are essential, healthcare organizations should be prepared with well-defined response plans. Unfortunately, response plans are often ignored or they are not considered as prevention and detection strategies. Response plans that are tested and practiced are required to minimize the negative consequences of an incident and ensure the provision of safe, secure, and reliable health care operations. Ultimately, while healthcare systems should allocate significant resources towards improving telemedicine capabilities, it is up to healthcare delivery organizations to ensure that these new capabilities are safe, secure, and protect patient privacy. Balancing the significant privacy and information security concerns with the enormous potential benefits of virtual care during this pandemic will remain a vital component to our continuously evolving response to COVID-19. None.
Mohammad S. Jalali, Adam B. Landman, William J. Gordon
J. Am. Medical Informatics Assoc.3
2019 Evaluation of a mandatory phishing training program for high-risk employees at a US healthcare system
abstract
OBJECTIVE: The study sought to understand the impact of a phishing training program on phishing click rates for employees at a single, anonymous US healthcare institution. MATERIALS AND METHODS: We stratified our population into 2 groups: offenders and nonoffenders. Offenders were defined as those that had clicked on at least 5 simulated phishing emails and nonoffenders were those that had not. We calculated click rates for offenders and nonoffenders, before and after a mandatory training program for offenders was implemented. RESULTS: A total of 5416 unique employees received all 20 campaigns during the intervention period; 772 clicked on at least 5 emails and were labeled offenders. Only 975 (17.9%) of our set clicked on 0 phishing emails over the course of the 20 campaigns; 3565 (65.3%) clicked on at least 2 emails. There was a decrease in click rates for each group over the 20 campaigns. The mandatory training program, initiated after campaign 15, did not have a substantial impact on click rates, and the offenders remained more likely to click on a phishing simulation. DISCUSSION: Phishing is a common threat vector against hospital employees and an important cybersecurity risk to healthcare systems. Our work suggests that, under simulation, employee click rates decrease with repeated simulation, but a mandatory training program targeted at high-risk employees did not meaningfully decrease the click rates of this population. CONCLUSIONS: Employee phishing click rates decrease over time, but a mandatory training program for the highest-risk employees did not decrease click rates when compared with lower-risk employees.
William J. Gordon, Adam Wright, Robert J. Glynn, Jigar Kadakia, Christina Mazzone, Elizabeth Leinbach, Adam B. Landman
J. Am. Medical Informatics Assoc.1
2019 EARS to cyber incidents in health care
abstract
Background: Connected medical devices and electronic health records have added important functionality to patient care, but have also introduced a range of cybersecurity concerns. When a healthcare organization suffers from a cybersecurity incident, its incident response strategies are critical to the success of its recovery. Objective: In this article, we identify gaps in research concerning cybersecurity response plans in healthcare. Through a systematic literature review, we develop aggregated strategies that professionals can use to construct better response strategies in their organizations. Methods: We reviewed journal articles on cyber incident response plans in healthcare published in PubMed and Web of Science. We sought to collect articles on the intersection of cybersecurity and healthcare that focused on incident response strategies. Results: We identified and reviewed 13 articles for cybersecurity response recommendations. We then extracted information such as research methods, findings, and implications. Finally, we synthesized the recommendations into a framework of eight aggregated response strategies (EARS) that fall under managerial and technological categories. Conclusions: We conducted a systematic review of the literature on cybersecurity response plans in healthcare and developed a novel framework for response strategies that could be deployed by healthcare organizations. More work is needed to evaluate incident response strategies in healthcare.
Mohammad S. Jalali, Bethany Russell, Sabina Razak, William J. Gordon
J. Am. Medical Informatics Assoc.4
2018 Employee Susceptibility to Phishing Attacks at US Healthcare Institutions
William J. Gordon, Adam Wright, Ranjit Aiyagari, Leslie Corbo, Jigar Kadakia, Jack Kufahl, Christina Mazzone, James Noga, Mark A. Parkulo, Brad Sanford, Paul Scheib, Adam B. Landman
AMIA1
1974 Bernstein-Bézier Methods for the Computer-Aided Design of Free-Form Curves and Surfaces
abstract
The m th degree Bernstein polynomial approximation to a function ƒ defined over [0, 1] is Σ m μ =0 ƒ( μ / m ) φ μ ( s ), where the weights φ μ ( s ) are binomial density functions. The Bernstein approximations inherit many of the global characteristics of ƒ, like monotonicity and convexity, and they always are at least as “smooth” as ƒ, where “smooth” refers to the number of undulations, the total variation, and the differentiability class of ƒ. Historically, their relatively slow convergence in the L ∞ -norm has tended to discourage their use in practical applications. However, in a large class of problems the smoothness of an approximating function is of greater importance than closeness of fit. This is especially true in connection with problems of computer-aided geometric design of curves and surfaces where aesthetic criteria and the intrinsic properties of shape are major considerations. For this latter class of problems, P. Bézier of Renault has successfully exploited the properties of parametric Bernstein polynomials. The purpose of this paper is to analyze the Bézier techniques and to explore various extensions and generalizations. In a sequel, the authors consider the extension of the results contained herein to free-form curve and surface design using polynomial splines . These B-spline methods have several advantages over the techniques described in the present paper.
William J. Gordon, Richard F. Riesenfeld
J. ACM1