Towards unobtrusive patient-centric access-control for Health Information System

被引:1
|
作者
de Carvalho Junior, Marcelo Antonio [1 ]
Bandiera-Paiva, Paulo [1 ]
机构
[1] Univ Fed Sao Paulo, Hlth Informat Dept, Sao Paulo, Brazil
来源
关键词
Access control (N04.452.758.849.350); Information systems (L01.700.508.300); Information security; RBAC; Privacy (SP9.130.010.010); Standards (E05.978.808);
D O I
10.1002/cpe.5845
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Patient consent is currently a missing piece on Health Information Systems (HIS) access permission. The control is needed to ensure personal data as the property of the individual, not data controllers or health-care service providers. This is a newly-designed access-decision flow for HIS secured by Role-Based Access Control (RBAC) including patient-centric control. It makes use of Colored Petri-Nets (CPN) to model RBAC restrictions. A Discretionary Access Control (DAC) functionality is added to Electronic Health-Records (EHR) control to convey a patient's explicit authorization to their data in a non-obstructive access flow. Mutual exclusion was designed to incorporate patient needs so that they could authorize healthcare professionals to access EHR data. Additional information was supplied to a PERMS Access Control matrix and this enabled DAC to be mimicked using existing RBAC Core functions. A minimal addition is proposed to incorporate RBAC-aware systems with no significant drawbacks when compared with previous CPN simulations. The article also discusses the limitations of this technique and the favorable conditions for implementing new features.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] SPS: Secure Personal Health Information Sharing with Patient-centric Access Control in Cloud Computing
    Barua, Mrinmoy
    Lu, Rongxing
    Shen, Xuemin
    [J]. 2013 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2013, : 647 - 652
  • [2] A Patient-Centric Access Control Scheme for Personal Health Records in the Cloud
    Huang, Kuo-Hsuan
    Chang, En-Chi
    Wang, Shao-Jui
    [J]. 2013 FOURTH INTERNATIONAL CONFERENCE ON NETWORKING AND DISTRIBUTED COMPUTING (ICNDC), 2013, : 85 - 88
  • [3] Towards a universal patient-centric health record sharing platform
    Azarm, Mana
    Meehan, Rebecca
    Kuziemsky, Craig
    [J]. HEALTH POLICY AND TECHNOLOGY, 2023, 12 (04)
  • [4] Patient-Centric Scheduling With the Implementation of Health Information Technology to Improve the Patient Experience and Access to Care: Retrospective Case-Control Analysis
    Chung, Sukyung
    Martinez, Meghan C.
    Frosch, Dominick L.
    Jones, Veena G.
    Chan, Albert S.
    [J]. JOURNAL OF MEDICAL INTERNET RESEARCH, 2020, 22 (06)
  • [5] The Patient Trifecta: A Basis for a Truly Patient-Centric Health System
    Boutin, Marc
    [J]. AMERICAN JOURNAL OF PHARMACY BENEFITS, 2015, 7 (05) : 239 - 240
  • [6] A Patient-Centric Approach to Delegation of Access Rights in Healthcare Information Systems
    Khan, M. Fahim Ferdous
    Sakamura, Ken
    [J]. 2016 INTERNATIONAL CONFERENCE ON ENGINEERING & MIS (ICEMIS), 2016,
  • [7] Granular Data Access Control with a Patient-Centric Policy Update for Healthcare
    Khan, Fawad
    Khan, Saad
    Tahir, Shahzaib
    Ahmad, Jawad
    Tahir, Hasan
    Shah, Syed Aziz
    [J]. SENSORS, 2021, 21 (10)
  • [8] Towards Patient-Centric Healthcare: Leveraging Blockchain for Electronic Health Records
    Nhan, Thuan
    Upadhyay, Kritagya
    Poudel, Khem
    [J]. PROCEEDINGS OF THE 2024 COMPUTERS AND PEOPLE RESEARCH CONFERENCE, SIGMIS-CPR 2024, 2024,
  • [9] Patient-centric analysis of dialysis access outcomes
    Solesky, Beverly C.
    Huber, Thomas S.
    Berceli, Scott A.
    [J]. JOURNAL OF VASCULAR ACCESS, 2010, 11 (01): : 31 - 37
  • [10] A Patient-Centric Interoperable Framework for Health Information Exchange via Blockchain
    Wu, Huiqun
    Shang, Yujuan
    Wang, Lei
    Shi, Lili
    Jiang, Kui
    Dong, Jiancheng
    [J]. ICBTA 2019: 2019 2ND INTERNATIONAL CONFERENCE ON BLOCKCHAIN TECHNOLOGY AND APPLICATIONS, 2019, : 76 - 80