Towards unobtrusive patient-centric access-control for Health Information System

被引:1
|
作者
de Carvalho Junior, Marcelo Antonio [1 ]
Bandiera-Paiva, Paulo [1 ]
机构
[1] Univ Fed Sao Paulo, Hlth Informat Dept, Sao Paulo, Brazil
来源
关键词
Access control (N04.452.758.849.350); Information systems (L01.700.508.300); Information security; RBAC; Privacy (SP9.130.010.010); Standards (E05.978.808);
D O I
10.1002/cpe.5845
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Patient consent is currently a missing piece on Health Information Systems (HIS) access permission. The control is needed to ensure personal data as the property of the individual, not data controllers or health-care service providers. This is a newly-designed access-decision flow for HIS secured by Role-Based Access Control (RBAC) including patient-centric control. It makes use of Colored Petri-Nets (CPN) to model RBAC restrictions. A Discretionary Access Control (DAC) functionality is added to Electronic Health-Records (EHR) control to convey a patient's explicit authorization to their data in a non-obstructive access flow. Mutual exclusion was designed to incorporate patient needs so that they could authorize healthcare professionals to access EHR data. Additional information was supplied to a PERMS Access Control matrix and this enabled DAC to be mimicked using existing RBAC Core functions. A minimal addition is proposed to incorporate RBAC-aware systems with no significant drawbacks when compared with previous CPN simulations. The article also discusses the limitations of this technique and the favorable conditions for implementing new features.
引用
收藏
页数:10
相关论文
共 50 条
  • [21] Designing efficient patient-centric smart contracts for healthcare ecosystems with access control capabilities
    Kalita, Kausthav Pratim
    Boro, Debojit
    Bhattacharyya, Dhruba Kumar
    [J]. SECURITY AND PRIVACY, 2024,
  • [22] A Patient-Centric Attribute Based Access Control Scheme for Secure Sharing of Personal Health Records Using Cloud Computing
    Pussewalage, Harsha S. Gardiyawasam
    Oleshchuk, Vladimir A.
    [J]. 2016 IEEE 2ND INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (IEEE CIC), 2016, : 46 - 53
  • [23] Securing Patient-Centric Personal Health Records Sharing System in Cloud Computing
    Chen Danwei
    Chen Linling
    Fan Xiaowei
    He Liwen
    Pan Su
    Hu Ruoxiang
    [J]. CHINA COMMUNICATIONS, 2014, 11 (01) : 121 - 127
  • [24] An adaptable patient-centric Electronic Health Record system for personalized home care
    Patara, Fulvio
    Vicario, Enrico
    [J]. 2014 8TH INTERNATIONAL SYMPOSIUM ON MEDICAL INFORMATION AND COMMUNICATION TECHNOLOGY (ISMICT), 2014,
  • [25] Knowledge Management within the Health, Pharmaceutical and Clinical Sectors: Towards patient-centric health care systems
    Lytras, Miltiadis D.
    Ordonez de Pablos, Patricia
    Naeve, Ambjorn
    Makropoulos, Constantin
    Kashyap, Vipul
    [J]. INTERNATIONAL JOURNAL OF TECHNOLOGY MANAGEMENT, 2009, 47 (1-3) : 1 - 4
  • [26] FORMAL SPECIFICATION OF AN ACCESS-CONTROL SYSTEM
    STEPNEY, S
    LORD, SP
    [J]. SOFTWARE-PRACTICE & EXPERIENCE, 1987, 17 (09): : 575 - 593
  • [27] Editorial: Personalized Digital Health and Patient-Centric Services
    Hagglund, Maria
    Cajander, Asa
    Rexhepi, Hanife
    Kane, Bridget
    [J]. FRONTIERS IN COMPUTER SCIENCE, 2022, 4
  • [28] A patient-centric approach to improve health care services
    Pergher, Isaac
    Brandolf, Vanessa Patzlaff
    de Jesus Pacheco, Diego Augusto
    Roehe Vaccaro, Guilherme Luis
    [J]. COGENT BUSINESS & MANAGEMENT, 2016, 3
  • [29] Tuberculosis control needs a complete and patient-centric solution
    Pai, Madhukar
    Yadav, Prashant
    Anupindi, Ravi
    [J]. LANCET GLOBAL HEALTH, 2014, 2 (04): : E189 - E190
  • [30] Privacy and Security for Patient-centric Elderly Health Care
    Alagar, Vangalur
    Periyasamy, Kasi
    Wan, KaiYu
    [J]. 2017 IEEE 19TH INTERNATIONAL CONFERENCE ON E-HEALTH NETWORKING, APPLICATIONS AND SERVICES (HEALTHCOM), 2017,