Towards unobtrusive patient-centric access-control for Health Information System

被引:1
|
作者
de Carvalho Junior, Marcelo Antonio [1 ]
Bandiera-Paiva, Paulo [1 ]
机构
[1] Univ Fed Sao Paulo, Hlth Informat Dept, Sao Paulo, Brazil
来源
关键词
Access control (N04.452.758.849.350); Information systems (L01.700.508.300); Information security; RBAC; Privacy (SP9.130.010.010); Standards (E05.978.808);
D O I
10.1002/cpe.5845
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Patient consent is currently a missing piece on Health Information Systems (HIS) access permission. The control is needed to ensure personal data as the property of the individual, not data controllers or health-care service providers. This is a newly-designed access-decision flow for HIS secured by Role-Based Access Control (RBAC) including patient-centric control. It makes use of Colored Petri-Nets (CPN) to model RBAC restrictions. A Discretionary Access Control (DAC) functionality is added to Electronic Health-Records (EHR) control to convey a patient's explicit authorization to their data in a non-obstructive access flow. Mutual exclusion was designed to incorporate patient needs so that they could authorize healthcare professionals to access EHR data. Additional information was supplied to a PERMS Access Control matrix and this enabled DAC to be mimicked using existing RBAC Core functions. A minimal addition is proposed to incorporate RBAC-aware systems with no significant drawbacks when compared with previous CPN simulations. The article also discusses the limitations of this technique and the favorable conditions for implementing new features.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] Transforming clinical trials in rheumatology: towards patient-centric precision medicine
    Costantino Pitzalis
    Ernest H. S. Choy
    Maya H. Buch
    [J]. Nature Reviews Rheumatology, 2020, 16 : 590 - 599
  • [42] Molecular Therapy Drives Patient-Centric Health Care Paradigms
    Waldman, Scott A.
    Terzic, Andre
    [J]. CTS-CLINICAL AND TRANSLATIONAL SCIENCE, 2010, 3 (04): : 170 - 171
  • [43] Meaningful use of patient-centric health records for healthcare transformation
    Shabo, A.
    [J]. IBM JOURNAL OF RESEARCH AND DEVELOPMENT, 2012, 56 (05)
  • [44] A Patient-Centric Distributed Architecture for Electronic Health Record Systems
    Grasso, Giorgio Mario
    Cuzzocrea, Alfredo
    Nucita, Andrea
    [J]. 2014 17TH INTERNATIONAL CONFERENCE ON NETWORK-BASED INFORMATION SYSTEMS (NBIS 2014), 2014, : 83 - 90
  • [45] Transforming clinical trials in rheumatology: towards patient-centric precision medicine
    Pitzalis, Costantino
    Choy, Ernest H. S.
    Buch, Maya H.
    [J]. NATURE REVIEWS RHEUMATOLOGY, 2020, 16 (10) : 590 - 599
  • [46] Effective visualization of file system access-control
    Heitzmann, Alexander
    Palazzi, Bernardo
    Papamanthou, Charalampos
    Tamassia, Roberto
    [J]. VISUALIZATION FOR COMPUTER SECURITY, PROCEEDINGS, 2008, 5210 : 18 - 25
  • [47] TYPICAL SYSTEM ACCESS-CONTROL PROBLEMS AND SOLUTIONS
    KARREN, DT
    [J]. INFORMATION AGE, 1988, 10 (01): : 23 - 32
  • [48] ACCESS-CONTROL AND SECURITY FOR A DISTRIBUTED CONTROL-SYSTEM
    MEYER, J
    GOTZ, A
    KLOTZ, WD
    [J]. NUCLEAR INSTRUMENTS & METHODS IN PHYSICS RESEARCH SECTION A-ACCELERATORS SPECTROMETERS DETECTORS AND ASSOCIATED EQUIPMENT, 1994, 352 (1-2): : 289 - 292
  • [49] A general and flexible access-control system for the web
    Bauer, L
    Schneider, MA
    Felten, EW
    [J]. USENIX ASSOCIATION PROCEEDINGS OF THE 11TH USENIX SECURITY SYMPOSIUM, 2002, : 93 - 108
  • [50] A BUILDING ACCESS-CONTROL SYSTEM WITH ALARM MONITORING
    SANZ, JV
    VIVES, JQ
    DELCAMPO, AF
    [J]. MICROPROCESSING AND MICROPROGRAMMING, 1983, 12 (02): : 111 - 114