Towards unobtrusive patient-centric access-control for Health Information System

被引:1
|
作者
de Carvalho Junior, Marcelo Antonio [1 ]
Bandiera-Paiva, Paulo [1 ]
机构
[1] Univ Fed Sao Paulo, Hlth Informat Dept, Sao Paulo, Brazil
来源
关键词
Access control (N04.452.758.849.350); Information systems (L01.700.508.300); Information security; RBAC; Privacy (SP9.130.010.010); Standards (E05.978.808);
D O I
10.1002/cpe.5845
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Patient consent is currently a missing piece on Health Information Systems (HIS) access permission. The control is needed to ensure personal data as the property of the individual, not data controllers or health-care service providers. This is a newly-designed access-decision flow for HIS secured by Role-Based Access Control (RBAC) including patient-centric control. It makes use of Colored Petri-Nets (CPN) to model RBAC restrictions. A Discretionary Access Control (DAC) functionality is added to Electronic Health-Records (EHR) control to convey a patient's explicit authorization to their data in a non-obstructive access flow. Mutual exclusion was designed to incorporate patient needs so that they could authorize healthcare professionals to access EHR data. Additional information was supplied to a PERMS Access Control matrix and this enabled DAC to be mimicked using existing RBAC Core functions. A minimal addition is proposed to incorporate RBAC-aware systems with no significant drawbacks when compared with previous CPN simulations. The article also discusses the limitations of this technique and the favorable conditions for implementing new features.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] Patient-centric medical service matching with fine-grained access control and dynamic user management
    Wu, Shu
    Zhang, Aiqing
    Gao, Ya
    Xie, Xiaojuan
    COMPUTER STANDARDS & INTERFACES, 2024, 89
  • [42] Patient-centric Authorization Framework for Sharing Electronic Health Records
    Jin, Jing
    Ahn, Gail-Joon
    Hu, Hongxin
    Covington, Michael J.
    Zhang, Xinwen
    SACMAT'09: PROCEEDINGS OF THE 14TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2009, : 125 - 134
  • [43] Molecular Therapy Drives Patient-Centric Health Care Paradigms
    Waldman, Scott A.
    Terzic, Andre
    CTS-CLINICAL AND TRANSLATIONAL SCIENCE, 2010, 3 (04): : 170 - 171
  • [44] Transforming clinical trials in rheumatology: towards patient-centric precision medicine
    Costantino Pitzalis
    Ernest H. S. Choy
    Maya H. Buch
    Nature Reviews Rheumatology, 2020, 16 : 590 - 599
  • [45] Transforming clinical trials in rheumatology: towards patient-centric precision medicine
    Pitzalis, Costantino
    Choy, Ernest H. S.
    Buch, Maya H.
    NATURE REVIEWS RHEUMATOLOGY, 2020, 16 (10) : 590 - 599
  • [46] A Patient-Centric Distributed Architecture for Electronic Health Record Systems
    Grasso, Giorgio Mario
    Cuzzocrea, Alfredo
    Nucita, Andrea
    2014 17TH INTERNATIONAL CONFERENCE ON NETWORK-BASED INFORMATION SYSTEMS (NBIS 2014), 2014, : 83 - 90
  • [47] Meaningful use of patient-centric health records for healthcare transformation
    Shabo, A.
    IBM JOURNAL OF RESEARCH AND DEVELOPMENT, 2012, 56 (05)
  • [48] Effective visualization of file system access-control
    Heitzmann, Alexander
    Palazzi, Bernardo
    Papamanthou, Charalampos
    Tamassia, Roberto
    VISUALIZATION FOR COMPUTER SECURITY, PROCEEDINGS, 2008, 5210 : 18 - 25
  • [49] TYPICAL SYSTEM ACCESS-CONTROL PROBLEMS AND SOLUTIONS
    KARREN, DT
    INFORMATION AGE, 1988, 10 (01): : 23 - 32
  • [50] ACCESS-CONTROL AND SECURITY FOR A DISTRIBUTED CONTROL-SYSTEM
    MEYER, J
    GOTZ, A
    KLOTZ, WD
    NUCLEAR INSTRUMENTS & METHODS IN PHYSICS RESEARCH SECTION A-ACCELERATORS SPECTROMETERS DETECTORS AND ASSOCIATED EQUIPMENT, 1994, 352 (1-2): : 289 - 292