Regulating access to electronic health records has become a major social and technical challenge. Unfortunately, existing access control models fail in translating accurately basic law principles related to the safeguard of personal information (e.g., medical folder). This paper identifies the problem and proposes a solution in the EHR context.