共 3 条
Strengthen Electronic Health Records System (EHR-S) Access-Control to Cope with GDPR Explicit Consent
被引:0
|作者:
Marcelo Antonio de Carvalho Junior
Paulo Bandiera-Paiva
机构:
[1] Universidade Federal de São Paulo,
来源:
关键词:
Access-control;
RBAC;
GDPR;
D O I:
暂无
中图分类号:
学科分类号:
摘要:
Patient consent is currently a missing piece on Electronic Health Records System (EHR-S) access permission. The control is needed to ensure personal data as the property of the individual, not data controllers or health-care service providers. To cope with this need, in this article, an adaptation of existent Role-Based Access Control (RBAC), including patient-centric control, is described. The revisited feature of existing administrative and supporting RBAC functions allows exclusive control orchestrated by the patient as sole information owner, including the ability to encrypt their data for confidentiality purposes. The additions mimic a Discretionary Access Control (DAC) capability using existing user group membership to vet access over symmetric keys bind to patient’s data via the associated PERMS matrix.
引用
收藏
相关论文