Strengthen Electronic Health Records System (EHR-S) Access-Control to Cope with GDPR Explicit Consent

被引:0
|
作者
Marcelo Antonio de Carvalho Junior
Paulo Bandiera-Paiva
机构
[1] Universidade Federal de São Paulo,
来源
关键词
Access-control; RBAC; GDPR;
D O I
暂无
中图分类号
学科分类号
摘要
Patient consent is currently a missing piece on Electronic Health Records System (EHR-S) access permission. The control is needed to ensure personal data as the property of the individual, not data controllers or health-care service providers. To cope with this need, in this article, an adaptation of existent Role-Based Access Control (RBAC), including patient-centric control, is described. The revisited feature of existing administrative and supporting RBAC functions allows exclusive control orchestrated by the patient as sole information owner, including the ability to encrypt their data for confidentiality purposes. The additions mimic a Discretionary Access Control (DAC) capability using existing user group membership to vet access over symmetric keys bind to patient’s data via the associated PERMS matrix.
引用
收藏
相关论文
共 3 条
  • [1] Strengthen Electronic Health Records System (EHR-S) Access-Control to Cope with GDPR Explicit Consent
    de Carvalho Junior, Marcelo Antonio
    Bandiera-Paiva, Paulo
    JOURNAL OF MEDICAL SYSTEMS, 2020, 44 (10)
  • [2] A blockchain-based privacy-preserving and access-control framework for electronic health records management
    Jakhar A.K.
    Singh M.
    Sharma R.
    Viriyasitavat W.
    Dhiman G.
    Goel S.
    Multimedia Tools and Applications, 2024, 83 (36) : 84195 - 84229
  • [3] Efficient Privacy-Preserving Access Control Scheme in Electronic Health Records System
    Ming, Yang
    Zhang, Tingting
    SENSORS, 2018, 18 (10)