Privacy Oriented Access Control for Electronic Health Records

Randike Gajanayake, Renato Iannella, Tony Sahama

Abstract


Security and privacy in electronic health record systems have been hindering the growth of e-health systems since their emergence. The development of policies that satisfy the security and privacy requirements of different stakeholders in healthcare has proven to be difficult. But, these requirements have to be met if the systems developed are to succeed in achieving their intended goals. Access control is a fundamental security barrier for securing data in healthcare information systems. In this paper we present an access control model for electronic health records. We address patient privacy requirements, confidentiality of private information and the need for flexible access for health professionals for electronic health records. We carefully combine three existing access control models and present a novel access control model for EHRs which satisfies requirements of electronic health records.

Keywords


Access control; MAC; DAC; RBAC; privacy; security; electronic health records; EHR

Full Text:

PDF




::::::::::::::  eJHI - electronic Journal of Health Informatics - ISSN 1446-4381  ::::::::::::::

                                     Privacy Statement - Uptime