首页 | 本学科首页   官方微博 | 高级检索  
     


Patient-centric authorization framework for electronic healthcare services
Authors:Jing Jin  Gail-Joon Ahn  Hongxin Hu  Michael J. Covington  Xinwen Zhang
Affiliation:1. Deutsche Bank Global Technologies, Cary, NC, USA;2. Arizona State University, 699 S. Mill Ave, Tempe, AZ, USA;3. Intel Corporation, Hillsboro, OR, USA;4. Samsung Information Systems America, San Jose, CA, USA
Abstract:In modern healthcare environments, a fundamental requirement for achieving continuity of care is the seamless access to distributed patient health records in an integrated and unified manner, directly at the point of care. However, Electronic Health Records (EHRs) contain a significant amount of sensitive information, and allowing data to be accessible at many different sources increases concerns related to patient privacy and data theft. Access control solutions must guarantee that only authorized users have access to such critical records for legitimate purposes, and access control policies from distributed EHR sources must be accurately reflected and enforced accordingly in the integrated EHRs. In this paper, we propose a unified access control scheme that supports patient-centric selective sharing of virtual composite EHRs using different levels of granularity, accommodating data aggregation and privacy protection requirements. We also articulate and address issues and mechanisms on policy anomalies that occur in the composition of discrete access control policies from different data sources.
Keywords:
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号