Privacy oriented access control for electronic health records


Autoria(s): Gajanayake, Randike; Iannella, Renato; Sahama, Tony R.
Data(s)

2014

Resumo

Information privacy is a critical success/failure factor in information technology supported healthcare (eHealth). eHealth systems utilise electronic health records (EHR) as the main source of information, thus, implementing appropriate privacy preserving methods for EHRs is vital for the proliferation of eHealth. Whilst information privacy may be a fundamental requirement for eHealth consumers, healthcare professionals demand non-restricted access to patient information for improved healthcare delivery, thus, creating an environment where stakeholder requirements are contradictory. Therefore, there is a need to achieve an appropriate balance of requirements in order to build successful eHealth systems. Towards achieving this balance, a new genre of eHealth systems called Accountable-eHealth (AeH) systems has been proposed. In this paper, an access control model for EHRs is presented that can be utilised by AeH systems to create information usage policies that fulfil both stakeholders’ requirements. These policies are used to accomplish the aforementioned balance of requirements creating a satisfactory eHealth environment for all stakeholders. The access control model is validated using a Web based prototype as a proof of concept.

Identificador

http://eprints.qut.edu.au/63620/

Publicador

Health Informatics Society of Australia (H I S A) Ltd

Relação

http://www.ejhi.net/ojs/index.php/ejhi/article/view/265

Gajanayake, Randike, Iannella, Renato, & Sahama, Tony R. (2014) Privacy oriented access control for electronic health records. Electronic Journal of Health Informatics, 8(2).

Direitos

Copyright 2014 The Authors

Fonte

School of Electrical Engineering & Computer Science; Information Security Institute; Science & Engineering Faculty

Palavras-Chave #080000 INFORMATION AND COMPUTING SCIENCES #100000 TECHNOLOGY #110000 MEDICAL AND HEALTH SCIENCES #Access Control #Information Privacy #eHealth #Electronic Health Records #Accountable-eHealth
Tipo

Journal Article