Suppr超能文献

基于 RBAC-矩阵的电子病历权利管理系统,以提高 HIPAA 合规性。

RBAC-Matrix-based EMR right management system to improve HIPAA compliance.

机构信息

Department of Information Management, TamKang University, New Taipei City, Taiwan.

出版信息

J Med Syst. 2012 Oct;36(5):2981-92. doi: 10.1007/s10916-011-9776-0. Epub 2011 Sep 1.

Abstract

Security control of Electronic Medical Record (EMR) is a mechanism used to manage electronic medical records files and protect sensitive medical records document from information leakage. Researches proposed the Role-Based Access Control(RBAC). However, with the increasing scale of medical institutions, the access control behavior is difficult to have a detailed declaration among roles in RBAC. Furthermore, with the stringent specifications such as the U.S. HIPAA and Canada PIPEDA etc., patients are encouraged to have the right in regulating the access control of his EMR. In response to these problems, we propose an EMR digital rights management system, which is a RBAC-based extension to a matrix organization of medical institutions, known as RBAC-Matrix. With the aim of authorizing the EMR among roles in the organization, RBAC-Matrix also allow patients to be involved in defining access rights of his records. RBAC-Matrix authorizes access control declaration among matrix organizations of medical institutions by using XrML file in association with each EMR. It processes XrML rights declaration file-based authorization of behavior in the two-stage design, called master & servant stage, thus makes the associated EMR to be better protected. RBAC-Matrix will also make medical record file and its associated XrML declaration to two different EMRA(EMR Authorization)roles, namely, the medical records Document Creator (DC) and the medical records Document Right Setting (DRS). Access right setting, determined by the DRS, is cosigned by the patient, thus make the declaration of rights and the use of EMR to comply with HIPAA specifications.

摘要

电子病历(EMR)的安全控制是一种用于管理电子病历文件并防止敏感医疗记录文档信息泄露的机制。研究人员提出了基于角色的访问控制(RBAC)。然而,随着医疗机构规模的不断扩大,在 RBAC 中,角色的访问控制行为很难进行详细声明。此外,随着美国 HIPAA 和加拿大 PIPEDA 等严格规范的出台,鼓励患者有权管理自己的 EMR 访问控制。针对这些问题,我们提出了一种 EMR 数字版权管理系统,它是基于角色的访问控制在医疗机构矩阵组织上的扩展,称为 RBAC-Matrix。RBAC-Matrix 的目的是在组织中的角色之间授权 EMR,同时允许患者参与定义其记录的访问权限。RBAC-Matrix 通过使用与每个 EMR 相关联的 XrML 文件,在医疗机构的矩阵组织之间授权访问控制声明。它采用主从阶段的两阶段设计处理基于 XrML 权限声明文件的授权行为,从而更好地保护相关的 EMR。RBAC-Matrix 还将医疗记录文件及其关联的 XrML 声明分配给两个不同的 EMRA(EMR 授权)角色,即医疗记录文档创建者(DC)和医疗记录文档权限设置者(DRS)。由 DRS 确定的访问权限设置由患者共同签署,从而使权利声明和 EMR 的使用符合 HIPAA 规范。

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验