Gope Prosanta, Amin Ruhul
iTrust, Centre for Research in Cyber Security, Singapore University of Technology and Design, Singapore, Singapore.
Department of Computer Science & Engineering, Thapar university, Patiala, Punjab, India.
J Med Syst. 2016 Nov;40(11):242. doi: 10.1007/s10916-016-0620-4. Epub 2016 Sep 29.
Electronic Patient Health Record (EPHR) systems may facilitate a patient not only to share his/her health records securely with healthcare professional but also to control his/her health privacy, in a convenient and easy way even in case of emergency. In order to fulfill these requirements, it is greatly desirable to have the access control mechanism which can efficiently handle every circumstance without negotiating security. However, the existing access control mechanisms used in healthcare to regulate and restrict the disclosure of patient data are often bypassed in case of emergencies. In this article, we propose a way to securely share EPHR data under any situation including break-the-glass (BtG) without compromising its security. In this regard, we design a reference security model, which consists of a multi-level data flow hierarchy, and an efficient access control framework based on the conventional Role-Based Access Control (RBAC) and Mandatory Access Control (MAC) policies.
电子患者健康记录(EPHR)系统不仅可以方便患者与医疗保健专业人员安全地共享其健康记录,还可以让患者控制自己的健康隐私,即使在紧急情况下也能以方便快捷的方式进行。为了满足这些要求,非常需要一种访问控制机制,该机制能够在不协商安全性的情况下有效处理各种情况。然而,医疗保健领域用于规范和限制患者数据披露的现有访问控制机制在紧急情况下往往会被绕过。在本文中,我们提出了一种在包括打破常规(BtG)在内的任何情况下安全共享EPHR数据的方法,同时不损害其安全性。在这方面,我们设计了一个参考安全模型,它由多级数据流层次结构和基于传统基于角色的访问控制(RBAC)和强制访问控制(MAC)策略的高效访问控制框架组成。