Jayabalan Manoj, O'Daniel Thomas
Asia Pacific University of Technology and Innovation, Technology Park Malaysia, Bukit Jalil, 57000, Kuala Lumpur, Malaysia.
J Med Syst. 2016 Dec;40(12):261. doi: 10.1007/s10916-016-0589-z. Epub 2016 Oct 8.
This study presents a systematic literature review of access control for electronic health record systems to protect patient's privacy. Articles from 2006 to 2016 were extracted from the ACM Digital Library, IEEE Xplore Digital Library, Science Direct, MEDLINE, and MetaPress using broad eligibility criteria, and chosen for inclusion based on analysis of ISO22600. Cryptographic standards and methods were left outside the scope of this review. Three broad classes of models are being actively investigated and developed: access control for electronic health records, access control for interoperability, and access control for risk analysis. Traditional role-based access control models are extended with spatial, temporal, probabilistic, dynamic, and semantic aspects to capture contextual information and provide granular access control. Maintenance of audit trails and facilities for overriding normal roles to allow full access in emergency cases are common features. Access privilege frameworks utilizing ontology-based knowledge representation for defining the rules have attracted considerable interest, due to the higher level of abstraction that makes it possible to model domain knowledge and validate access requests efficiently.
本研究对电子健康记录系统的访问控制进行了系统的文献综述,以保护患者隐私。2006年至2016年的文章是从美国计算机协会数字图书馆、电气与电子工程师协会(IEEE)Xplore数字图书馆、科学Direct、医学文献数据库(MEDLINE)和MetaPress中提取的,采用了广泛的纳入标准,并根据ISO22600的分析进行选择。加密标准和方法不在本综述范围内。目前正在积极研究和开发三大类模型:电子健康记录的访问控制、互操作性的访问控制和风险分析的访问控制。传统的基于角色的访问控制模型通过空间、时间、概率、动态和语义等方面进行扩展,以捕获上下文信息并提供细粒度的访问控制。维护审计跟踪以及在紧急情况下允许完全访问的覆盖正常角色的设施是常见特征。利用基于本体的知识表示来定义规则的访问权限框架引起了相当大的兴趣,因为其较高的抽象级别使得能够对领域知识进行建模并有效地验证访问请求。