My Notes
Privacy, Confidentiality, and Electronic Medical Records
A Review of Security of Electronic Health Records
Digest of the Discussion Group Sessions
Giving Patients Access to Their Medical Records via the Internet: The PCASSO Experience
An Introduction to Role-Based Access Control
Role-Based Access Control Models
A Study of Access Control Requirements for Healthcare Systems Based on Audit Trails from Access Logs
The findings of this study are surprising and I summarize some of them below:
In the case of emergency access the numbers were too low to analyze. This is probably due to the fact that only a relatively few number of people have this capability. However, actualization is used too frequently to be considered an exception! In contrast to the emergency access, the percentage of people with actualization capability is enormous. The next obvious question is whether this large percentage is justified by the perceived need for this ability. The authors show persuasively that is indeed not the case. Moreover, in analyzing the reasons for why actualization was invoked, the authors found that only 8% of the reasons were self-defined. The use of predefined reasons is both easier for health professionals and provides less specificity; this is not necessarily a good thing.
The authors identified several predefined reasons which they suggest could be folded into normal access control privileges (rather than reserved for the execution of an exception mechanism). They also suggest that the number of individuals with actualization capability should be reduced; the current large numbers are not justified. Adoption of these suggestions would clearly reduce the amount of audit trail data which, in turn, would reduce the burden of checking such voluminous amounts of data.
How to Break Access Control in a Controlled Manner
Authorisation and Access Control for Electronic Health Record Systems
e-Consent: The Design and Implementation of Consumer Consent Mechanisms in an Electronic Environment
Cassandra: Flexible Trust Management, Applied to Electronic Health Records
OASIS Role-Based Access Control for Electronic Health Records