A Novel Reference Security Model with the Situation Based Access Policy for Accessing EPHR Data

J Med Syst. 2016 Nov;40(11):242. doi: 10.1007/s10916-016-0620-4. Epub 2016 Sep 29.

Abstract

Electronic Patient Health Record (EPHR) systems may facilitate a patient not only to share his/her health records securely with healthcare professional but also to control his/her health privacy, in a convenient and easy way even in case of emergency. In order to fulfill these requirements, it is greatly desirable to have the access control mechanism which can efficiently handle every circumstance without negotiating security. However, the existing access control mechanisms used in healthcare to regulate and restrict the disclosure of patient data are often bypassed in case of emergencies. In this article, we propose a way to securely share EPHR data under any situation including break-the-glass (BtG) without compromising its security. In this regard, we design a reference security model, which consists of a multi-level data flow hierarchy, and an efficient access control framework based on the conventional Role-Based Access Control (RBAC) and Mandatory Access Control (MAC) policies.

Keywords: Access control; Break-the-glass; EPHR; Mac; RBAC.

MeSH terms

  • Computer Security / instrumentation*
  • Confidentiality*
  • Electronic Health Records / instrumentation*
  • Health Information Exchange
  • Humans