A Context-Aware Authorization Model for Process-Oriented Personal Health Record Systems
نویسندگان
چکیده
Healthcare delivery is a highly complex process involving a broad range of healthcare services, typically performed by a number of geographically distributed and organizationally disparate healthcare providers requiring increased collaboration and coordination of their activities in order to provide shared and integrated care. Under an IT-enabled, patient-centric model, health systems can integrate care delivery across the continuum of services, from prevention to follow-up, and also coordinate care across all settings. In particular, much potential can be realized if cooperation among disparate healthcare organizations is expressed in terms of cross-organizational healthcare processes, where information support is provided by means of Personal Health Record (PHR) systems. This chapter assumes a process-oriented PHR system and presents a security framework that addresses the authorization and access control issues arisen in these systems. The proposed framework ensures provision of tight, just-in-time permissions so that authorized users get access to specific objects according to the current context. These permissions are subject to continuous adjustments triggered by the changing context. Thus, the risk of compromising information integrity during task executions is reduced. DOI: 10.4018/978-1-61692-895-7.ch003
منابع مشابه
Context-Based Integrative Educational Technique in Profession-Oriented Foreign Language Teaching (Academic Model United Nations)
The aim of the article is to examine the Academic Model United Nations (Model UN) as a context-based integrative educational technique in profession-oriented foreign language teaching (FLT); to point out the context-based integrative nature of profession-oriented language learning and highlight the importance of using product-based educational techniques in FLT for developing students’ future p...
متن کاملCAMAC: a context-aware mandatory access control model
Mandatory access control models have traditionally been employed as a robust security mechanism in multilevel security environments such as military domains. In traditional mandatory models, the security classes associated with entities are context-insensitive. However, context-sensitivity of security classes and flexibility of access control mechanisms may be required especially in pervasive c...
متن کاملA Context-aware Architecture for Mental Model Sharing through Semantic Movement in Intelligent Agents
Recent studies in multi-agent systems are paying increasingly more attention to the paradigm of designing intelligent agents with human inspired concepts. One of the main cognitive concepts driving the core of many recent approaches in multi agent systems is shared mental models. In this paper, we propose an architecture for sharing mental models based on a new concept called semantic movement....
متن کاملAccess Control Policy Administration supporting User-defined Privacy Preferences A Use-case in the context of Patient-centric Health-care
The protection of medical records is understood to be an issue related to privacy and therefore closely bound to the patient her/himself, playing a crucial role in networked electronic health-care. Awarding users to have control over personal data stored and processed by information systems is important as it allows a user to communicate individual privacy concerns. Still, users self-maintainin...
متن کاملOpenAmbient: a Pervasive Access Control Architecture
For a long time, lack of reliable security and privacy solutions has been considered to be a major hurdle toward the development of pervasive computing applications for critical domains such as secure workplace, healthcare and assisted living. Today, an advanced security infrastructure for context-aware and personalized authentication and authorization services in heterogeneous networks is grad...
متن کامل