One Way to Patient Empowerment - The Proposal of an Authorization Model
نویسندگان
چکیده
American and European Legislation for protection of medical data agree that the patient has the right to play a pivotal role in the decisions regarding the content and distribution of her/his medical records. The Role Based Access Control (RBAC) model is the most commonly used authorization model in healthcare. The first goal of this work is to review if existing models and standards provide for patients accessing their medical records and customizing access control rules, the second goal is to define and propose an authorization model based on RBAC to be used and customized by the patient. A literature review was performed and encompassed 22 articles and standards from which 12 were included for analysis. Results show that existing standards define guidelines for these issues but they are too generic to be directly applied to real healthcare settings. The proposed authorization model combines characteristics of RBAC, ISO/TS 13606-4, temporal constraints and break the glass. With this model we hope to start bridging the gap between legislation and what really happens in practice in terms of patients controlling and being actively involved in their healthcare. Future work includes the implementation and evaluation of the proposed model in a healthcare setting.
منابع مشابه
تحلیل مفهوم مشارکت بیمار مبتلا به بیماری مزمن: استفاده از الگوی هیبرید
Background and Aim: Approaches to professional health care have changed along with changes in health measures and progression of chronic diseases. Patient participation is an international golden standard in new nursing paradigm. Despite the importance of patient participation and its routine usage in professional care, this concept is not clear, especially in social and cultural context of I...
متن کاملAccess control in ultra-large-scale systems using a data-centric middleware
The primary characteristic of an Ultra-Large-Scale (ULS) system is ultra-large size on any related dimension. A ULS system is generally considered as a system-of-systems with heterogeneous nodes and autonomous domains. As the size of a system-of-systems grows, and interoperability demand between sub-systems is increased, achieving more scalable and dynamic access control system becomes an im...
متن کاملAuthorization models for secure information sharing: a survey and research agenda
This article presents a survey of authorization models and considers their 'fitness-for-purpose' in facilitating information sharing. Network-supported information sharing is an important technical capability that underpins collaboration in support of dynamic and unpredictable activities such as emergency response, national security, infrastructure protection, supply chain integration and emerg...
متن کاملAn Effective Modality Conflict Model for Identifying Applicable Policies During Policy Evaluation
Policy evaluation is a process to determine whether a request submitted by a user satisfies the access control policies defined by an organization. Modality conflict is one of the main issues in policy evaluation. Existing modality conflict detection approaches do not consider complex condition attributes such as spatial and temporal constraints. An effective authorization propagation rule is n...
متن کاملNursing Workloads and Psychological Empowerment in Hospitals: Structural Equations Modeling
Background: The high workload of nurses in hospitals has been identified as a patient safety and worker stress problem. Psychological empowerment is a motivational concept demonstrated in four dimensions: meaning, competence, self-determination, and impact. Objective: This study investigated the relationship between nurses’ workloads and psychological emp...
متن کامل