Access control for smarter healthcare using policy spaces

نویسندگان

  • Claudio Agostino Ardagna
  • Sabrina De Capitani di Vimercati
  • Sara Foresti
  • Tyrone Grandison
  • Sushil Jajodia
  • Pierangela Samarati
چکیده

A fundamental requirement for the healthcare industry is that the delivery of care comes first and nothing should interfere with it. As a consequence, the access control mechanisms used in healthcare to regulate and restrict the disclosure of data are often bypassed in case of emergencies. This phenomenon, called “break the glass”, is a common pattern in healthcare organizations and, though quite useful and mandatory in emergency situations, from a security perspective, it represents a serious system weakness. Malicious users, in fact, can abuse the system by exploiting the break the glass principle to gain unauthorized privileges and accesses. In this paper, we propose an access control solution aimed at better regulating break the glass exceptions that occur in healthcare systems. Our solution is based on the definition of different policy spaces, a language, and a composition algebra to regulate access to patient data and to balance the rigorous nature of traditional access control systems with the “delivery of care comes first” principle.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Regulating Exceptions in Healthcare Using Policy Spaces

One truth holds for the healthcare industry nothing should interfere with the delivery of care. Given this fact, the access control mechanisms used in healthcare to regulate and restrict the disclosure of data are often bypassed. This “break the glass” phenomenon is an established pattern in healthcare organizations and, though quite useful and mandatory in emergency situations, it represents a...

متن کامل

Patient Safety and Healthcare Quality: The Case for Language Access

This paper aims to provide a description of the need for Culturally and Linguistically Appropriate Services (CLAS) for Limited English Proficient (LEP) patients, an identification of how the lack of CLAS for LEP patients can compromise patient safety and healthcare quality, and discuss barriers to the provision of CLAS.

متن کامل

National Health Service Principles as Experienced by Vulnerable London Migrants in “Austerity Britain”: A Qualitative Study of Rights, Entitlements, and Civil-Society Advocacy

Background Recent British National Health Service (NHS) reforms, in response to austerity and alleged ‘health tourism,’ could impose additional barriers to healthcare access for non-European Economic Area (EEA) migrants. This study explores policy reform challenges and implications, using excerpts from the perspectives of non-EEA migrants and health advocates in London.   Methods A qualitative ...

متن کامل

Improving Maternal and Child Healthcare Programme Using Community-Participatory Interventions in Ebonyi State Nigeria

In Nigeria, the government is implementing the Free Maternal and Child Health Care Programme (FMCHCP). The policy is premised on the notion that financial barriers are one of the most important constraints to equitable access and use of skilled maternal and child healthcare. In Ebonyi State, Southeastern Nigeria the FMCHCP is experiencing implementation challenges including: inadequate human re...

متن کامل

Social Determinants of Equity in Access to Healthcare for Tuberculosis Patients in Republic of Macedonia – Results from a Case-Control Study

Background Health is a complex phenomenon and equity as a basic human right an integral part of constitutions in almost all countries in the world. In Republic of Macedonia (RM), Tuberculosis (TB) is clustered regionally and in certain ethnic groups. The main objective of this study was to analyze Social Determinants of Health (SDH) and equity in access to healthcare services for TB patients in...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Computers & Security

دوره 29  شماره 

صفحات  -

تاریخ انتشار 2010