Blobel, Bernd (2004) Authorisation and access control for electronic health record systems. International Journal of Medical Informatics 73 (3), pp. 251-257.
Full text not available from this repository.
Enabling the shared care paradigm, centralised or even decentralised electronic health record (EHR) systems increasingly become core applications in hospital information systems and health networks. For realising multipurpose use and reuse as well as inter-operability at knowledge level, EHR have to meet special architectural requirements. The component-oriented and model-based architecture should meet international standards. Especially in extended health networks realising inter-organisational communication and co-operation, authorisation cannot be organised at user level anymore. Therefore, models, methods and tools must be established to allow formal and structured policy definition, policy agreements, role definition, authorisation and access control.
Based on the author’s international engagement in EHR architecture and security standards referring to the revision of CEN ENV 13606, the GEHR/open EHR approach, HL7 and CORBA, models for health-specific and EHR-related roles, for authorisation management and access control have been developed. The basic concept is the separation of structural roles defining organisational entity-to-entity relationships and enabling specific acts on the one hand, and functional roles bound to specific activities and realising rights and duties on the other hand. Aggregation of organisational, functional, informational and technological components follows specific rules. Using UML and XML, the principles as well as some examples for analysis, design, implementation and maintenance of policy and authorisation management as well as access control have been practically implemented.
|Institutions:||Medicine > Zentren des Universitätsklinikums Regensburg > eHealth Competence Center|
|Keywords:||Electronic healthcare record; Security; Privilege management; Role management; Authorisation; Access control; Enhanced TTP services|
|Subjects:||600 Technology > 610 Medical sciences Medicine|
|Refereed:||Yes, this version has been refereed|
|Created at the University of Regensburg:||Unknown|
|Deposited On:||14 Oct 2008 13:43|
|Last Modified:||12 Aug 2009 03:02|