Authorisation and access control for electronic health record systems

Blobel, Bernd (2004) Authorisation and access control for electronic health record systems. International Journal of Medical Informatics 73 (3), pp. 251-257.

Full text not available from this repository.

Abstract

Enabling the shared care paradigm, centralised or even decentralised electronic health record (EHR) systems increasingly become core applications in hospital information systems and health networks. For realising multipurpose use and reuse as well as inter-operability at knowledge level, EHR have to meet special architectural requirements. The component-oriented and model-based architecture should meet international standards. Especially in extended health networks realising inter-organisational communication and co-operation, authorisation cannot be organised at user level anymore. Therefore, models, methods and tools must be established to allow formal and structured policy definition, policy agreements, role definition, authorisation and access control.
Based on the author’s international engagement in EHR architecture and security standards referring to the revision of CEN ENV 13606, the GEHR/open EHR approach, HL7 and CORBA, models for health-specific and EHR-related roles, for authorisation management and access control have been developed. The basic concept is the separation of structural roles defining organisational entity-to-entity relationships and enabling specific acts on the one hand, and functional roles bound to specific activities and realising rights and duties on the other hand. Aggregation of organisational, functional, informational and technological components follows specific rules. Using UML and XML, the principles as well as some examples for analysis, design, implementation and maintenance of policy and authorisation management as well as access control have been practically implemented.

Item Type:Article
Institutions: Medicine > Zentren des Universitätsklinikums Regensburg > eHealth Competence Center
Identification Number:
ValueType
10.1016/j.ijmedinf.2003.11.018DOI
Keywords:Electronic healthcare record; Security; Privilege management; Role management; Authorisation; Access control; Enhanced TTP services
Subjects:600 Technology > 610 Medical sciences Medicine
Status:Published
Refereed:Yes, this version has been refereed
Created at the University of Regensburg:Unknown
Owner:Petra Gürster
Deposited On:14 Oct 2008 15:43
Last Modified:12 Aug 2009 05:02
Item ID:4179
Owner Only: item control page