首页> 外文会议>International Conference on Communication Systems and Networks >A Dynamic Access Control Policy for Healthcare Service Delivery in Healthcare Ecosystem using Electronic Health Records
【24h】

A Dynamic Access Control Policy for Healthcare Service Delivery in Healthcare Ecosystem using Electronic Health Records

机译:医疗保健生态系统中医疗服务交付的动态访问控制策略使用电子健康记录

获取原文

摘要

Recent developments in the global healthcare scenario from technology, regulatory and societal perspectives have catalyzed the emergence of several healthcare ecosystems. These ecosystems facilitate a comprehensive view and exchange of health records of an individual that are scattered across different healthcare service providers (ecosystem components) for cost effective, better quality and evidence based healthcare service delivery. Typically, the activities of a healthcare service delivery process are executed by one or more end users and different activities may be performed by different end users. In an ecosystem, service execution may also involve dynamic interlinking and orchestration amongst inter organization ecosystem components. The dynamic nature of service delivery and interactions in a distributed environment raises various security and privacy concerns. Hence in this paper we propose a novel dynamic access control policy for healthcare service delivery using Electronic Health Records (EHR) in a healthcare ecosystem. This policy lays down the requirements of its main components viz. Activity Based Specification, Access Enforcement Mechanism and Consent Repository. The Activity Based Specification consists of collections of activity rules and an activity rule validator. The Access Enforcement Mechanism mediates request made by an end user to perform activity of a healthcare service delivery process based not only on their role but also patient’s consent and other contextual information. The aim is to enable activity based, consent aware and fine grained access on a patient’s EHR to the end user at the time of healthcare service delivery in a distributed environment.
机译:来自技术,监管和社会观点的全球医疗情况的最新进展促进了几种医疗保健生态系统的出现。这些生态系统促进了跨越不同医疗服务提供商(生态系统组件)分散的个人的综合视图和交流,以实现成本效益,更好的质量和基于证据的医疗服务交付。通常,医疗保健服务交付过程的活动由一个或多个最终用户执行,并且可以由不同的最终用户执行不同的活动。在生态系统中,服务执行还可能涉及组织间生态系统组件之间的动态互连和编排。分布式环境中服务交付和交互的动态性质提出了各种安全和隐私问题。因此,在本文中,我们提出了一种使用电子健康记录(EHR)在医疗保健生态系统中的医疗服务交付的新型动态访问控制政策。此策略下调其主要组件viz的要求。基于活动的规范,访问强制机制和同意存储库。基于活动的规范包括活动规则和活动规则验证器的集合。访问强制机制调解最终用户所提出的请求,不仅基于其角色而且基于患者的同意和其他上下文信息执行医疗服务交付过程的活动。目的是在分布式环境中医疗服务交付时,在患者的EHR上以基于活动,同意知识和对最终用户的精细访问权限。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号