Authors:
Nahid AlThqafi
;
Hessah AlSalamah
and
Ahmad Daraiseh
Affiliation:
King Saud University, Saudi Arabia
Keyword(s):
Access Control, Business Process Management (BPM), Electronic Medical Record (EMR), Hospital Information System (HIS), Patient-Centric Fine-Grained Access Control (PCFGAC).
Related
Ontology
Subjects/Areas/Topics:
Artificial Intelligence
;
Biomedical Engineering
;
Business Analytics
;
Cardiovascular Technologies
;
Computing and Telecommunications in Cardiology
;
Confidentiality and Data Security
;
Data Engineering
;
Decision Support Systems
;
Decision Support Systems, Remote Data Analysis
;
Electronic Health Records and Standards
;
Health Engineering and Technology Applications
;
Health Information Systems
;
Healthcare Management Systems
;
Knowledge-Based Systems
;
Medical and Nursing Informatics
;
Symbolic Systems
Abstract:
Access Control to patients’ medical information in Hospital Information Systems (HIS) is a challenge in
modern Patient-Centered (PC) healthcare. Fine–Grained Access Control (FGAC) in particular has been
identified as one of the security requirements in these systems. In FGAC, only parts of medical information
that are relevant and required by healthcare providers are accessed at the point of care. This cannot be
achieved without a holistic view of a medical condition through a Patient-Centered Fine-Grained Access
Control (PCFGAC), in which patient-centricity is considered. This research proposes using Business
Process Management (BPM) to achieve PCFGAC in order to provide a real-time access control based on a
“need-to-know” principle. Through a prototype that uses BPM, security requirements of PCFGAC were
met. These include: authority control, informed decision support, fine-grained access control, and dynamic
policies support. Thus, a contribution to the knowledge and practice has b
een introduced.
(More)