for digital rights management and the description of
access policies for the protection of EHR data.
We foresee a need to mediate distributed data ac-
cess, where data is stored, accessed and processed in
a truly distributed fashion without the help of cen-
tralised policy mechanisms. Distributed data access,
however, also requires a dedicated access control ar-
chitecture, which we presented in Section 3 as a gen-
eral model for access control in distributed processing
environments, e.g. the medical IT environment de-
scribed in the use case. Any concrete implementation
of an policy enforcement mechanism can be analysed
and compared with respect to this model.
The analysis of current EHR standards has shown
that they are not ideally suited for reliable data pro-
tection and patient-controlled access restrictions. In-
stead, they should be used in combination with dedi-
cated policy languages.
Section 4 presents two dedicated policy descrip-
tion languages that might be used to specify data ac-
cess policies for EHR. A structural analysis and short-
ened example explains how these languages could be
used. Even though a full policy description repre-
senting the use case could not be given for reasons
of readability and length, their general applicability is
shown. The two languages are compared face to face,
outlining important differences when used for EHR
protection.
An open issue and potential basis for further work
is the formulation of a generic set of actions, rich
enough for the fine-grained control over medical data
in the workflow and simple enough for the patient to
reliably apply in EHR policies.
REFERENCES
Apitzsch, F. (2007). Digital Rights Management for Elec-
tronic Health Records. In Proceedings of CeHR Inter-
national Conference 2007 (to appear).
Blobel, B., Nordberg, R., Davis, J., and Pharow, P. (2006).
Modelling privilege management and access control.
In International Journal of Medical Informatics, vol-
ume 75, pages 597–623.
BMG (2006). Die Spezifikation der elektro-
nischen Gesundheitskarte. Bundesmin-
isterium für Gesundheit, Version 1.1.0,
http://www.dimdi.de/static/de/ehealth/karte/index.htm.
CEN/TS-15211 (2006). Health informatics - Mapping of
hierarchical message descriptions to XML. European
Committee for Standardisation, http://www.cen.eu.
ContentGuard (2001). eXtensible rights Markup Language
(XrML) 2.0, Specification.
DeRose, J. C. S. (1999). XML Path Lan-
guage (XPath). W3C Recommendation,
http://www.w3.org/TR/1999/REC-xpath-19991116.
Eastlake, D., Reagle, J., and Solo, D. (2002).
RFC3235: Extensible Markup Language - XML-
Signature Syntax and Processing. http://www.rfc-
editor.org/rfc/rfc3275.txt.
EN-13606-1 (2007). Health informatics - Electronic
health record communication - Part 1: Reference
model. European Committee for Standardisation,
http://www.cen.eu.
EN-13606-2 (2005). Health informatics - Electronic health
record communication - Part 2: Archetypes. European
Committee for Standardisation, http://www.cen.eu.
EN-13606-4 (2007). Health informatics - Electronic health
record communication - Part 4: Security. European
Committee for Standardisation, http://www.cen.eu.
Giere, W. (1986). BAIK - Befunddokumentation und Arzt-
briefbeschreibung im Krankenhaus.
HL7 (2005). HL7 Clinical Document Architecture, Release
2.0, Normative Edition.
ISO/HL7-21731 (2006). Health informatics - HL7 version
Reference information model Release 1).
Karjoth, G., Schunter, M., and Waidner, M. (2003).
Platform For Enterprise Privacy Practices: Privacy-
enabled Management Of Customer Data. In
2nd Workshop on Privacy Enhancing Technologies
(PET2002), volume Lecture Notes in Computer Sci-
ence 2482, pages 69–84. Springer Verlag.
Mont, M. C., Pearson, S., and Bramhall, P. (2003). To-
wards Accountable Management of Identity and Pri-
vacy: Sticky Policies and Enforceable Tracing Ser-
vices. In Proceedings of the 14th International Work-
shop on Database and Expert Systems Applications,
page 377. IEEE Computer Society.
openEHR (2007). openEHR Release 1.0.1.
http://www.openehr.org.
Stefik, M. (September 18th, 1996). The Digital Property
Rights Language, Manual and Tutorial, Version 1.02.
Technical report, Xerox Palo Alto Research Center,
Palo Alto, CA.
Walmsley, D. C. F. P. (2004). XML Schema. W3C
Recommendation, http://www.w3.org/TR/2004/REC-
xmlschema-0-20041028/.
Wang, X. (2005). Desing Principles and Issues of Rights
Expression Languages for Digital Rights Manage-
ment. In Proceedings SPIE, Conference on Vi-
sual Communications and Image Processing, volume
5960, pages 1130–1141.
Woo, T. Y. C. and Lam, S. S. (1993). Authorizations in
Distributed Systems: A New Approach. Journal of
Computer Security, 2(2-3):107–136.
XACML-2.0 (2005). eXtensible Access Control
Markup Language (XACML). OASIS-Standard,
http://www.oasis-open.org/committees/xacml.