Title :
A virtual PHR authorization system
Author :
Poulymenopoulou, M. ; Malamateniou, Flora ; Vassilacopoulos, George
Author_Institution :
Dept. of Digital Syst., Univ. of Piraeus, Piraeus, Greece
Abstract :
Cloud computing and Internet of things (IOT) technologies can support a new generation of PHR systems which are provided as cloud services that contain patient data (health and social) from various sources, including automatically transmitted data from Internet connected devices of patient living space (e.g. medical devices connected to patients at home care). In this paper, the virtual PHR concept is introduced as an entity on the network consisted of (a) a non-healthcare component containing health and social information collected by either the patient or non-healthcare providers, (b) a medical device component containing health information transmitted from Internet connected medical devices and (c) a healthcare professional component containing information stored into various healthcare information systems. The PHR concept is based on the patient-centered model dictating that patients are the owners of their information. Hence, patients are empowered to authorize other subjects to access it that introduces specific security challenges which are further accentuated by the fact that diverse local security policies may need to be reconciled. The PHR authorization system proposed here is based on a combination of role-based and attribute-based access control (RABAC) and supports patient-specified authorization policies of various granularity levels subject to constraints imposed by the security policies of the various health and social care providers involved. To this end, an ontology of granular security concepts is built to aid in semantically matching diverse authorization requests and to enable semantic rule reasoning on whether a requested access should be permitted or denied.
Keywords :
authorisation; electronic health records; granular computing; ontologies (artificial intelligence); IOT; Internet of things; RABAC; attribute-based access control; cloud computing; data access; granular security concepts; granularity levels; health care providers; health information collection; health information transmission; healthcare information systems; healthcare professional component; information storage; local security policies; medical device component; nonhealthcare component; nonhealthcare providers; ontology; patient data; patient-centered model; patient-specified authorization policies; personal health record; role-based access control; semantic matching; semantic rule reasoning; social care providers; social information collection; virtual PHR authorization system; Authorization; Cloud computing; Filtering; Medical services; Ontologies; Semantics;
Conference_Titel :
Biomedical and Health Informatics (BHI), 2014 IEEE-EMBS International Conference on
Conference_Location :
Valencia
DOI :
10.1109/BHI.2014.6864307