• DocumentCode
    1805150
  • Title

    A security policy model for clinical information systems

  • Author

    Anderson, Ross J.

  • Author_Institution
    Comput. Lab., Cambridge Univ., UK
  • fYear
    1996
  • fDate
    6-8 May 1996
  • Firstpage
    30
  • Lastpage
    43
  • Abstract
    The protection of personal health information has become a live issue in a number of countries, including the USA, Canada, Britain and Germany. The debate has shown that there is widespread confusion about what should be protected, and why. Designers of military and banking systems can refer to Bell & LaPadula (1973) and Clark & Wilson (1987) respectively, but there is no comparable security policy model that spells out clear and concise access rules for clinical information systems. In this article, we present just such a model. It was commissioned by doctors and is driven by medical ethics; it is informed by the actual threats to privacy, and reflects current best clinical practice. Its effect is to restrict both the number of users who can access any record and the maximum number of records accessed by any user. This entails controlling information flows across rather than down and enforcing a strong notification property. We discuss its relationship with existing security policy models, and its possible use in other applications where information exposure must be localised; these range from private banking to the management of intelligence data
  • Keywords
    DP management; data privacy; medical information systems; security of data; clinical information systems; information flow control; intelligence data management; localized information exposure; medical ethics; personal health information protection; privacy threats; private banking; restricted record numbers; restricted user numbers; security policy model; strong notification property enforcement; Banking; Clinical diagnosis; Data security; Ethics; Information security; Intelligent networks; Laboratories; Privacy; Protection; Terminology;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 1996. Proceedings., 1996 IEEE Symposium on
  • Conference_Location
    Oakland, CA
  • ISSN
    1081-6011
  • Print_ISBN
    0-8186-7417-2
  • Type

    conf

  • DOI
    10.1109/SECPRI.1996.502667
  • Filename
    502667