• DocumentCode
    2504850
  • Title

    HealthPass: Fine-Grained Access Control to Portable Personal Health Records

  • Author

    Steele, Robert ; Min, Kyongho

  • Author_Institution
    Discipline of Health Inf., Univ. of Sydney, Sydney, NSW, Australia
  • fYear
    2010
  • fDate
    20-23 April 2010
  • Firstpage
    1012
  • Lastpage
    1019
  • Abstract
    At present, emerging possibilities for patients to access their health records or health information may potentially lead to changes within the current health care delivery system from an institution-centered to a patient-centered model and an electronic personal health record (PHR) may greatly influence such a shift. However, the use of PHRs does introduce specific challenges in terms of accidental disclosure of or malicious access to an individual´s health data. Hence a high level of security for data access is required due to the sensitivity and confidentiality of the health data in PHRs. In this paper, we present extensible models for defining and configuring fine-grained, role-based access control policies for XML-based portable personal health records using an extended digital certificate approach, called HealthPass which enables flexible and dynamic interactions without using a classical authorization and authentication approach like username and password.
  • Keywords
    XML; authorisation; health care; medical information systems; message authentication; HealthPass; XML-based portable personal health records; authentication; authorization; data access security; digital certificate; electronic personal health record; fine-grained access control; health care delivery system; health information; institution-centered model; patient-centered model; role-based access control; Access control; Authentication; Authorization; Biomedical informatics; Data security; Health information management; Medical services; Mobile handsets; Universal Serial Bus; XML; XML document; access control; health informatics; portable personal health record; role-based access control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications (AINA), 2010 24th IEEE International Conference on
  • Conference_Location
    Perth, WA
  • ISSN
    1550-445X
  • Print_ISBN
    978-1-4244-6695-5
  • Type

    conf

  • DOI
    10.1109/AINA.2010.176
  • Filename
    5474820