• DocumentCode
    3643256
  • Title

    Usable access control policy and model for healthcare

  • Author

    Ana Ferreira;Ricardo Correia;Marta Brito;Luís Antunes

  • Author_Institution
    CINTESIS - Centre for Research in Health Technologies and Information Systems, Faculty of Medicine, University of Porto, Al. Prof. Hernâ
  • fYear
    2011
  • fDate
    6/1/2011 12:00:00 AM
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Access control defines what users can perform within a system. It is usually defined by software engineers and end users are seldom asked for cooperation. The main objective of this paper is to gather the necessary knowledge from the end users of an Electronic Medical Record (EMR) regarding access control and, with their collaboration, define a list of usable access control rules and access control model, which are closer to user needs and workflows. Access control standards in healthcare were also analyzed. Afterwards, focus groups were applied to health professionals and several access control rules were extracted from the analysis of all the information that was gathered. The Break The Glass - Role Based Access Control model (BTG-RBAC) was created and includes the generated access control rules, which are closer to users´ workflows and needs and can, therefore, improve EMR´s usability while reducing some barriers for its effective integration.
  • Keywords
    "Access control","Medical services","Text analysis","Engines","Glass","Sensitivity"
  • Publisher
    ieee
  • Conference_Titel
    Computer-Based Medical Systems (CBMS), 2011 24th International Symposium on
  • ISSN
    1063-7125
  • Print_ISBN
    978-1-4577-1189-3
  • Type

    conf

  • DOI
    10.1109/CBMS.2011.5999035
  • Filename
    5999035