DocumentCode :
3722477
Title :
Access Control for Multi-tenancy in Cloud-Based Health Information Systems
Author :
Mohd Anwar;Ashiq Imran
Author_Institution :
Dept. of Comput. Sci., North Carolina A&
fYear :
2015
Firstpage :
104
Lastpage :
110
Abstract :
Cloud technology can be used to support costeffective, scalable, and well-managed healthcare information systems. However, cloud computing, particularly multitenancy, introduces privacy and security issues related to personal health information (PHI). In this paper, we designed ontological models for healthcare workflow and multi-tenancy, and then applied HIPAA requirements on the models to generate HIPAA-compliant access control policies. We used Semantic Web Rule Language (SWRL) to represent access control policies as rules, and we verified the rules with an OWL-DL reasoner. Additionally, we implemented HIPAA security rules through access control policies in a cloud-based simulated healthcare environment. More specifically, we investigated access control policy specification and enforcement for cloud based healthcare information systems using an open source cloud platform, OpenStack. The results manifest HIPAA compliance through authorization policies that are capable of addressing vulnerabilities of multi-tenancy.
Keywords :
"Access control","Medical services","Cloud computing","Ontologies","Insurance","Databases"
Publisher :
ieee
Conference_Titel :
Cyber Security and Cloud Computing (CSCloud), 2015 IEEE 2nd International Conference on
Type :
conf
DOI :
10.1109/CSCloud.2015.95
Filename :
7371467
Link To Document :
بازگشت