• DocumentCode
    652106
  • Title

    Secure Access Control for Health Information Sharing Systems

  • Author

    Alshehri, Suhair ; Raj, Rajesh Kumar

  • Author_Institution
    B. Thomas Golisano Coll. of Comput. & Inf. Sci., Rochester Inst. of Technol. Rochester, Rochester, NY, USA
  • fYear
    2013
  • fDate
    9-11 Sept. 2013
  • Firstpage
    277
  • Lastpage
    286
  • Abstract
    The Health Information Technology for Economic and Clinical Health Act (HITECH) of 2009 encourages healthcare providers to share information to improve healthcare quality at reduced cost. Such information sharing, however, raises security and privacy concerns that require appropriate access control mechanisms to ensure Health Insurance Portability and Accountability Act (HIPAA) compliance. Current approaches such as Role-Based Access Control (RBAC) and its variants, and newer approaches such as Attribute-Based Access Control (ABAC) are inadequate. RBAC provides simple administration of access control and user permission review, but demands complex initial role engineering and makes access control inflexible. ABAC, on the other hand, simplifies initial setup but increases the complexity of managing privileges and user permissions. These limitations have motivated research into the development of newer access control models that use attributes and policies while preserving RBAC´s strengths. The BiLayer Access Control (BLAC) model is a two-step method being proposed to integrate attributes with roles: an access request is checked against pseudoroles, i.e., the list of subject attributes (first layer), and then against rules within the policies (second layer) associated with the requested object. This paper motivates the BLAC approach, outlines the BLAC model, and illustrates its usefulness to healthcare information sharing environments.
  • Keywords
    authorisation; computational complexity; medical information systems; ABAC; BLAC; HIPAA; HITECH; RBAC; attribute-based access control; bilayer access control model; health information sharing systems; health information technology for economic and clinical health act; health insurance portability and accountability act compliance; healthcare information sharing environments; healthcare providers; healthcare quality; privacy concerns; privilege complexity; role-based access control; secure access control; security concerns; user permission review; Authorization; Biological system modeling; Boolean functions; Complexity theory; Information management; Medical services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Healthcare Informatics (ICHI), 2013 IEEE International Conference on
  • Conference_Location
    Philadelphia, PA
  • Type

    conf

  • DOI
    10.1109/ICHI.2013.40
  • Filename
    6680488