Title :
Secure Access Control for Health Information Sharing Systems
Author :
Alshehri, Suhair ; Raj, Rajesh Kumar
Author_Institution :
B. Thomas Golisano Coll. of Comput. & Inf. Sci., Rochester Inst. of Technol. Rochester, Rochester, NY, USA
Abstract :
The Health Information Technology for Economic and Clinical Health Act (HITECH) of 2009 encourages healthcare providers to share information to improve healthcare quality at reduced cost. Such information sharing, however, raises security and privacy concerns that require appropriate access control mechanisms to ensure Health Insurance Portability and Accountability Act (HIPAA) compliance. Current approaches such as Role-Based Access Control (RBAC) and its variants, and newer approaches such as Attribute-Based Access Control (ABAC) are inadequate. RBAC provides simple administration of access control and user permission review, but demands complex initial role engineering and makes access control inflexible. ABAC, on the other hand, simplifies initial setup but increases the complexity of managing privileges and user permissions. These limitations have motivated research into the development of newer access control models that use attributes and policies while preserving RBAC´s strengths. The BiLayer Access Control (BLAC) model is a two-step method being proposed to integrate attributes with roles: an access request is checked against pseudoroles, i.e., the list of subject attributes (first layer), and then against rules within the policies (second layer) associated with the requested object. This paper motivates the BLAC approach, outlines the BLAC model, and illustrates its usefulness to healthcare information sharing environments.
Keywords :
authorisation; computational complexity; medical information systems; ABAC; BLAC; HIPAA; HITECH; RBAC; attribute-based access control; bilayer access control model; health information sharing systems; health information technology for economic and clinical health act; health insurance portability and accountability act compliance; healthcare information sharing environments; healthcare providers; healthcare quality; privacy concerns; privilege complexity; role-based access control; secure access control; security concerns; user permission review; Authorization; Biological system modeling; Boolean functions; Complexity theory; Information management; Medical services;
Conference_Titel :
Healthcare Informatics (ICHI), 2013 IEEE International Conference on
Conference_Location :
Philadelphia, PA
DOI :
10.1109/ICHI.2013.40