Literature DB >> 20696276

A method to implement fine-grained access control for personal health records through standard relational database queries.

Walter V Sujansky1, Sam A Faus2, Ethan Stone3, Patricia Flatley Brennan4.   

Abstract

Online personal health records (PHRs) enable patients to access, manage, and share certain of their own health information electronically. This capability creates the need for precise access-controls mechanisms that restrict the sharing of data to that intended by the patient. The authors describe the design and implementation of an access-control mechanism for PHR repositories that is modeled on the eXtensible Access Control Markup Language (XACML) standard, but intended to reduce the cognitive and computational complexity of XACML. The authors implemented the mechanism entirely in a relational database system using ANSI-standard SQL statements. Based on a set of access-control rules encoded as relational table rows, the mechanism determines via a single SQL query whether a user who accesses patient data from a specific application is authorized to perform a requested operation on a specified data object. Testing of this query on a moderately large database has demonstrated execution times consistently below 100ms. The authors include the details of the implementation, including algorithms, examples, and a test database as Supplementary materials.
Copyright © 2010 Elsevier Inc. All rights reserved.

Entities:  

Mesh:

Year:  2010        PMID: 20696276     DOI: 10.1016/j.jbi.2010.08.001

Source DB:  PubMed          Journal:  J Biomed Inform        ISSN: 1532-0464            Impact factor:   6.317


  5 in total

Review 1.  Access control and privilege management in electronic health record: a systematic literature review.

Authors:  Manoj Jayabalan; Thomas O'Daniel
Journal:  J Med Syst       Date:  2016-10-08       Impact factor: 4.460

2.  We work with them? Healthcare workers interpretation of organizational relations mined from electronic health records.

Authors:  You Chen; Nancy Lorenzi; Steve Nyemba; Jonathan S Schildcrout; Bradley Malin
Journal:  Int J Med Inform       Date:  2014-04-28       Impact factor: 4.046

3.  Patients want granular privacy control over health information in electronic medical records.

Authors:  Kelly Caine; Rima Hanania
Journal:  J Am Med Inform Assoc       Date:  2012-11-26       Impact factor: 4.497

4.  Architecture of a consent management suite and integration into IHE-based Regional Health Information Networks.

Authors:  Oliver Heinze; Markus Birkle; Lennart Köster; Björn Bergh
Journal:  BMC Med Inform Decis Mak       Date:  2011-10-04       Impact factor: 2.796

5.  Two complementary personal medication management applications developed on a common platform: case report.

Authors:  Stephen E Ross; Kevin B Johnson; Katie A Siek; Jeffry S Gordon; Danish U Khan; Leah M Haverhals
Journal:  J Med Internet Res       Date:  2011-07-12       Impact factor: 5.428

  5 in total

北京卡尤迪生物科技股份有限公司 © 2022-2023.