| Literature DB >> 29670743 |
Marcelo Antonio de Carvalho Junior1, Paulo Bandiera-Paiva1.
Abstract
Objective: This article objective is to highlight implementation characteristics, concerns, or limitations over role-based access control (RBAC) use on health information system (HIS) using industry-focused literature review of current publishing for that purpose. Based on the findings, assessment for indication of RBAC is obsolete considering HIS authorization control needs. Method: We have selected articles related to our investigation theme "RBAC trends and limitations" in 4 different sources related to health informatics or to the engineering technical field. To do so, we have applied the following search query string: "Role-Based Access Control" OR "RBAC" AND "Health information System" OR "EHR" AND "Trends" OR "Challenges" OR "Security" OR "Authorization" OR "Attacks" OR "Permission Assignment" OR "Permission Relation" OR "Permission Mapping" OR "Constraint". We followed PRISMA applicable flow and general methodology used on software engineering for systematic review.Entities:
Mesh:
Year: 2018 PMID: 29670743 PMCID: PMC5836325 DOI: 10.1155/2018/6510249
Source DB: PubMed Journal: J Healthc Eng ISSN: 2040-2295 Impact factor: 2.682
Figure 1User, roles, and permission relationship and role hierarchy accumulating access permissions over an EHR object representation.
Figure 2Literature review systematic retrieval process.
Content/type of classification for fetched articles.
| Type/theme | Selected articles for review | |
|---|---|---|
| Titles | Author(s) | |
| RBAC novels or adaptations | [ | Khan and Sakamura; Liu et al.; Maw et al.; Amato et al.; Chen and Hoang; Premarathne et al.; De la Rosa Algarin et al.; Mchumo and Chi; Zhou et al.; Warren and Chi; Zhang et al.; Liu et al.; Basant and Kumar; Bhatti et al.; Alhaqbani and Fidge |
| RBAC security and efficiency assessments | [ | Lee et al.; Helms and Williams; Beimel and Peleg |
Figure 3Selected studies' chronological view.