Requirements for access control: US Healthcare domain

K. Beznosov
{"title":"Requirements for access control: US Healthcare domain","authors":"K. Beznosov","doi":"10.1145/286884.286892","DOIUrl":null,"url":null,"abstract":"The di erences in the requirements of disclosing patient information from state to state, the diversity in healthcare providers' business models, the increased rate of merges, and the upcoming federal regulations in healthcare make access control requirements a moving target for application developers and healthcare enterprise designers and administrators. We suggest two major design principles for access control infrastructure deployed in the healthcare enterprises: isolation of the application logic from the authorization logic and centralized administration of the authorization logic. Application systems and healthcare enterprises constructed according to these two principles will be able to accommodate changes in access control logic and will enforce a uniform access control model across an enterprise. However, the complexity and instability of the healthcare access control model makes the task of applying these design principles somewhat di cult. The notion of roles and their hierarchies help to alleviate complexity of controlling access to patient data, but it has to be used in conjunction with other information, such as a liation, relationship, location and so on. We identi ed the following factors that have to be used to make elaborate authorization decisions in order to comply with patient information discloser requirements:","PeriodicalId":355233,"journal":{"name":"ACM Workshop on Role-Based Access Control","volume":"40 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1998-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"41","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"ACM Workshop on Role-Based Access Control","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/286884.286892","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 41

Abstract

The di erences in the requirements of disclosing patient information from state to state, the diversity in healthcare providers' business models, the increased rate of merges, and the upcoming federal regulations in healthcare make access control requirements a moving target for application developers and healthcare enterprise designers and administrators. We suggest two major design principles for access control infrastructure deployed in the healthcare enterprises: isolation of the application logic from the authorization logic and centralized administration of the authorization logic. Application systems and healthcare enterprises constructed according to these two principles will be able to accommodate changes in access control logic and will enforce a uniform access control model across an enterprise. However, the complexity and instability of the healthcare access control model makes the task of applying these design principles somewhat di cult. The notion of roles and their hierarchies help to alleviate complexity of controlling access to patient data, but it has to be used in conjunction with other information, such as a liation, relationship, location and so on. We identi ed the following factors that have to be used to make elaborate authorization decisions in order to comply with patient information discloser requirements:
访问控制要求:美国医疗保健领域
各州之间披露患者信息的需求差异、医疗保健提供商业务模型的多样性、合并率的增加以及即将出台的医疗保健联邦法规,使得访问控制需求成为应用程序开发人员、医疗保健企业设计人员和管理员的一个不断变化的目标。我们建议在医疗保健企业中部署访问控制基础设施的两个主要设计原则:将应用程序逻辑与授权逻辑隔离,以及对授权逻辑进行集中管理。根据这两个原则构建的应用程序系统和医疗保健企业将能够适应访问控制逻辑的变化,并在整个企业中实施统一的访问控制模型。然而,医疗保健访问控制模型的复杂性和不稳定性使得应用这些设计原则的任务有些困难。角色及其层次结构的概念有助于减轻对患者数据访问控制的复杂性,但它必须与其他信息(如联系、关系、位置等)结合使用。我们确定了以下因素,这些因素必须用于制定详细的授权决策,以符合患者信息披露要求:
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信