卫生信息系统中患者隐私保护的量化风险自适应访问控制

Qihua Wang, Hongxia Jin
{"title":"卫生信息系统中患者隐私保护的量化风险自适应访问控制","authors":"Qihua Wang, Hongxia Jin","doi":"10.1145/1966913.1966969","DOIUrl":null,"url":null,"abstract":"In traditional access control systems, security administrators determine whether an information consumer can access a certain resource. However, in reality, it is very difficult for policy makers to foresee what information a user may need in various situations. In hospitals, failing to authorize a doctor for the medical information she needs about a patient could lead to severe or fatal consequences. In this paper, we propose a practical access control approach to protect patient privacy in health information systems by taking the realities in healthcare into consideration. First, unlike traditional access control systems, our proposed access control model allows information consumers (i.e. doctors) to make access decisions, while still being able to detect and control the over-accessing of patients' medical data by quantifying the risk associated with doctors' data-accessing activities. Second, we do not require doctors to do anything special in order to use our system. We learn about common practices among doctors and apply statistical methods and information theory techniques to quantify the risk of privacy violation. Third, occasional exceptions on information needs, which is common in healthcare, is taken into account in our model. We have implemented a prototype of our solution and performed simulations on real-world medical history records.","PeriodicalId":72308,"journal":{"name":"Asia CCS '22 : proceedings of the 2022 ACM Asia Conference on Computer and Communications Security : May 30-June 3, 2022, Nagasaki, Japan. ACM Asia Conference on Computer and Communications Security (17th : 2022 : Nagasaki-shi, Japan ; ...","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2011-03-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"70","resultStr":"{\"title\":\"Quantified risk-adaptive access control for patient privacy protection in health information systems\",\"authors\":\"Qihua Wang, Hongxia Jin\",\"doi\":\"10.1145/1966913.1966969\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In traditional access control systems, security administrators determine whether an information consumer can access a certain resource. However, in reality, it is very difficult for policy makers to foresee what information a user may need in various situations. In hospitals, failing to authorize a doctor for the medical information she needs about a patient could lead to severe or fatal consequences. In this paper, we propose a practical access control approach to protect patient privacy in health information systems by taking the realities in healthcare into consideration. First, unlike traditional access control systems, our proposed access control model allows information consumers (i.e. doctors) to make access decisions, while still being able to detect and control the over-accessing of patients' medical data by quantifying the risk associated with doctors' data-accessing activities. Second, we do not require doctors to do anything special in order to use our system. We learn about common practices among doctors and apply statistical methods and information theory techniques to quantify the risk of privacy violation. Third, occasional exceptions on information needs, which is common in healthcare, is taken into account in our model. We have implemented a prototype of our solution and performed simulations on real-world medical history records.\",\"PeriodicalId\":72308,\"journal\":{\"name\":\"Asia CCS '22 : proceedings of the 2022 ACM Asia Conference on Computer and Communications Security : May 30-June 3, 2022, Nagasaki, Japan. ACM Asia Conference on Computer and Communications Security (17th : 2022 : Nagasaki-shi, Japan ; ...\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2011-03-22\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"70\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Asia CCS '22 : proceedings of the 2022 ACM Asia Conference on Computer and Communications Security : May 30-June 3, 2022, Nagasaki, Japan. ACM Asia Conference on Computer and Communications Security (17th : 2022 : Nagasaki-shi, Japan ; ...\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/1966913.1966969\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Asia CCS '22 : proceedings of the 2022 ACM Asia Conference on Computer and Communications Security : May 30-June 3, 2022, Nagasaki, Japan. ACM Asia Conference on Computer and Communications Security (17th : 2022 : Nagasaki-shi, Japan ; ...","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/1966913.1966969","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 70

摘要

在传统的访问控制系统中,安全管理员决定信息使用者是否可以访问某个资源。然而,在现实中,决策者很难预见用户在各种情况下可能需要什么信息。在医院里,没有授权医生获得她需要的关于病人的医疗信息可能会导致严重甚至致命的后果。在本文中,我们提出了一种实用的访问控制方法,以保护患者隐私在卫生信息系统中,考虑到现实医疗保健。首先,与传统的访问控制系统不同,我们提出的访问控制模型允许信息消费者(即医生)做出访问决策,同时仍然能够通过量化与医生数据访问活动相关的风险来检测和控制对患者医疗数据的过度访问。其次,我们不要求医生为了使用我们的系统而做任何特别的事情。我们学习医生之间的常见做法,并应用统计方法和信息论技术来量化隐私侵犯的风险。第三,我们的模型考虑了信息需求的偶尔例外,这在医疗保健中很常见。我们已经实现了解决方案的原型,并对现实世界的病史记录进行了模拟。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Quantified risk-adaptive access control for patient privacy protection in health information systems
In traditional access control systems, security administrators determine whether an information consumer can access a certain resource. However, in reality, it is very difficult for policy makers to foresee what information a user may need in various situations. In hospitals, failing to authorize a doctor for the medical information she needs about a patient could lead to severe or fatal consequences. In this paper, we propose a practical access control approach to protect patient privacy in health information systems by taking the realities in healthcare into consideration. First, unlike traditional access control systems, our proposed access control model allows information consumers (i.e. doctors) to make access decisions, while still being able to detect and control the over-accessing of patients' medical data by quantifying the risk associated with doctors' data-accessing activities. Second, we do not require doctors to do anything special in order to use our system. We learn about common practices among doctors and apply statistical methods and information theory techniques to quantify the risk of privacy violation. Third, occasional exceptions on information needs, which is common in healthcare, is taken into account in our model. We have implemented a prototype of our solution and performed simulations on real-world medical history records.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信