The advances in computing and communication technologies are allowing an incremental number of access to the Electronic Patient Record (EPR) information. However, to enable clinical information on computer networks claims to be careful about patients privacy and data integrity and confidentiality. The access control mechanisms are a key point to maintain these system requirements. In general, only the patient and his doctor are authorized to access the EPR, except when the access is necessary to provide care on patient behalf. Further, on a hospital environment also the context (time, location, attributes, and so one) could be considered. This paper proposes a context-based access control model (CBAC), that works by considering the context of properties in access time and allows the context relations before setting an authorization. This feature enables the implementation of complex access policies that demand separation of duties and delegation.
|