DocumentCode
153681
Title
Integrated Modeling and Analysis of Attribute Based Access Control Policies and Workflows in Healthcare
Author
Lakkaraju, Sandeep ; Dianxiang Xu
Author_Institution
Coll. of Bus. & Inf. Syst., Dakota State Univ., Madison, SD, USA
fYear
2014
fDate
9-10 June 2014
Firstpage
36
Lastpage
43
Abstract
Healthcare information systems deal with sensitive data across complex workflows. They often allow various stakeholders from different environments to access data across organizational boundaries. This elevates the risk of exposing sensitive healthcare information to unauthorized personnel. To prevent unwanted access to sensitive information, healthcare organizations need to adopt effective workflows and access control mechanisms. This research addresses this issue by developing a methodology for integrated modeling and analysis of organizational workflows and attribute-based access control policies. This methodology can help identify workflow activities that are not being protected by access control policies and improve existing access control policies. In addition to subjects, resources, and actions, our methodology introduces ´environment´ as a new element to workflow activity. This allows more contextual information to be associated with workflow activity for access control analysis.
Keywords
authorisation; health care; medical information systems; attribute based access control policy; healthcare information system; organizational workflow; Access control; Analytical models; Insurance; Medical diagnostic imaging; Medical services; Organizations;
fLanguage
English
Publisher
ieee
Conference_Titel
Trustworthy Systems and their Applications (TSA), 2014 International Conference on
Conference_Location
Taichung
Print_ISBN
978-1-4799-6565-6
Type
conf
DOI
10.1109/TSA.2014.15
Filename
6956709
Link To Document