DocumentCode
3722477
Title
Access Control for Multi-tenancy in Cloud-Based Health Information Systems
Author
Mohd Anwar;Ashiq Imran
Author_Institution
Dept. of Comput. Sci., North Carolina A&
fYear
2015
Firstpage
104
Lastpage
110
Abstract
Cloud technology can be used to support costeffective, scalable, and well-managed healthcare information systems. However, cloud computing, particularly multitenancy, introduces privacy and security issues related to personal health information (PHI). In this paper, we designed ontological models for healthcare workflow and multi-tenancy, and then applied HIPAA requirements on the models to generate HIPAA-compliant access control policies. We used Semantic Web Rule Language (SWRL) to represent access control policies as rules, and we verified the rules with an OWL-DL reasoner. Additionally, we implemented HIPAA security rules through access control policies in a cloud-based simulated healthcare environment. More specifically, we investigated access control policy specification and enforcement for cloud based healthcare information systems using an open source cloud platform, OpenStack. The results manifest HIPAA compliance through authorization policies that are capable of addressing vulnerabilities of multi-tenancy.
Keywords
"Access control","Medical services","Cloud computing","Ontologies","Insurance","Databases"
Publisher
ieee
Conference_Titel
Cyber Security and Cloud Computing (CSCloud), 2015 IEEE 2nd International Conference on
Type
conf
DOI
10.1109/CSCloud.2015.95
Filename
7371467
Link To Document