Privacy Preserving For Patients' Information: A Knowledge-Constrained Access Control Model For Hospital Information Systems

Runtong Zhang,Donghua Chen,Xiaopu Shang
DOI: https://doi.org/10.1109/INDIN.2016.7819293
2016-01-01
Abstract:Access control is an important technical method to protect the sensitive data in the information system. This paper mainly focuses on the issue of privacy preserving for patients' information in HIS. On the basis of providing hospital employees necessary patient information that can support the treatment, the proposed Knowledge-Constrained Role Based Access Control (KC-RBAC) model tries to reduce the scope of patients' information that can be accessed by hospital employees. Compared with the traditional RBAC model, the medical knowledge and nonmedical knowledge lying in the process of treatment are introduced into KC-RBAC, which outline the boundary of accessible data for different users in the system.
What problem does this paper attempt to address?