Abstract
Authorisation is a compulsory function in information systems that contain patient data. The proposed authorisation model is a refinement of a role-based content-dependent authorisation model. The access permissions are inferred from authorisation rules based on the role of the health care consultant, the association of the consultant with the patient, the security level and the state of the information object within the life-cycle. The design of the system is based on a three-level access control, and a combination of the existing information system with an expert database system.
The author is indebted to P. Verpalen, coauthor of a previous paper, and to B.E. Voeten and H.M. Blanken, University of Twente, Enschede, The Netherlands, for their valuable contribution.
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Bertino, E., Weigand, H.: An approach to authorization modeling in object-oriented database systems. Data & Knowledge Engineering 12(1994) 1–29
Date, C.J., Darwen, H.: Relational Database Writings 1989–1991. Addison-Wesley (1992)
Dick, R.S., Steen, E.B., editors: The Computer-Based Patient record: An Essential Technology for Health Care. Institute of Medicine, National Academy Press (1991)
Khair, M., Pangalos, G., Andria, F., Bozios, L.: Implementing security on a proto-type hospital database. In Pappas, C. et al., editors: Medical Informatics Europe 97, IOS Press (1997) 176–180
Missiko, M., Wiederhold, G.: Towards a unified approach for expert and database systems. In Kerschberg, L. editor: Expert Database Systems, Benjamin Cummings (1986) 383–399
Vassilacopoulos, G., Peppes, D. A front end authorization mechanism for hospital information systems. Medical Informatics 21 (1996) 93–103
Verpalen, P., O, Y.-L.: Definable confidentiality of information in patient records. In Harnu, A., editor: Proceedings of the 8th European Health Record Conference, NVMA (1995) 311–318
Voeten, B.E.: Content-dependent authorisation for a patient hospital information system. Master’s thesis, University of Twente, The Netherlands (1996)
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 1999 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
O, YL. (1999). A Life-Cycle Based Authorisation Expert Database System. In: Horn, W., Shahar, Y., Lindberg, G., Andreassen, S., Wyatt, J. (eds) Artificial Intelligence in Medicine. AIMDM 1999. Lecture Notes in Computer Science(), vol 1620. Springer, Berlin, Heidelberg. https://doi.org/10.1007/3-540-48720-4_16
Download citation
DOI: https://doi.org/10.1007/3-540-48720-4_16
Published:
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-66162-7
Online ISBN: 978-3-540-48720-3
eBook Packages: Springer Book Archive