Reference Hub18
Health Insurance Portability and Accountability Act (HIPPA) Compliant Access Control Model for Web Services

Health Insurance Portability and Accountability Act (HIPPA) Compliant Access Control Model for Web Services

Vivying S.Y. Cheng, Patrick C.K. Hung
Copyright: © 2006 |Volume: 1 |Issue: 1 |Pages: 18
ISSN: 1555-3396|EISSN: 1555-340X|ISSN: 1555-3396|EISBN13: 9781615203024|EISSN: 1555-340X|DOI: 10.4018/jhisi.2006010102
Cite Article Cite Article

MLA

Cheng, Vivying S.Y., and Patrick C.K. Hung. "Health Insurance Portability and Accountability Act (HIPPA) Compliant Access Control Model for Web Services." IJHISI vol.1, no.1 2006: pp.22-39. http://doi.org/10.4018/jhisi.2006010102

APA

Cheng, V. S. & Hung, P. C. (2006). Health Insurance Portability and Accountability Act (HIPPA) Compliant Access Control Model for Web Services. International Journal of Healthcare Information Systems and Informatics (IJHISI), 1(1), 22-39. http://doi.org/10.4018/jhisi.2006010102

Chicago

Cheng, Vivying S.Y., and Patrick C.K. Hung. "Health Insurance Portability and Accountability Act (HIPPA) Compliant Access Control Model for Web Services," International Journal of Healthcare Information Systems and Informatics (IJHISI) 1, no.1: 22-39. http://doi.org/10.4018/jhisi.2006010102

Export Reference

Mendeley
Favorite Full-Issue Download

Abstract

Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a set of rules to be followed by health plans, doctors, hospitals, and other healthcare providers in the U.S. HIPAA privacy rules create national standards to protect individuals’ health information. Recently, there have been increasing demands and discussions about Web services-based healthcare applications. It is, therefore, necessary for HIPAA privacy rules to be standardized in Web services. However, so far no comprehensive solutions to the various privacy issues have been defined in this area. This paper summarizes the HIPAA privacy rules and surveys the topic of protecting health data privacy under the HIPAA. We propose a vocabulary-based Web services privacy framework with Role-based Access Control (RBAC) with privacy extensions and argue the HIPAA compliance for such framework. For illustration, we present the first two HIPAA rules in the extended RBAC model and embed into the HIPAA-compliant technical architecture for implementation of Web services.

Request Access

You do not own this content. Please login to recommend this title to your institution's librarian or purchase it from the IGI Global bookstore.