Abstract

In the healthcare field, preserving privacy of the patient's electronic health records has been an elementary issue. Numerous techniques have been emerged to maintain privacy of the susceptible information. Acting as a first line of defence against illegal access, traditional access control schemes fall short of defending against misbehaviour of the already genuine and authoritative users: a risk that can harbour overwhelming consequences upon probable data release or leak. This paper introduces a novel risk reduction strategy for the healthcare domain so that the risk related with an access request is evaluated against the privacy preferences of the patient who is undergoing for the medical procedure. The proposed strategy decides the set of data objects that can be safely uncovered to the healthcare service provider such that unreasonably repeated tests and measures can be avoided and the privacy preferences of the patient are preserved.

Highlights

  • This paper introduces a novel risk reduction strategy for the healthcare domain so that the risk related with an access request is evaluated against the privacy preferences of the patient who is undergoing for the medical procedure

  • A risk reduction technique is proposed to lower the risk associated with an access request initiated by a healthcare professional to a particular patient’s health record

  • Trust Calculation In order to assess the risk incurred of an access request, trust level of the requesting entity must be calculated and later it is evaluated in the other components

Read more

Summary

INTRODUCTION

Access control technique is one of the major processes for preserving privacy of the medical records. This technique is elementary security mechanism that works by assessing an access request against a set of constraints and rules before granting or denying such access to system resources (Stallings et al, (2014). Healthcare professionals can abuse their access rights with regards to patients’ private health records; which could increase the risk of potential leakage of the sensitive information. A risk reduction technique is proposed to lower the risk associated with an access request initiated by a healthcare professional to a particular patient’s health record.

PRELIMINARIES
Risk Assessment in Information Security
Risk-Aware Access Control Models
THE PROPOSED RISK REDUCTION STRATEGY
Disease Relevance Matrix
Patient Privacy Preferences
The Risk Measure Formula
The Risk Reduction Strategy
CONCLUSION
Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call