A security framework for XML schemas and documents for healthcare

Alberto De La Rosa Algarin, Steven A. Demurjian, Solomon Berhe, Jaime A. Pavlich-Mariscal

Producción: Capítulo del libro/informe/acta de congresoContribución a la conferenciarevisión exhaustiva

24 Citas (Scopus)

Resumen

The extensible Markup Language (XML) has wide usage in healthcare to facilitate health information exchange via the Continuity of Care Record (CCR) for storing/managing patient data, diagnoses, medical notes, tests, scans, etc. Health IT products like electronic health record (EHR, e.g., GE Centricity) and personal health record (PHR, e.g., MS Health Vault) use CCR for data representation. To manage patient data in CCR, security as governed by HTPAA must be attained when using XML and its technologies (XACML, XSLT, etc.). Our objective is to have an XML document (CCR instance) appear differently to authorized users at different times based on a user's role, constraints, separation of duty, delegation of authority, etc. In this paper, we propose a security framework that targets XML schémas and documents, in general, and CCR schémas and documents, in particular with control capabilities that achieve customizable access to an XML document's elements by applying secure software engineering methodologies and defining new UML XML-focused diagrams for schémas and permissions. This allows us to generate XACML policies, and enforce security at the runtime level on XML instances to insure that correct and required patient data is securely delivered. In a market of rapidly emerging mobile healthcare applications to allow patients to manage their own data (PHRs) and for self-management of chronic diseases, the need for secure access to information and its authorization and transmission to providers (and EHRs) will be critical.

Idioma originalInglés
Título de la publicación alojadaProceedings - 2012 IEEE International Conference on Bioinformatics and Biomedicine Workshops, BIBMW 2012
Páginas782-789
Número de páginas8
DOI
EstadoPublicada - 2012
Evento2012 IEEE International Conference on Bioinformatics and Biomedicine Workshops, BIBMW 2012 - Philadelphia, PA, Estados Unidos
Duración: 04 oct. 201207 oct. 2012

Serie de la publicación

NombreProceedings - 2012 IEEE International Conference on Bioinformatics and Biomedicine Workshops, BIBMW 2012

Conferencia

Conferencia2012 IEEE International Conference on Bioinformatics and Biomedicine Workshops, BIBMW 2012
País/TerritorioEstados Unidos
CiudadPhiladelphia, PA
Período04/10/1207/10/12

Huella

Profundice en los temas de investigación de 'A security framework for XML schemas and documents for healthcare'. En conjunto forman una huella única.

Citar esto