The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

A Multi-policy Framework for Mitigating Insider Threat in Healthcare Domain

Author

Zahid Pervaiz

Tech report number

CERIAS TR 2013-14

Entry type

phdthesis

Abstract

Access control policies in healthcare domain define permissions for users to access different medical records. Role Based Access Control (RBAC) helps to restrict medical records to users in a certain role but sensitive information in medical records can still be compromised by authorized insiders. The disclosure of sensitive medical information can create embarrassing situation for a patient or even cause discrimination based on medical ailment. The threat is from users who are not treating the patient but have access to medical records. We propose selective combination of policies where sensitive records are only available to primary doctor under Discretionary Access Control (DAC) and he may share it for consultation after permission from patient. This helps not only better compliance of principle of least privilege but also helps to mitigate the threat of authorized insiders disclosing sensitive patient information. We use Policy Machine (PM) proposed by National Institute of Standards and Technology (NIST) to combine policies and develop a flexible healthcare access control policy which has benefits of context awareness and discretionary access. We have implemented temporal constraints for RBAC in PM and after combination of Generalized Temporal Role Based Access Control (GTRBAC) and DAC, an example healthcare scenario has been established. ^

Date

2013 – 8 – 6

Key alpha

Pervaiz

School

Purdue University

Publication Date

2013-08-06

Location

A hard-copy of this is in REC 216

BibTex-formatted data

To refer to this entry, you may select and copy the text below and paste it into your BibTex document. Note that the text may not contain all macros that BibTex supports.