Vis enkel innførsel

dc.contributor.authorHystad, Rune
dc.date.accessioned2014-09-29T10:44:00Z
dc.date.available2014-09-29T10:44:00Z
dc.date.issued2014
dc.identifier.urihttp://hdl.handle.net/11250/221988
dc.descriptionMasteroppgave i helse- og sosialinformatikk HSI 500 Universitetet Agder 2014nb_NO
dc.description.abstractIn health care, access to sensitive information about patients is a necessity in order to offer care to the patient, and maintain patient safety. At the same time it is important that the information is protected against unauthorized access, to ensure patient privacy. Access control is an essential function in electronic health records (EHR) to maintain the duality between patient safety and patient privacy by ensuring that authorized personnel are allowed access to information they need. However, care processes are often unpredictable, and a number of end users can be involved in treatment across organizational units in the same health enterprise. As a consequence, it is hard to implement strict access control rules, and exception mechanisms must be used. In the specialist care, role based access control (RBAC) is mainly used as access control model, and it has since 2001 been a requirement in Norway that access control in EHR must be given on the basis of decisions about health care, so called decision based access. Within few years, this will be used in all Norwegian health enterprises. Literature shows a number of challenges with access control in EHR, but empirical data on experiences with the use and setup of decision based access, is almost nonexistent. The purpose of this study was therefore to identify what the end users and system administrators are experiencing as the most important challenges using decision based access, and what they consider important factors for the improvement of the access control. To answer this, a Delphi survey was conducted, and it is taken out reports from an EHR database. The survey and reports show that a number of challenges that have been identified in previous studies are still present. The access control is not sufficiently tailored to treatment processes, and extensive use of exception mechanisms is necessary to protect patient safety, which generates long event records that are not followed up systematically, and therefore may go at the expense of patient privacy. Possible improvements of the challenges uncovered include more education, standardization of access control, easier use of exception mechanisms and a more process oriented access control. Keywords Access Control, Delphi, Electronic Health Records, Information security, Patient safetynb_NO
dc.language.isonobnb_NO
dc.publisherUniversitetet i Agder ; University of Agdernb_NO
dc.subjecthsi500nb_NO
dc.subjectTilgangsstyring ; Tilgangskontroll, Delphi ; Elektronisk pasientjournal ; Informasjonssikkerhet ; Spesialisthelsetjeneste ; Pasientsikkerhet ; Access Control ; Delphi ; Electronic Health Records ; Information security ; Patient safetynb_NO
dc.titleTilgangsstyring av elektronisk pasientjournal : en Delphistudie av dagens utfordringer og synliggjøring av potensielle forbedringernb_NO
dc.typeMaster thesisnb_NO
dc.subject.nsiVDP::Technology: 500::Information and communication technology: 550nb_NO
dc.source.pagenumber117 s.nb_NO


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel