PubMed Health⌕ Search

Biomedical subjects

Ragnar Nordberg

Publications and source records attributed to Ragnar Nordberg.

4 recordsLinked to original sources

EHR in the perspective of security, integrity and ethics.

Success stories of modern applications in healthcare and welfare, like the electronic health record, are always linked to end user awareness, confidence, and acceptance. Reports and surveys have given proof of these dependencies. Knowing about existing and emerging concerns and weaknesses right in advance allows to taking actions on an ethical, social, and societal level. This paper gives a review of specific observations regarding security, privacy, authentication, integrity and ethical aspects when operating an electronic health record (EHR) system in a hospital, an open care department and in a wider community of the health care sector. A reference is given to existing and emerging international standards related to the aforementioned aspects.

Authorship↗

Modelling privilege management and access control.

OBJECTIVES: For establishing trustworthiness in advanced architectures for future-proof health information systems being open, flexible, scaleable, portable, and semantically interoperable, security and privacy services needed must be designed as an inherent part of the architecture. Such architecture has to meet the paradigms of distribution, component orientation, formal modelling, separation of logical and technological aspects, etc. METHODS: In model-driven architectures components providing security and privacy services have to be specified using the same methodology of formal models with meta-languages as expression means, as deployed in computational, technical, or medical domains. The resulting approach must be based on the ISO Reference Model-Open Distributed Processing. RESULTS: Currently, standards developing organisation are defining emerging tasks and standards for semantic interoperability and trustworthy collaboration for advanced health information systems. Communication security issues have been specified and implemented, while application security challenges such as privilege management and access control are still under development. Therefore, a series of formal models have been developed by the authors covering, e.g. domains, service delegation, claims control, policies, roles, authorisations, and access control. The required models are introduced and interpreted in a generic way. The crucial concept of security policy and its relationship to the other concepts has been considered in detail. CONCLUSION: Based on formal models, security services can be integrated into advanced systems architectures enabling semantic interoperability in the context of trustworthiness of communication and co-operation.

Access to Information↗

Policy management and access control in practice.

This paper reflects how the combined CEN and ISO standard Privilege Management and Access Control (PMAC) Part 1 to 3 is intended to work. It also gives experiences from a test implementation.

Access to Information↗

Privilege management and access control in Shared Care IS and EHR.

Realising the shared care concept based on distributed health information systems, we have to meet the challenge for advanced security and privacy based on a Public Key Infrastructure (PKI) Beside strong authentication, authorisation of principals and access control using role concepts and security object classification schemes are essential application security services. The paper presents the actual drafts of ISO and CEN standards dealing with privilege management and access control.

Access to Information↗