{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T05:02:46Z","timestamp":1784869366454,"version":"3.55.0"},"reference-count":37,"publisher":"Springer Science and Business Media LLC","issue":"7-8","license":[{"start":{"date-parts":[[2026,1,22]],"date-time":"2026-01-22T00:00:00Z","timestamp":1769040000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,22]],"date-time":"2026-01-22T00:00:00Z","timestamp":1769040000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Ann. Telecommun."],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1007\/s12243-026-01152-1","type":"journal-article","created":{"date-parts":[[2026,1,22]],"date-time":"2026-01-22T07:13:04Z","timestamp":1769065984000},"page":"509-533","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Towards a formal framework for blockchain-based access control in e-health systems"],"prefix":"10.1007","volume":"81","author":[{"given":"Aida","family":"Ben Chehida Douss","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ryma","family":"Abassi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,1,22]]},"reference":[{"issue":"1","key":"1152_CR1","first-page":"5","volume":"12","author":"W Raghupathi","year":"2024","unstructured":"Raghupathi W, Raghupathi V (2024) Big data analytics in healthcare: promise and potential. Health Inf Sci Syst 12(1):5","journal-title":"Health Inf Sci Syst"},{"issue":"2","key":"1152_CR2","first-page":"102","volume":"7","author":"N Khan","year":"2025","unstructured":"Khan N, McDaniel P (2025) Challenges in healthcare data management: privacy, security, and regulatory compliance. J Healthcare Inf Res 7(2):102\u2013120","journal-title":"J Healthcare Inf Res"},{"issue":"1","key":"1152_CR3","first-page":"50","volume":"11","author":"T Alam","year":"2025","unstructured":"Alam T, Sengupta S (2025) Secure e-health systems: managing privacy and compliance in multi-stakeholder environments. IEEE Trans Emerging Top Comput 11(1):50\u201363","journal-title":"IEEE Trans Emerging Top Comput"},{"key":"1152_CR4","first-page":"150234","volume":"11","author":"A Singh","year":"2023","unstructured":"Singh A, Kim T (2023) Limitations of traditional access control in healthcare and the potential of blockchain. IEEE Access 11:150234\u2013150247","journal-title":"IEEE Access"},{"issue":"2","key":"1152_CR5","first-page":"38","volume":"29","author":"RS Sandhu","year":"1996","unstructured":"Sandhu RS, Coyne EJ, Feinstein HL, Youman CE (1996) Role-based access control models IEEE Comput 29(2):38\u201347","journal-title":"Role-based access control models IEEE Comput"},{"key":"1152_CR6","doi-asserted-by":"crossref","unstructured":"Hu VC, Ferraiolo D, Kuhn DR, Schnitzer A, Sandlin K, Miller R, Scarfone K (2014) Guide to attribute based access control (ABAC) definition and considerations. Special publication 800-162, NIST","DOI":"10.6028\/NIST.SP.800-162"},{"key":"1152_CR7","doi-asserted-by":"publisher","unstructured":"Alruwaill MN, Mohanty SP, Kougianos E (2025) hChain 4.0: A secure and scalable permissioned blockchain for EHR management in smart healthcare. https:\/\/doi.org\/10.48550\/arXiv.2505.13861","DOI":"10.48550\/arXiv.2505.13861"},{"issue":"17","key":"1152_CR8","doi-asserted-by":"publisher","first-page":"23567","DOI":"10.1007\/s11042-022-12674-w","volume":"81","author":"SK Kavuri","year":"2022","unstructured":"Kavuri SK, Sree TK (2022) AB-DAM: attribute-based data access model in blockchain for healthcare applications. Multimedia Tools Appl 81(17):23567\u201323588. https:\/\/doi.org\/10.1007\/s11042-022-12674-w","journal-title":"Multimedia Tools Appl"},{"key":"1152_CR9","unstructured":"Al Amin M, Tummala H, Mohan S, Ray I (2023) Healthcare policy compliance: a blockchain smart contract-based approach. arXiv:2312.10214"},{"key":"1152_CR10","doi-asserted-by":"publisher","unstructured":"Pu X, Jiang R, Song Z, Liang Z, Yang L (2024) A medical big data access control model based on smart contracts and risk in the blockchain environment. Front Public Health 12. https:\/\/doi.org\/10.3389\/fpubh.2024.1358184","DOI":"10.3389\/fpubh.2024.1358184"},{"key":"1152_CR11","doi-asserted-by":"publisher","unstructured":"Psarra E, Apostolou D, Verginadis Y, al, (2024) Permissioned blockchain network for proactive access control to electronic health records. BMC Med Inform Decis Mak 24:303. https:\/\/doi.org\/10.1186\/s12911-024-02708-8","DOI":"10.1186\/s12911-024-02708-8"},{"issue":"4","key":"1152_CR12","doi-asserted-by":"publisher","first-page":"98","DOI":"10.3390\/informatics11040098","volume":"11","author":"T Guimar\u00e3es","year":"2024","unstructured":"Guimar\u00e3es T, Duarte R, Hak F, Santos M (2024) Context-aware electronic health record\u2013internet of things and blockchain approach. Informatics 11(4):98. https:\/\/doi.org\/10.3390\/informatics11040098","journal-title":"Informatics"},{"issue":"3","key":"1152_CR13","doi-asserted-by":"publisher","first-page":"219","DOI":"10.3390\/info16030219","volume":"16","author":"A Alabdulatif","year":"2025","unstructured":"Alabdulatif A (2025) Blockchain-based privacy-preserving authentication and access control model for e-health users. Information 16(3):219. https:\/\/doi.org\/10.3390\/info16030219","journal-title":"Information"},{"key":"1152_CR14","doi-asserted-by":"crossref","unstructured":"Rivera V (2020) Formal verification of access control model for my health record system. In: 2020 25th International conference on engineering of complex computer systems (ICECCS), pp 21\u201330","DOI":"10.1109\/ICECCS51672.2020.00010"},{"key":"1152_CR15","doi-asserted-by":"publisher","first-page":"1303","DOI":"10.1007\/978-3-030-44041-1_111","volume-title":"Advanced Information Networking and Applications","author":"A Lahbib","year":"2020","unstructured":"Lahbib A, Ait Wakrime A, Laouiti A, Toumi K, Martin S (2020) An event-b based approach for formal modelling and verification of smart contracts. In: Barolli L, Amato F, Moscato F, Enokido T, Takizawa M (eds) Advanced Information Networking and Applications. Springer, pp 1303\u20131318"},{"key":"1152_CR16","unstructured":"Gkoulalas-Divanis A, Loukides G (2022) Anonymization techniques for health data. In: Health data privacy handbook, pp 39\u201375. Springer,"},{"issue":"1","key":"1152_CR17","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1049\/blc2.12058","volume":"1","author":"S Zorlu","year":"2020","unstructured":"Zorlu S (2020) Blockchain privacy: fundamental aspects and challenges for the future internet data sharing. IET Blockchain 1(1):1\u201312. https:\/\/doi.org\/10.1049\/blc2.12058","journal-title":"IET Blockchain"},{"key":"1152_CR18","unstructured":"European Union (2016) General Data Protection Regulation (GDPR) \u2013 Article 15: right of access by the data subject. Official Journal of the European Union, L119, 1\u201388. Accessed: 30 May 2025. https:\/\/gdpr-info.eu\/art-15-gdpr\/"},{"key":"1152_CR19","unstructured":"U.S. Department of Health and Human Services (2003) HIPAA privacy rule \u2013 \u00a7164.524: access of individuals to protected health information. Code of Federal Regulations (45 CFR \u00a7164.524). Accessed: 30 May 2025. https:\/\/www.ecfr.gov\/current\/title-45\/subtitle-A\/subchapter-C\/part-164\/subpart-E\/section-164.524"},{"key":"1152_CR20","unstructured":"European Union (2016) General Data Protection Regulation (GDPR) \u2013 Article 6(1)(a): lawfulness of processing \u2013 consent. Official Journal of the European Union, L119, 1\u201388. Accessed: 30 May 2025. https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/article\/6\/oj"},{"key":"1152_CR21","unstructured":"U.S. Department of Health and Human Services (2003) HIPAA \u2013 \u00a7164.502(g): uses and disclosures to personal representatives. Code of Federal Regulations (45 CFR \u00a7164.502(g)). Accessed: 30 May 2025. https:\/\/www.ecfr.gov\/current\/title-45\/subtitle-A\/subchapter-C\/part-164\/subpart-E\/section-164.502"},{"key":"1152_CR22","unstructured":"European Union (2016) General Data Protection Regulation (GDPR) \u2013 Article 6(1)(b): lawfulness of processing \u2013 contract necessity. Official Journal of the European Union, L119, 1\u201388. Accessed: 30 May 2025. https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/article\/6\/oj"},{"key":"1152_CR23","unstructured":"European Union (2016) General Data Protection Regulation (GDPR) \u2013 Article 5(1)(c): data minimization. Official Journal of the European Union, L119, 1\u201388. Accessed: 30 May 2025. https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/article\/5\/oj"},{"key":"1152_CR24","unstructured":"U.S. Department of Health and Human Services (2003) HIPAA \u2013 \u00a7164.502(b): minimum necessary standard. Code of Federal Regulations (45 CFR \u00a7164.502(b)). Accessed: 30 May 2025. https:\/\/www.ecfr.gov\/current\/title-45\/subtitle-A\/subchapter-C\/part-164\/subpart-E\/section-164.502"},{"key":"1152_CR25","unstructured":"U.S. Department of Health and Human Services (2003) HIPAA \u2013 \u00a7164.506: uses and disclosures for treatment, payment, and healthcare operations. Code of Federal Regulations (45 CFR \u00a7164.506). Accessed: 30 May 2025. https:\/\/www.ecfr.gov\/current\/title-45\/subtitle-A\/subchapter-C\/part-164\/subpart-E\/section-164.506"},{"key":"1152_CR26","unstructured":"European Union (2016) General Data Protection Regulation (GDPR) \u2013 Recital 26: not applicable to anonymized data. Official Journal of the European Union, L119, 1\u201388. Accessed: 30 May 2025. https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj"},{"key":"1152_CR27","unstructured":"U.S. Department of Health and Human Services (2003) HIPAA \u2013 \u00a7164.512(i): disclosures for research purposes. Code of Federal Regulations (45 CFR \u00a7164.512(i)). Accessed: 30 May 2025. https:\/\/www.ecfr.gov\/current\/title-45\/subtitle-A\/subchapter-C\/part-164\/subpart-E\/section-164.512"},{"key":"1152_CR28","unstructured":"European Union (2016) General Data Protection Regulation (GDPR) \u2013 Article 6(1)(c): lawfulness of processing \u2013 legal obligation. Official Journal of the European Union, L119, 1\u201388. Accessed: 30 May 2025. https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/article\/6\/oj"},{"key":"1152_CR29","unstructured":"U.S. Department of Health and Human Services (2003) HIPAA \u2013 \u00a7164.512(e): disclosures for judicial and administrative proceedings. Code of Federal Regulations (45 CFR \u00a7164.512(e)). Accessed: 30 May 2025. https:\/\/www.ecfr.gov\/current\/title-45\/subtitle-A\/subchapter-C\/part-164\/subpart-E\/section-164.512"},{"key":"1152_CR30","unstructured":"European Union (2016) General Data Protection Regulation (GDPR) \u2013 Article 6(1)(f): lawfulness of processing \u2013 legitimate interests. Official Journal of the European Union, L119, 1\u201388. Accessed: 30 May 2025. https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/article\/6\/oj"},{"key":"1152_CR31","unstructured":"U.S. Department of Health and Human Services (2003) HIPAA \u2013 \u00a7164.506(c): use and disclosure for treatment purposes. Code of Federal Regulations (45 CFR \u00a7164.506(c)). Accessed: 30 May 2025. https:\/\/www.ecfr.gov\/current\/title-45\/subtitle-A\/subchapter-C\/part-164\/subpart-E\/section-164.506"},{"key":"1152_CR32","unstructured":"U.S. Department of Health and Human Services (2003) HIPAA \u2013 \u00a7164.506(b): use and disclosure for healthcare operations. Code of Federal Regulations (45 CFR \u00a7164.506(b)). Accessed: 30 May 2025. https:\/\/www.ecfr.gov\/current\/title-45\/subtitle-A\/subchapter-C\/part-164\/subpart-E\/section-164.506"},{"key":"1152_CR33","unstructured":"U.S. Department of Health and Human Services (2003) HIPAA \u2013 \u00a7164.514(d): minimum necessary standard. Code of Federal Regulations (45 CFR \u00a7164.514(d)). Accessed: 30 May 2025. https:\/\/www.ecfr.gov\/current\/title-45\/subtitle-A\/subchapter-C\/part-164\/subpart-E\/section-164.514"},{"key":"1152_CR34","unstructured":"U.S. Department of Health and Human Services (2003) HIPAA \u2013 \u00a7164.514(e): use and disclosure for research purposes. Code of Federal Regulations (45 CFR \u00a7164.514(e)). Accessed: 30 May 2025. https:\/\/www.ecfr.gov\/current\/title-45\/subtitle-A\/subchapter-C\/part-164\/subpart-E\/section-164.514"},{"key":"1152_CR35","first-page":"1","volume":"L119","author":"E Union","year":"2016","unstructured":"Union E (2016) GDPR - Article 5(1)(b): purpose limitation. Off J Eur Union L119:1\u201388","journal-title":"Off J Eur Union"},{"key":"1152_CR36","unstructured":"European Union (2016) General Data Protection Regulation (GDPR) \u2013 Article 5(1)(e): storage limitation (related to operational necessity). Official Journal of the European Union, L119, 1\u201388. Accessed: 30 May 2025. https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/article\/5\/oj"},{"key":"1152_CR37","unstructured":"European Union (2016) General Data Protection Regulation (GDPR) \u2013 Article 89: safeguards and derogations relating to processing for archiving, research and statistical purposes. Official Journal of the European Union, L119, 1\u201388. Accessed: 30 May 2025. https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/article\/89\/oj"}],"container-title":["Annals of Telecommunications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s12243-026-01152-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s12243-026-01152-1","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s12243-026-01152-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T04:31:50Z","timestamp":1784867510000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s12243-026-01152-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1,22]]},"references-count":37,"journal-issue":{"issue":"7-8","published-print":{"date-parts":[[2026,8]]}},"alternative-id":["1152"],"URL":"https:\/\/doi.org\/10.1007\/s12243-026-01152-1","relation":{},"ISSN":["0003-4347","1958-9395"],"issn-type":[{"value":"0003-4347","type":"print"},{"value":"1958-9395","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1,22]]},"assertion":[{"value":"2 June 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 January 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 January 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare no competing interests.","order":1,"name":"Ethics","label":"Competing interests","group":{"name":"EthicsHeading","label":"Declarations"}}]}}