{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:51:41Z","timestamp":1781106701206,"version":"3.54.1"},"reference-count":28,"publisher":"IGI Global Scientific Publishing","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012,4,1]]},"abstract":"<p>A central building block of data privacy is the individual right of information self-determination. Following from that when dealing with shared electronic health records (SEHR), citizens, as the identified individuals of such records, have to be enabled to decide what medical data can be used in which way by medical professionals. In this context individual preferences of privacy have to be reflected by authorization policies to control access to personal health data. There are two potential challenges when enabling patient-controlled access control policy authoring: First, an ordinary citizen neither can be considered a security expert, nor does she or he have the expertise to fully understand typical activities and workflows within the health-care domain. Thus, a citizen is not necessarily aware of implications her or his access control settings have with regards to the protection of personal health data. Both privacy of citizen\u2019s health-data and the overall effectiveness of a health-care information system are at risk if inadequate access control settings are in place. This paper refers to scenarios of a case study previously conducted and shows how privacy and information system effectiveness can be defined and evaluated in the context of SEHR. The paper describes an access control policy analysis method which evaluates a patient-administered access control policy by considering the mentioned evaluation criteria.<\/p>","DOI":"10.4018\/jcmam.2012040103","type":"journal-article","created":{"date-parts":[[2012,11,19]],"date-time":"2012-11-19T13:30:01Z","timestamp":1353331801000},"page":"43-62","source":"Crossref","is-referenced-by-count":0,"title":["Managing Privacy and Effectiveness of Patient-Administered Authorization Policies"],"prefix":"10.4018","volume":"3","author":[{"given":"Thomas","family":"Trojer","sequence":"first","affiliation":[{"name":"University of Innsbruck, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Basel","family":"Katt","sequence":"additional","affiliation":[{"name":"University of Innsbruck, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ruth","family":"Breu","sequence":"additional","affiliation":[{"name":"University of Innsbruck, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thomas","family":"Schabetsberger","sequence":"additional","affiliation":[{"name":"ITH-icoserve Technology for Healthcare, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Richard","family":"Mair","sequence":"additional","affiliation":[{"name":"ITH-icoserve Technology for Healthcare, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jcmam.2012040103-0","author":"I. B. M.Austria","year":"2006","journal-title":"Feasibility study for implementing the electronic health record (ELGA) in the Austrian health system"},{"key":"jcmam.2012040103-1","doi-asserted-by":"crossref","unstructured":"Bertino, E., Catania, B., Ferrari, E., & Perlasca, P. (2001). A logical framework for reasoning about access control models. In Proceedings of the Sixth ACM Symposium on Access Control Models and Technologies (pp. 41-52).","DOI":"10.1145\/373256.373261"},{"key":"jcmam.2012040103-2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijmedinf.2003.11.018"},{"key":"jcmam.2012040103-3","doi-asserted-by":"crossref","unstructured":"Brucker, A. D., & Petritsch, H. (2009). Extending access control models with break-glass. In Proceedings of the 14th ACM Symposium on Access Control Models and Technologies (pp. 197-206).","DOI":"10.1145\/1542207.1542239"},{"key":"jcmam.2012040103-4","doi-asserted-by":"crossref","unstructured":"Chadha, R. (2006). A cautionary note about policy conflict resolution. In Proceedings of the Military Communications Conference (pp. 1-8).","DOI":"10.1109\/MILCOM.2006.302500"},{"key":"jcmam.2012040103-5","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1253568"},{"key":"jcmam.2012040103-6","doi-asserted-by":"crossref","unstructured":"Damianou, N., Dulay, N., Lupu, E., & Sloman, M. (2001). The ponder policy specification language. In Proceedings of the International Workshop on Policies for Distributed Systems and Networks (pp. 18-38).","DOI":"10.1007\/3-540-44569-2_2"},{"key":"jcmam.2012040103-7","year":"1995","journal-title":"Directive 95\/46\/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data"},{"key":"jcmam.2012040103-8","doi-asserted-by":"crossref","unstructured":"Fong, P. W. (2012). Relationship-based access control: Protection model and policy language. In Proceedings of the First ACM Conference on Data and Application Security and Privacy (pp. 191-202).","DOI":"10.1145\/1943513.1943539"},{"key":"jcmam.2012040103-9","year":"2009","journal-title":"IT infrastructure access control"},{"key":"jcmam.2012040103-10","doi-asserted-by":"crossref","unstructured":"Karat, C., Karat, J., Brodie, C., & Feng, J. (2006). Evaluating interfaces for privacy policy rule authoring. In Proceedings of the SIGCHI Conference on Human Factors in Computing Systems (pp. 83-92).","DOI":"10.1145\/1124772.1124787"},{"key":"jcmam.2012040103-11","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2010.155"},{"key":"jcmam.2012040103-12","doi-asserted-by":"crossref","unstructured":"LeMay, M., Fatemieh, O., & Gunter, C. A. (2007). PolicyMorph: Interactive policy transformations for a logical attribute-based access control framework. In Proceedings of the 12th ACM Symposium on Access Control Models and Technologies (pp. 205-214).","DOI":"10.1145\/1266840.1266874"},{"key":"jcmam.2012040103-13","doi-asserted-by":"publisher","DOI":"10.1109\/32.824414"},{"key":"jcmam.2012040103-14","unstructured":"Massacci, F., Mylopoulos, J., & Zannone, N. (2006). A privacy model to support minimal disclosure in virtual organizations. In Proceedings of the W3C Workshop on Languages for Privacy Policy Negotiation and Semantics-Driven Enforcement."},{"key":"jcmam.2012040103-15","doi-asserted-by":"publisher","DOI":"10.1080\/10919399409540214"},{"key":"jcmam.2012040103-16","unstructured":"Moses, T. (2005). eXtensible Access Control Markup Language (XACML) Version 2.0.Retrieved fromhttp:\/\/docs.oasis-open.org\/xacml\/3.0\/xacml-3.0-core-spec-cd-1-en.html"},{"key":"jcmam.2012040103-17","doi-asserted-by":"crossref","unstructured":"Ni, Q., Trombetta, A., Bertino, E., & Lobo, J. (2007). Privacy-aware role based access control. In Proceedings of the 12th ACM Symposium on Access Control Models and Technologies (pp. 41-50).","DOI":"10.1145\/1266840.1266848"},{"key":"jcmam.2012040103-18","unstructured":"OASIS. (2005). Privacy policy profile of XACML v2.0. Retrieved from http:\/\/docs.oasis-open.org\/xacml\/2.0\/access_control-xacml-2.0-privacy_profile-spec-os.pdf"},{"key":"jcmam.2012040103-19","year":"1980","journal-title":"Guidelines on the protection of privacy and transborder flows of personal data"},{"key":"jcmam.2012040103-20","doi-asserted-by":"crossref","unstructured":"Reeder, R. W., Karat, C., Karat, J., & Brodie, C. (2007). Usability challenges in security and privacy policy--Authoring interfaces. In C. Baranauskas, P. Palanque, J. Abascal, & S. D. Barbosa (Eds.), Proceedings of the 11th IFIP TC 13 International Conference on Human-Computer Interaction (LNCS 4663, pp. 141-155).","DOI":"10.1007\/978-3-540-74800-7_11"},{"key":"jcmam.2012040103-21","doi-asserted-by":"crossref","unstructured":"R\u00f8stad, L. (2008). An initial model and a discussion of access control in patient controlled health records. In Proceedings of the Third International Conference on Availability, Reliability and Security (pp. 935-942).","DOI":"10.1109\/ARES.2008.185"},{"key":"jcmam.2012040103-22","doi-asserted-by":"publisher","DOI":"10.1145\/361011.361067"},{"key":"jcmam.2012040103-23","doi-asserted-by":"publisher","DOI":"10.1109\/2.485845"},{"key":"jcmam.2012040103-24","doi-asserted-by":"crossref","unstructured":"Trojer, T., Katt, B., Schabetsberger, T., Breu, R., & Mair, R. (2012). Considering privacy and effectiveness of authorization policies for shared electronic health records. In Proceedings of the 2nd ACM SIGHIT Symposium on International Health Informatics (pp. 553-562).","DOI":"10.1145\/2110363.2110425"},{"key":"jcmam.2012040103-25","doi-asserted-by":"crossref","unstructured":"Trojer, T., Katt, B., Schabetsberger, T., Mair, R., & Breu, R. (2011). The process of policy authoring of patient-controlled privacy preferences. In Proceedings of the 4th International Conference on Electronic Health (Vol. 91).","DOI":"10.1007\/978-3-642-29262-0_14"},{"key":"jcmam.2012040103-26","doi-asserted-by":"crossref","unstructured":"Wang, L., Wijesekera, D., & Jajodia, S. (2004). A logic-based framework for attribute based access control. In Proceedings of the 2nd ACM Workshop on Formal Methods in Security Engineering (pp. 45-55).","DOI":"10.1145\/1029133.1029140"},{"key":"jcmam.2012040103-27","author":"A.Westin","year":"1967","journal-title":"Privacy and freedom"}],"container-title":["International Journal of Computational Models and Algorithms in Medicine"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=72875","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T10:48:44Z","timestamp":1654080524000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jcmam.2012040103"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2012,4,1]]},"references-count":28,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2012,4]]}},"URL":"https:\/\/doi.org\/10.4018\/jcmam.2012040103","relation":{},"ISSN":["1947-3133","1947-3141"],"issn-type":[{"value":"1947-3133","type":"print"},{"value":"1947-3141","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,4,1]]}}}