{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:47:18Z","timestamp":1781110038887,"version":"3.54.1"},"reference-count":26,"publisher":"IGI Global Scientific Publishing","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,4]]},"abstract":"<jats:p>Many initiatives exist that integrate e-health systems on a large scale. One of the main technical challenges is access control, although several frameworks and solutions, like XACML, are becoming standard practice. Data is no longer shared within one affinity domain but becomes ubiquitous, which results in a loss of control. As patients will be less willing to participate without additional control strategies, patient consents are introduced that allow the patients to determine precise access rules on their medical data. This paper explores the consequences of integrating consent in e-health access control. First, consent requirements are examined, after which an architecture is proposed which incorporates patient consent in the access control service of an e-health system. To validate the proposed concepts, a proof-of-concept implementation is built and evaluated.<\/jats:p>","DOI":"10.4018\/jsse.2011040101","type":"journal-article","created":{"date-parts":[[2011,10,19]],"date-time":"2011-10-19T12:46:17Z","timestamp":1319028377000},"page":"1-24","source":"Crossref","is-referenced-by-count":6,"title":["Integrating Patient Consent in e-Health Access Control"],"prefix":"10.4018","volume":"2","author":[{"given":"Kim","family":"Wuyts","sequence":"first","affiliation":[{"name":"Katholieke Universiteit Leuven, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Riccardo","family":"Scandariato","sequence":"additional","affiliation":[{"name":"Katholieke Universiteit Leuven, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Griet","family":"Verhenneman","sequence":"additional","affiliation":[{"name":"Katholieke Universiteit Leuven, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wouter","family":"Joosen","sequence":"additional","affiliation":[{"name":"Katholieke Universiteit Leuven, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jsse.2011040101-0","doi-asserted-by":"crossref","unstructured":"Al-Kahtani, M. A., & Sandhu, R. (2003). Induced role hierarchies with attribute-based RBAC. In Proceedings of the 8th ACM Symposium on Access Control Models and Technologies (pp. 142-148).","DOI":"10.1145\/775412.775430"},{"key":"jsse.2011040101-1","doi-asserted-by":"crossref","unstructured":"Anderson, R. J. (1996). A security policy model for clinical information systems. In Proceedings of the IEEE Symposium on Security and Privacy (pp. 30-43). Washington, DC: IEEE Computer Society.","DOI":"10.1109\/SECPRI.1996.502667"},{"key":"jsse.2011040101-2","doi-asserted-by":"crossref","unstructured":"Barkley, J., Beznosov, K., & Uppal, J. (1999). Supporting relationships in access control using role based access control. In Proceedings of the Fourth ACM Workshop on Role-Based Access Control (pp. 55-65).","DOI":"10.1145\/319171.319177"},{"key":"jsse.2011040101-3","doi-asserted-by":"crossref","unstructured":"Becker, M. Y., & Sewell, P. (2004). Cassandra: Flexible trust management, applied to electronic health records. In Proceedings of the 17th IEEE Workshop on Computer Security Foundations (p. 139). Washington, DC: IEEE Computer Society.","DOI":"10.1109\/CSFW.2004.1310738"},{"key":"jsse.2011040101-4","doi-asserted-by":"publisher","DOI":"10.1197\/jamia.M1480"},{"key":"jsse.2011040101-5","unstructured":"European Communities. (1995). Directive 95\/46\/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data. Retrieved from http:\/\/old.cdt.org\/privacy\/eudirective\/EU_Directive_.html"},{"key":"jsse.2011040101-6","unstructured":"Goovaerts, T. (2011). Distributed authorization middleware for service-oriented architectures. Unpublished doctoral dissertation, Katholieke Universiteit Leuven, Leuven, Belgium."},{"key":"jsse.2011040101-7","unstructured":"International, I. H. E. (2010). IHE integration profiles, revision 7.0, technical framework volume 1. Retrieved from http:\/\/www.ihe.net\/Technical_Framework\/"},{"key":"jsse.2011040101-8","doi-asserted-by":"crossref","unstructured":"Jin, J., Ahn, G. J., Hu, H., Covington, M. J., & Zhang, X. (2009). Patient-centric authorization framework for sharing electronic health records. In Proceedings of the 14th ACM Symposium on Access Control Models and Technologies (pp. 125-134).","DOI":"10.1145\/1542207.1542228"},{"key":"jsse.2011040101-9","unstructured":"Katt, B., Breu, R., Hafner, M., Schabetsberger, T., Mair, R., & Wozak, F. (2008). Privacy and access control for IHE-based systems. In Proceedings of the 1st International Conference on Electronic Healthcare in the 21st Century."},{"key":"jsse.2011040101-10","unstructured":"King, G., Bauer, C., Andersen, M. R., Bernard, E., Ebersole, S., & Ferentschik, H. (2011). Hibernate reference documentation 3.6.1. final. Retrieved from http:\/\/www.hibernate.org\/"},{"key":"jsse.2011040101-11","doi-asserted-by":"crossref","unstructured":"Liu, A. X., Chen, F., Hwang, J., & Xie, T. (2008). Xengine: A fast and scalable XACML policy evaluation engine. In Proceedings of the ACM SIGMETRICS International Conference on Measurement and Modeling of Computer Systems (pp. 265-276).","DOI":"10.1145\/1375457.1375488"},{"key":"jsse.2011040101-12","doi-asserted-by":"crossref","unstructured":"Marouf, S., Shehab, M., Squicciarini, A., & Sundareswaran, S. (2009). Statistics & clustering based framework for efficient XACML policy evaluation. In Proceedings of the 10th IEEE International Conference on Policies for Distributed Systems and Networks (pp. 118-125). Washington, DC: IEEE Computer Society.","DOI":"10.1109\/POLICY.2009.36"},{"key":"jsse.2011040101-13","unstructured":"Microsoft. (2009). Connected health framework architecture and design blueprint, part 3 - technical framework. Retrieved from http:\/\/www.interoperabilityshowcase.com\/himss10\/ docs\/himss09examples\/HIMSS09LeadershipWhitePaper-Microsoft.pdf"},{"key":"jsse.2011040101-14","unstructured":"Moses, T. (2005). eXtensible access control markup language version 2.0, specifications document. Retrieved from http:\/\/www.oasis-open.org\/committees\/tc_home.php?wg_abbrev=xacml"},{"key":"jsse.2011040101-15","unstructured":"News, B. B. C. (2009). Facebook faces criticism on privacy change. Retrieved from http:\/\/news.bbc.co.uk\/2\/hi\/technology\/8405334.stm"},{"key":"jsse.2011040101-16","unstructured":"O\u2019Keefe, C., Greenfield, P., & Goodchild, A. (2005). a decentralized approach to electronic consent and health information access control. Journal of Research and Practice in Information Technology, 37."},{"key":"jsse.2011040101-17","unstructured":"OASIS. (2009). HIMSS interop scenarios - demonstration of XSPA profile of SAML. Retrieved from http:\/\/lists.oasis-open.org\/archives\/xspa\/200901\/msg00001.html"},{"key":"jsse.2011040101-18","unstructured":"Ragouzis, N., Hughes, J., Philpott, R., Maler, E., Madsen, P., & Scavo, T. (2008). Security assertion markup language (SAML) v2.0 technical overview, committee draft 02. Retrieved from http:\/\/www.oasis-open.org\/committees\/download.php\/ 27819\/sstc-saml-tech-overview-2.0-cd-02.pdf"},{"key":"jsse.2011040101-19","doi-asserted-by":"crossref","unstructured":"Russello, G., Dong, C., & Dulay, N. (2008). Consent-based workflows for healthcare management. In Proceedings of the IEEE International Workshop on Policies for Distributed Systems and Networks (pp. 153-161). Washington, DC: IEEE Computer Society.","DOI":"10.1109\/POLICY.2008.22"},{"key":"jsse.2011040101-20","unstructured":"Saldhana, A. (2010). Xacml caching for performance. Retrieved from http:\/\/community.jboss.org\/wiki\/ XACMLCachingforPerformance"},{"key":"jsse.2011040101-21","unstructured":"U. S. Department of Health and Human Services. (1996). Health insurance portability and accountability act. Retrieved from http:\/\/www.hhs.gov\/ocr\/privacy\/hipaa\/understanding\/index.html"},{"key":"jsse.2011040101-22","unstructured":"U. S. Department of Health and Human Services. (2003). Summary of the HIPAA privacy rule (HIPAA privacy). Retrieved from http:\/\/www.hhs.gov\/ocr\/privacy\/hipaa\/understanding\/summary\/privacysummary.pdf"},{"key":"jsse.2011040101-23","unstructured":"Verhenneman, G. (2010). Consent, an instrument for patient empowerment? In Proceedings of the 49th FITCE Congress."},{"key":"jsse.2011040101-24","unstructured":"XStream. (n. d.). About XStream. Retrieved from http:\/\/xstream.codehaus.org"},{"key":"jsse.2011040101-25","doi-asserted-by":"crossref","unstructured":"Yuan, E., & Tong, J. (2005). Attributed based access control (ABAC) for web services. In Proceedings of the IEEE International Conference on web services. Washington, DC: IEEE Computer Society.","DOI":"10.1109\/ICWS.2005.25"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=55267","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,2,8]],"date-time":"2019-02-08T01:38:40Z","timestamp":1549589920000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jsse.2011040101"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2011,4]]},"references-count":26,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.4018\/jsse.2011040101","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,4]]}}}