Related Experiment Video
Updated: Jun 4, 2026

Implementation of a Real-Time Psychosis Risk Detection and Alerting System Based on Electronic Health Records using CogStack
Published on: May 15, 2020
Learning relational policies from electronic health record access logs
Bradley Malin1, Steve Nyemba, John Paulett
1Department of Biomedical Informatics, School of Medicine, Vanderbilt University, Nashville, TN 37203, USA. b.malin@vanderbilt.edu
This study introduces an automated method for generating healthcare access control policies by analyzing electronic health record (EHR) usage patterns. This approach balances patient privacy with functional needs, improving upon manual policy creation.
Area of Science:
- Health Informatics
- Data Mining
- Social Network Analysis
Background:
- Healthcare organizations (HCOs) face challenges in defining access control policies due to complex team dynamics and the fluid nature of clinical operations.
- Manual policy creation is labor-intensive, error-prone, and can lead to inappropriate access levels, compromising patient privacy or hindering legitimate care.
- Existing systems struggle to balance patient privacy with the need for timely access to medical records by healthcare providers.
Purpose of the Study:
- To propose an automated method for generating access control policies in healthcare organizations by mining usage patterns from electronic health record (EHR) systems.
- To develop a generalizable approach that assists in the design and evaluation of local access control policies across different HCOs.
- To provide a technique that enables the review of existing policies and the discovery of previously unknown user behaviors within EHR systems.
Main Methods:
- Utilizing data mining and social network analysis theory to extract a statistical model of the organization from EHR access logs.
- Analyzing 5 months of access logs from Vanderbilt University Medical Center to evaluate the proposed technique.
- Identifying stable social structures and business operations within the healthcare environment.
Main Results:
- Confirmed the existence of stable social structures and intuitive business operations within the analyzed healthcare data.
- Demonstrated significant turnover in user interactions within the healthcare organization.
- Showed that policies learned at the department level offer greater long-term stability.
Conclusions:
- Automated policy generation from EHR usage patterns offers a viable alternative to manual methods, improving efficiency and accuracy.
- The proposed technique effectively models organizational behavior and identifies both established and emergent interaction patterns.
- Department-level policy learning provides a more stable and manageable approach to access control in dynamic healthcare environments.
Related Concept Videos
Methods of Documentation VII: EMR
Legal Guidelines for Documentation
Types of Records II: Educational and Administrative Records
Purpose of Health Records II
Guidelines and Strategies for Safe Computer Charting
Maintain Confidentiality and Security:
Purpose of Health Records I
Here's a breakdown of how health records serve these purposes:
