Related Experiment Video
Updated: Dec 11, 2025

TBase - an Integrated Electronic Health Record and Research Database for Kidney Transplant Recipients
Published on: April 13, 2021
Strengthen Electronic Health Records System (EHR-S) Access-Control to Cope with GDPR Explicit Consent
Marcelo Antonio de Carvalho Junior1, Paulo Bandiera-Paiva2
1Universidade Federal de São Paulo, São Paulo, SP, Brazil. carvalho.junior@unifesp.br.
Abstract:
Patient consent is currently a missing piece on Electronic Health Records System (EHR-S) access permission. The control is needed to ensure personal data as the property of the individual, not data controllers or health-care service providers. To cope with this need, in this article, an adaptation of existent Role-Based Access Control (RBAC), including patient-centric control, is described. The revisited feature of existing administrative and supporting RBAC functions allows exclusive control orchestrated by the patient as sole information owner, including the ability to encrypt their data for confidentiality purposes. The additions mimic a Discretionary Access Control (DAC) capability using existing user group membership to vet access over symmetric keys bind to patient's data via the associated PERMS matrix.
More Related Videos
Related Concept Videos
Legal Guidelines for Documentation
Ethical Standards I
The Code of Ethics provisions outline the nurse's duty to the patient, the healthcare team, the profession, and society. The Code's fundamental principles include advocacy,...
Ethical Standards II
Nurses are entrusted with upholding various ethical principles and standards. Nurses forge solid therapeutic relationships using trust, empathy, autonomy, confidentiality, and professional competence.
Confidentiality is crucial, embodying respect for individual privacy...
Guidelines and Strategies for Safe Computer Charting
Maintain Confidentiality and Security:
Standards of Care II
Methods of Documentation VII: EMR

