메뉴 건너뛰기




Volumn 1, Issue 1, 2006, Pages 22-39

Health Insurance Portability and Accountability Act (HIPPA) Compliant Access Control Model for Web Services

Author keywords

access control; health information management; healthcare information systems; healthcare infrastructure; healthcare privacy issues; privacy protection; privacy regulations; Web enabled healthcare

Indexed keywords


EID: 85001817360     PISSN: 15553396     EISSN: 1555340X     Source Type: Journal    
DOI: 10.4018/jhisi.2006010102     Document Type: Article
Times cited : (29)

References (39)
  • 3
    • 85001731484 scopus 로고    scopus 로고
    • A P3P preference exchange language 1.0 (APPEL1.0) (Working Draft)
    • Retrieved on April 15, 2002, from http://www.w3.org/TR/P3P-preferences/
    • APPEL. (2002). A P3P preference exchange language 1.0 (APPEL1.0) (Working Draft). World Wide Web Consortium (W3C). Retrieved on April 15, 2002, from http://www.w3.org/TR/P3P-preferences/
    • (2002) World Wide Web Consortium (W3C)
  • 4
    • 85001603322 scopus 로고    scopus 로고
    • Web services solution for HIPAA compliance using J2EE-based Web services
    • Retrieved on May 15, 2002, from http://www.webservicesarchitect.com/content/ar-ticles/apshankar02.asp
    • Apshankar, K. (2002). Web services solution for HIPAA compliance using J2EE-based Web services. Web Services Architect. Retrieved on May 15, 2002, from http://www.webservicesarchitect.com/content/ar-ticles/apshankar02.asp
    • (2002) Web Services Architect
    • Apshankar, K.1
  • 5
    • 0031521323 scopus 로고    scopus 로고
    • Arguments for the standardization of privacy protection policy: Canadian initiatives and American and international responses
    • Bennett, C. J. (1997). Arguments for the standardization of privacy protection policy: Canadian initiatives and American and international responses. Government Information Quarterly, 14(4), 351–362.
    • (1997) Government Information Quarterly , vol.14 , Issue.4 , pp. 351-362
    • Bennett, C.J.1
  • 7
    • 33749064628 scopus 로고    scopus 로고
    • Towards an integrated privacy framework for HIPAA-compliant Web services
    • Munich, Germany July 19–22 Washington, DC: IEEE Computer Society
    • Cheng, V. S. Y., & Hung, P. C. K. (2005, July 19–22). Towards an integrated privacy framework for HIPAA-compliant Web services. In Proceedings of the 2005 IEEE International Conference on E-Commerce Technology, Munich, Germany (pp. 480–483). Washington, DC: IEEE Computer Society.
    • (2005) In Proceedings of the 2005 IEEE International Conference on E-Commerce Technology , pp. 480-483
    • Cheng, V.S.Y.1    Hung, P.C.K.2
  • 12
    • 33749073849 scopus 로고    scopus 로고
    • Retrieved on May 31, 2004, from http://www.hl7.org/memonly/downloads/Attachment_Specifications/HIPAA_and_Claims_Attachments_White_Paper_20040518.pdf
    • HL7. (2004). HIPAA claims and attachments preparing for regulation. Retrieved on May 31, 2004, from http://www.hl7.org/memonly/downloads/Attachment_Specifications/HIPAA_and_Claims_Attachments_White_Paper_20040518.pdf
    • (2004) HIPAA claims and attachments preparing for regulation
  • 13
    • 85001733684 scopus 로고    scopus 로고
    • Retrieved on April 2005, from http://www.va.gov/rbac/docs/HL7RBACHealthcarePermissionCatalogv1.0.doc
    • HL7. (2005). HL7 RBAC healthcare permission catalog. Retrieved on April 2005, from http://www.va.gov/rbac/docs/HL7RBACHealthcarePermissionCatalogv1.0.doc
    • (2005) HL7 RBAC healthcare permission catalog
  • 15
    • 85001643473 scopus 로고    scopus 로고
    • Protecting personal health information in research: Understanding the HIPAA privacy rule. U.S
    • Retrieved on July 13, 2004, from http://privacyruleandresearch.nih.gov/pr_02.asp
    • HSS. (2004). Protecting personal health information in research: Understanding the HIPAA privacy rule. U.S. Department of Health & Human Services (HSS). Retrieved on July 13, 2004, from http://privacyruleandresearch.nih.gov/pr_02.asp
    • (2004) Department of Health & Human Services (HSS)
  • 16
    • 4544228476 scopus 로고    scopus 로고
    • Towards standardized Web services privacy technologies
    • Washington, DC: IEEE Computer Society June 6–9 Retrieved from http://dx.doi.org/10.1109/ICWS.2004.116
    • Hung, P. C. K., Ferrari, E., & Carminati, B. (2004, June 6–9). Towards standardized Web services privacy technologies. In Proceedings of the 2004 IEEE International Conference on Web Services (pp.174–181). Washington, DC: IEEE Computer Society. Retrieved from http://dx.doi.org/10.1109/ICWS.2004.116
    • (2004) In Proceedings of the 2004 IEEE International Conference on Web Services , pp. 174-181
    • Hung, P.C.K.1    Ferrari, E.2    Carminati, B.3
  • 17
    • 24944578141 scopus 로고    scopus 로고
    • Retrieved on June 12, 2003, from http://www.zurich.ibm.com/security/enterprise-privacy/epal
    • IBM. (2003). Enterprise Privacy Authorization Language (EPAL) (IBM Research Report). Retrieved on June 12, 2003, from http://www.zurich.ibm.com/security/enterprise-privacy/epal
    • (2003) Enterprise Privacy Authorization Language (EPAL) (IBM Research Report)
  • 18
    • 1542318699 scopus 로고    scopus 로고
    • Security in a Web Services world: A proposed architecture and roadmap
    • Retrieved on April 7, 2002, from http://www-106.ibm.com/developerworks/library/ws-secmap/
    • IBM and Microsoft. (2002). Security in a Web Services world: A proposed architecture and roadmap (White Paper, Version 1.0). Retrieved on April 7, 2002, from http://www-106.ibm.com/developerworks/library/ws-secmap/
    • (2002) White Paper, Version 1.0
  • 19
    • 85001828254 scopus 로고    scopus 로고
    • A code of ethics for professionals (HIPs)
    • Retrieved on March 31, 2001, from http://www.imia.org/ pubdocs/Code_of_ethics.pdf
    • IMIA. (2001). A code of ethics for professionals (HIPs). International Medical Informatics Association (IMIA). Retrieved on March 31, 2001, from http://www.imia.org/ pubdocs/Code_of_ethics.pdf
    • (2001) International Medical Informatics Association (IMIA)
  • 22
    • 0032031231 scopus 로고    scopus 로고
    • The electronic patient record; The management of access — Case study: Leiden University Hospital
    • Louwerse, K. (1998). The electronic patient record; The management of access — Case study: Leiden University Hospital. International Journal of Medical Informatics, 49(1), 39–44.
    • (1998) International Journal of Medical Informatics , vol.49 , Issue.1 , pp. 39-44
    • Louwerse, K.1
  • 24
    • 33847722781 scopus 로고    scopus 로고
    • National Institute of Standard and Technology (NIST) Retrieved on May 18, 2005, from http://csrc.nist.gov/rbac/rbac-stds-roadmap.html
    • NIST. (2005). Role based access control standards roadmap. National Institute of Standard and Technology (NIST). Retrieved on May 18, 2005, from http://csrc.nist.gov/rbac/rbac-stds-roadmap.html
    • (2005) Role based access control standards roadmap
  • 26
    • 84884311106 scopus 로고    scopus 로고
    • Configuring role-based access control to enforce mandatory and discretionary access control policies
    • Osborn, S., Sandhu, R., & Munawer, Q. (2000). Configuring role-based access control to enforce mandatory and discretionary access control policies. ACM Transactions on Information and Systems Security (TISSEC), 3(2), 85–106.
    • (2000) ACM Transactions on Information and Systems Security (TISSEC) , vol.3 , Issue.2 , pp. 85-106
    • Osborn, S.1    Sandhu, R.2    Munawer, Q.3
  • 27
    • 84874834655 scopus 로고    scopus 로고
    • Privacy promises, access control, and privacy management — Enforcing privacy throughout an enterprise by extending access control
    • October 18–19 Washington, DC: ISEC
    • Powers, C. S., Ashley, P., & Schunter, M. (2002, October 18–19). Privacy promises, access control, and privacy management — Enforcing privacy throughout an enterprise by extending access control. In Proceedings of the Third International Symposium on Electronic Commerce (pp. 13–21). Washington, DC: ISEC.
    • (2002) In Proceedings of the Third International Symposium on Electronic Commerce , pp. 13-21
    • Powers, C.S.1    Ashley, P.2    Schunter, M.3
  • 31
    • 85001566792 scopus 로고    scopus 로고
    • New opportunities for Web services technology: New laws create new needs
    • Retrieved October 1, 2004, from http://www.findarticles.com/p/articles/mi_m0MLV/is_10_4/ai_n7073760
    • Steger, H. (2004). New opportunities for Web services technology: New laws create new needs. Web Services Journal. Retrieved October 1, 2004, from http://www.findarticles.com/p/articles/mi_m0MLV/is_10_4/ai_n7073760
    • (2004) Web Services Journal
    • Steger, H.1
  • 32
    • 39749159432 scopus 로고    scopus 로고
    • Retrieved on May 12, 2005, from http://privacy.med.miami.edu/glossary/xd_privacy_stds.htm
    • University of Miami Ethics Programs. (2005). Privacy standard/rule (HIPAA). Retrieved on May 12, 2005, from http://privacy.med.miami.edu/glossary/xd_privacy_stds.htm
    • (2005) Privacy standard/rule (HIPAA)
  • 33
    • 85001632403 scopus 로고    scopus 로고
    • The platform for privacy preferences 1.0 (P3P1.0) specification (Recommendation)
    • W3C Retrieved on April 16, 2002, from http://www.w3.org/TR/P3P/
    • W3C. (2002a). The platform for privacy preferences 1.0 (P3P1.0) specification (Recommendation). World Wide Web Consortium (W3C). Retrieved on April 16, 2002, from http://www.w3.org/TR/P3P/
    • (2002) World Wide Web Consortium (W3C)
  • 34
    • 85001576454 scopus 로고    scopus 로고
    • Web services description language (WSDL), Version 1.2 (Working Draft)
    • Retrieved on July 9, 2002, from http://www.w3.org/TR/2002/WD-wsdl12–20020709/
    • W3C. (2002b). Web services description language (WSDL), Version 1.2 (Working Draft). World Wide Web Consortium (W3C). Retrieved on July 9, 2002, from http://www.w3.org/TR/2002/WD-wsdl12–20020709/
    • (2002) World Wide Web Consortium (W3C)
  • 35
    • 85001632418 scopus 로고    scopus 로고
    • Web services architecture usage scenarios (Working Draft)
    • W3C Retrieved on July 30, 2002, from http://www.w3.org/TR/2002/WD-ws-archscenarios-20020730/
    • W3C. (2002c). Web services architecture usage scenarios (Working Draft). World Wide Web Consortium (W3C). Retrieved on July 30, 2002, from http://www.w3.org/TR/2002/WD-ws-archscenarios-20020730/
    • (2002) World Wide Web Consortium (W3C)
  • 36
    • 85001519425 scopus 로고    scopus 로고
    • Web services architecture requirements (Working Draft)
    • W3C Retrieved on November 14, 2002, from http://www.w3.org/TR/2002/WD-wsa-reqs-20021114
    • W3C. (2002d). Web services architecture requirements (Working Draft). World Wide Web Consortium (W3C). Retrieved on November 14, 2002, from http://www.w3.org/TR/2002/WD-wsa-reqs-20021114
    • (2002) World Wide Web Consortium (W3C)
  • 37
    • 85001741273 scopus 로고    scopus 로고
    • SOAP Version 1.2 Part 1: Messaging framework (Proposed Recommendation)
    • W3C Retrieved on May 7, 2003, from http://www.w3c.org/TR/2003/PR-soap12-part1–20030507/
    • W3C. (2003a). SOAP Version 1.2 Part 1: Messaging framework (Proposed Recommendation). World Wide Web Consortium (W3C). Retrieved on May 7, 2003, from http://www.w3c.org/TR/2003/PR-soap12-part1–20030507/
    • (2003) World Wide Web Consortium (W3C)
  • 38
    • 85001846912 scopus 로고    scopus 로고
    • SOAP Version 1.2 part 2: Adjuncts (Proposed Recommendation)
    • W3C Retrieved on May 7, 2003, from http://www.w3.org/TR/2003/PR-soap12-part2–20030507/
    • W3C. (2003b). SOAP Version 1.2 part 2: Adjuncts (Proposed Recommendation). World Wide Web Consortium (W3C). Retrieved on May 7, 2003, from http://www.w3.org/TR/2003/PR-soap12-part2–20030507/
    • (2003) World Wide Web Consortium (W3C)
  • 39
    • 4544364777 scopus 로고    scopus 로고
    • Privacy policy compliance for Web services
    • June 6–9 Washington, DC: IEEE Computer Society
    • Yee, G., & Korba, L. (2004, June 6–9). Privacy policy compliance for Web services. In Proceedings of IEEE International Conference on Web Services (pp.158–165). Washington, DC: IEEE Computer Society.
    • (2004) In Proceedings of IEEE International Conference on Web Services , pp. 158-165
    • Yee, G.1    Korba, L.2


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.