Access Control for Electronic Health Records. A Delphi study of current challenges and highlighting of potential improvements

Rune Hystad
Department of Health and Nursing Science, University of Agder, Norway

Rune Fensli
Center for eHealth and Health Care Technology, Department of ICT, University of Agder, Norway

Ingår i: Scandinavian Conference on Health Informatics; August 22; 2014; Grimstad; Norway

Linköping Electronic Conference Proceedings 102:6, s. 37-44

Publicerad: 2014-08-20

ISBN: 978-91-7519-241-3

ISSN: 1650-3686 (tryckt), 1650-3740 (online)


Access control is an essential function in electronic health records (EHR) to maintain the duality between patient safety and patient privacy by ensuring that authorized personnel are allowed access to health records. In the Norwegian secondary care; access control in EHR must be given on the basis of decisions about health care; so called decision based access. There is however no empirical data on experiences with the use and setup of decision based access. A Delphi survey was therefore undertaken to identify what end users and system administrators consider to be important challenges; and ways to improve the access control. The survey shows that challenges identified in previous studies are still present. Access control is not sufficiently tailored to treatment processes; and there is extensive use of exception mechanisms; which creates long event records that are not followed up systematically and therefore may go at the expense of patient privacy. Possible improvements include more education; standardization of access control; easier use of exception mechanisms and a more process oriented access control.


Access control; Electronic health records; Security measures; Patient safety; Delphi Technique


