article · East African Journal of Information Technology
Emergency access to electronic health records often forces a compromise between protecting patient privacy and providing prompt clinical care. Existing security architectures evaluate user credentials, devices, or network contexts, but ignore the real-time clinical state of the patient. A newly developed framework addresses this gap by directly linking Zero-Trust security policies to real-time clinical deterioration. Using a long short-term memory model, the system assesses five vital signs to classify patient condition into stable, warning, or critical states. This clinical risk combines with clinical role authority to assign one of four access tiers, while automatically revoking elevated privileges once the patient stabilises. In evaluations using clinical database records and thousands of simulated access requests, the system achieved high predictive accuracy and strong critical-event recall. The access engine operated with sub-millisecond decision latency while maintaining strict security compliance and comprehensive audit logging.
During medical emergencies, delayed access to medical records can endanger lives, yet granting unrestricted emergency access risks exposing sensitive patient data. Dynamically aligning security permissions with acute patient deterioration ensures medical staff instantly receive necessary patient records during life-threatening crises. Crucially, the automatic withdrawal of privileges once patients stabilise prevents unauthorised data exposure, safeguarding patient privacy without hindering urgent care.
This technology offers an access-control mechanism for electronic health record developers and hospital IT security teams. Because testing was conducted using clinical database records and simulated emergency requests rather than a live hospital infrastructure, the system represents an applied and tested proof of concept. Further validation and deployment in real clinical settings are required before it can be commercially adopted or integrated into existing hospital management systems.
AI-generated from the published abstract. Always read the original work before citing.
Emergency access to Electronic Health Record (EHR) systems presents a difficult balance between protecting sensitive patient information and ensuring that clinicians can obtain critical information without delay. Existing security approaches, including Zero-Trust Architecture (ZTA), multi-factor authentication (MFA), and conventional break-glass mechanisms, primarily rely on user identity, device, or network context and do not consider the patient's current clinical condition. No existing approach uses the patient's real-time clinical deterioration as the signal that drives the access decision, which is the specific gap this study addresses. The novelty of the proposed framework lies in coupling clinical-deterioration prediction directly to Zero-Trust policy enforcement, together with automatic privilege revocation once the patient stabilises, rather than in any single component. This study proposes an AI-driven risk-adaptive Zero-Trust framework that incorporates real-time patient deterioration into access control decisions. An LSTM model analyses five vital signs and classifies patient status as STABLE, WARNING, or CRITICAL. The predicted clinical risk is combined with role-specific emergency authority to calculate a composite risk score that determines one of four access levels: Direct Access, MFA Required, Restricted Access, or Denied. The framework was evaluated using the MIMIC-III Clinical Database Demo, comprising 98 patients and 5,992 NEWS2-labelled time-series sequences, together with 6,000 simulated access requests across six clinical specialities. The proposed model achieved an overall accuracy of 82.20%, a CRITICAL-class recall of 88.00%, and an AUC of 0.9752. The access-control engine produced an average decision latency of 0.265 ms while maintaining complete audit logging and 99.3% least-privilege compliance. These findings suggest that integrating clinical deterioration predictions into Zero-Trust access control can improve emergency responsiveness while preserving security and accountability. Although the framework was evaluated in a simulated environment, the results demonstrate its potential for future deployment and validation in real clinical settings.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.37284/eajit.9.1.5560
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.