Comparing the context and the SitBAC models for privacy preservation in terms of model understanding and synthesis.

There is an increasing interest in preserving patients' privacy while accessing Electronic Health Record (EHR) data. Two models that support representation of data-request authorization policies are the Contextual Role-Based Access Control (Context) model [1] and the Situation-Based Access Control (SitBAC) model [2]. We conducted a controlled experiment that compared the two models with respect to model-understanding and model-synthesis.