Establishment of Access Levels for Health Sensitive Data Exchange through Semantic Web

Abstract Data exchange in health information systems must be carefully planned and needs to be protected from unauthorized access due to sensibility of stored content. Security aspects like authentication, authorization and encryption must be considered in this context. The main goal of this article is to present the implementation of security mechanisms to a semantic API that allows data extraction from a regional health information system designed to create notifications and to follow patients diagnosed with Tuberculosis. Data semantically tagged will be mapped individually to several access levels. It will be showed how external systems can connect, authenticate and retrieve only authorized data that are classified in the scope of its maximum access level.