Author(s):
Farhadighalati, Nastaran ; Estrada-Jimenez, Luis A. ; Kalateh, Sepideh ; Nikghadam-Hojjati, Sanaz ; Barata, Jose
Date: 2026
Persistent ID: http://hdl.handle.net/10362/202304
Origin: Repositório Institucional da UNL
Subject(s): access control; behavior monitoring; healthcare data security and privacy; LLM-based security; retrieval-augmented generation (RAG); rule-based access control; Communication; Human-Computer Interaction; Computer Networks and Communications; SDG 3 - Good Health and Well-being
Description
Healthcare faces a critical challenge: protecting sensitive medical data while enabling necessary clinical access. Evolving user behaviors, dynamic clinical contexts, and strict regulatory requirements demand adaptive access control mechanisms. Despite strict regulations, healthcare remains the most breached industry, consistently facing severe security risks related to unauthorized access. Traditional access control models cannot handle contextual variations, detect credential compromise, or provide transparent decision rationales. To address this, SAFE-GUARD (Semantic Access Control Framework Employing Generative User Assessment and Rule Decisions) is proposed as a two-layer framework that combines behavioral analysis with policy enforcement. The Behavioral Analysis Layer uses Retrieval-Augmented Generation (RAG) to detect contextual anomalies by comparing current requests against historical patterns. The Rule-Based Policy Evaluation Layer independently validates organizational procedures and regulatory requirements. Access is granted only when behavioral consistency and both organizational and regulatory policies are satisfied. We evaluate SAFE-GUARD using simulated healthcare scenarios with three LLMs (GPT-4o, Claude 3.5 Sonnet, and Gemini 2.5 Flash) achieving an anomaly detection accuracy of 95.2%, 94.1%, and 91.3%, respectively. The framework effectively identifies both compromised credentials and insider misuse by detecting deviations from established behavioral patterns, significantly outperforming conventional RBAC and ABAC approaches that rely solely on static rules.