Authorization, in the context of eHealth information security, refers to rights a particular user (e.g., health professional) has with regards to eHealth service systems. Authorization is not to be confused with Authentication, which deals with the question of whether the user demanding access to eHealth service systems really is the person he/she claims to be.

While Authorization deals with questions like: “Does Dr. X have the right to access this specific kind of data?“, Authentication might ask “Is this person really Dr. X?“.

