The present paper addresses privacy and security enhancements to a basic role-based access control system. The contribution
is twofold. First, the paper presents an approach to personalized access control, i.e. a combination of role-based access
control and user-managed access control. Second, the proposed access control approach is cryptographically enforced and an
efficient key management method for the personalized role-based access control is described. The proposed solutions are discussed
in the context of a system architecture for secure management of Electronic Health Records.