Implementation of Personal Health Record (PHR) systems involves multiple stakeholders with different interpretations and expectations;
more importantly it involves changes in the custody of data, patient privacy, and consent management. In PHR analysis we need
to answer questions such as: Who is the provider of PHR? Who has access to the patient data and why? And how the system can
empower the patient? And how can the patient privacy be managed. This paper exploits techniques from Goal and Agent-oriented
Requirements Engineering and proposes a methodological framework for dealing with concerns surrounding PHR systems. The framework
is illustrated through an example that emphasizes the privacy aspects of PHRs.