• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

一种符合健康保险流通与责任法案(HIPAA)的用于保护临床图像安全的架构。

A HIPAA-compliant architecture for securing clinical images.

作者信息

Liu Brent J, Zhou Zheng, Huang H K

机构信息

Image Processing & Informatics Laboratory, Department of Radiology, Keck School of Medicine, University of Southern California, Los Angeles, CA, USA.

出版信息

J Digit Imaging. 2006 Jun;19(2):172-80. doi: 10.1007/s10278-005-9248-5.

DOI:10.1007/s10278-005-9248-5
PMID:16341963
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC3045193/
Abstract

The Health Insurance Portability and Accountability Act (HIPAA, instituted April 2003) Security Standards mandate health institutions to protect health information against unauthorized use or disclosure. One approach to addressing this mandate is by utilizing user access control and generating audit trails of the various authorized as well as unauthorized user access of health data. Although most current clinical image systems [e.g., picture archiving and communication system (PACS)] have components that generate log files for application debugging purposes, there is a lack of methodology to obtain and synthesize the pertinent data from the large volumes of log data generated by these multiple components within a PACS. We have designed a HIPAA-compliant architecture specifically for tracking and auditing the image workflow of clinical imaging systems such as PACS. As an initial first step, we developed HIPAA-compliant auditing system (H-CAS) based on parts of this HIPAA-compliant architecture. H-CAS was implemented within a test-bed PACS simulator located in the Image Processing and Informatics lab at the University of Southern California. Evaluation scenarios were developed where different user types performed legal and illegal access of PACS image data within each of the different components in the PACS simulator. Results were based on whether the scenarios of unauthorized access were correctly identified and documented as well as on normal operational activity. Integration and implementation pitfalls were also noted and included.

摘要

《健康保险流通与责任法案》(HIPAA,2003年4月颁布)的安全标准要求医疗机构保护健康信息,防止其被未经授权使用或披露。实现这一要求的一种方法是利用用户访问控制,并生成各种授权和未经授权的健康数据用户访问的审计跟踪记录。尽管当前大多数临床图像系统[例如,图像存档与通信系统(PACS)]都有用于应用程序调试目的而生成日志文件的组件,但缺乏从PACS内这些多个组件生成的大量日志数据中获取和综合相关数据的方法。我们设计了一种符合HIPAA的架构,专门用于跟踪和审计诸如PACS之类的临床成像系统的图像工作流程。作为第一步,我们基于此符合HIPAA的架构的部分内容开发了符合HIPAA的审计系统(H-CAS)。H-CAS在位于南加州大学图像处理与信息学实验室的测试平台PACS模拟器中实现。开发了评估场景,不同用户类型在PACS模拟器的每个不同组件内对PACS图像数据进行合法和非法访问。结果基于未经授权访问的场景是否被正确识别和记录以及正常操作活动。还指出并包括了集成和实施过程中的陷阱。

相似文献

1
A HIPAA-compliant architecture for securing clinical images.一种符合健康保险流通与责任法案(HIPAA)的用于保护临床图像安全的架构。
J Digit Imaging. 2006 Jun;19(2):172-80. doi: 10.1007/s10278-005-9248-5.
2
HIPAA compliant auditing system for medical images.符合健康保险流通与责任法案(HIPAA)的医学图像审计系统。
Comput Med Imaging Graph. 2005 Mar-Apr;29(2-3):235-41. doi: 10.1016/j.compmedimag.2004.09.009. Epub 2005 Jan 22.
3
Medical image security in a HIPAA mandated PACS environment.《健康保险流通与责任法案》(HIPAA)规定的PACS环境中的医学图像安全
Comput Med Imaging Graph. 2003;27(2-3):185-96. doi: 10.1016/s0895-6111(02)00073-3.
4
Business Model for the Security of a Large-Scale PACS, Compliance with ISO/27002:2013 Standard.符合ISO/27002:2013标准的大规模PACS安全商业模式
J Digit Imaging. 2015 Aug;28(4):481-91. doi: 10.1007/s10278-014-9746-4.
5
HIPAA: ensuring patients' privacy and security.《健康保险流通与责任法案》:保障患者隐私与安全。
Radiol Manage. 2004 Mar-Apr;26(2):31-3.
6
This is not your parents' security system. Defining user roles and creating audit trails in a HIPAA-compliant system are two critical steps to successful compliance.
Health Manag Technol. 2002 Nov;23(11):16, 19.
7
A novel key management solution for reinforcing compliance with HIPAA privacy/security regulations.一种用于加强对《健康保险流通与责任法案》(HIPAA)隐私/安全法规合规性的新型密钥管理解决方案。
IEEE Trans Inf Technol Biomed. 2011 Jul;15(4):550-6. doi: 10.1109/TITB.2011.2154363. Epub 2011 May 12.
8
HIPPA's compliant Auditing System for Medical Imaging System.
Conf Proc IEEE Eng Med Biol Soc. 2005;2006:562-3. doi: 10.1109/IEMBS.2005.1616473.
9
Creating an IHE ATNA-based audit repository.创建一个基于IHE ATNA的审计存储库。
J Digit Imaging. 2006 Dec;19(4):307-15. doi: 10.1007/s10278-006-0927-7.
10
Security middleware infrastructure for DICOM images in health information systems.健康信息系统中用于DICOM图像的安全中间件基础设施。
J Digit Imaging. 2003 Dec;16(4):356-64. doi: 10.1007/s10278-003-1710-7. Epub 2004 Jan 30.

引用本文的文献

1
Data Integrity of Radiology Images Over an Insecure Network Using AES Technique.利用 AES 技术在不安全网络上实现放射图像的数据完整性。
Asian Pac J Cancer Prev. 2021 Jan 1;22(1):185-193. doi: 10.31557/APJCP.2021.22.1.185.
2
Building blocks for a clinical imaging informatics environment.临床影像信息学环境的构建要素。
J Digit Imaging. 2014 Apr;27(2):174-81. doi: 10.1007/s10278-013-9645-0.
3
The information security needs in radiological information systems-an insight on state hospitals of Iran, 2012.放射信息系统中的信息安全需求——对伊朗公立医院的洞察,2012 年。
J Digit Imaging. 2013 Dec;26(6):1040-4. doi: 10.1007/s10278-013-9618-3.
4
Realizing digital signatures for medical imaging and reporting in a PACS environment.在PACS环境中实现医学成像和报告的数字签名。
J Med Syst. 2013 Feb;37(1):9924. doi: 10.1007/s10916-012-9924-1. Epub 2013 Jan 13.
5
Design of a Web-tool for diagnostic clinical trials handling medical imaging research.用于处理医学影像研究的诊断临床试验的网络工具设计。
J Digit Imaging. 2011 Apr;24(2):196-202. doi: 10.1007/s10278-010-9304-7.
6
A knowledge-anchored integrative image search and retrieval system.一个基于知识的综合图像搜索与检索系统。
J Digit Imaging. 2009 Apr;22(2):166-82. doi: 10.1007/s10278-007-9086-8. Epub 2007 Nov 27.
7
Creating an IHE ATNA-based audit repository.创建一个基于IHE ATNA的审计存储库。
J Digit Imaging. 2006 Dec;19(4):307-15. doi: 10.1007/s10278-006-0927-7.

本文引用的文献

1
Medical image security in a HIPAA mandated PACS environment.《健康保险流通与责任法案》(HIPAA)规定的PACS环境中的医学图像安全
Comput Med Imaging Graph. 2003;27(2-3):185-96. doi: 10.1016/s0895-6111(02)00073-3.
2
New direction in PACS education and training.PACS教育与培训的新方向。
Comput Med Imaging Graph. 2003;27(2-3):147-56. doi: 10.1016/s0895-6111(02)00088-5.