Liu Brent J, Zhou Zheng, Huang H K
Image Processing & Informatics Laboratory, Department of Radiology, Keck School of Medicine, University of Southern California, Los Angeles, CA, USA.
J Digit Imaging. 2006 Jun;19(2):172-80. doi: 10.1007/s10278-005-9248-5.
The Health Insurance Portability and Accountability Act (HIPAA, instituted April 2003) Security Standards mandate health institutions to protect health information against unauthorized use or disclosure. One approach to addressing this mandate is by utilizing user access control and generating audit trails of the various authorized as well as unauthorized user access of health data. Although most current clinical image systems [e.g., picture archiving and communication system (PACS)] have components that generate log files for application debugging purposes, there is a lack of methodology to obtain and synthesize the pertinent data from the large volumes of log data generated by these multiple components within a PACS. We have designed a HIPAA-compliant architecture specifically for tracking and auditing the image workflow of clinical imaging systems such as PACS. As an initial first step, we developed HIPAA-compliant auditing system (H-CAS) based on parts of this HIPAA-compliant architecture. H-CAS was implemented within a test-bed PACS simulator located in the Image Processing and Informatics lab at the University of Southern California. Evaluation scenarios were developed where different user types performed legal and illegal access of PACS image data within each of the different components in the PACS simulator. Results were based on whether the scenarios of unauthorized access were correctly identified and documented as well as on normal operational activity. Integration and implementation pitfalls were also noted and included.
《健康保险流通与责任法案》(HIPAA,2003年4月颁布)的安全标准要求医疗机构保护健康信息,防止其被未经授权使用或披露。实现这一要求的一种方法是利用用户访问控制,并生成各种授权和未经授权的健康数据用户访问的审计跟踪记录。尽管当前大多数临床图像系统[例如,图像存档与通信系统(PACS)]都有用于应用程序调试目的而生成日志文件的组件,但缺乏从PACS内这些多个组件生成的大量日志数据中获取和综合相关数据的方法。我们设计了一种符合HIPAA的架构,专门用于跟踪和审计诸如PACS之类的临床成像系统的图像工作流程。作为第一步,我们基于此符合HIPAA的架构的部分内容开发了符合HIPAA的审计系统(H-CAS)。H-CAS在位于南加州大学图像处理与信息学实验室的测试平台PACS模拟器中实现。开发了评估场景,不同用户类型在PACS模拟器的每个不同组件内对PACS图像数据进行合法和非法访问。结果基于未经授权访问的场景是否被正确识别和记录以及正常操作活动。还指出并包括了集成和实施过程中的陷阱。