Suppr超能文献

一种符合健康保险流通与责任法案(HIPAA)的用于保护临床图像安全的架构。

A HIPAA-compliant architecture for securing clinical images.

作者信息

Liu Brent J, Zhou Zheng, Huang H K

机构信息

Image Processing & Informatics Laboratory, Department of Radiology, Keck School of Medicine, University of Southern California, Los Angeles, CA, USA.

出版信息

J Digit Imaging. 2006 Jun;19(2):172-80. doi: 10.1007/s10278-005-9248-5.

Abstract

The Health Insurance Portability and Accountability Act (HIPAA, instituted April 2003) Security Standards mandate health institutions to protect health information against unauthorized use or disclosure. One approach to addressing this mandate is by utilizing user access control and generating audit trails of the various authorized as well as unauthorized user access of health data. Although most current clinical image systems [e.g., picture archiving and communication system (PACS)] have components that generate log files for application debugging purposes, there is a lack of methodology to obtain and synthesize the pertinent data from the large volumes of log data generated by these multiple components within a PACS. We have designed a HIPAA-compliant architecture specifically for tracking and auditing the image workflow of clinical imaging systems such as PACS. As an initial first step, we developed HIPAA-compliant auditing system (H-CAS) based on parts of this HIPAA-compliant architecture. H-CAS was implemented within a test-bed PACS simulator located in the Image Processing and Informatics lab at the University of Southern California. Evaluation scenarios were developed where different user types performed legal and illegal access of PACS image data within each of the different components in the PACS simulator. Results were based on whether the scenarios of unauthorized access were correctly identified and documented as well as on normal operational activity. Integration and implementation pitfalls were also noted and included.

摘要

《健康保险流通与责任法案》(HIPAA,2003年4月颁布)的安全标准要求医疗机构保护健康信息,防止其被未经授权使用或披露。实现这一要求的一种方法是利用用户访问控制,并生成各种授权和未经授权的健康数据用户访问的审计跟踪记录。尽管当前大多数临床图像系统[例如,图像存档与通信系统(PACS)]都有用于应用程序调试目的而生成日志文件的组件,但缺乏从PACS内这些多个组件生成的大量日志数据中获取和综合相关数据的方法。我们设计了一种符合HIPAA的架构,专门用于跟踪和审计诸如PACS之类的临床成像系统的图像工作流程。作为第一步,我们基于此符合HIPAA的架构的部分内容开发了符合HIPAA的审计系统(H-CAS)。H-CAS在位于南加州大学图像处理与信息学实验室的测试平台PACS模拟器中实现。开发了评估场景,不同用户类型在PACS模拟器的每个不同组件内对PACS图像数据进行合法和非法访问。结果基于未经授权访问的场景是否被正确识别和记录以及正常操作活动。还指出并包括了集成和实施过程中的陷阱。

相似文献

2
HIPAA compliant auditing system for medical images.符合健康保险流通与责任法案(HIPAA)的医学图像审计系统。
Comput Med Imaging Graph. 2005 Mar-Apr;29(2-3):235-41. doi: 10.1016/j.compmedimag.2004.09.009. Epub 2005 Jan 22.
8
HIPPA's compliant Auditing System for Medical Imaging System.
Conf Proc IEEE Eng Med Biol Soc. 2005;2006:562-3. doi: 10.1109/IEMBS.2005.1616473.
9
Creating an IHE ATNA-based audit repository.创建一个基于IHE ATNA的审计存储库。
J Digit Imaging. 2006 Dec;19(4):307-15. doi: 10.1007/s10278-006-0927-7.

引用本文的文献

2
6
A knowledge-anchored integrative image search and retrieval system.一个基于知识的综合图像搜索与检索系统。
J Digit Imaging. 2009 Apr;22(2):166-82. doi: 10.1007/s10278-007-9086-8. Epub 2007 Nov 27.
7
Creating an IHE ATNA-based audit repository.创建一个基于IHE ATNA的审计存储库。
J Digit Imaging. 2006 Dec;19(4):307-15. doi: 10.1007/s10278-006-0927-7.

本文引用的文献

2
New direction in PACS education and training.PACS教育与培训的新方向。
Comput Med Imaging Graph. 2003;27(2-3):147-56. doi: 10.1016/s0895-6111(02)00088-5.

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验