Gregg Bill, D'Agostino Horacio, Toledo Eduardo Gonzalez
Department of Radiology, LSU Health Sciences Center, Shreveport, LA, USA.
J Digit Imaging. 2006 Dec;19(4):307-15. doi: 10.1007/s10278-006-0927-7.
Compliance with the Health Insurance Portability and Accountability Act (HIPAA) requires gathering audit information from picture archiving and communications systems (PACS) regarding evidence trails of human interactions. Until recently, most PACS users have had limited access to auditing information. Access required resources to handle manual inspection of audit logs, and access to proprietary databases was not always available. Some vendors now produce eXtensible Markup Language (XML) audit logs based on certain events occurring in PACS. However, it is up to the user to convert this information into an easily mined data repository supporting compliance and quality control. This process can be handled in multiple ways, which could mean different audit mechanisms depending on the PACS (or other hospital system) used. It is apparent that an organized method of dealing with audit information is needed. This help may be provided within the Integrating the Healthcare Environment (IHE) framework. The IHE initiative defines a set of profiles, actors, and transactions that create common scenarios for particular workflow processes. The Integration Profiles depict security as a fundamental requirement of the framework. Specifically, the Audit Trail and Node Authentication (ATNA) profile defines standards based mechanisms for securely transmitting and storing audit records in a central repository. The data structure defined by the profile provides a number of record types that capture different audit events. A general feasibility study for storing currently available PACS audit information following the profile is defined, and steps to an automated solution are discussed.
遵守《健康保险流通与责任法案》(HIPAA)要求从图像存档与通信系统(PACS)收集有关人际交互证据线索的审计信息。直到最近,大多数PACS用户获取审计信息的机会仍然有限。获取信息需要资源来处理审计日志的人工检查,而且并非总能访问专有数据库。现在一些供应商会根据PACS中发生的某些事件生成可扩展标记语言(XML)审计日志。然而,将这些信息转换为支持合规性和质量控制的易于挖掘的数据存储库则取决于用户。这个过程可以通过多种方式处理,这可能意味着根据所使用的PACS(或其他医院系统)采用不同的审计机制。显然,需要一种有组织的方法来处理审计信息。这可能会在整合医疗环境(IHE)框架内得到帮助。IHE计划定义了一组配置文件、参与者和事务,为特定的工作流程创建通用场景。集成配置文件将安全性描述为框架的一项基本要求。具体而言,审计跟踪与节点认证(ATNA)配置文件定义了基于标准的机制,用于在中央存储库中安全地传输和存储审计记录。该配置文件定义的数据结构提供了多种记录类型,用于捕获不同的审计事件。定义了一项关于按照该配置文件存储当前可用的PACS审计信息的总体可行性研究,并讨论了实现自动化解决方案的步骤。