McEvoy Fintan J, Svalastoga Eiliv
Department of Small Animal Clinical Sciences, Faculty of Life Sciences, Frederiksberg Campus, University of Copenhagen, Copenhagen, Denmark.
J Digit Imaging. 2009 Mar;22(1):65-70. doi: 10.1007/s10278-007-9068-x. Epub 2007 Aug 21.
The transmission of patient and imaging data between imaging centers and other interested individuals is increasingly achieved by means of compact disc digital media (CD). These CDs typically contain, in addition to the patient images, a DICOM reader and information about the origin of the data. While equipment manufacturers attach disclaimers to these discs and specify the intended use of such media, they are often the only practical means of transmitting data for small medical, dental, or veterinary medical centers. Images transmitted by these means are used for clinical diagnosis. This has lead to a heavy reliance on the integrity of the data. This report describes attempts to alter significant patient and study data on CD media and their outcome. The results show that data files are extremely vulnerable to alteration, and alterations are not detectable without detailed analysis of file structure. No alterations to the DICOM readers were required to achieve this; changes were applied only to the data files. CDs with altered data can be readily prepared, and from the point of view of individuals viewing the images, function identically to the original manufacturer's CD. Such media should be considered unsafe where there is a potential for financial or other gain to be had from altering the data, and the copy cannot be cross-checked with the original data.
影像中心与其他相关人员之间的患者及影像数据传输越来越多地通过光盘数字媒体(CD)来实现。这些CD除了包含患者图像外,通常还包含一个DICOM阅读器以及有关数据来源的信息。尽管设备制造商在这些光盘上附加了免责声明并规定了此类媒体的预期用途,但对于小型医疗、牙科或兽医医疗中心而言,它们往往是传输数据的唯一实用手段。通过这些方式传输的图像用于临床诊断。这导致严重依赖数据的完整性。本报告描述了对CD媒体上重要患者和研究数据进行更改的尝试及其结果。结果表明,数据文件极易被更改,而且如果不对文件结构进行详细分析,更改是无法检测到的。实现这一点无需对DICOM阅读器进行任何更改;仅对数据文件进行了修改。可以轻松制备数据被更改的CD,从查看图像的人的角度来看,其功能与原始制造商的CD完全相同。在存在因更改数据而可能获得经济利益或其他收益且无法将副本与原始数据进行交叉核对的情况下,此类媒体应被视为不安全的。