National Institute for Health and Welfare, Helsinki, Finland.
Eur J Radiol. 2010 Jan;73(1):31-5. doi: 10.1016/j.ejrad.2009.10.018. Epub 2009 Nov 13.
Teleradiology is probably the most successful eHealth service available today. Its business model is based on the remote transmission of radiological images (e.g. X-ray and CT-images) over electronic networks, and on the interpretation of the transmitted images for diagnostic purpose. Two basic service models are commonly used teleradiology today. The most common approach is based on the message paradigm (off-line model), but more developed teleradiology systems are based on the interactive use of PACS/RIS systems. Modern teleradiology is also more and more cross-organisational or even cross-border service between service providers having different jurisdictions and security policies. This paper defines the requirements needed to make different teleradiology models trusted. Those requirements include a common security policy that covers all partners and entities, common security and privacy protection principles and requirements, controlled contracts between partners, and the use of security controls and tools that supporting the common security policy. The security and privacy protection of any teleradiology system must be planned in advance, and the necessary security and privacy enhancing tools should be selected (e.g. strong authentication, data encryption, non-repudiation services and audit-logs) based on the risk analysis and requirements set by the legislation. In any case the teleradiology system should fulfil ethical and regulatory requirements. Certification of the whole teleradiology service system including security and privacy is also proposed. In the future, teleradiology services will be an integrated part of pervasive eHealth. Security requirements for this environment including dynamic and context aware security services are also discussed in this paper.
远程放射学可能是当今最成功的电子健康服务。它的商业模式基于通过电子网络远程传输放射学图像(例如 X 射线和 CT 图像),并对传输的图像进行解释以进行诊断。远程放射学目前通常使用两种基本服务模型。最常见的方法基于消息范式(离线模型),但更先进的远程放射学系统基于 PACS/RIS 系统的交互使用。现代远程放射学也越来越多地跨越组织,甚至是服务提供商之间具有不同管辖权和安全策略的跨境服务。本文定义了使不同远程放射学模型值得信赖所需的要求。这些要求包括涵盖所有合作伙伴和实体的通用安全策略、通用安全和隐私保护原则和要求、合作伙伴之间的受控合同以及支持通用安全策略的安全控制和工具的使用。任何远程放射学系统的安全性和隐私保护都必须提前计划,并根据法规设定的风险分析和要求选择必要的安全和隐私增强工具(例如强身份验证、数据加密、不可否认服务和审核日志)。在任何情况下,远程放射学系统都应符合道德和法规要求。还提议对整个远程放射学服务系统(包括安全性和隐私性)进行认证。未来,远程放射学服务将成为普及电子健康的一个组成部分。本文还讨论了这种环境的安全要求,包括动态和上下文感知的安全服务。