Tehran University of Medical Science, Tehran, Iran,
J Digit Imaging. 2013 Dec;26(6):1040-4. doi: 10.1007/s10278-013-9618-3.
Picture Archiving and Communications System (PACS) was originally developed for radiology services over 20 years ago to capture medical images electronically. Medical diagnosis methods are based on images such as clinical radiographs, ultrasounds, CT scans, MRIs, or other imaging modalities. Information obtained from these images is correlated with patient information. So with regards to the important role of PACS in hospitals, we aimed to evaluate the PACS and survey the information security needed in the Radiological Information system. First, we surveyed the different aspects of PACS that should be in any health organizations based on Department of Health standards and prepared checklists for assessing the PACS in different hospitals. Second, we surveyed the security controls that should be implemented in PACS. Checklists reliability is affirmed by professors of Tehran Science University. Then, the final data are inputted in SPSS software and analyzed. The results indicate that PACS in hospitals can transfer patient demographic information but they do not show route of information. These systems are not open source. They don't use XML-based standard and HL7 standard for exchanging the data. They do not use DS digital signature. They use passwords and the user can correct or change the medical information. PACS can detect alternation rendered. The survey of results demonstrates that PACS in all hospitals has the same features. These systems have the patient demographic data but they do not have suitable flexibility to interface network or taking reports. For the privacy of PACS in all hospitals, there were passwords for users and the system could show the changes that have been made; but there was no water making or digital signature for the users.
影像归档与通信系统(PACS)最初是在 20 多年前为放射科服务开发的,用于电子捕获医学图像。医学诊断方法基于临床 X 光片、超声、CT 扫描、MRI 或其他成像方式的图像。从这些图像中获得的信息与患者信息相关联。因此,鉴于 PACS 在医院中的重要作用,我们旨在评估 PACS 并调查放射信息系统所需的信息安全。首先,我们根据卫生部标准调查了任何卫生组织都应该具备的 PACS 的不同方面,并为不同医院的 PACS 评估准备了检查表。其次,我们调查了应该在 PACS 中实施的安全控制措施。检查表的可靠性得到了德黑兰科技大学教授的肯定。然后,将最终数据输入 SPSS 软件进行分析。结果表明,医院的 PACS 可以传输患者人口统计信息,但不能显示信息路径。这些系统不是开源的。它们不使用基于 XML 的标准和 HL7 标准来交换数据。它们不使用 DS 数字签名。它们使用密码,用户可以更正或更改医疗信息。PACS 可以检测到呈现的更改。所有医院的 PACS 调查结果都表明,这些系统都具有患者人口统计数据,但缺乏与网络接口或报告的适当灵活性。对于所有医院的 PACS 隐私,用户都有密码,系统可以显示已进行的更改;但是,用户没有水印或数字签名。