Skip to main content
Top
Published in: Journal of Digital Imaging 2/2006

01-06-2006

A HIPAA-Compliant Architecture for Securing Clinical Images

Authors: Brent J. Liu, Zheng Zhou, H. K. Huang

Published in: Journal of Imaging Informatics in Medicine | Issue 2/2006

Login to get access

Abstract

The Health Insurance Portability and Accountability Act (HIPAA, instituted April 2003) Security Standards mandate health institutions to protect health information against unauthorized use or disclosure. One approach to addressing this mandate is by utilizing user access control and generating audit trails of the various authorized as well as unauthorized user access of health data. Although most current clinical image systems [e.g., picture archiving and communication system (PACS)] have components that generate log files for application debugging purposes, there is a lack of methodology to obtain and synthesize the pertinent data from the large volumes of log data generated by these multiple components within a PACS. We have designed a HIPAA-compliant architecture specifically for tracking and auditing the image workflow of clinical imaging systems such as PACS. As an initial first step, we developed HIPAA-compliant auditing system (H-CAS) based on parts of this HIPAA-compliant architecture. H-CAS was implemented within a test-bed PACS simulator located in the Image Processing and Informatics lab at the University of Southern California. Evaluation scenarios were developed where different user types performed legal and illegal access of PACS image data within each of the different components in the PACS simulator. Results were based on whether the scenarios of unauthorized access were correctly identified and documented as well as on normal operational activity. Integration and implementation pitfalls were also noted and included.
Literature
4.
go back to reference Cao, F, Huang, HK, Zhou, XQ 2003Medical image security in a HIPAA mandated PACS environmentComput Med Imaging Graph27185196PubMedCrossRef Cao, F, Huang, HK, Zhou, XQ 2003Medical image security in a HIPAA mandated PACS environmentComput Med Imaging Graph27185196PubMedCrossRef
8.
go back to reference Huang HK: PACS: Basic Principles and Applications. Wiley-Liss, p. 291, 1999 Huang HK: PACS: Basic Principles and Applications. Wiley-Liss, p. 291, 1999
9.
go back to reference Zhou Z: Lossless Digital Signature Embedding for Medical Image Integrity Assurance, Ph.D. Dissertation, Chap. 5–6, July 2005 Zhou Z: Lossless Digital Signature Embedding for Medical Image Integrity Assurance, Ph.D. Dissertation, Chap. 5–6, July 2005
10.
go back to reference Zhou, Z, Huang, HK, Liu, B 2005Digital signature embedding for medical image integrity in a data grid off-site backup archiveSPIE Med Imaging6306317 Zhou, Z, Huang, HK, Liu, B 2005Digital signature embedding for medical image integrity in a data grid off-site backup archiveSPIE Med Imaging6306317
12.
go back to reference White, GB, Fisch, EA, Pooch, UW 1996Computer System and Network SecurityCRC PressBoca Raton, FL White, GB, Fisch, EA, Pooch, UW 1996Computer System and Network SecurityCRC PressBoca Raton, FL
13.
go back to reference Law, MYY, Zhou, Z 2003New direction in PACS education and trainingComput Med Imaging Graph27147156PubMedCrossRef Law, MYY, Zhou, Z 2003New direction in PACS education and trainingComput Med Imaging Graph27147156PubMedCrossRef
14.
go back to reference Zhou, Z, Huang, HK, Cao, F, Liu, BJ, Zhang, J, Mogel, GT 2003Educational RIS/PACS simulatorSPIE Med Imaging4139147 Zhou, Z, Huang, HK, Cao, F, Liu, BJ, Zhang, J, Mogel, GT 2003Educational RIS/PACS simulatorSPIE Med Imaging4139147
Metadata
Title
A HIPAA-Compliant Architecture for Securing Clinical Images
Authors
Brent J. Liu
Zheng Zhou
H. K. Huang
Publication date
01-06-2006
Publisher
Springer-Verlag
Published in
Journal of Imaging Informatics in Medicine / Issue 2/2006
Print ISSN: 2948-2925
Electronic ISSN: 2948-2933
DOI
https://doi.org/10.1007/s10278-005-9248-5

Other articles of this Issue 2/2006

Journal of Digital Imaging 2/2006 Go to the issue