Skip to main content
Top
Published in: Journal of Digital Imaging 4/2006

01-12-2006

Creating an IHE ATNA-Based Audit Repository

Authors: Bill Gregg, Horacio D’Agostino, Eduardo Gonzalez Toledo

Published in: Journal of Imaging Informatics in Medicine | Issue 4/2006

Login to get access

Abstract

Compliance with the Health Insurance Portability and Accountability Act (HIPAA) requires gathering audit information from picture archiving and communications systems (PACS) regarding evidence trails of human interactions. Until recently, most PACS users have had limited access to auditing information. Access required resources to handle manual inspection of audit logs, and access to proprietary databases was not always available. Some vendors now produce eXtensible Markup Language (XML) audit logs based on certain events occurring in PACS. However, it is up to the user to convert this information into an easily mined data repository supporting compliance and quality control. This process can be handled in multiple ways, which could mean different audit mechanisms depending on the PACS (or other hospital system) used. It is apparent that an organized method of dealing with audit information is needed. This help may be provided within the Integrating the Healthcare Environment (IHE) framework. The IHE initiative defines a set of profiles, actors, and transactions that create common scenarios for particular workflow processes. The Integration Profiles depict security as a fundamental requirement of the framework. Specifically, the Audit Trail and Node Authentication (ATNA) profile defines standards based mechanisms for securely transmitting and storing audit records in a central repository. The data structure defined by the profile provides a number of record types that capture different audit events. A general feasibility study for storing currently available PACS audit information following the profile is defined, and steps to an automated solution are discussed.
Literature
1.
go back to reference Liu, BJ, Zhou, Z, Huang, HK 2006A HIPAA-compliant architecture for securing clinical imagesJ Digit Imaging19172180CrossRefPubMed Liu, BJ, Zhou, Z, Huang, HK 2006A HIPAA-compliant architecture for securing clinical imagesJ Digit Imaging19172180CrossRefPubMed
2.
go back to reference Huang, HK 2004PACS and Imaging Informatics (Basic Principles and Applications)Wiley-LissNew JerseyCrossRef Huang, HK 2004PACS and Imaging Informatics (Basic Principles and Applications)Wiley-LissNew JerseyCrossRef
3.
go back to reference Coleman, RM, Ralston, MD, Szafran, A, Beaulieu, DM 2004Multidimensional analysis: a management tool for monitoring HIPAA compliance and departmental performanceJ Digit Imaging17196204CrossRefPubMed Coleman, RM, Ralston, MD, Szafran, A, Beaulieu, DM 2004Multidimensional analysis: a management tool for monitoring HIPAA compliance and departmental performanceJ Digit Imaging17196204CrossRefPubMed
5.
go back to reference IHE IT Infrastructure Technical Framework, Volume 1, Rev 2.0, 08/15/2005, p. 57, 9.2.1 Audit Messages IHE IT Infrastructure Technical Framework, Volume 1, Rev 2.0, 08/15/2005, p. 57, 9.2.1 Audit Messages
7.
go back to reference IHE IT Infrastructure Technical Framework, Volumes 1–2, Rev 2.0, 08/15/2005 IHE IT Infrastructure Technical Framework, Volumes 1–2, Rev 2.0, 08/15/2005
8.
go back to reference Marshall G: Security Audit and Access Accountability Message XML Data Definitions for Healthcare Applications, The Internet Society, Network Working Group, RFC 3881, 2004 Marshall G: Security Audit and Access Accountability Message XML Data Definitions for Healthcare Applications, The Internet Society, Network Working Group, RFC 3881, 2004
9.
go back to reference IHE IT Infrastructure Technical Framework, Supplement 2004–2005, Audit Trail and Node Authentication Profile (ATNA), Trial Implementation, 08/15/2004, 3.20.7 Audit Message Formats IHE IT Infrastructure Technical Framework, Supplement 2004–2005, Audit Trail and Node Authentication Profile (ATNA), Trial Implementation, 08/15/2004, 3.20.7 Audit Message Formats
10.
go back to reference Digital Imaging and Communications in Medicine (DICOM), Supplement 95: Audit Trail Messages, Trial Use Draft, 06/18/2004 Digital Imaging and Communications in Medicine (DICOM), Supplement 95: Audit Trail Messages, Trial Use Draft, 06/18/2004
Metadata
Title
Creating an IHE ATNA-Based Audit Repository
Authors
Bill Gregg
Horacio D’Agostino
Eduardo Gonzalez Toledo
Publication date
01-12-2006
Publisher
Springer-Verlag
Published in
Journal of Imaging Informatics in Medicine / Issue 4/2006
Print ISSN: 2948-2925
Electronic ISSN: 2948-2933
DOI
https://doi.org/10.1007/s10278-006-0927-7

Other articles of this Issue 4/2006

Journal of Digital Imaging 4/2006 Go to the issue