Audit Trail and Node Authentication - Radiology Option

From IHE Wiki
Revision as of 04:55, 19 March 2008 by Anaest (talk | contribs)
Jump to navigation Jump to search

The ATNA Radiology profile specifies basic security measures that can help protect the confidentiality of patient information as part of an institution's overall security policies and procedures. ATNA provides institutions with a mechanism to consolidate audit trail events on user activity across several imaging and information systems throughout the enterprise systems interconnected in a secure manner.


Summary

The Radiology Audit Trail Option defines the specific requirements of the IHE Radiology transactions for supporting the IHE ITI Audit Trail and Node Authentication profile. This option deals largely with the details of the Record Audit Event transaction in the IHE ITI Technical Framework. The option details the required audit events for each of the IHE Radiology transactions,based on the different trigger events.



Figure 12 SEC.jpg

Benefits

Securing the exchange of patient healthcare information, and logging key events during the processing of healthcare data increases the reliability of the underlying information systems and provides accountability for users of these systems. This is achieved by combining the ATNA requirements with the relevant IHE profiles, using industry standards like TLS and Syslog.

Some of the benefits are:

- Authentication/Access control: network access are limited between nodes (access restriction to secure nodes only) and between each nodes to authorized users (depending on local authentication and access control policy)

- Audit trail: allows detection of non-compliant behaviour instances, or improper creation, access, modification and deletion of Protected Health Information (PHI)

- Centralized audit record repository, making easier the implementation of security requirements


Details

Node authentication gives a means to control network access by : - Using, from and to each node, a mandatory bi-directional certificate-based node authentication, - Allowing, for each node, the use of the user’s authentication and access control policy of its choice.

Audit Trails are based on the production of audit records, that provide a record of actions such as queries, views, additions, deletions and changes that are processed within the Security Domain covered by ATNA. Records are triggered by trigger events described in this profile.

Some of the trigger events described in ATNA are not relevant in the ATNA Radiology option. These trigger events are: - Health-service-event - Medication - Patient-care-assignment - Patient-care-episode - Patient-care-protocol

The details concering the ATNA profile can be seen on the: http://wiki.ihe.net/index.php?title=Audit_Trail_and_Node_Authentication

Systems Affected

All systems which participate in Radiology Framework transactions with corresponding audit events are affected. See Table 5.12 IHE Radiology transactions and resulting ATNA trigger events in volume 3 of the IHE Radiology technical framework.


Actors & Transactions:

<Insert an actor-transaction diagram, and or list of Content Definitions>

Specification

Profile Status: Final Text <Replace "Final Text" with "Trial Implementation" or "Public Comment" as appropriate.>

Documents:

<Provide direct links to the specific volumes or supplements, and list the volume sections relevant to this profile. E.g.>

IHE Radiology Technical Framework:

  • Vol. 1 - Section 5 documents the profile
  • Vol. 2 - Sections 4.8 to 4.10, 4.14 to 4.19, and 4.23 document specific transactions
  • Vol. 3 - Appendix E provides additional informative text

Underlying Standards:

  • <list standards on which this profile is based; if possible with links to sources>
  • DICOM
  • HL7
  • ...

See Also

<The following sections can be left out if there is nothing to point to. This is just to show where such information can go.>


Related Profiles

<List profiles this one depends on, profiles that depend on this one, profiles that are synergistic with this one>

Consumer Information

The Profile FAQ Template answers typical questions about what the Profile does. <Replace the link with a link to the actual FAQ page for the Profile>

The Profile Purchasing Template describes considerations when purchasing equipment to deploy this Profile. <Replace the link with a link to the actual Purchasing page for the Profile>

Implementer Information

The Profile Implementation Template provides additional information about implementing this Profile in software. <Replace the link with a link to the actual Implementation page for the Profile>

Reference Articles

<List References (good and bad) (with link if possible) to Journal Articles that mention IHE's work (and hopefully include some analysis) >


This page is based on the Profile Template


<Delete this Category Templates line since your Profile page is no longer a template.>