首页 | 本学科首页   官方微博 | 高级检索  
检索        


Business Model for the Security of a Large-Scale PACS,Compliance with ISO/27002:2013 Standard
Authors:Josefina Gutiérrez-Martínez  Marco Antonio Núñez-Gaona  Heriberto Aguirre-Meneses
Institution:1. Subdirección de Investigación Tecnológica, Instituto Nacional de Rehabilitación, Av. México Xochimilco 289, Col. Arenal de Guadalupe Tlalpan, 14389, México, D. F., Mexico
2. Departamento de Desarrollo Tecnológico, Instituto Nacional de Rehabilitación, Av. México Xochimilco 289, Col. Arenal de Guadalupe Tlalpan, 14389, México, D. F., Mexico
Abstract:Data security is a critical issue in an organization; a proper information security management (ISM) is an ongoing process that seeks to build and maintain programs, policies, and controls for protecting information. A hospital is one of the most complex organizations, where patient information has not only legal and economic implications but, more importantly, an impact on the patient’s health. Imaging studies include medical images, patient identification data, and proprietary information of the study; these data are contained in the storage device of a PACS. This system must preserve the confidentiality, integrity, and availability of patient information. There are techniques such as firewalls, encryption, and data encapsulation that contribute to the protection of information. In addition, the Digital Imaging and Communications in Medicine (DICOM) standard and the requirements of the Health Insurance Portability and Accountability Act (HIPAA) regulations are also used to protect the patient clinical data. However, these techniques are not systematically applied to the picture and archiving and communication system (PACS) in most cases and are not sufficient to ensure the integrity of the images and associated data during transmission. The ISO/IEC 27001:2013 standard has been developed to improve the ISM. Currently, health institutions lack effective ISM processes that enable reliable interorganizational activities. In this paper, we present a business model that accomplishes the controls of ISO/IEC 27002:2013 standard and criteria of security and privacy from DICOM and HIPAA to improve the ISM of a large-scale PACS. The methodology associated with the model can monitor the flow of data in a PACS, facilitating the detection of unauthorized access to images and other abnormal activities.
Keywords:Availability  BPMN  DICOM  HIPAA  Integrity
本文献已被 SpringerLink 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号