PubMed Health⌕ Search

SEARCH · PubMed Health

Results for “secured computing”

Explore indexed PubMed citations for clinical trials, systematic reviews and public health research. Read source abstracts and follow each citation to its original PubMed record.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 451 records · Page 25Linked to original sources

Access control based on attribute certificates for medical intranet applications.

BACKGROUND: Clinical information systems frequently use intranet and Internet technologies. However these technologies have emphasized sharing and not security, despite the sensitive and private nature of much health information. Digital certificates (electronic documents which recognize an entity or its attributes) can be used to control access in clinical intranet applications. OBJECTIVES: To outline the need for access control in distributed clinical database systems, to describe the use of digital certificates and security policies, and to propose the architecture for a system using digital certificates, cryptography and security policy to control access to clinical intranet applications. METHODS: We have previously developed a security policy, DIMEDAC (Distributed Medical Database Access Control), which is compatible with emerging public key and privilege management infrastructure. In our implementation approach we propose the use of digital certificates, to be used in conjunction with DIMEDAC. RESULTS: Our proposed access control system consists of two phases: the ways users gain their security credentials; and how these credentials are used to access medical data. Three types of digital certificates are used: identity certificates for authentication; attribute certificates for authorization; and access-rule certificates for propagation of access control policy. Once a user is identified and authenticated, subsequent access decisions are based on a combination of identity and attribute certificates, with access-rule certificates providing the policy framework. CONCLUSIONS: Access control in clinical intranet applications can be successfully and securely managed through the use of digital certificates and the DIMEDAC security policy.

Certification↗

eCare and eHealth: the Internet meets health care.

Increasing use of the Internet by consumers in general is being reflected in greater reliance on this medium for health information and health care. Patients are consulting the Web for medical information and resources from databases that are generally accessible to the public as well as physicians. In addition, interactions between physicians and patients via e-mail present an opportunity for greater efficiency in medical practice. Though physicians have been somewhat reluctant to embrace this modality, it offers significant opportunities for enhancing patient care without undue liability. Issues of confidentiality and security of medical information are also discussed.

Community Participation↗

Patient-Centered Access to Secure Systems Online (PCASSO): a secure approach to clinical data access via the World Wide Web.

The Internet's World-Wide Web (WWW) provides an appealing medium for the communication of health related information due to its ease of use and growing popularity. But current technologies for communicating data between WWW clients and servers are systematically vulnerable to certain types of security threats. Prominent among these threats are "Trojan horse" programs running on client workstations, which perform some useful and known function for a user, while breaching security via background functions that are not apparent to the user. The Patient-Centered Access to Secure Systems Online (PCASSO) project of SAIC and UCSD is a research, development and evaluation project to exploit state-of-the-art security and WWW technology for health care. PCASSO is designed to provide secure access to clinical data for healthcare providers and their patients using the Internet. PCASSO will be evaluated for both safety and effectiveness, and may provide a model for secure communications via public data networks.

Computer Communication Networks↗

The AIM SEISMED guidelines for system development and design.

Discussion of the process of drafting guidelines that provide managers within the Health Care Establishments with guidance on how to ensure that safety, security and soundness aspects are taken care of in the development and design of new systems to be used within their establishments. The resulting guidelines focus on requirements for organisations which are involved in the development and design of (secure) information systems to be used in a health care environment, where confidentiality, integrity and availability of the stored data is of the utmost importance. Because of the importance of one European direction in constructing and maintaining secure environments we took the ITSEC criteria as the main guide.

Computer Security↗

[IT safety in medical networks--current problems and approach to solutions].

Designers and users of medical networks have to face strong requirements for data protection and security. Professional discretion and data protection laws allow the transfer of or access to patient data only in a therapeutic context. These data should also be protected from the network provider. Patients should be safe from any harm by faulty data or buggy procedures. On the other hand the security of the most used software products gets worse and worse. The use of the internet endangers more and more the integrity of the user's computer. The security requirements can be met only through strict care in planning, building, and configuring the infrastructure. Some concrete recommendations and guiding principles can immediately be realized. If these recommendations are followed, the internet can be of immense value for health care.

Computer Security↗

Forming a health care incident reporting scheme.

In this paper the initial design steps of an Incident Reporting Scheme for Health Care are presented. The results of a short survey for the determination of Health Care user needs and expectations from such a scheme are given. The paper outlines a concise description of the proposed system and presents the conceptual model of the IRS database, and the developed prototype version of this database. Finally, future steps and security issues are described.

Computer Security↗

Biomolecular optical data storage and data encryption.

The use of bacteriorhodopsin (BR) as an active layer in write-once-read-many optical storage is presented. This novel feature of BR materials may be used on a wide variety of substrates, among them transparent substrates but also paper and plastics. The physical basis of the recording process is polarization-sensitive two-photon absorption. As an example for this new BR application, an identification card equipped with an optical recording strip is presented, which has a capacity of about 1 MB of data. The recording density currently used is 125 kB/cm2, which is far from the optical limits but allows operation with cheap terminals using plastic optics. In the examples given, data are stored in blocks of 10 kB each. A special optical encryption procedure allows the stored data to be protected from unauthorized reading. The molecular basis of this property is again the polarization-sensitive recording mechanism. The unique combination of optical storage, photochromism, and traceability of the BR material is combined on the single-molecule level. BR introduces a new quality of storage capability for applications with increased security and anticounterfeiting requirements.

Bacteriorhodopsins↗

High speed digital circuits for medical communication; the MINCS-UH project.

In Japan, a high speed, bidirectional digital satellite communication system called Medical Information Network by Communications Satellite for University Hospitals is currently available in 30 national universities, and many programs, including clinical conferences, lectures and tutorials, have been broadcasted. Its characteristics are: (1) a state-of-the-art digital high-definition television system, (2) excellent security protection using digital encryption (3) bidirectional communications using two satellite circuits simultaneously, and (4) easy operability. High-quality motion images, and security protection mechanisms are essential for use in clinical medicine.

Computer Communication Networks↗

A real time patient monitoring system on the World Wide Web.

World Wide Web (Web) technology has become increasingly popular and successful, because it uses standard communication protocols and Hyper Text Markup Language(HTML), and is supported on multiple platforms. Innovations such as server push, secure socket layer and Java make it possible to use the Web as the basis for creating monitoring systems of dynamic processes. This paper presents a project, whose goal is to develop a Web based Intelligent on-line Monitoring system for Intensive Care Units (IMI). IMI has been tested and evaluated in an intensive care unit since October 1995, and the results are promising. After presenting the motivations of using Web technology, we present the system structure and the functionality of IMI as well as the testing and evaluation results. Security issues are also addressed.

Computer Communication Networks↗

In the palm of your hand.

The explosive growth of handheld personal digital assistants (PDAs) in health care has been nothing short of amazing. What applications--business and clinical--do these devices have in medicine, and what is their potential? PDAs are simple and intuitive; their applications require minimal interaction time, so they have minimal impact on work flow: the investment is small; and the lightweight form is relatively nonintrusive during a patient encounter. The devices are being used to capture charges for medical services at the point of care. Encounter capture, online prescription writing and other applications will soon come on the scene. This article discusses current and possible future uses for PDAs in health care, interfaces with other technologies and security concerns.

Computer Peripherals↗

FOIN: a nominative information occultation function.

This article is intended to show that a great amount of work has to (and will) be done in terms of security for the healthcare information system community. Some very promising results have already been obtained in France, especially at CNAMTS, for providing the required security and privacy of nominative information in the context of future electronic exchanges between private/public hospital and CNAMTS, the french biggest mandatory healthcare insurance. FOIN, a robust anonymisation function, is just an example of such recent progress that traduces the french national engagement towards more flexible interconnection between various authorised healthcare information systems in close conjunction with more and more reliable and secure procedural and technical requirements. Firstly, the legal and medical needs for so strong anonymisation functions are described; secondly, the most important security requirements of these sensible functions are detailed and, lastly, the main security and implementation features of FOIN are globally indicated.

Algorithms↗

Using a WWW-based mail user agent for secure electronic mail service for health care users.

WWW-based user interface is presented for secure electronic mail service for healthcare users. Using this method, communications between an electronic mail (WWW) server and users (WWW browsers) can be performed securely using Secure Socket Layer protocol-based Hypertext Transfer Protocol (SSL-HTTP). The mail can be encrypted, signed, and sent to the recipients and vice versa on the remote WWW server. The merit of this method is that many healthcare users can use a secure electronic mail system easily and immediately, because SSL-compatible WWW browsers are widely used and this system can be made available simply by installing a WWW-based mail user agent on a mail server. We implemented a WWW-based mail user agent which is compatible with PEM-based secure mail and made it available to about 16,000 healthcare users. We believe this approach is effective in facilitating secure network-based information exchange among medical professionals.

Computer Communication Networks↗

Security model for picture archiving and communication systems.

The modern information revolution has facilitated a metamorphosis of health care delivery wrought with the challenges of securing patient sensitive data. To accommodate this reality, Congress passed the Health Insurance Portability and Accountability Act (HIPAA). While final guidance has not fully been resolved at this time, it is up to the health care community to develop and implement comprehensive security strategies founded on procedural, hardware and software solutions in preparation for future controls. The Virtual Radiology Environment (VRE) Project, a landmark US Army picture archiving and communications system (PACS) implemented across 10 geographically dispersed medical facilities, has addressed that challenge by planning for the secure transmission of medical images and reports over their local (LAN) and wide area network (WAN) infrastructure. Their model, which is transferable to general PACS implementations, encompasses a strategy of application risk and dataflow identification, data auditing, security policy definition, and procedural controls. When combined with hardware and software solutions that are both non-performance limiting and scalable, the comprehensive approach will not only sufficiently address the current security requirements, but also accommodate the natural evolution of the enterprise security model.

Computer Communication Networks↗