PubMed Health⌕ Search

SEARCH · PubMed Health

Results for “secured computing”

Explore indexed PubMed citations for clinical trials, systematic reviews and public health research. Read source abstracts and follow each citation to its original PubMed record.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 541 records · Page 30Linked to original sources

Critical success factors for a hospital-wide PACS.

Since 1996 a picture archiving and communications system (PACS) is installed at the university hospital of Freiburg. The PACS is integrated in the hospital information system (HIS) and several modalities of different vendors are attached to it. During the implementation phase three critical factors to the success of our PACS installation where identified: the support of the workflow, the interface of the radiological information system (RIS) to the modalities, and the security policy to allow hospital-wide access to the images and results in the PACS.

Computer Security↗

Managing medical and insurance information through a smart-card-based information system.

The continuously increased mobility of patients and doctors, in conjunction with the existence of medical groups consisting of private doctors, general practitioners, hospitals, medical centers, and insurance companies, pose significant difficulties on the management of patients' medical data. Inevitably this affects the quality of the health care services provided. The evolving smart card technology can be utilized for the implementation of a secure portable electronic medical record, carried by the patient herself/himself. In addition to the medical data, insurance information can be stored in the smart card thus facilitating the creation of an "intelligent system" supporting the efficient management of patient's data. In this paper we present the main architectural and functional characteristics of such a system. We also highlight how the security features offered by smart cards can be exploited in order to ensure confidentiality and integrity of the medical data stored in the patient cards.

Computer Security↗

TealLock 5.20 security software program for handheld devices.

The TealLock has a simple graphic interface, and the program is user-friendly with well thought out options to customize security settings. The program is inexpensive and works seamlessly with the Palm OS platform's built-in basic Security application. The developer offers a 30-day free trial version and there is no downside to trying it to see if it meets your needs. It seems to be an effective security software program for psychiatrists who keep confidential and sensitive patient information on their PDAs. In keeping with HIPAA regulations, the TealLock bolsters security for protected health information stored on PDAs or other handheld devices by providing safeguards that address authentication, access control, encryption, and selected aspects of transmission.

Computer Security↗

GEMSS: privacy and security for a medical Grid.

OBJECTIVES: The GEMSS project is developing a secure Grid infrastructure through which six medical simulations services can be invoked. We examine the legal and security framework within which GEMSS operates. METHODS: We provide a legal qualification to the operations performed upon patient data, in view of EU directive 95/46, when using medical applications on the GEMSS Grid. We identify appropriate measures to ensure security and describe the legal rationale behind our choice of security technology. RESULTS: Our legal analysis demonstrates there must be an identified controller (typically a hospital) of patient data. The controller must then choose a processor (in this context a Grid service provider) that provides sufficient guarantees with respect to the security of their technical and organizational data processing procedures. These guarantees must ensure a level of security appropriate to the risks, with due regard to the state of the art and the cost of their implementation. Our security solutions are based on a public key infrastructure (PKI), transport level security and end-to-end security mechanisms in line with the web service (WS Security, WS Trust and SecureConversation) security specifications. CONCLUSION: The GEMSS infrastructure ensures a degree of protection of patient data that is appropriate for the health care sector, and is in line with the European directives. We hope that GEMSS will become synonymous with high security data processing, providing a framework by which GEMSS service providers can provide the security guarantees required by hospitals with regard to the processing of patient data.

Access to Information↗

Knowledge management and electronic care records: Incorporating social, legal and ethical issues.

Many challenges face developers of secure computer-based clinical systems but the technical problems are overshadowed by many obstacles, key amongst them being social and ethical issues. A sound Knowledge Management (KM) structure within clinical environments can recognise the responsibility of healthcare professionals to keep patient clinical data (for example, electronic care record (ECR) systems) secure. An arrangement is proposed that gives the most senior clinician in a healthcare facility the ultimate responsibility for security of clinical data held in the organisation. Ideally, the senior clinician would possess training and experience in information systems and their security. Contracts should be developed between healthcare facilities and their patients, defining the limits to the use and disclosure of clinical health data. However, we are observing increasing confusion about the term 'Knowledge Management' which may be limited both its efficacy and effectiveness. Health organisations are referring to the term in various contexts and health informatics articles frequently use the term and interpret it in diverse ways. Given the divergence of views, this paper will attempt to establish KM's efficacy for the implementation of electronic care record systems.

Computer Communication Networks↗

Security for decentralized health information systems.

Health care information systems must reflect at least two basic characteristics of the health care community: the increasing mobility of patients and the personal liability of everyone giving medical treatment. Open distributed information systems bear the potential to reflect these requirements. But the market for open information systems and operating systems hardly provides secure products today. This 'missing link' is approached by the prototype SECURE Talk that provides secure transmission and archiving of files on top of an existing operating system. Its services may be utilized by existing medical applications. SECURE Talk demonstrates secure communication utilizing only standard hardware. Its message is that cryptography (and in particular asymmetric cryptography) is practical for many medical applications even if implemented in software. All mechanisms are software implemented in order to be executable on standard-hardware. One can investigate more or less decentralized forms of public key management and the performance of many different cryptographic mechanisms. That of, e.g. hybrid encryption and decryption (RSA+DES-PCBC) is about 300 kbit/s. That of signing and verifying is approximately the same using RSA with a DES hash function. The internal speed, without disk accesses etc., is about 1.1 Mbit/s. (Apple Quadra 950 (MC 68040, 33 MHz, RAM: 20 MB, 80 ns. Length of RSA modulus is 512 bit).

Computer Communication Networks↗

Tools and techniques for the development of secure software.

System development projects in health care have not properly addressed the issues of availability, confidentiality and integrity. The safety critical aspects of health care have not been well recognised in the context of information systems, as opposed to medical devices where considerable effort has been made to ensure the 'correctness' of the device before it is authorized for use. Consideration should be given at the start of the development process to the particular requirements of the project and the project should be structured to ensure that the specific functional requirements for security are satisfied. In addition the development process itself must be conducted in a rigorous fashion in order to ensure-and to demonstrate--that the end product has the appropriate degree of 'correctness'. Suitable tools and techniques will be required to assist the efficiency and the integrity of this process.

Computer Security↗

Exploring the Internet frontier.

M-Bone, multimedia e-mail and teleconferencing are drawing providers to the Internet as a telemedicine network alternative. But security and reliability issues remain unresolved.

Computer Communication Networks↗

Design and implementation of a smart card based healthcare information system.

Smart cards are used in information technologies as portable integrated devices with data storage and data processing capabilities. As in other fields, smart card use in health systems became popular due to their increased capacity and performance. Their efficient use with easy and fast data access facilities leads to implementation particularly widespread in security systems. In this paper, a smart card based healthcare information system is developed. The system uses smart card for personal identification and transfer of health data and provides data communication via a distributed protocol which is particularly developed for this study. Two smart card software modules are implemented that run on patient and healthcare professional smart cards, respectively. In addition to personal information, general health information about the patient is also loaded to patient smart card. Health care providers use their own smart cards to be authenticated on the system and to access data on patient cards. Encryption keys and digital signature keys stored on smart cards of the system are used for secure and authenticated data communication between clients and database servers over distributed object protocol. System is developed on Java platform by using object oriented architecture and design patterns.

Computer Communication Networks↗

Clinical communication among health providers and systems using Web tools.

Three needs have driven the development of a Web front end to our legacy system. 1) A Web Intranet is needed to provide service for the quantity and diversity of platforms within our health care system. 2) Information transfer in our system is required in more than one format: in viewer-friendly, HTML format and in a database-friendly, down-loadable format. 3) The system encounters the need to electronically exchange information with providers that are not employees of our health care enterprise. This presents a problem with the authentication aspect of security for which we have devised a system to allow the carefully-monitored exchange of records with care providers who are "strangers" to our system.

Communication↗

Planning and implementing a microcomputer local-area network.

Factors to be considered in planning and implementing a microcomputer local-area network (LAN) in a pharmacy department are discussed. Reasons for implementing a LAN include the ability to share data, programs, and peripheral devices among multiple users. The network operating system may be full featured or a peer-to-peer system. Full-featured networks require a dedicated file server but are more powerful and versatile. The file server, if used, is the most important piece of equipment. Factors that affect the choice of a file server are the processor, the bus, memory and speed, the supplier, and the power supply. It is necessary to select network adapters and wiring and to decide whether any of the department's current computer equipment will be used in the network. Decisions must also be made about software. The equipment should be set up by the computer services department or a vendor. Two or more pharmacists must be appointed and trained as supervisors to manage the network, diagnose and correct problems, perform network backup, and guard against computer viruses. Security is a major concern because of the need for confidentiality, the licensure of software for only a limited number of users, and the risk of inadvertent alteration or erasure of data. Network users must be trained to use the system properly. Department managers should consider the need to access the LAN from computers outside the department and the possible incorporation of the LAN into a wide-area network. A microcomputer LAN can provide valuable information services, but careful planning is necessary to avoid pitfalls and to ensure that the network meets current and future needs.

Clinical Pharmacy Information Systems↗

Implementing security in a distributed web-based EHCR.

PURPOSE: In many countries there are initiatives for building an integrated patient-centric electronic health record. There are also initiatives for transnational integrations. These growing demands for integration result from the fact that it can provide improving healthcare treatments and reducing the cost of healthcare services. While in European highly developed countries computerisation in healthcare sector began in the 1970s and reached a high level, some developing countries, and Serbia among them, have started computerisation recently. This is why MEDIS (MEDical Information System) is aimed at integration itself from the very beginning instead of integration of heterogeneous information systems on a middle layer or using HL7 protocol. APPROACH: The implementation of a national healthcare information system requires using standards as integrated and widely accepted solutions. Therefore, we have started building MEDIS to meet the requirements of CEN ENV 13606 and CEN ENV 13729 standards. The prototype version has a distributed component-based architecture with modern security solutions applied. MEDIS has been implemented as a federated system where the central server hosts basic EHCR information about a patient, and clinical servers contain their own part of patients' EHCR. RESULTS: At present, there is an initial version of prototype planned to be deployed at first in a small community. In particular, open source API for X.509 authentication and authorisation has been developed. Our project meets the requirements for education in health informatics, including appropriate knowledge and skills on EHCR. The points included in this article have been presented on several national conferences and widely discussed. CONCLUSION: MEDIS has explored a federated, component-based EHCR architecture and related security aspects. In its initial version it shows acceptable performances and administrative simplicity. It emphasizes the importance of using standards in building EHCR in our country, in order to prepare it for future integrations.

Computer Security↗

Data security issues arising from integration of wireless access into healthcare networks.

The versatility of having Ethernet speed connectivity without wires is rapidly driving adoption of wireless data networking by end users across all types of industry. Designed to be easy to configure and work among diverse platforms, wireless brings online data to mobile users. This functionality is particularly useful in modern clinical medicine. Wireless presents operators of networks containing or transmitting sensitive and confidential data with several new types of security vulnerabilities, and potentially opens previously protected core network resources to outside attack. Herein, we review the types of vulnerabilities, the tools necessary to exploit them, and strategies to thwart a successful attack.

Computer Communication Networks↗

A WWW implementation of national recommendations for protecting electronic health information.

In March of 1997, the National Research Council (NRC) of the National Academy of Sciences issued the report, "For the Record: Protecting Electronic Health Information." Concluding that the current practices at the majority of health care facilities in the United States are insufficient, the Council delineated both technical and organizational approaches to protecting electronic health information. The Beth Israel Deaconess Medical Center recently implemented a proof-of-concept, Web-based, cross-institutional medical record, CareWeb, which incorporates the NRC security and confidentiality recommendations. We report on our WWW implementation of the NRC recommendations and an initial evaluation of the balance between ease of use and confidentiality.

Computer Communication Networks↗

An X Window system for statlab results reporting.

We have developed a system that receives "stat" results encoded in Health Level Seven from the Laboratory Information System, prints a report in destination Intensive Care Units (ICUs), and captures the data for review in a custom spreadsheet format at color X-terminals located in ICUs. Available services include a reference nomogram plot of arterial blood gas data, printed summaries, automated access to the Clinical Information System and a Medline database, electronic mail, a simulated electronic calculator, and general news and information. Security mechanisms include an audit trail of user activities on the system. Noteworthy technical aspects and non-technical factors impacting success are discussed.

Clinical Laboratory Information Systems↗

A systematic approach for analysis and design of secure health information systems.

A toolset using object-oriented techniques including the nowadays popular unified modelling language (UML) approach has been developed to facilitate the different users' views for security analysis and design of health care information systems. Paradigm and concepts used are based on the component architecture of information systems and on a general layered security model. The toolset was developed in 1996/1997 within the ISHTAR project funded by the European Commission as well as through international standardisation activities. Analysing and systematising real health care scenarios, only six and nine use case types could be found in the health and the security-related view, respectively. By combining these use case types, the analysis and design of any thinkable system architecture can be simplified significantly. Based on generic schemes, the environment needed for both communication and application security can be established by appropriate sets of security services and mechanisms. Because of the importance and the basic character of electronic health care record (EHCR) systems, the understanding of the approach is facilitated by (incomplete) examples for this application.

Computer Security↗

Real and imagined barriers to an electronic medical record.

We developed an electronic medical record for ambulatory patients as part of the integrated clinical information system at Beth Israel Hospital. During the four years since it was installed, clinicians have entered 76,060 patient problems, 137,713 medications, and 33,938 notes. Residents, who had to type notes in themselves, entered 49.5% of their notes into OMR. Several factors that we had predicted would be barriers to an electronic medical record, such as clinician reluctance to type or perform data entry, have not proved to be significant problems. Other anticipated barriers, such as difficulties with dual charting on paper during transition to an electronic medical record, have been realized. The major unexpected barrier that has been encountered is increased clinician concern about the privacy and security of full text notes relative to other data elements in the clinical information system. We have attempted to modify the electronic medical record so as to overcome some of these barriers.

Attitude to Computers↗