PubMed Health⌕ Search

SEARCH · PubMed Health

Results for “secured computing”

Explore indexed PubMed citations for clinical trials, systematic reviews and public health research. Read source abstracts and follow each citation to its original PubMed record.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 613 records · Page 34Linked to original sources

Applying your corporate compliance skills to the HIPAA security standard.

Compliance programs are an increasingly hot topic among healthcare providers. These programs establish policies and procedures covering billing, referrals, gifts, confidentiality of patient records, and many other areas. The purpose is to help providers prevent and detect violations of the law. These programs are voluntary, but are also simply good business practice. Any compliance program should now incorporate the Health Insurance Portability and Accountability Act (HIPAA) security standard. Several sets of guidelines for development of compliance programs have been issued by the federal government, and each is directed toward a different type of healthcare provider. These guidelines share certain key features with the HIPAA security standard. This article examines the common areas between compliance programs and the HIPAA security standard to help you to do two very important things: (1) Leverage your resources by combining compliance with the security standard with other legal and regulatory compliance efforts, and (2) apply the lessons learned in developing your corporate compliance program to developing strategies for compliance with the HIPAA security standard.

Computer Security↗

Health informatics for improving the Dutch healthcare system.

Some recent developments around the organisation of ICT applications in healthcare in the Netherlands are discussed, in relation with the installation of a new National ICT Institute for Healthcare (NICTIZ). Some examples are given, especially from the field of Quality Assurance and Information Security.

Computer Security↗

A monitoring/auditing mechanism for SSL/TLS secured service sessions in Health Care Applications.

This paper analyzes the SSL/TLS procedures and defines the functionality of a monitoring/auditing entity running in parallel with the protocol, which is decoding, checking the certificate and permitting session establishment based on the decoded certificate information, the network addresses of the endpoints and a predefined access list. Finally, this paper discusses how such a facility can be used for detection impersonation attempts in Health Care applications and provides case studies to show the effectiveness and applicability of the proposed method.

Computer Communication Networks↗

[Filmless documentation and image distribution to referring physicians exemplified by a radiologic community practice].

In healthcare, cost effectiveness as well as the quality of examinations and procedures are subjected to quickly increasing expectations and demands: we like to demonstrate how the resulting challenges and problems can be met with implementation of modern information technology. Analysing the respective demands (pattern of quantities) and choosing the adequate technical solution/technical approach, we found filmless reading and the usage of digital image distribution to communicate with referring physicians to be cost effective as well as of higher quality. Special attention should be paid to the rigorous maintenance of data security and access. Today's information technology allows individual adjustment to the respective size and requirements of a radiological department or practice for filmless reading and digital image distribution. Working with the systems as a matter of routine and using all of the expanding technological possibilities, an important improvement of service and quality can be achieved. Amortisation will be obtained despite high investments, due to the subsequent savings in personal- and enterprise costs.

Computer Security↗

Cryptography with DNA binary strands.

Biotechnological methods can be used for cryptography. Here two different cryptographic approaches based on DNA binary strands are shown. The first approach shows how DNA binary strands can be used for steganography, a technique of encryption by information hiding, to provide rapid encryption and decryption. It is shown that DNA steganography based on DNA binary strands is secure under the assumption that an interceptor has the same technological capabilities as sender and receiver of encrypted messages. The second approach shown here is based on steganography and a method of graphical subtraction of binary gel-images. It can be used to constitute a molecular checksum and can be combined with the first approach to support encryption. DNA cryptography might become of practical relevance in the context of labelling organic and inorganic materials with DNA 'barcodes'.

Computer Communication Networks↗

Implementation and integration of regional health care data networks in the Hellenic National Health Service.

BACKGROUND: Modern health care is provided with close cooperation among many different institutions and professionals, using their specialized expertise in a common effort to deliver best-quality and, at the same time, cost-effective services. Within this context of the growing need for information exchange, the demand for realization of data networks interconnecting various health care institutions at a regional level, as well as a national level, has become a practical necessity. OBJECTIVES: To present the technical solution that is under consideration for implementing and interconnecting regional health care data networks in the Hellenic National Health System. METHODS: The most critical requirements for deploying such a regional health care data network were identified as: fast implementation, security, quality of service, availability, performance, and technical support. RESULTS: The solution proposed is the use of proper virtual private network technologies for implementing functionally-interconnected regional health care data networks. CONCLUSIONS: The regional health care data network is considered to be a critical infrastructure for further development and penetration of information and communication technologies in the Hellenic National Health System. Therefore, a technical approach was planned, in order to have a fast cost-effective implementation, conforming to certain specifications.

Computer Communication Networks↗

Flexible software architecture for user-interface and machine control in laboratory automation.

We describe a modular, layered software architecture for automated laboratory instruments. The design consists of a sophisticated user interface, a machine controller and multiple individual hardware subsystems, each interacting through a client-server architecture built entirely on top of open Internet standards. In our implementation, the user-interface components are built as Java applets that are downloaded from a server integrated into the machine controller. The user-interface client can thereby provide laboratory personnel with a familiar environment for experiment design through a standard World Wide Web browser. Data management and security are seamlessly integrated at the machine-controller layer using QNX, a real-time operating system. This layer also controls hardware subsystems through a second client-server interface. This architecture has proven flexible and relatively easy to implement and allows users to operate laboratory automation instruments remotely through an Internet connection. The software architecture was implemented and demonstrated on the Acapella, an automated fluid-sample-processing system that is under development at the University of Washington.

Automation↗

Determination of user requirements for the secure communication of electronic medical record information.

Health professionals need to have accurate patient data in order to make the right diagnosis and to give an optimal treatment. In many cases, the 'medical' record, whether in electronic form or paper form is distributed over several health care providers and health care enterprises. Technically, there are several ways to provide access to remote record information or parts thereof. Legislation however puts restrictions on the communication of personal information in order to protect the privacy of the patient. This paper gives an overview of requirements and constraints when communicating electronic medical record information and summarises the findings of the SEMRIC project in determining requirements from a number of practical cases.

Computer Communication Networks↗

Integrated web-based viewing and secure remote access to a clinical data repository and diverse clinical systems.

The advent of the World-Wide-Web protocols and client-server technology has made it easy to build low-cost, user-friendly, platform-independent graphical user interfaces to health information systems and to integrate the presentation of data from multiple systems. The authors describe a Web interface for a clinical data repository (CDR) that was moved from concept to production status in less than six months using a rapid prototyping approach, multi-disciplinary development team, and off-the-shelf hardware and software. The system has since been expanded to provide an integrated display of clinical data from nearly 20 disparate information systems.

Computer Graphics↗

Model-based design and implementation of secure, interoperable EHR systems.

For designing and implementing secure, interoperable, portable, and future-proof EHR systems, a comprehensive and standardized methodology supported by appropriate tools has to be established and applied. Based on the component paradigm, the ISO Reference Model - Open Distributed Processing has been used to describe the different views on information systems deploying the appropriate vocabulary for each single model view. The concepts considered rank from legal, organizational, and functional up to technical aspects of systems. The harmonization of vocabularies can be performed by meta-languages. The approach has been demonstrated for the model-based design, implementation and maintenance of a clinical study distributed over the Internet.

Computer Security↗

[Internet technology for clinical applications in a digital radiography department].

PROBLEM: To provide an overview and to assess the clinical feasibility of Internet technology-based systems for hospital-wide image and report distribution as well as for video conferencing. METHODS: The paper describes the theoretical concept behind, the various technical approaches and the experience gained from different systems. RESULTS: Image and report distribution: Advantages include the universal availability of images and reports inside and outside hospitals; ease of use; security features; image and report integration; cost savings by reducing support and training efforts and by optimising available hardware. The main critical issues are performance and workflow integration with RIS and PACS. Video conferencing: main advantages are the standardised, software-based approach and the low investments for hard- and software. Depending on the desired usage the communication performance can be seen as inappropriate. CONCLUSION: Today, Internet technology-based systems appear to satisfy the main clinical needs in radiology. The mentioned drawbacks could be eliminated by means of modified software implementation and focused standardisation efforts. Considering the numerous advantages of these systems a further distribution can be expected for the future.

Communication↗

Multiscale fragile watermarking based on the Gaussian mixture model.

In this paper, a new multiscale fragile watermarking scheme based on the Gaussian mixture model (GMM) is presented. First, a GMM is developed to describe the statistical characteristics of images in the wavelet domain and an expectation-maximization algorithm is employed to identify GMM model parameters. With wavelet multiscale subspaces being divided into watermarking blocks, the GMM model parameters of different watermarking blocks are adjusted to form certain relationships, which are employed for the presented new fragile watermarking scheme for authentication. An optimal watermark embedding method is developed to achieve minimum watermarking distortion. A secret embedding key is designed to securely embed the fragile watermarks so that the new method is robust to counterfeiting, even when the malicious attackers are fully aware of the watermark embedding algorithm. It is shown that the presented new method can securely embed a message bit stream, such as personal signatures or copyright logos, into a host image as fragile watermarks. Compared with conventional fragile watermark techniques, this new statistical model based method modifies only a small amount of image data such that the distortion on the host image is imperceptible. Meanwhile, with the embedded message bits spreading over the entire image area through the statistical model, the new method can detect and localize image tampering. Besides, the new multiscale implementation of fragile watermarks based on the presented method can help distinguish some normal image operations such as JPEG compression from malicious image attacks and, thus, can be used for semi-fragile watermarking.

Algorithms↗

Privacy enhancing techniques - the key to secure communication and management of clinical and genomic data.

OBJECTIVES: To introduce some of the privacy protection problems related to genomics based medicine and to highlight the relevance of Trusted Third Parties (TTPs) and of Privacy Enhancing Techniques (PETs) in the restricted context of clinical research and statistics. METHODS: Practical approaches based on two different pseudonymisation models, both for batch and interactive data collection and exchange, are described and analysed. RESULTS AND CONCLUSIONS: The growing need of managing both clinical and genetic data raises important legal and ethical challenges. Protecting human rights in the realm of privacy, while optimising research potential and other statistical activities is a challenge that can easily be overcome with the assistance of a trust service provider offering advanced privacy enabling/enhancing solutions. As such, the use of pseudonymisation and other innovative Privacy Enhancing Techniques can unlock valuable data sources.

Computational Biology↗

Distributed certification application via a trusted dealer.

Distributed certification via threshold cryptography is much more secure than other ways to protect certification authority (CA)'s private key, and can tolerate some intrusions. As the original system such as ITTC, etc., is unsafe, inefficient and impractical in actual network environment, this paper brings up a new distributed certification scheme, which although it generates key shares concentratively, it updates key shares distributedly, and so, avoids single-point failure like ITTC. It not only enhances robustness with Feldman verification and SSL protocol, but can also change the threshold (t, k) flexibly and robustly, and so, is much more practical. In this work, the authors implement the prototype system of the new scheme and test and analyze its performance.

Algorithms↗

[Requirements for a teleradiology system. Experiences with the MEDICUS-2 field test].

During the Medicus field test we gained experience using the teleradiology system for almost daily teleconferences between a radiology department and clinics for internal medicine, urology, and gynecology. The existing system has a high degree of functionality. The full 12-bit data format is available using the DICOM protocol. A data security concept is implemented, ensuring data integrity, privacy and authentication of communication partners. This concept covers the areas of organization, technique, user training, and software implementation. A future system should be a general purpose radiology workstation covering viewing functionality, image manipulation, and digital archive access. Dedicated teleradiology features have to be a part. Specialized evaluation software, e.g. for dynamic MRI, should be integratable in a modular way. For data exchange with other systems and for the synchronization of teleconference sessions, the protocols should be independent of the network standard used (ISDN, Ethernet, ATM) and based on the DICOM protocol. Extensions of the existing standard are therefore necessary. Besides future technical developments, reimbursement for teleradiology must be accomplished.

Computer Communication Networks↗

Speaker verification using committee neural networks.

Security is a major problem in web based access or remote access to data bases. In the present study, the technique of committee neural networks was developed for speech based speaker verification. Speech data from the designated speaker and several imposters were obtained. Several parameters were extracted in the time and frequency domains, and fed to neural networks. Several neural networks were trained and the five best performing networks were recruited into the committee. The committee decision was based on majority voting of the member networks. The committee opinion was evaluated with further testing data. The committee correctly identified the designated speaker in (50 out of 50) 100% of the cases and rejected imposters in (150 out of 150) 100% of the cases. The committee decision was not unanimous in majority of the cases tested.

Algorithms↗

Automated monitoring of medical protocols: a secure and distributed architecture.

The control of the right application of medical protocols is a key issue in hospital environments. For the automated monitoring of medical protocols, we need a domain-independent language for their representation and a fully, or semi, autonomous system that understands the protocols and supervises their application. In this paper we describe a specification language and a multi-agent system architecture for monitoring medical protocols. We model medical services in hospital environments as specialized domain agents and interpret a medical protocol as a negotiation process between agents. A medical service can be involved in multiple medical protocols, and so specialized domain agents are independent of negotiation processes and autonomous system agents perform monitoring tasks. We present the detailed architecture of the system agents and of an important domain agent, the database broker agent, that is responsible of obtaining relevant information about the clinical history of patients. We also describe how we tackle the problems of privacy, integrity and authentication during the process of exchanging information between agents.

Artificial Intelligence↗

Distributed data processing for public health surveillance.

BACKGROUND: Many systems for routine public health surveillance rely on centralized collection of potentially identifiable, individual, identifiable personal health information (PHI) records. Although individual, identifiable patient records are essential for conditions for which there is mandated reporting, such as tuberculosis or sexually transmitted diseases, they are not routinely required for effective syndromic surveillance. Public concern about the routine collection of large quantities of PHI to support non-traditional public health functions may make alternative surveillance methods that do not rely on centralized identifiable PHI databases increasingly desirable. METHODS: The National Bioterrorism Syndromic Surveillance Demonstration Program (NDP) is an example of one alternative model. All PHI in this system is initially processed within the secured infrastructure of the health care provider that collects and holds the data, using uniform software distributed and supported by the NDP. Only highly aggregated count data is transferred to the datacenter for statistical processing and display. RESULTS: Detailed, patient level information is readily available to the health care provider to elucidate signals observed in the aggregated data, or for ad hoc queries. We briefly describe the benefits and disadvantages associated with this distributed processing model for routine automated syndromic surveillance. CONCLUSION: For well-defined surveillance requirements, the model can be successfully deployed with very low risk of inadvertent disclosure of PHI--a feature that may make participation in surveillance systems more feasible for organizations and more appealing to the individuals whose PHI they hold. It is possible to design and implement distributed systems to support non-routine public health needs if required.

Bioterrorism↗