NODE 9145966fMedical Records
"E. ALLEN SMITH" <EALLENSMITH@ocelot.Rutgers.EDU>Thu, 30 Nov 1995 03:05:49 +0800
Here's something that may make attempts such as Clipper a bit harder to
mandate, if this (non-escrowed, I believe) system becomes common. It should
also provide some pressure for relaxation of ITAR.
-Allen
(c) 1995 Copyright Nando.net
(c) 1995 Reuter Information Service
[...]
A security system developed at the University of California at San
Francisco prevents unauthorized access to x-rays and other medical
images transmitted via computer networks. A scientist described the
system in a report prepared for a radiologists' convention here.
[...]
Stephen Wong, assistant professor of radiology and bioengineering, and
colleagues developed the system for the picture archiving and
communications system used at the university to store and transmit
digitized medical images.
He said the authenticity of the images as well as patient
confidentiality must be protected.
"We have to make sure that the digital information and images are not
altered accidentally or surreptitiously," Wong said. "In addition,
x-rays and other imaging studies are part of the patient's medical
record and must be protected from unauthorized access."
The system uses mathematical formulas or codes to scramble the images
through encryption. It involves a "two-key" system -- one code enables
public access but a second, private code is required to unscramble the
information.
The private code, known only to the individual to whom the information
is transmitted, is 1,024 computer bits long, Wong said.
In emergencies where fast transmission is needed, the unscrambled
image is transmitted with a digital "fingerprint," a smaller code that
assures the intended viewer that no one has altered the original
image.
Wong prepared his report for the annual meeting of the Radiological
Society of North America.
NODE 36cc19a1Re: Medical Records
Adam Shostack <adam@lighthouse.homeport.org>Thu, 30 Nov 1995 03:31:34 +0800
It seems that they use signatures & hashes; nice work, a good
advance for medical records storage, but I'd ask how keys are managed,
and also what prevents me exploiting the 'hash-only' mode of sending
in what I'm cliaming to be is an emergency. (Not that these
invalidate the system; they're just interesting areas to work on.)
E. ALLEN SMITH wrote:
| "We have to make sure that the digital information and images are not
| altered accidentally or surreptitiously," Wong said. "In addition,
| x-rays and other imaging studies are part of the patient's medical
| record and must be protected from unauthorized access."
|
| The system uses mathematical formulas or codes to scramble the images
| through encryption. It involves a "two-key" system -- one code enables
| public access but a second, private code is required to unscramble the
| information.
|
| The private code, known only to the individual to whom the information
| is transmitted, is 1,024 computer bits long, Wong said.
|
| In emergencies where fast transmission is needed, the unscrambled
| image is transmitted with a digital "fingerprint," a smaller code that
| assures the intended viewer that no one has altered the original
| image.
--
"It is seldom that liberty of any kind is lost all at once."
-Hume
NODE 9a8d526eRe: Medical Records
hallam@w3.orgThu, 30 Nov 1995 04:22:49 +0800
Exactly! We need to point out that crypto is essential to protect us from
criminals. Some criminials may use crypto technology, just as they use faxes and
portable phones. But just because a portable phone could be used by a drug
dealer does not mean they should be illegal.
Jim Bizdos just pinned a rather cool poster to the wall of the 3rd florr coffee
lounge here at MIT today. It has a woman on a phone labeled "escrow enabled" and
then the spooks listening in from a post marked "escrow integrity center". The
motto is "A good Marketing Agency Listens to its Customers - We Hear You!"
Phill