Securing a web-based teleradiology platform according to German law and "best practices"

Stud Health Technol Inform. 2009:150:730-4.

Abstract

The Medical Data and Picture Exchange platform (MDPE), as a teleradiology system, facilitates the exchange of digital medical imaging data among authorized users. It features extensive support of the DICOM standard including networking functions. Since MDPE is designed as a web service, security and confidentiality of data and communication pose an outstanding challenge. To comply with demands of German laws and authorities, a generic data security concept considered as "best practice" in German health telematics was adapted to the specific demands of MDPE. The concept features strict logical and physical separation of diagnostic and identity data and thus an all-encompassing pseudonymization throughout the system. Hence, data may only be merged at authorized clients. MDPE's solution of merging data from separate sources within a web browser avoids technically questionable techniques such as deliberate cross-site scripting. Instead, data is merged dynamically by JavaScriptlets running in the user's browser. These scriptlets are provided by one server, while content and method calls are generated by another server. Additionally, MDPE uses encrypted temporary IDs for communication and merging of data.

MeSH terms

  • Computer Security
  • Evidence-Based Practice*
  • Family Practice
  • Germany
  • Internet*
  • Radiology Information Systems / legislation & jurisprudence*
  • Radiology Information Systems / organization & administration
  • Teleradiology / legislation & jurisprudence*
  • Teleradiology / organization & administration