4 ms·
Not only is transport security mostly lacking in DICOM, but there is little to no notion of access control for records. And I'm not just talking DICOM, but the
by 7QdfBKNNfP 7y ago
Not only is transport security mostly lacking in DICOM, but there is little to no notion of access control for records. And I'm not just talking DICOM, but the apps themselves. It's no surprise though, when the DICOM standard has sections like this:
The DICOM Standard does not address issues of security policies, though clearly adherence to appropriate security policies is necessary for any level of security. The Standard only provides mechanisms that could be used to implement security policies with regard to the interchange of DICOM objects between Application Entities. For example, a security policy may dictate some level of access control. This Standard does not consider access control policies, but does provide the technological means for the Application Entities involved to exchange sufficient information to implement access control policies.
http://dicom.nema.org/medical/dicom/current/output/html/part15.html http://dicom.nema.org/medical/dicom/current/output/html/part...
The original DICOM TCP protocol requires that every device connected use an encrypted tunnel, and it's not easy to get all the device venders to agree on which ones to use, and then update their software. DICOM Web Services are a thing, and at least they would get HTTPS basically for free from their choice of web client and server.
HIPAA has been out since the 90's so we need to get more fines against the providers to make them implement confidentiality and access controls. It's actually the GDPR which is now driving access controls rather than HIPAA.
To be fair though, the DICOM folks are busy constantly trying to standardize new image data coming from innovations in the modalities (scanners).