Japanese Journal of Medical Physics (Igakubutsuri)
Online ISSN : 2186-9634
Print ISSN : 1345-5354
ISSN-L : 1345-5354
Methodology development for quantitative optimization of security enhancement in medical information systems -Case study in a PACS and a multi-institutional radiotherapy database -
Kiyofumi HanedaTokuo UmedaTadashi KoyamaHajime HarauchiKiyonari Inamura
Author information
JOURNAL FREE ACCESS

2002 Volume 22 Issue 4 Pages 302-317

Details
Abstract

The target of our study is to establish the methodology for analyzing level of security requirements, for searching suitable security measures and for optimizing security distribution to every portion of medical practice. Quantitative expression must be introduced to our study as possible for the purpose of easy follow up of security procedures and easy evaluation of security outcomes or results.
Results of system analysis by fault tree analysis (FTA) clarified that subdivided system elements in detail contribute to much more accurate analysis. Such subdivided composition factors very much depended on behavior of staff, interactive terminal devices, kinds of service, and routes of network. As conclusion, we found the methods to analyze levels of security requirements for each medical information systems employing FTA, basic events for each composition factor and combination of basic events. Methods for searching suitable security measures were found. Namely risk factors for each basic event, number of elements for each composition factor and candidates of security measure elements were found. Method to optimize the security measures for each medical information system was proposed, Namely optimum distribution of risk factors in terms of basic events were figured out, and comparison of them between each medical information systems became possible.

Content from these authors
© The Japan Society of Medical Physics
Previous article Next article
feedback
Top