Page 426 |
DICOM PS3.17 2020a - Explanatory Information |
code="110153"
codeSystemName="DCM" displayName="Source Role ID"/>
</ActiveParticipant>
<AuditSourceIdentification
AuditEnterpriseSiteID="Hospital"
AuditSourceID="ReadingRoom"> <AuditSourceTypeCode code="1"/>
</AuditSourceIdentification>
<ParticipantObjectIdentification
ParticipantObjectID="1.2.840.10008.2.3.4.5.6.7.78.8"
ParticipantObjectTypeCode="2"
ParticipantObjectTypeCodeRole="3"
ParticipantObjectDataLifeCycle="1">
<ParticipantObjectIDTypeCode
code="110180"
codeSystemName="DCM" displayName="Study Instance UID"/>
<ParticipantObjectDescription>
<MPPS UID="1.2.840.10008.1.2.3.4.5"/> <Accession Number="12341234" />
<SOPClass UID="1.2.840.10008.5.1.4.1.1.2" NumberOfInstances="1500"/> <SOPClass UID="1.2.840.10008.5.1.4.1.1.11.1" NumberOfInstances="3"/>
</ParticipantObjectDescription>
</ParticipantObjectIdentification>
<ParticipantObjectIdentification
ParticipantObjectID="ptid12345"
ParticipantObjectTypeCode="1"
ParticipantObjectTypeCodeRole="1"> <ParticipantObjectIDTypeCode code="2"/> <ParticipantObjectName>John Doe</ParticipantObjectName>
</ParticipantObjectIdentification>
</AuditMessage>
The message describes a study transfer initiated at the request of Dr. Smith on the system at the IP address 192.168.1.2 to a system at IP address 192.168.1.5. The study contains 1500 CT SOP Instances and 3 GSPS SOP Instances. The audit report came from the audit source "ReadingRoom".
WW.2 Workflow Example
The following is an example of audit trail message use in a hypothetical workflow. It is not intended to be all-inclusive, nor does it cover all possible scenarios for audit trail message use. There are many alternatives that can be utilized by the system designer, or that could be configured by the local site security administrator to fit security policies.
As this example scenario begins, an imaging workstation boots up. During its start up process, a DICOM-enabled viewing application is launched by the start up sequence. This triggers an Application Activity message with the Event Type Code of (110120, DCM, "Application Start").
After start up, a curious, but unauthorized visitor attempts to utilize the reviewing application. Since the reviewing application cannot verify the identity of this visitor, the attempt fails, and the reviewing application generates a User Authentication message, recording the fact that this visitor attempted to enter the application, but failed.
Later,anauthorizeduseraccessesthereviewingapplication.Uponsuccessfullyidentifyingtheuser,thereviewingapplicationgenerates a User Authentication message indicating a successful login to the application.