GEHealthcare
MUSE™CardiologyInformationSystem
AdvancedSecurityGuide
SoftwareVersion8.0
2034539-048A
MUSECardiologyInformation
Systems
English
©2011GeneralElectricCompany.
AllRightsReserved.
TheinformationinthismanualonlyappliestoMUSE™CardiologyInformationSystemsoftwareversion8.Itdoesnotapplytoearlier
softwareversions.Duetocontinuingproductinnovation,specicationsinthismanualaresubjecttochangewithoutnotice.
MUSEandInSitearetrademarksownedbyGEMedicalSystemsInformationTechnologies,Inc.,aGeneralElectricCompanygoingtomarket
asGEHealthcare.Allothertrademarkscontainedhereinarethepropertyoftheirrespectiveowners.
Thedocumentpartnumberandrevisionappearatthebottomofeachpage.Therevisionidentiesthedocument’supdatelevel.The
revisionhistoryofthisdocumentissummarizedinthefollowingtable.
Revision
A
Date
29March2011 InitialRelease
Comment
2
MUSE™CardiologyInformationSystem
2034539-048A
29March2011
Contents
1 Introduction
SecurityFeaturesOverview........................................................................5
RegulatoryandSafetyInformation.............................................................5
SafetyConventions...................................................................................6
SafetyHazards.........................................................................................6
DocumentConventions...............................................................................6
TypographicalConventions.........................................................................6
Illustrations.............................................................................................7
Notes....................................................................................................7
2 MUSESecurityFeatures
ChecklistforMUSESecurityFeatures.........................................................9
MUSEFeaturesthatRequirePolicies/Procedures.....................................10
AccessControlSecurity.............................................................................11
ChangingtheDefaultSystemAccounts....................................................12
3 UserAuthentication
WindowsAuthenticationvs.MUSEAuthentication..................................13
AllowingMUSEAuthentication..................................................................13
UnattendedWorkstationSecurity............................................................14
4 Accounting/Logging
PrintLog....................................................................................................17
ChangeLog...............................................................................................17
EditChangeLog........................................................................................19
ProcessLog...............................................................................................19
MUSEAdministratorAccount......................................................................11
MUSEBackgroundAccount........................................................................12
SettingUpSecurityforanUnattendedWorkstation...........................................15
LoggingSystemSecurityEvents...............................................................20
2034539-048A
MUSE™CardiologyInformationSystem
3
5 MUSEWeb
ConguringIIStoLogWebsiteActivityonMUSEWeb.............................23
SettingupClientBrowserfor128-bitEncryption......................................24
6 Anti-VirusSoftwareandSecurityUpdates
Anti-VirusSoftware...................................................................................25
SecurityUpdates.......................................................................................25
A AppendixA—HIPAAOverview
HIPAAIntroduction....................................................................................27
HIPAALawOverview.................................................................................27
PrivacyandCondentiality.......................................................................29
ElectronicHealthTransactionsandCodeSetsStandards........................30
B AppendixB—SummaryofMUSESecurity
Introduction..............................................................................................33
C AppendixC—21CFRPart11Option
Introduction..............................................................................................47
ElectronicSignature..................................................................................47
Other/RelatedFeatures............................................................................48
4
MUSE™CardiologyInformationSystem
2034539-048A
Introduction
SecurityFeaturesOverview
TheMUSE™CardiologyInformationSystem(alsoreferredtoastheMUSEsystem)has
severalsecurityfeatureswhich,whenproperlyusedandcongured,cansupport
U.S.A.facilitiesincomplyingwiththeHealthInsurancePortabilityandAccountability
Act(HIPAA)SecurityandElectronicSignatureStandards.Thesenewsecuritystandards
weredesignedtoprotectpatient’shealthinformationfromimproperaccess,
alteration,andlosswhenitismaintainedortransmittedelectronically.
FormoreinformationontheHIPAASecurityandElectronicSignatureStandardsrefer
tothefollowinglink:
http://ge.com/hipaa
CompliancewiththeHIPAASecurityandElectronicSignatureStandardscannotbe
attainedsolelythroughtheuseofthesecurityfeaturesontheMUSEsystem.Sites
whichusetheMUSEsystemtomaintainandtransmitpatienthealthinformation,must
usethesecurityfeaturesinconjunctionwithasecurityplanwhichprovidesforthe
usertrainingandsecurephysicalaccesstopatienthealthinformation.
1
Thisdocumentisprovidedtodescribehowtoproperlysetupandusethesecurity
featuresontheMUSEsystem.Theresponsibilityofdevelopingthesecurityplanfor
usertrainingandsecurephysicalaccesstopatienthealthlieswiththeenduser .
Ifyouhaveanyquestionsorneedassistancewithanyofthesesecuritysetups,call
theGEHealthcareSupportCenterat1-800-558-7044.
RegulatoryandSafetyInformation
Thissectionprovidesinformationaboutthesafeuseandregulatorycomplianceof
thisdevice.Familiarizeyourselfwiththisinformationandreadandunderstandall
instructionsbeforeattemptingtousethisdevice.Thesystemsoftwareisconsidered
medicalsoftware.Assuch,itwasdesignedandmanufacturedtotheappropriate
medicalregulationsandcontrols.AnyexceptionsarenotedintheCompliance
Information-Exceptionssection.
NOTE:
Disregardingthesafetyinformationprovidedisconsideredabnormaluseof
thisdeviceandcouldresultininjury,lossofdata,andvoidanyexistingproduct
warranties.
2034539-048A
MUSE™CardiologyInformationSystem
5
Introduction
SafetyConventions
AHazardisasourceofpotentialinjurytoaperson,property,ortheproduct.
ThismanualusesthetermsDANGER,WARNING,andCAUTIONtopointouthazards
andtodesignateadegreeorlevelofseriousness.Familiarizeyourselfwiththe
followingdenitionsandtheirsignicance.
DenitionsofSafetyConventions
SafetyHazards
WARNING:
DocumentConventions
Safety
Convention
DANGER
WARNING
CAUTION
Denition
Indicatesanimminenthazard,which,ifnotavoided,willresultindeath
orseriousinjury.
Indicatesapotentialhazardorunsafepractice,which,ifnotavoided,
couldresultindeathorseriousinjury.
Indicatesapotentialhazardorunsafepractice,which,ifnotavoided,
couldresultinminorpersonalinjuryorproduct/propertydamage.
INCORRECTTREATMENT:Someofthecommunicationsprotocolsusedinthis
product(CSIandDCP)donotprovideencryptionorauthenticationatthistime.
TheseprotocolsareusedtosendclinicaldatatotheMUSEsystemfromECGcarts
andotherclinicaldevices.
Youshouldtakeappropriatestepstosecuretheprivacyofcommunicationson
yournetworkwhenusingthisproduct.
Thismanualusesthefollowingconventions.
TypographicalConventions
Convention Description
BoldText Indicateskeysonthekeyboard,texttoenter,orhardwareitemssuchas
Italicized-Bold
Text
CTRL+ESC
6
buttonsorswitchesontheequipment.
Indicatessoftwaretermsthatidentifymenuitems,buttonsoroptionsin
variouswindows.
Indicatesakeyboardoperation.Aplus(+)signbetweenthenamesoftwo
keysindicatesthatwhileholdingtherstkey,youshouldpressandrelease
thesecondkey.Forexample,PressCTRL+ESCmeanstopressandholdthe
CTRL keyandthenpressandreleasetheESCkey.
MUSE™CardiologyInformationSystem
2034539-048A
Convention Description
<space>
Enter
>
Introduction
Indicatesthatyoumustpressthespacebar.Wheninstructionsaregiven
fortypingaprecisetextstringwithoneormorespaces,thepointwhere
youmustpressthespacebarisindicatedas:<space>.Thisensuresthat
thecorrectnumberofspacesareinsertedinthecorrectpositionswithin
theliteraltextstring.Thepurposeofthe<>bracketsistodistinguishthe
commandfromtheliteraltextwithinthestring.
IndicatesthatyoumustpresstheEnterorReturnkeyonthekeyboard.Do
nottypeEnter.
Thegreaterthansymbol,orrightanglebracket,isaconcisemethodto
indicateasequenceofmenuselections.
Forexample,thestatement“Fromthemainmenu,selectSystem>Setup>
Options toopentheOptionActivationwindow”replacesthefollowing:
1. Fromthemainmenu,selectSystemtoopentheSystemmenu.
2. FromtheSystemmenu,selectSetuptoopentheSetupmenu.
3. FromtheSetupmenu,selectOptionstoopentheOptionActivation
window.
Illustrations
Notes
Allillustrationsinthemanualareprovidedasexamplesonly.Dependingonsystem
conguration,screensthatappearinthemanualmaydifferfromthescreensasthey
appearonyoursystem.
Allpatientnamesanddataarectitious.Anysimilaritytoactualpersonsis
coincidental.
Notesprovideapplicationtipsoradditionalinformationthat,whileuseful,arenot
essentialtothecorrectoperationoftheproduct.Theyarecalledoutfromthebody
textthroughaagwordandindentation,asfollows:
NOTE:
ThetiporadditionalinformationappearsindentedbelowtheNOTEagword.
2034539-048A
MUSE™CardiologyInformationSystem
7
Introduction
8
MUSE™CardiologyInformationSystem
2034539-048A
MUSESecurityFeatures
ChecklistforMUSESecurityFeatures
WhensettingupsecurityontheMUSEsystem,usethefollowingchecklistasa
reminderofsecurityfeaturesavailableonthesystemthataddressbothHIPAAand
FDA21CFRPart11requirements.Shadedfeaturesarenotrequiredfor21CFRPart11
compliance,butareconsideredgoodsecuritypractices.
2
FDA
Requirement
Authentication
&
Authorization
MUSEFeature
Access
Control
Security
User
Authentication
Unattended
Workstation
Security
Conguration Recommended Solution
MUSEUsers’
Password
Windows
Authentication
Logoutor
Lockout
ScreenSavers
MUSEAdmin,MUSEBkgnd,
andMUSEUsers’
passwordsshouldadhere
tofacility’sbestpracticeor
policy.
WindowsUsersshouldbe
mappedtoMUSEUsers.
AllowOnlyWindows
Authenticationoptionis
installed
Allworkstationsare
conguredtouseLogout
ScreenSaverorLockout
ScreenSaver.
1
r
r
r
1. EnablingthisfeaturerequirestheassistanceoftheGEHealthcareSupportCenter .Pleasedial1-800-558-7044torequestassistance
withactivatingthisfeature.
2034539-048A
MUSE™CardiologyInformationSystem
9
MUSESecurityFeatures
FDA
Requirement
Accounting&
Tracking
Web
Encryption&
Logging
DataIntegrity AntiVirus AntiVirus
MUSEFeature
Windows
EventLog
AuditTrails EditorSecurity EnabletheChangeLog.
Secure
Conguration
MUSEWeb
Conguration Recommended Solution
AuditPolicy TheWindowsutility“Audit
RemoteQuery
UserEntered
Destination
SSL
Encryption
SSLLogging
Software
Conguration
Policy”issetontheMUSE
serverandallworkstations
tologcertainevents.
TheRemoteQueryfeature
isdisabled.
TheUserEntered
Destination featureis
disabled.
TheMUSEleserverisset
touseSSLtoforce128-bit
encryption.
TheMUSEleserverisset
touseIIStologMUSEWeb
activities.
Virusprotectionsoftware
isinstalledandproperly
conguredontheMUSEle
serverandallworkstations.
r
r
r
r
r
r
r
MUSEFeaturesthatRequirePolicies/Procedures
ThefollowingMUSEfeaturesrequirepoliciesandprocedurestoachievesecurity
compliance.
PoliciesandProceduresRequiredforHIPAA&21CFRPartIISecurityCompliance
MUSEFeature
HL7Device
Folder,FTPFolder,Email PatientDataleavingthesystem,thus,no
MUSEAPI
Fax
WhyaPolicy/ProcedureisNeeded
PatientDataleavingthesystem,thus,no
longerchangeloggingorprotectingaccess
ofrecords.
longerchangeloggingorprotectingaccess
ofrecords.
Dataisleavingthesystemandmaynotbe
underanysecuritycontrol.
Faxedinformationcanbeviewedbyanyone,
thusapolicyshouldbeinplaceregarding
coverpages,andcondentialityofpatient
information.Workwithyourlegaldepartment
indevelopingthesepolicies/procedures.
10
MUSE™CardiologyInformationSystem
2034539-048A
PoliciesandProceduresRequiredforHIPAA&21CFRPartIISecurityCompliance
MUSESecurityFeatures
AccessControlSecurity
RemoteQuery
Allowinguserstoenterdestination Dataisleavingthesystemandmaynotbe
PoliciesandProceduresRequiredfor21CFRPartIISecurityCompliance
Feature
AcquiringECGsrequiresTechniciansto
enterIDNumberatcart
Dataisleavingthesystemandmaynotbe
underanysecuritycontrol.
underanysecuritycontrol.
WhyaPolicy/ProcedureisNeeded
Dataleavesthesystemandnotunderany
securitycontrol
TheMUSEsystemrequirestwoWindowsuseraccounts:
•MuseAdmin–usedbyGEHealthcareservicepersonneltoaccessandworkon
thesystem
•MuseBkgnd–usedbytheMUSEsystemtorunbackgroundWindowsServices
AccountnamesandpasswordsfortheMUSEAdminandMUSEBkgndWindowsuser
accountsaremanagedthroughWindowslikeanyotherWindowsuseraccount.
Bothaccountsshouldhavepasswordsthataresettoneverexpire.Ifthepasswords
change,GEHealthcareservicepersonnelmaynotbeabletologintothesystemto
providesupport,andthebackgroundserviceswillfailtostart,causingtheMUSE
systemtostopfunctioning.AllotherusersoftheMUSEsystemcanusetheirnormal
WindowsusercredentialstoaccesstheMUSEsystem.InsidetheMUSEapplication,
theusersaresetupwiththeirdomain\useraccountinformation.Nopassword
informationisrequiredwhenconguringaMUSEuser.Theuserpasswordscanbe
controlledorchangedthroughWindowsasrequired.
Thefollowingsectionsdescribestheseaccounts,howtheyareused,andthesystem
requirements.TheserequirementsaremetbyfollowingtheinstructionsintheMUSE
CardiologyInformationSystemInstallationManual .
MUSEAdministratorAccount
TheMuseAdminaccountisusedbyGEHealthcareservicepersonneltologintothe
MUSEsystemtoperforminitialsetupandconguration,andtoprovideongoing
serviceandsupport.
Thisaccountmustmeetthefollowingrequirements:
•NeedstobeamemberoftheWindowsAdministratorsGroupontheMUSEle
server.
•MustbeassignedasystemadministratorroleinSQLserver.Forinstructions
onaddingasystemadministratorroleinSQLserver,seetheMUSECardiology
InformationSystemInstallationManual .
•Shouldbeadomainaccountwheneverpossible.Asanalternative,itcanbean
accountlocaltotheMUSEleserver.
2034539-048A
MUSE™CardiologyInformationSystem
11
MUSESecurityFeatures
•BoththeaccountnameandpasswordfortheMUSEAdminaccountcanbe
•Thecustomershouldnotusethisaccountforanypurposeandshouldinstead
MUSEBackgroundAccount
TheMuseBkgndaccountisusedtostarttheMUSErelatedbackgroundservicesonthe
MUSEleserver.Thisaccountneedstomeetthefollowingrequirements:
•NeedstobeamemberoftheWindowsAdministratorsGroupontheMUSEle
•MustbeassignedasystemadministratorroleinSQLserver.Forinstructions
•Mustnotbesubjecttoanypoliciesthatwouldnotallowtheaccountthe“LogonAs
determinedbythecustomer,butmustbesharedwithGEHealthcareservice
personnelsothattheycanusethataccountwhentheyworkontheMUSEsystem.
Forinstructionsonchangingtheaccountnameandpassword,seetheMUSE
CardiologyInformationSystemServiceManual .
createanaccountforeachindividualuserusingthesystem.
server.
onaddingasystemadministratorroleinSQLserver,seetheMUSECardiology
InformationSystemInstallationManual .
Service”right,sincethatrightisarequirementfortheaccounttobeabletostart
theMUSErelatedbackgroundservices.
•Shouldbeadomainaccountwheneverpossible.Asanalternative,itcanbean
accountlocaltotheMUSEleserver.
•BoththeaccountnameandpasswordfortheMUSEAdminaccountcanbe
determinedbythecustomer,butmustbesharedwithGEHealthcareservice
personnelsothattheycanusethataccountwhentheyworkontheMUSEsystem.
Forinstructionsonchangingtheaccountnameandpassword,seetheMUSE
CardiologyInformationSystemServiceManual .
•Thecustomershouldnotusethisaccountforanypurposeandshouldinstead
createanaccountforeachindividualuserusingthesystem.
ChangingtheDefaultSystemAccounts
CustomersusingWindowsauthenticationmaychoosetochangetheWindows
accountnames,accountpasswords,orbothtoaddresssecurityissuesortocomply
withchangesinnetworkstandardsatanytime(see“WindowsAuthenticationvs.
MUSEAuthentication”onpage13).Thenameandpasswordchangesaremadeusing
theLocalUsersandGroupsfunctionoftheAdministrativeToolsontheMUSEle
server.Inaddition,severalcommandlineutilitiesmustberuntoensurethatthe
changesarereectedintheMUSEsystem.
CustomersusingMUSEauthentication,maychoosetochangethepasswordsforthe
defaultaccountsatanytime(see“WindowsAuthenticationvs.MUSEAuthentication”
onpage13).Theycannot,however ,changetheaccountnames.Thepassword
changesaremadeusingthestandardMUSEUserSetupfunction.
FordetailedinstructionsonchangingtheWindowsaccountnames,theWindows
accountpasswords,ortheMUSEaccountpasswords,refertotheMUSE™Cardiology
InformationSystemServiceManual .
12
MUSE™CardiologyInformationSystem
2034539-048A
UserAuthentication
MUSEprovidestwotypesofuserauthentication:
•WindowsAuthentication
•MUSEAuthentication
WindowsAuthenticationvs. MUSE
Authentication
UsingWindowsAuthenticationonaMUSEworkstationnotonlyeliminatesasecond
logonusingMUSEauthentication,butalsosupportsahigherlevelofsecurityasis
recommendedtomeetHIPAAcompliancestandards.
MUSEauthenticationismostcommonlyusedonaclientworkstationthatissharedby
multipleusers,andwherethoseusersdonotwanttologoutofWindowsandlogback
intoruntheMUSEapplicationandberecognizedasadifferentuser .Eachpersonthat
runstheMUSEapplicationonthesharedworkstationcanlogintoMUSEwiththeirown
usernameandpassword.TohelpmeetHIPAAcompliance,policiesandprocedures
willneedtobeinplacewhenusingMUSEauthentication.
3
UsingWindowsauthentication,usersarenotrequiredtologintotheMUSEapplication
separately.WhentheMUSEapplicationislaunched,MUSEwillautomaticallylogthem
inastheproperuser,basedontheuserthatisloggedintoWindowsonthatcomputer.
Windowsauthenticationsupportsahigherlevelofsecurityasrecommendedtomeet
HIPAAcompliancestandards.
AllowingMUSEAuthentication
Bydefault,thesystemallowseitherMUSEorWindowsauthentication.Todisable
MUSEauthenticationonthesystemsothatWindowsauthenticationcanbeused,
contacttheGEHealthcareSupportCenterat1-800-558-7044,orcontactyour
regionalsupportcenterifyouareoutsidetheUnitedStates.
IfMUSEauthenticationisallowed,itcanbeenabledatindividualworkstations
byaddingthefollowingswitchtotheshortcutthatisusedtolaunchMUSE:
-museauthenticate .
IfMUSEauthenticationisdisabledandausertriestologinusingMUSEauthentication,
amessagewillappearstatingMUSEauthenticationisnotenabled.
2034539-048A
MUSE™CardiologyInformationSystem
13
UserAuthentication
IfauserisloggedintotheMUSEsystemusingtheircorrectWindowsauthentication,
anerrormessageappears,buttheywillbeallowedintothesystem.
IfauserisloggedintotheMUSEsystemasadifferentuser,andlogsinusingMUSE
authentication,anerrormessageappearsandtheywillnotbeallowedintothesystem.
UnattendedWorkstationSecurity
Twooptionsareavailableforsettinguplogout/lockoutsecurityonworkstationsthat
areleftunattendedforaspeciedamountoftime:
•Logout—Whenaworkstationisinactive(nomouseorkeyboardinput)fora
speciedamountoftime,thecurrentuserwillbeloggedoffWindows,andthe
MUSEsessionwillend.
•Lockout—Whenaworkstationisinactiveforaspeciedamountoftime,the
screensaverselectedintheControlPanelisactivated.
Thefollowingtablesummarizesthesetwooptionsforunattendedworkstation
security.Besureyouunderstandhoweachoptionimpactstheuserbeforechoosing
oneofthem.Informallsystemusersabouthowtheunattendedworkstationsecurity
optionaffectstheiruseofthesystem.
DifferencesbetweentheTwoOptionsforUnattendedWorkstationSecurity
Item
Accesswillbeterminated
afterapredeterminedtime
ofinactivity
Requiresauthentication
tologbackintotheMUSE
system
Theworkstationislocked
Userscanunlockworkstation
TheMUSEapplicationexits
LogoutScreenSaver
WINEXIT
Yes Yes
Yes Yes
No Yes
N/A
Yes
LockoutScreenSaverLogon
withPasswordProtected
•Lastuser
•Administrator
•No,ifthelastuserunlocks
theworkstation
•Yes,iftheAdministrator
unlockstheworkstation
14
MUSE™CardiologyInformationSystem
2034539-048A
DifferencesbetweentheTwoOptionsforUnattendedWorkstationSecurity
UserAuthentication
Item
Loseunsavedchanges
Possibilityoflockingarecord
thatwasbeingeditedwhen
thescreensavertookcontrol.
2
.
LogoutScreenSaver
Yes
Yes
SettingUpSecurityforanUnattendedWorkstation
Therearetwowaysyoucansetupsecurityforanunattendedworkstation.
•WINEXITcanbeusedifyouarerunningWindowsXP .
•SettingupascheduledtaskcanbeusednomatterwhichWindowsversionyou
areusing.
ConguringtheWinexit.scrScreensaverforWindowsXP
IfyouarerunningWindowsXP,theWinexit.scrscreensaverforcestheusertoquit
programsandlogoffafterasetperiodofinactivity.Toinstallthewinexitscreensaver
onatypicalWindowsXPsystem,usethefollowinginstructionsortheinstructions
foundathttp://support.microsoft.com/kb/314999.
WINEXIT
LockoutScreenSaverLogon
withPasswordProtected
•No,ifthelastuserunlocks
theworkstation
•Yes,iftheAdministrator
unlockstheworkstation
•No,ifthelastuserunlocks
theworkstation
•Yes,iftheAdministrator
unlockstheworkstation
1. DownloadthelefromtheWindows2003ResourceKitat
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=
9D467A69-57FF-4AE7-96EE-B18C4790CFFD&=en,oruseWindowsExplorer
tolocatetheWinexit.scrleintheWindows2000ResourceKitfolderonyour
harddrive.
2. Right-clicktheWinexit.scrle,andthenclickInstall.
TheDisplayPropertiesdialogboxopenswiththeScreenSavertabactive.and
theLogoffScreenSaverentryisautomaticallyselected.
3. ClickSettings.
4. SelecttheForceapplicationterminationcheckboxtoforceprogramstoquit.
5. IntheCountdownfornsecondsbox,typethenumberofsecondsthelogoff
dialog boxwillappearbeforetheuserisloggedoff.
6. IntheLogoffMessagebox,typethemessagethatappearsduringthelogoff
countdown.
7. ClickOK.
8. IntheDisplayPropertiesdialogbox,clickPreview.
2. Ifarecordislocked,amessagewillbedisplayedindicatingtherecordisbeingusedbyanotherworkstation.Themessagewilldisplaythe
NodeIDoftheworkstationthathaslockedtherecord.Tounlocktherecord,auserwithsufcientprivilegescanlogontheworkstation
whichhaslockedtherecordandstarttheMUSEapplication.
2034539-048A
MUSE™CardiologyInformationSystem
15
UserAuthentication
9. ReviewtheAutoLogoffdialogbox.
10. ClickCancel.
11. ClickOKtosavethesettings.
AlternativetoWINEXIT
Theotherwaytologoffusersafterinactivityistousethepssshutdown.exeprogram
fromsysinternals.Thisprogramwilllogoutthecurrentlyloggedinuseronthe
systemwhereitisinstalled.Youcanusethesystemschedulertorunthistaskafter
thesystemhasbeenidle.
1. Logontohttp://technet.microsoft.com/en-us/sysinternals/bb897541.aspxfor
2. PlacetheleintotheC:\windowsfolder.
3. Scheduleataskasthelocaladministratorusingc:\windows\psshutdown.exe
4. UndertheScheduletab>ScheduleTask,selectWhenidle.
Itdisplaysthelogoffmessageandthecountdowntimer.
instructionsanddownloadthesysinternalspsshutdown.execommand.
-o-f .
5. IntheeldWhenthecomputerhasbeenidlefor,enterthenumberofminutes
beforeautomaticshutdown.
6. UndertheSettingstab,leavethe72hoursatthetopasis.SelectOnlystart
thetaskifthecomputerhasbeenidleforatleast: ,andenterthenumberof
minutesthatthecomputercanbeidle.
7. Leaveifthecomputerhasnotbeenidlethatlong,retryforupto:atzero.
8. Leaveallotherboxesbeyondthispointempty.
9. Exitthescreen.
16
MUSE™CardiologyInformationSystem
2034539-048A
Accounting/Logging
PrintLog
4
OutboundeventsrefertodatathatissentoutoftheMUSEsystem,suchaspatient
tests,reports,sendingoutlistsforprinting,andsoon.
Thesystemlogsthefollowingoutboundevents:
•PrintingtoPostscriptandPCLprinters
•Fax
•CSI
•Email
•HL7
ChangeLog
•Folder
•FTPFolder
TheseoutboundeventscanbeviewedinthePrintLog.ToopenthePrintLog,select
Status >PrintLog.
RefertotheMUSECardiologyInformationSystemsOperatorManualforinstructionson
conguringthePrintLog.
TheChangeLogtrackschangestopatientdataandmayfacilitatendingatest
thathadincorrectdataenteredonthedeviceandhassincebeencorrectedinthe
MUSEsystem.
TheChangeLogfunctionmustbeactivatedwithinSystem>Setup>Sites>Test
TypeSettings .AllchangesmadetoarecordappearintheChangeLog.Thisincludes
changestopatientdemographics,testmeasurements,anddiagnosticstatements
withintheinterpretivewindow.
NOTE:
YoucannotviewtheChangeLogattheSerialComparisonlayout.
1. AttheEditlist,openapatienttest.
2. SelecttheClericaltab.
2034539-048A
MUSE™CardiologyInformationSystem
17
Accounting/Logging
3. ClicktheChangeLogbuttontoopentheChangeLogwindow.
Eachtimeyoumakeachangetoapatienttest(includingchangesmadeatthe
HIS),thechangesarerecorded.Afteratestisupdatedorsavedinthedatabase,
thechangesaresavedbydate.
4. Toviewthechangelogdetails,double-clickonachangeditemtoexpandit.
TheChangeLogEntryDetailswindowopens.
Thiswindowishelpfulwhendisplayinglongeldssuchasthediagnosis.
18
MUSE™CardiologyInformationSystem
2034539-048A
5. ToprinttheChangeLog:
6. Toenablethedisplayofsupplementaltesteldsthataregeneratedand
7. ClickClosewhennishedtoexittheChangeLog.
EditChangeLog
TheEditChangeLogisalistofchangesmadetoatest’spatientID,name(rst
andlast),location,dateandtime.Thelogexiststofacilitatendingatestthathad
incorrectdataenteredonthedeviceandwascorrectedinthesystem.
Accounting/Logging
a. ClickthePrintbutton
TheSelectDeviceandFormattingOptionswindowopens.
b. MaketheappropriatechoicesandclickOKtoprintthelog.
maintainedbytheMUSEsystem,selecttheShowChangesforVirtualFields
checkbox.Examplesofsomeoftheseeldsare:EditTime,EditDateand
identicationcodesthatuniquelyidentifythepatienttotheMUSEsystem.
ProcessLog
TheProcessLogisalistofalloftheprocessesthesystemran.Thislogincludes
processescurrentlyrunningandthosethatterminatedsuccessfully.Youcanidentify
currentprocessesbecausetheydonothaveanendtime.Processeswithanoldstart
timeandnoendtimehavemostlikelyfailedandcanbeinvestigatedforissues.
2034539-048A
MUSE™CardiologyInformationSystem
19
Accounting/Logging
LoggingSystemSecurityEvents
TheMUSEapplicationserverandworkstationsshouldbeconguredtologWindows
securityeventstotheWindowsViewer.Ateachleserverandworkstation,repeat
thefollowingstepstosetupthisaudit.
1. ClickStart>Programs>AdministrativeTools>LocalSecurityPolicy.
TheLocalSecuritySettingswindowopens.
2. SelectLocalPolicies>AuditPolicy.
3. Clickoneacheventandselectthecheckboxesindicatedinthefollowingtable.
Event
Auditaccountlogonevents
Auditaccountmanagement
Auditdirectoryserviceaccess
Auditlogonevents
Auditobjectaccess
Auditpolicychange
Auditprivilegeuse
Auditprocesstracking
Auditsystemevents
20
MUSE™CardiologyInformationSystem
Success
ü ü
ü ü
ü ü
ü ü
Failure
ü
ü
ü
ü
ü
2034539-048A
4. ClickOKtosaveyourchanges.
5. ClosetheLocalSecuritySettingswindow.
Accounting/Logging
2034539-048A
MUSE™CardiologyInformationSystem
21
Accounting/Logging
22
MUSE™CardiologyInformationSystem
2034539-048A
MUSEWeb
InternetInformationServices(IIS)isrequiredontheMUSEWebserver.Toaccessthe
MUSEWeb,theusermusthavetheirbrowserconguredfor128-bitencryption.
Fordetailedprocedures,seetheMUSEWebServerInstructionGuidetoEnablingSSL.
ConguringIIStoLogWebsiteActivityonMUSE
Web
TheMUSEapplicationservershouldbeconguredtoenableloggingWebsiteactivity
asfollows:
1. Right-clickMyComputerandselectManage.
2. ExpandServices&Application>InternetApplicationServices>Websitesin
thelistfoundintheTreelist(leftpanel).
3. Right-clickonMUSEWebsiteandselectPropertiesintheWebsitetab.
4. MakesurethattheEnableLoggingcheckboxisselectedintheWebsitetab.
5. ForActivelogformat,makesureitisW3CExtendedLogFileFormat.
6. SelectProperties.....
a. SelecttheGeneraltab.
b. SelectWeeklyforNewLogTimePeriod.
c. MakesuretheLogledirectoryis%WinDir%\System32\LogFiles.
d. SelecttheAdvancedtab.
e. Add/delete/verifycheckmarkstoobtainthefollowingExtendedLogging
Options .
5
ü
ü
ü
ü
ü
2034539-048A
Date
Time
ClientIPAddress
UserName
ServiceName
ServerName
MUSE™CardiologyInformationSystem
ü
URIQuery
HttpStatus
Win32Status
BytesSent
BytesReceived
TimeTaken
23
MUSEWeb
ü
ü
f. ClickOKtoclosetheLoggingPropertieswindow.
g. ClickOKtoclosetheWebsitePropertieswindow.
ServerIP
ServerPort
Method Cookie
ProtocolVersion
UserAgent
Referred
SettingupClientBrowserfor128-bitEncryption
TheMUSEWebserverwillonlyallow128-bitencryptionaccesses.Userswillneedto
updatetheirInternetExplorer(IE)5.0or6.0tohave“HighEncryptionPack”installed.
NOTE:
TheHighEncryptionPackcanbedownloadedfromtheMicrosoftWebsite.
ThefollowingstepsdescribehowtodeterminetheIEencryptionlevel.
1. StartInternetExplorer.
2. SelectHelp>AboutInternetExplorer.
3. IfCipherStrengthislessthan128-bit,youwillneedtoinstallHighEncryption
Pack .
24
MUSE™CardiologyInformationSystem
2034539-048A
Anti-VirusSoftwareandSecurity
Updates
Anti-VirusSoftware
GEHealthcarehasvalidatedtheproperoperationoftheMUSEsystemwithNorton
Anti-VirusCorporateEditionandMcAfeeNetShieldinstalled.Eitherofthesetwovirus
protectionsoftwareapplicationscanbeinstalledonthesystemwithoutaffecting
functionorperformance.
Anti-virussoftwareisnotprovidedwiththeMUSEsystem.Itremainsthecustomer’s
responsibilitytoacquireandinstallanti-virussoftwareontheirMUSEsystemperthe
recommendationsofthemanufactureroftheanti-virussoftware.
SeetheMUSEPre-InstallationManualforadditionalinformationoninstallinganti-virus
softwareontheMUSEsystem.Whenproperlyused,anti-virussoftwarecanprotect
theMUSEsystemfromvirusinfectionandthesubsequentdatacorruptionwhichcan
resultfromavirusinfection.However,ifimproperlycongured,anti-virussoftware
cancausesystemdegradation.
6
SecurityUpdates
AlistofvirusesthatposeasignicantthreattoGEHealthcarecustomers’product
securityispostedontheGEHealthcareProductSecuritywebsite.
Asnewvulnerabilitiesandpotentialsecurityissuesarise,GEHealthcaremakesevery
efforttoquicklyidentifyandnotifycustomersofapprovedxes.Timeisrequired
forGEHealthcaretoidentifythevulnerability,testthex,andrunavalidationtest
ontheproductforsafetyandfunctionality.OnlyafterthisrigorousprocessdoesGE
Healthcarereleasetheofcialpatch.Whilewerecognizetheurgencytocorrectthese
problems,wemustensurethattheintegrityofthesystemisnotcompromised.
AftersecuritypatchesarevalidatedforspecicGEHealthcareproducts,the
informationisaddedtotheProductSecuritywebsite.Youcandownloadthepatch
directlyfromthewebsiteofthesoftwaremanufacturer(Microsoft,andsoforth)and
2034539-048A
MUSE™CardiologyInformationSystem
25
Anti-VirusSoftwareandSecurityUpdates
applyittoyourGEHealthcareproduct.Tocheckonthelatestinformationregarding
validatedsecuritypatches:
1. BrowsetotheGEHealthcareProductSecuritywebsite:http://
prodsecdb.gehealthcare.com
TheSingleSignOn(SSO)windowopens.
2. EnteryourSSOnumberandpasswordandclickLogIn..
IfyoudonothaveanSSOnumber,clicktheSignUplinktoobtainone.
3. UsethefeaturesontheGEHealthcareProductSecurityDatabaseWebsiteto
determinesecuritypatchesthatyoucanapplytoyoursystem.
26
MUSE™CardiologyInformationSystem
2034539-048A
AppendixA—HIPAAOverview
HIPAAIntroduction
ThefutureofhealthcareintheUnitedStateschangedonAugust2,1996when
theHealthInsurancePortabilityandAccountabilityAct(HIPAA)becamelaw.The
complexandfar-reachingfederallegislationsignicantlyaffectseverypersonand
organizationinvolvedinhealthcare.HIPAArulesspelloutstandardsandrequirements
forprotectingthecondentiality,security,andintegrityofallhealthinformation.
HIPAALawOverview
TheprimarygoalsofHIPAAarequanticationofconsumerhealthcarerightsalong
withimprovedprivacyandsecurityofmedicalrecords.Thetwomaincomponents
ofHIPAAareHealthCarePortabilityandAdministrativeSimplication.TheHealth
CarePortabilitylegislationbecameeffectivein1996.ThePortabilitypartofHIPAA
iswellunderstoodandwassuccessfullyimplementedbytheU.S.governmentand
themedicalindustryin1996and1997.ThePortabilitylegislationguaranteesthe
followingrightstohealthcareconsumers:
A
•Improvedavailabilityandaccessibilityofhealthinsurance
•Guaranteedrightofportabilityandcontinuityofhealthinsurancecoveragefor
individualsandgroups
•Prohibitionofdiscriminationbasedonhealthstatus
HIPAA’sAdministrativeSimplicationprovisioniscomposedoffourpartsandinvolves
thesehealthcareissues:
•Standardizationofelectronictransfersofpatienthealth,administrative,and
nancialdata
•Privacyandsecuritystandardsprotectingthecondentialityandintegrityofhealth
information
•Uniquehealthidentiersforindividuals,employers,healthplans,andhealthcare
providers
Eachpartwilleventuallyproduceavarietyofrulesandstandards.Manyoftherules
andstandardsareunderdevelopment.Astherulesandstandardsarenalized
2034539-048A
MUSE™CardiologyInformationSystem
27
AppendixA—HIPAAOverview
andbecomelaw,theywillhavedifferentcompliancedeadlines.Thefourpartsof
AdministrativeSimplicationare:
•ElectronicHealthTransactionsStandards
•UniqueIdentiers
•Security&ElectronicSignatureStandards
•Privacy&CondentialityStandards
HIPAA’scomplexityconfusescustomers.EventheHIPAAnamecausesconfusion.
RecentlythescopeofthetermHIPAAchanged.InitiallyHIPAAreferredtoallparts
ofthelegislation.CurrentusagenarrowsHIPAA’smeaningtotherulesgenerated
fromtheAdministrativeSimplicationsubsection.GEHealthcarefollowscommon
usage,andunlessotherwisenoted,HIPAAreferstotherulesdevelopedfromthe
AdministrativeSimplicationsubsection.
ThemaincomponentsofHIPAAandtheirrelationshipsarepresentedinthefollowing
diagram.
TheHIPAAcomponentwiththegreatestimpactonGEHealthcarecustomersisthe
PrivacyStandard,asdenedintheAdministrativeSimplicationsubsection.TheFinal
VersionofthePrivacyStandard,(StandardsforPrivacyofIndividuallyIdentiable
HealthInformation,45CFRParts160and164),waspublishedintheFederalRegister
onDecember20,2000.
TheHIPAAimplementationandenforcementschedulespansseveralyears.The
PrivacyStandardbecomesenforceableonApril14,2003.Thefollowingtable
summarizestheHHSreleasestatusandtimetablefortheHIPAArules.
28
MUSE™CardiologyInformationSystem
2034539-048A
AppendixA—HIPAAOverview
HIPAARulesandRulemakingTimetable
Standard PublicationDate FinalRuling Required
Compliance
1.Insurance
Portability
2.Electronic
Transactions&Code
3
Sets
3.Privacy&
Condentiality
4.NationalProvider
Identier
5.NationalEmployer
Identier
6.Security
7.NationalHealth
PlanIdentier
8. Claims
Enforcement
Procedures
9.NationalIndividual
Identier
4
August02,1996 August02,1996
May07,1998 August17,2000
November03,1999 December28,2000 April14,2003
May7,1998
June16,1998
August12,1998
InDevelopment
InDevelopment
Withdrawn
Expected2002
Expected2002
Expected2002
– –
– –
– –
July01,1997
October16,2003
–
–
–
PrivacyandCondentiality
TheFinalRuleforPrivacywaspublishedDecember28,2000.Compliancewillbe
requiredonApril14,2003formostcoveredentities.Ingeneral,privacyisaboutwho
hastherighttoaccesspersonallyidentiablehealthinformation.Therulecoversall
individuallyidentiablehealthinformationinthehandsofcoveredentities,regardless
ofwhethertheinformationisorhasbeeninelectronicform.ThePrivacystandards
limitthenon-consensualuseandreleaseofprivatehealthinformation;givespatients
newrightstoaccesstheirmedicalrecordsandtherighttoknowwhoelseaccessed
them;restrictmostdisclosureofhealthinformationtotheminimumneededforthe
intendedpurpose;establishesnewcriminalandcivilsanctionsforimproperuseor
disclosure;establishesnewrequirementsforaccesstorecordsbyresearchersand
others.
3. InJanuary,2002theBushAdministrationextendedthedeadlineforthe‘ElectronicTransactions&CodeSets’fromOct2002untilOctober
2003.
4. AlthoughtheHIPAAlawcalledforauniquehealthidentierforindividuals,HHSandCongressindenitelypostponedanyefforttodevelop
suchastandard.(HHSFactSheet,AdministrativeSimplication,2001)
2034539-048A
MUSE™CardiologyInformationSystem
29
AppendixA—HIPAAOverview
ThePrivacyandCondentialityregulationsincorporatevebasicpatientrightsrelated
tohealthcareinformation:
•ConsumerControl:Theregulationprovidesconsumerswithcriticalnewrightsto
controlthereleaseoftheirmedicalinformation.
•Boundaries:Withfewexceptions,anindividual’shealthcareinformationshouldbe
usedforhealthpurposesonly,includingtreatmentandpayment.
•Accountability:UnderHIPAA,forthersttime,therewillbespecicfederalpenalties
ifapatient’srighttoprivacyisviolated.
•PublicResponsibility:Thenewstandardsreecttheneedtobalanceprivacy
protectionswiththepublicresponsibilitytosupportsuchnationalprioritiesas
protectingpublichealth,conductingmedicalresearch,improvingthequalityof
care,andghtinghealthcarefraudandabuse.
•Security:Itistheresponsibilityoforganizationsthatareentrustedwithhealth
informationtoprotectitagainstdeliberateorinadvertentmisuseordisclosure.
ElectronicHealthTransactionsandCodeSets
Standards
Healthcareorganizationsroutinelystoreandtransmitmedicalinformationin
electronicformat.Electronicmedicalinformationismanipulatedthroughawide
varietyofencodingschemesandformats.Standardelectronicdatainterchange
improvestheefciencyofhealthcaredelivery.Nationalstandardsmakeiteasierfor
healthplans,doctors,hospitals,andotherhealthcareproviderstoprocessclaims
andothertransactions(HHSFactSheet,AdministrativeSimplication,2001).The
governmentandthemedicalindustryperceivestandardizedrepresentationsof
routinemedicaldataasbenecialforallpartiesinvolved.TheTransactionsStandards
mandatesuseofstandardizedelectronicformatsdevelopedbytheAmericanNational
StandardsInstitute(ANSI).TheCodeSetStandardsrequireuseofthemostcommonly
usedmedicalterminologycodesets.Finalstandardsforelectronictransactionsand
codesetswerereleasedinAugust2000.TheoriginalcompliancedeadlineofOctober
2002wasextendedtoOctober2003.
TheTransactionsStandardsspecifytheformatandcontentofthefollowingmedical
transactions:
•Healthclaimsorequivalentencounterinformationtransfer
•Healthclaimsattachments
•Enrollmentanddisenrollmentactionsinahealthplan
•Eligibilitystatusinahealthplan
•Healthcarepaymentandremittanceadvice
•Healthplanpremiumpayments
•Firstreportofinjury
•Healthclaimstatus
•Referralcerticationandauthorization
TheHealthorganizationsmustadoptstandardcodesetsforallhealthtransactions.
Codesetsarealphanumericidentiersrepresentingmedicaldata.Medicalcoding
systemsdescribediseases,injuries,andotherhealthproblems,aswellascauses,
symptoms,andactionstaken.Allpartiesexchangingmedicaltransactionsmust
30
MUSE™CardiologyInformationSystem
2034539-048A
AppendixA—HIPAAOverview
generateandacceptthesamecoding.Consistentcodingreducesmistakes,
duplicationofeffort,andcosts.HIPAAspeciesthefollowingcommonlyusedcode
sets:
•InternationalClassicationofDiseases,9thEdition,ClinicalModication,(ICD-9-CM),
Vols1,2,3
•NationalDrugCodes(NDC)
•CodeonDentalProceduresandNomenclature
•HealthCareFinancingAdministrationCommonProcedureCodingSystem(HCPCS)
•CurrentProceduralTerminology,FourthEdition(CPT-4)
TheTransactionsStandardsregulateinformationrelatedtohealthinsurancestatus
andremittance.GEHealthcarecardiologyproductsareclinicalsystemsandrarely
(ifever)processthehealthinsuranceandremittanceinformationaffectedbythe
TransactionsStandards.TheGEHealthcarecardiologyproductsarenotaffected
bytheTransactionsStandards.
TheCodeSetStandardsregulateuseofclinicalmedicalinformation.TheCodeSet
StandardsmayaffectGEHealthcarecardiologyequipment.Thecardiologyequipment
mayneedtosupportinputofcodesetvalueswhentestinformationisacquired.
2034539-048A
MUSE™CardiologyInformationSystem
31
AppendixA—HIPAAOverview
32
MUSE™CardiologyInformationSystem
2034539-048A
AppendixB—SummaryofMUSE
Security
Introduction
TheGEHealthcareProductSecuritywebsitehasthe HIMSSManufacturerDisclosure
StatementforMedicalDeviceSecurityorMDS2formfordifferentMUSEversions.
Thisformhassomeofthesameanswersasthosefoundinthissection.See
http://prodsecdb.gehealthcare.com/andloginwithyourSingleSignOn(SSO).Ifyou
donothaveanSSO,clicktheSignUplinktoobtainone.
ThefollowingtableisbasedonaMUSEsystemrunningversion8withouttheMUSE
Weboption.Thesetablesareindirectresponsetotheneedforsecurityfeaturesin
medicalsystems.GEHealthcareprovidestheseanswerstoassistyouindiscovering
yourrisksandinthecreationofyourmitigationplan.GEHealthcareprovidesthese
answerstothebestofourknowledgegiventherequirementsandcurrentstateof
theproduct.
B
ThisdocumentcontainsasummaryoftheLegalRequirementsoftheHealthInsurance
PortabilityandAccountabilityAct(HIPAA).Itisnotintendedaslegaladvice.Every
entitymustmakeitsownjudgmentregardingwhatwillberequiredtoenableitto
complywithHIPAA.GeneralElectricCompanyreservestherighttomakechangesin
specicationsandfeaturesshownherein,ordiscontinuetheproductdescribedatany
timewithoutnoticeorobligation.ContactyourGEHealthcarerepresentativefor
themostcurrentinformation.
BackgroundInformation
Enteranydescriptionthathelpsclarifythesecuritycontext.Thesecurity
contextwouldincludeproductoptions,environmentalconditions,andso
forth.
DoestheproductCapture,Store,orTransmitanyPatientidentiabledata?
Identifythearchitecturethatbestdescribesthisproduct:
WhatOperatingSystemisthisproductClientbasedon? WindowsXP
WhatOperatingSystemisthisproductbasedon(orinthecaseof
client/serverproducts–whatistheserver)?
WhichGSPPlatformdoestheproductutilize?
2034539-048A
MUSE™CardiologyInformationSystem
Unknown
Yes
3tier
application
WIN2003
None
33
AppendixB—SummaryofMUSESecurity
Cantheproductdisplayacustomersuppliedmessageonbootuporlogin? Yes&No,the
Doestheproductprovideatrainingmodethatallowsfortrainingwithout
corruptingtheoperationaldata?
Doesthisproducthaveacommunications/networkinterface(Notincluding
RemoteService)?
IdentifyalloftheCommunicationsinterfacesthatthisproducthas:
Ethernet
Token-Ring
ATM No
RF(802.11,bluetooth,otherradio)
COTSModem
OtherModem(egSDLC)
DirectSerial
Other
DoesthisproducthaveaDatabase?
application
cannot,but
Windowscan
atlogin
No
NetworkPresence
Yes
Yes
No
No
Yes
No
Yes
No
Yes,SQL
Server2005
IdentifyalloftheServices/Protocolstheproductprovides:
AnyDirectNetworkdbAccess(JDBC,ODBC,SQL,etc)
DICOM
HL7 Yes
XML Yes
HillTop
Unity
AdvantageNET
PostScriptorPCLprinters
SMTPorMAPI
FAX Yes
SNMP
FTP Yes
Telnet/Xwindows
Share(NFS,SMB,etc.)
CustomerAccessibleAPI?
Other
None No
Yes
No
Yes
No
No
Yes
Yes
Yes
No
Yes
Yes
No
34
MUSE™CardiologyInformationSystem
2034539-048A
AppendixB—SummaryofMUSESecurity
IdentifythemodesofNetworkCommunicationsofPatientIdentiableDatathatissupported
usingtheaboveprotocols:
SendPatientIdentiableDatatoothersystems
ReceivePatientIdentiableDatafromothersystems
ProvideaQueryinterfacethatothersystemscanusetoextractPatient
Yes
Yes
Yes
IdentiableData
DoesthisproducthaveaWebServer?
Yes
Transactions,CodeSets,andIdentiers
IdentifyalloftheCodeSetsthisproductsendsorreceives:
non-standardequivalentstoX12NTransactions(BillingEDItransactions)?
standardX12NTransactions(BillingEDItransactions)?
non-standardequivalentstoCDTcodesets(DentalServices)?
standardCDTcodesets(DentalServices)?
No
No
No
No
non-standardequivalentstoCPT4codesets(Physicianservices)?
standardCPT4codesets(Physicianservices)?
non-standardequivalentstoICD9codesets(Diseases,injuries,etc)?
standardICD9codesets(Diseases,injuries,etc)?
non-standardequivalentstoNDCcodesets(DrugsandBiotics)?
standardNDCcodesets(DrugsandBiotics)?
non-standardequivalentstoHCPCScodesets(otherservices)?
standardHCPCScodesets(otherservices)?
User(soft)conguredcodesthatmaybeconguredtoincludeCDT,CPT4,
ICD9,NDC,orHCPCS?
Noneoftheabove
Identifyalloftheidentiersthisproductsupports
“NationalProviderIdentier”(USAUniqueidentierforallindividuals
providinghealthcareservices)?
“NationalEmployerIdentier”(USAUniqueidentierforallhealthcare
facilities)?
“NationalPayerIdentier”(USAUniqueidentierforallinsurancecarriers)?
Noneoftheabove
No
No
No
No
No
No
No
No
Yes
No
No
No
No
Yes
UserIdentication
Doestheproductprovideforindividualidentication(accounts)ofclinical
Yes
users(excludingserviceusers)?
Whatisthemaximumnumberofaccounts(0<zero>==>theoretically
10,000
innite)
2034539-048A
MUSE™CardiologyInformationSystem
35
AppendixB—SummaryofMUSESecurity
Doestheproductsupportpasswordsforauthenticationoftheclinicalusers?
Doestheproductutilizetheoperatingsystemauthenticationforclinical
Yes
Yes
users?
Doestheproductplaceconstraintsonusername? 16char.max
Identifyalloftheauthenticationtechnologiesthisproductsupports
WindowsDomain
MicrosoftActiveDirectory
Non-WindowsKerberos
NIS/YP
CCOW
Other
Yes
Yes
No
No
No
No
None No
Duringlogindoestheproductinformtheuserofthelasttimethesystem
No
wasaccessedusingthatuseraccount?
Cantheuserauthenticationbeaugmentedbyabiometric,token,orother
Yes
methodbesidespasswords?
Identifyalloftheadvancedauthenticationtheproductsupports:
tokens
smartcards
badgereaders
writtensignatureverication
one-timepasswordgenerators
biometricidentiers
Certicateidentication
dial-backmodems
Other
Yes
Yes
No
No
No
No
No
No
No
None No
Howdoesthecustomergettheseadvancedauthenticationmethods?
Customer
supplied
UserAccountMaintenance
Identifyalloftheinformationassociatedwithauseraccount:
FullName
AdditionalIdentier
Title
Yes
Yes
Yes
Department No
PhoneNumber
E-mailAddress
36
MUSE™CardiologyInformationSystem
Yes
Yes
2034539-048A
AppendixB—SummaryofMUSESecurity
StreetAddress
FAXNumber
Other
None No
Whocanadministeruseraccounts? Multiple
IdentifyalloftheUserAdministrativecontrolssupported
AuditLogofallaccountchanges
Setanaccountinactivewithoutremovingtheaccount?
Forcealogoffofanactiveuser?
Automaticde-activationofanaccountonaspecieddateornumberof
days/time?
Automaticde-activationofanaccountafteracongurednumberofdays
ofnon-use?
Other
None No
IdentifyalloftheUserAccountReportssupported:
Listofalluseraccounts
Listofcurrentlyactiveusers
Listofalluseraccountswithlastuseddate/time
Other
None No
No
Yes
No
Accounts
No
Yes
No
No
No
No
Yes
Yes
No
No
Whenanaccountismarkedinactiveordeleteddoestheproductdisablein
Yes
real-timeanyactivesessionsusingthatID?
Doestheproductprovideatoolforbatchmanagementofuseraccounts?
Yes
Authorizations
Doestheproductsupportmultiplelevelsofaccesscontrolthatcanbe
Yes
assignedtouseraccounts?
Doestheproductsupportmultiplelevelsofaccesscontrolthatcanbe
Yes
assignedtogroupsofuseraccounts?
Identifyalloftheaccesscontrolrightsthatcanbeappliedtoauser:
ViewPatientIdentiableDataonscreen
PrintPatientIdentiableDatatopaperorlm
ModifyPatientIdentiableData
2034539-048A
MUSE™CardiologyInformationSystem
Yes
Yes
Yes
37
AppendixB—SummaryofMUSESecurity
ExportPatientIdentiableDatatoremovabledigitalmedia
Delete
Identifyallthemethodsbywhichtheaccesscontrolrightareapplied:
Accessatdatabaseviewlevel
Accessatlelevel
Accessatlesystemdirectorylevel
Time-of-Day
WeeklySchedule
Workstation(location)
Other
None No
Doesproducthidefunctionalitythattheuserdoesnothaverightsto(to
preventtheuserfromevenknowingafunctionalityexists)?
Doestheproductfurtherrestrictaccessbasedonpatientspecicconsent?
Auto-Logoff
IdentifyalloftheinactivityAutoLogoffcapabilitysupported:
UnprotectedScreenSaver
PasswordprotectedScreenSaver(screenblanking)
ApplicationLogout
Applicationblanking,withre-authenticationallowingcontinuation.
Other
None No
Cantheadministratoroverrideanyinactivityscreen/applicationblanking?
No
Yes
No
No
No
No
No
No
Yes
Yes
No
Yes
Yes
No
No
No
Yes
Identifyhowtheinactivitytimeoutcanbecongured:
SystemWide
Workstation(location)
No
Yes
Per-User Yes
DevicetoDeviceAuthentication
Identifyalloftheentityauthenticationthatisused,whencommunicating
andtheremoteuserisnotorcannotbeauthenticatedserialnumber
Macaddress
IPAddress
AE-Title
Processidentier
Taskidentier
UnidirectionalPKIcerticatechallenge(ex:simpleSSL)
38
MUSE™CardiologyInformationSystem
No
No
No
No
No
No
2034539-048A
AppendixB—SummaryofMUSESecurity
BidirectionalPKIcerticatechallenge(ex:clientandserverauthSSL)
Other
None Yes
LogAllSecurityEvents
IdentifyalloftheSecurityEventsthatcanbelogged:
MachineShutdown
MachineBoot
Applicationstart
Applicationstop
Networklink/connectionfailures
DataIntegrityfailure
SuccessfulUserLogin
FailedUserLogin
UserLogout Yes
Auto-Logoff
Forcedlogoffbyadministrator
Auserchangedtheirpassword
Anadminreset/clearedauserspassword
Attemptbyausertoaccessfunction/datathattheydonothaveaccessto
User/Groupaccountcreation
User/Groupaccountdeletion
User/GroupAccessrightsmodication
Other
None No
No
No
Yes
Yes
Yes
Yes
Yes
No
Yes
Yes
Yes
No
Yes
Yes
No
Yes
Yes
No
No
IdentifyallofthecontentsofaSecurityEventlogentry:
DateandTime
Timetomillisecondaccuracy
IdentieroftheUser
Identierofthedevice(workstation,IP ,orotherstationidentication)
Eventdescription
Arethesesecurityeventstrackedinadifferentlogthanpatientidentiable
Yes
No
Yes
Yes
Yes
Yes
datarelatedevents?
Onfailedauthenticationattempts,isthepasswordattemptedenteredinto
No
thelog?
Istheloglepersistent(NOTautomaticallyoverwrittenordeleted)? Notlimited
Isaccesstothislogrestrictedtoauthorizedindividuals?
Canthecustomerspecifythelistofeventstotrack?
2034539-048A
MUSE™CardiologyInformationSystem
Yes
No
39
AppendixB—SummaryofMUSESecurity
IdentifyallofthePatientIdentiableDataVieweventsthatcanbelogged:
Printouts
Exporttoles
LogAllPatientDataViews
Yes
Yes
Exporttoremovablemedia
Faxed
E-Mailed
Viewbybrowser
Viewbyclientapplication
Retrievedovernetworkprotocol(DICOM,XML,API,etc.)
De-identication
Other
None No
IdentifyallofthecontentsofaPatientIdentiableDataViewlogentry:
DateandTime
Timetomillisecondaccuracy
IdentierofUser
IdentierofDevice(workstation,IP,orotherstationidentication)
Identieroftheapplication
Identierofthefunctionwithintheapplication
IdenticationofthePatient
Howlongthedatawasdisplayed
Eventdescription
Yes
Yes
Yes
Yes
No
No
No
No
Yes
No
Yes
Yes
No
No
Yes
No
Yes
Istheloglepersistent(NOTautomaticallyoverwrittenordeleted)? Notlimited
Isaccesstothislogrestrictedtoauthorizedindividuals?
Canthecustomerspecifythelistofeventstotrack?
Yes
No
LogAllPatientDataModications
IdentifyallofthePatientIdentiableDataModicationeventsthatcanbe
logged:
Modicationofclinicaldatapriortoanalreport(diagnosis,medications,
Yes
observations,measurements,etc.)
Modicationoramendmentstoanalreport
Modicationofpatientdemographics
Modicationoftestdate,time,orsetupparameters
Modicationofdiagnosis
40
MUSE™CardiologyInformationSystem
Yes
Yes
Yes
Yes
2034539-048A
AppendixB—SummaryofMUSESecurity
None No
IdentifyallofthecontentsofaPatientIdentiableDataModicationlogentry
DateandTime
Timetomillisecondaccuracy
IdentierofUser
IdentierofDevice(workstation,IP,orotherstationidentication)
Yes
No
Yes
Yes
Identieroftheapplication
Identierofthefunctionwithintheapplication
IdenticationofthePatient
Eventdescription
Istheloglepersistent(NOTautomaticallyoverwrittenordeleted)? Notlimited
Isaccesstothislogrestrictedtoauthorizedindividuals?
Canthecustomerspecifythelistofeventstotrack?
LogAllChangestotheConguration
IdentifyalloftheCongurationChangeeventsthatcanbelogged:
ChangeofthesystemDateand/orTime
Installationofpatches,maintenance,FMI,hotx,etc.
IPAddressorothernetworkconguration
Analysisalgorithmparameters
Creation,modication,ordeletionofoutputdevices/API/interface/AE
Creation,modication,ordeletionofinputdevices/API/interface/AE
Other
None No
No
No
Yes
Yes
Yes
No
No
Yes
No
No
No
No
No
IdentifyallofthecontentsofaCongurationChangelogentry:
DateandTime
Timetomillisecondaccuracy
IdentierofUser
IdentierofDevice(workstation,IP,orotherstationidentication)
Identieroftheapplication
Identierofthefunctionwithintheapplication
Eventdescription
Yes
No
No
No
No
No
Yes
Istheloglepersistent(NOTautomaticallyoverwrittenordeleted)? Datelimited
Isaccesstothislogrestrictedtoauthorizedindividuals?
Canthecustomerspecifythelistofeventstotrack?
Yes
No
AuditLogViewing
2034539-048A
MUSE™CardiologyInformationSystem
41
AppendixB—SummaryofMUSESecurity
IsthereprotectionagainstALLmodicationofalllogles?
Isdeletionofalogtrackedinadifferentlog?
Isviewingofalogtrackedinadifferentlog?
Doestheproductprovidealertsbasedonautomatedadvancedlog
analysis?
Aretheaudittrailalertstrackedinalog?
Isthereatimesynchronizationfunctionincludedanddocumented?
AuditLogMining
Doestheproductsupporttheuseofthird-partyauditminingpackages?
Doestheproductsupportamechanismforcreatingatextbasedauditlog
(oraretheauditlogsalreadytext)?
DoestheproductintegratewithCAUnicenterorHPOpenview?
Doestheproductprovidesearchingtoolsfortheauditlogs?
Doestheproductprovidesortingtoolsfortheauditlogs?
IdentifyalloftheAuditTrailReportsthatcanbecreated:
Usersaccessingrecordswiththesamelastnameastheuser
Usersaccessingrecordswiththesameaddressastheiraddress
Accesstorecordsthathavenotbeenaccessedinalongtime
Accesstoanemployee’sownpatientdata
Accessestominor’spatientdata
Accessestoterminatedemployeespatientidentiabledata
Multipleloginattemptswithimproperauthentication
Allusersthathaveuseaspecicfunction
Allactivityofaspecicuser
Yes
No
No
No
No
Yes
No
No
No
No
Yes
No
No
No
No
No
No
No
No
No
Allaccessestoaspecicpatient
Allactivityfromaspecicworkstationorcommunicationslink
Allloginandlogoutactivitywithinaperiodoftime
Allloginfailures
AllAccesscontrolfailures
AllModicationstosecuritysettings
Allchangestoauthenticationsettings
Allaccessviaremoteserviceinterface
Allchangestotheaudittrailsconguration
Other
No
No
No
No
No
No
No
No
No
No
None Yes
CongurationLockdown&SecurityFixes
42
MUSE™CardiologyInformationSystem
2034539-048A
AppendixB—SummaryofMUSESecurity
IsthisOSconguredtomeetDOD-C2Compliance?
Haveunnecessaryservicesandprotocolsbeenturnedoff?
Haveunnecessaryservicesandprotocolsbeenuninstalled?
Aredefaultpasswordsdocumentedinanyformofmanual?
Arepasswordsthatarenotchangeableusedforadministrativeaccounts?
IstheSNMPcommunitynamesetto"public"or"private"?
Istheredocumentationavailablethatdescribestheservicesandprotocols
thatarenecessaryforproperoperationoftheproduct?
IsthecustomerfreetoapplyanyOperatingSystemortoolvendorxes
totheproduct?
DoestheM4releasecontainallsecurityxesfortheOS,database,orany
otherthirdpartytoolswithin6monthsoftheM4date?
ForOperatingSystems:
Thetypicaltimewindowbetweenwhenapatchisavailableandwhenit
canbeappliedtoacustomersystemis6months
Thetypicaltimewindowbetweenwhenapatchisavailableandwhenitcan
beappliedtoacustomersystemis12months
ThecustomercangetOSxesthatarenomorethan12monthsold
Isthisdatabaseconguredwiththeminimalservicesandprotocols
running?
No
Yes
Yes
Yes
No
No
Yes
No
Yes
Yes
Yes
Yes
Yes
ForDatabases:
Thetypicaltimewindowbetweenwhenapatchisavailableandwhenit
canbeappliedtoacustomersystemis6months
Thetypicaltimewindowbetweenwhenapatchisavailableandwhenitcan
beappliedtoacustomersystemis12months
Thecustomercangetdatabasexesthatarenomorethan12monthsold
Doestheproductincludeotherthirdpartytoolorapplication(Backup
software,SNMPagent,pcAnywhere,maintenancetool,MicrosoftOfce,etc.)
Forother3rdpartytools:
Thetypicaltimewindowbetweenwhenapatchisavailableandwhenit
canbeappliedtoacustomersystemis6months
Thetypicaltimewindowbetweenwhenapatchisavailableandwhenitcan
beappliedtoacustomersystemis12months
Thecustomercanget3rdpartytoolxesthatarenomorethan12months
old
ListanyThirdPartyApplications,Tools,Libraries,Drivers?
Yes
Yes
Yes
Yes
Yes
Yes
Yes
InSite2,
Antivirus
software,
Digiboard,IE,
MSDE,MDAC,
MMC,Disk
AntiVirus
2034539-048A
MUSE™CardiologyInformationSystem
43
AppendixB—SummaryofMUSESecurity
Areallproductreleasesandmaintenancereleasesscannedforany
maliciouscode(Virus,Worm,Trojan)?
IdentifyalloftheMaliciousCodedetectionsupported:
HostbasedIntrusionDetection
NortonAntiVirus
McAfeeAntiVirus
OtherWindowsAntiVirus
CustomersuppliedAntiVirussoftware
CustomeradministratedAntiVirusSignatureFiles
Tripwireorother
None No
IntegrityControlsonData
Doestheproductutilizetransparentend-to-enddataintegritycontrols?
(memoryparity,tcpchecksums,etc.)
Doestheproductenforceapplicationmanageddataintegritycontrolslike
objectchecksums?
DoestheproductsupportPKIbasedDigitalSignaturestomaintaindata
integrity?
Doestheproductenforcerequiredeldsduringdataentrytoensure
completenessofrecords?
Doestheproducthaveadataentryvalidationmechanismsuchasdouble
keyingofpatientidentiabledatatoensureaccuracyofthedataentered?
Doestheproductstorerejectedtransactionswiththereasonforthe
rejection?
Doestheproductensurethatdatabaseupdatesaredoneinafail-safeway?
IsthereanyOtherformofintegritycontrolprovided?
Yes
No
Yes
Yes
No
No
No
No
Yes
No
No
Yes
No
Yes
Yes
No
BackupandRecovery
Howmanypatientrecordsdoesthisproductstoreormanage? Unlimited
Identifyallthewaysthattheproductprotectsagainstdisasters/failures:
Exporttoremovablemedia
RAIDharddrive
backupofpatientdataonly(typicallytotape)
backupoffullsystem(typicallytotape)
UPS
Offsitemirroring
Near-linestorage
Other
No
Yes
Yes
Yes
Yes
No
No
No
None No
BackupandRecoveryproceduresaredocumented?
44
MUSE™CardiologyInformationSystem
Yes
2034539-048A
AppendixB—SummaryofMUSESecurity
CantheIntegrityandcompletenessofthebackupbeveriedbythe
operatorthroughtheuseofofinemeans?
Encryption
Isanyformofencryptionofpatientidentiabledatasupported(not
includingtheserviceinterface)?
De-Identication
Isthereabulkde-identicationfunctionalitythattheusercanuse?(not
serviceinterface)
DigitalSignatures
Doestheproductprovideforsomeformofelectronicacceptancestamp
onPatientIdentiableData?
DoestheproductprovideforaPKIbaseddigitalsignature?
DoestheproductsupportDICOMsupplement41DigitalSignature
Extensions?
Service
Isthereamethodthatservicecanusetoaccessthesysteminthecaseof
anemergencywhennormaladministrationisnotpossible?
Doestheproducthaveatleastoneloginspecicallyforservicingthe
equipment?
Doestheproductrestrictserviceindividualswithmultiplelevelsofaccess
control?
Doestheproductsupportmultipleindividualserviceaccounts?
AreServiceaccountsrestrictedfromviewing,ormanipulatingPatientData?
Yes
Yes
No
Yes
No
No
Yes
Yes
No
Yes
No
AreallaccessestoPatientDatabyservicerestrictedtode-identieddata?
AreServiceactionsaccountedforinaloglesomewhere? Manually
ArepasswordsthatarenotchangeableusedforOperatingSystem
administrativeaccounts?
Arepasswordsthatarenotchangeableusedforserviceaccounts?
AreServicedefaultpasswordsdescribedindetailsinanyformofmanual?
Isthecustomerallowedtochangetheservicepasswords?
Doestheproductsupportremoteservice?
Doestheremoteservicesessionrequireauthenticationtoaserviceuser?
Canthecustomertellthataremoteservicesessionisinprogress?
Canthecustomer,throughautomaticormanualmethods,knowwhich
specicserviceindividualiscurrentlyremotelyloggedin?
Canthecustomerseewhatishappeninginanactiveremoteservice
session?
Canthecustomerstopanactiveremoteservicesession?
Specifytheequivalentencryptionstrengththataremoteservicesession
canoperateover?
No
No
No
No
Yes
Yes
Yes
Yes
No
Yes
Yes
3DES
2034539-048A
MUSE™CardiologyInformationSystem
45
AppendixB—SummaryofMUSESecurity
IstheproductspecicGERemoteServicenetworkisolatedfromtherestof
theGEintranet?
AreaccesspointstotheGEservicenetworkprotectedwithanICSA
equivalentrewall?
AreremotesessionseverinitiatedwithoutaServicecallbeingloggedby
thecustomer?
No
No
No
46
MUSE™CardiologyInformationSystem
2034539-048A
AppendixC—21CFRPart11Option
Introduction
TheFDAhasissuedregulationsregardingelectronicrecordsandelectronicsignatures
called21CFRPart11.TheregulationsarerequiredforcustomerswhousetheMUSE
asasystemtosupportclinicaltrials.Thissectiondescribesthe21CFRpart11
functionalityontheMUSEsystem.
Thisoption,whenactivated,willdisableautomaticchangestopatientdata,require
entryofareasonforchangestopatientdata,andallowsyoutoenableasecond
optiontopromptforapasswordwhenpatientdataischanged.
ElectronicSignature
21CFRPart11statesthatusersmustbepromptedforapasswordoneachsitewhen
theyarenotbiometricallyauthenticated.The21CFRPart11optionisavailablewith
MUSEsoftwareversion7.xsoftware.Whenthisoptionisenabled,theSiteInformation
windowcontainstwoadditionalcheckboxes.
C
•Enable21CFRPart11
•RequirePasswordPromptwhensaving
2034539-048A
MUSE™CardiologyInformationSystem
47
AppendixC—21CFRPart11Option
1. Toenable21CFRPart11,atSystem>Setup>Sites>Advanced,selectthe
2. IfbiometricauthenticationisbeingusedforEVERYUSERonthesite,selectthe
3. Ifthesitehassomeuserswhousebiometricauthenticationandsomeusers
Enable21CFRPart11checkbox.
RequirePasswordPromptwhenSavingcheckbox.
whodonotusebiometricauthentication,selectthe21CFRPart11checkbox
andleaveRequirePasswordPromptwhenSavingunchecked.
WhenRequirePasswordPromptwhenSavingisleftuncheckedinSiteSetup,
theindividual’susersetupswillbeusedbythesystemwhenareportissaved.
Thefollowingtablesummarizeshowtheindividualuser’sRequirePassword
PromptwhenSaving optionfunctions.
UserElectronicSignatureSummary
SiteSetupWindow UserSetupWindow
21CFRPart11þ
RequirePasswordPrompt
whenSaving¨
21CFRPart11þ
RequirePasswordPrompt
whenSaving¨
21CFRPart11þ
RequirePasswordPrompt
whenSavingþ
RequirePasswordPrompt
whenSavingþ
RequirePasswordPrompt
whenSaving¨
RequirePasswordPrompt
whenSavingþ
-or-
RequirePasswordPrompt
whenSaving¨
PromptforPasswordon
eachSave?
Yes,forthatuseratthat
site.
No
Yes,forallusersatthat
site.
Other/RelatedFeatures
Inadditiontopromptingtheuserforapasswordwhensavingarecord,enablingthe
21CFRPart11optionalsoaffectsthefollowingfeatures:
48
MUSE™CardiologyInformationSystem
2034539-048A
AppendixC—21CFRPart11Option
Feature
PatientDataMerge
Description
Bydefaultthesystemmergesstored
patientdata(age,gender ,race,height,and
weight)whenanewlyacquiredordiagnosis
completetestisopenedintheeditor.Ifthe21
CFRPart11optionisenabled,thesystemwill
notmergethatdatawhenanunconrmed
testisopened.
QTCCalculation Bydefault,thesystemrecalculatesQTCdata
whenitisacquiredfromthecart.Ifthe21
CFRPart11optionisenabled,thisdataisno
longerrecalculateduponitsacquisition.
UserNameRetrieval Bydefault,thesystemassignsusernames
whenitacquiresIDsthatwereenteredatthe
card.Ifthe21CFRPart11optionisenabled,
thesystemnolongerassignsusernamesto
theseIDs.
ElectronicSignatureMessage TheMUSEsystemwilldisplaythe21CFR
Part11eSignatureMessagewhenthe
passwordpromptappears.Thismessage
canbemodiedinSystem>Setup>Sites
>Advanced.
ReasonforChangeTheMUSEsystemwillprompttheuserfor
areasonforchangeswhenupdatingor
discardingpatientdata.Thereasoncanbe
chosenfromalistorifOtherisselected,the
usercantypeareason.
ChangeLog Thisfeaturelogschangestopatientdata.
EnabletheChangeLogatSystem>Setup
>Sites>TestTypeSettings,selecttheLog
Changes checkboxesforeachtesttype.See
Chapter4“Accounting/Logging”onpage17
forinstructionsonhowtoviewtheChange
Log.
SignatureMessageinDiagnosis
TheMUSEsystemcanbeconguredtoplace
asignaturemessageinthediagnosiswhen
thetestisconrmed.Enablethesignature
messageatSystem>Setup>Sites>Test
TypeSettings,selecttheSignatureMessage
inDiagnosischeckboxesforthedesiredtest
types.
2034539-048A
MUSE™CardiologyInformationSystem
49
AppendixC—21CFRPart11Option
50
MUSE™CardiologyInformationSystem
2034539-048A
GEMedicalSystems
InformationTechnologies ,Inc.
8200WestTowerAvenue
Milwaukee,WI53223USA
Tel: +14143555000
+18005587044(USOnly)
Fax:+14143553790
GEMedicalSystems
InformationTechnologies GmbH
MunzingerStraße5
D-79111FreiburgGermany
Tel: +497614543-0
Fax:+497614543-233
AsiaHeadquarters
GEMedicalSystems
InformationTechnologies ,Inc.
Asia;GE(China)Co.,Ltd.
No.1HuatuoRoad
ZhangjiangHi-techParkPudong
Shanghai,People’sRepublicofChina201203
Tel: +862152574650
Fax:+862152082008
GEMedicalSystemsInformationTechnologies,Inc.,aGeneralElectricCompany,goingtomarketas
GEHealthcare.
www.gehealthcare.com