DICOM PS3.15 2025e - Security and System Management Profiles

A.5.3.14 Patient Record

This message describes the event of a patient record being created, modified, accessed, or deleted.

Note

There are several types of patient records managed by both DICOM and non-DICOM system. DICOM applications often manipulate patient records managed by a variety of systems, and thus may be obligated by site security policies to record such events in the audit logs. This audit event can be used to record the access or manipulation of patient records where specific DICOM SOP Instances are not involved.

Table A.5.3.14-1. Audit Message for Patient Record

Real-World Entities

Field Name

Opt.

Value Constraints

Event: EventIdentification

EventID

M

EV (110110, DCM, "Patient Record")

EventActionCode

M

Enumerated Value:

C

Create

R

Read

U

Update

D

Delete

EventDateTime

M

Not specialized.

EventOutcomeIndicator

M

Not specialized.

EventTypeCode

U

Not specialized.

Active Participant: ActiveParticipant

Person and/or process accessing or manipulating the data (1..2)

UserID

M

The identity of the person or process accessing or manipulating the data. If both are known, then two active participants shall be included (both the person and the process).

AlternativeUserID

U

Not specialized.

UserName

U

Not specialized.

UserIsRequestor

U

Not specialized.

RoleIDCode

U

Not specialized.

NetworkAccessPointTypeCode

U

Not specialized.

NetworkAccessPointID

U

Not specialized.

Participant Object: ParticipantObjectIdentification

Patient (1)

ParticipantObjectTypeCode

M

Shall be:

1

Person

ParticipantObjectTypeCodeRole

M

Shall be:

1

Patient)

ParticipantObjectDataLifeCycle

U

Not specialized.

ParticipantObjectIDTypeCode

M

Shall be:

2

Patient Number

ParticipantObjectSensitivity

U

Not specialized.

ParticipantObjectID

M

The patient ID.

ParticipantObjectName

M

The patient name.

ParticipantObjectDetail

U

Not specialized.

ParticipantObjectDescription

U

Not further specialized.


DICOM PS3.15 2025e - Security and System Management Profiles