DICOM PS3.15 2025e - Security and System Management Profiles

A.5.3.4 Data Export

This message describes the event of exporting data from a system, meaning that the data is leaving control of the system's security domain. Examples of exporting include printing to paper, recording on film, conversion to another format for storage in an EHR, writing to removable media, or sending via e-mail. Multiple patients may be described in one event message.

Table A.5.3.4-1. Audit Message for Data Export

Real-World Entities

Field Name

Opt.

Value Constraints

Event: EventIdentification

EventID

M

EV (110106, DCM, "Export")

EventActionCode

M

Shall be:

R

Read

EventDateTime

M

Not specialized.

EventOutcomeIndicator

M

Not specialized.

EventTypeCode

U

Not specialized.

Active Participant: ActiveParticipant

Remote users and/or processes (0..N)

UserID

M

The identity of the remote user or process receiving the data.

AlternativeUserID

U

Not specialized.

UserName

U

Not specialized.

UserIsRequestor

M

See Section A.5.3.4.1.

RoleIDCode

M

EV (110152, DCM, "Destination Role ID")

NetworkAccessPointTypeCode

U

Not specialized.

NetworkAccessPointID

U

Not specialized.

Active Participant: ActiveParticipant

User and/or process exporting the data (1..2)

UserID

M

The identity of the local user or process exporting the data. If both are known, then two active participants shall be included (both the person and the process).

AlternativeUserID

U

Not specialized.

UserName

U

Not specialized.

UserIsRequestor

M

See Section A.5.3.4.1.

RoleIDCode

M

EV (110153, DCM, "Source Role ID")

NetworkAccessPointTypeCode

U

Not specialized.

NetworkAccessPointID

U

Not specialized.

Active Participant: ActiveParticipant

Media (1)

UserID

M

See Section A.5.2.1.

AlternativeUserID

U

See Section A.5.2.2.

UserName

U

Not specialized.

UserIsRequestor

M

Shall be:

false

RoleIDCode

M

EV (110154, DCM, "Destination Media")

NetworkAccessPointTypeCode

MC

Required if being exported to other than physical media, e.g., to a network destination rather than to film, paper or CD. May be present otherwise.

NetworkAccessPointID

MC

Required if Net Access Point Type Code is present. May be present otherwise.

MediaIdentifier

MC

Volume ID, URI, or other identifier for media.

Required if digital media. May be present otherwise.

MediaType

M

DCID 405 “Media Type Code”

Participant Object: ParticipantObjectIdentification

Studies (0..N)

ParticipantObjectTypeCode

M

Shall be:

2

System Object

ParticipantObjectTypeCodeRole

M

Shall be:

3

3 = Report

ParticipantObjectDataLifeCycle

U

Not specialized.

ParticipantObjectIDTypeCode

M

EV (110180, DCM, "Study Instance UID")

ParticipantObjectSensitivity

U

Not specialized.

ParticipantObjectID

M

The Study Instance UID.

ParticipantObjectName

MC

Required if ParticipantObjectQuery is not present.

ParticipantObjectQuery

MC

Required if ParticipantObjectName is not present.

ParticipantObjectDetail

U

Not specialized.

ParticipantObjectDescription

U

Not specialized.

SOPClass

MC

See Section A.5.2.

Accession

U

Not specialized.

NumberOfInstances

U

Not specialized.

Instances

U

Not specialized.

Encrypted

U

Not specialized.

Anonymized

U

Not specialized.

Participant Object: ParticipantObjectIdentification

Patients (1..N)

ParticipantObjectTypeCode

M

Shall be:

1

Person

ParticipantObjectTypeCodeRole

M

Shall be:

1

Patient

ParticipantObjectDataLifeCycle

U

Not specialized.

ParticipantObjectIDTypeCode

M

Shall be:

2

Patient Number

ParticipantObjectSensitivity

U

Not specialized.

ParticipantObjectID

M

The patient ID.

ParticipantObjectName

M

The patient name.

ParticipantObjectDetail

U

Not specialized.

ParticipantObjectDescription

U

Not specialized.


A.5.3.4.1 UserIsRequestor

A single user (either local or remote) shall be identified as the requestor, i.e., UserIsRequestor with a value of true. This accommodates both push and pull transfer models for media.

DICOM PS3.15 2025e - Security and System Management Profiles