
Download our fact sheet "epSOS - Technical Aspects"! To access other epSOS documents and print materials, please visit the Download Area.
All attempts to access a patient’s data through epSOS are recorded in audit trails. By regular evaluation of audit trails illegitimate disclosures of medical data can be detected and prosecuted.
Auditing and Authentication are achieved using the IHE Profile “Audit Trail & Node Authentication”. This profile contributes to access control by limiting network access between nodes and limiting access to each node to authorized users. Network communications between secure nodes in a secure domain are restricted to other secure nodes in that domain. Secure nodes limit access to authorized users as specified by the local authentication and access control policy.
Profile secure communication is realized through RFC 2246 Transport Layer Security (TLS) 1.0 and WS-I Basic Security Profile 1.1. Audit Log transport is executed using RFC 5424/5425/5426 Syslog Protocol, and Audit Log messages are performed using RFC 3881 Security Audit and Access Accountability Message XML Data Definitions for Healthcare Applications.