The importance of reliable time synchronisation in hospitals

Time synchronisation in hospitals
6 minutes read

Timestamping of data is not the first thing that comes to mind when we think of the hospital environment. We don’t immediately see a hospital as a giant information system: from electronic patient records and all hospital room equipment to MRIs, a hospital is made up of hundreds of pieces of equipment that continuously produce and exchange timestamped data. 
A reliable and secure time guarantees the value of patient records and imaging consistency, as well as the facility’s information security and regulatory compliance.

Patient records are legally binding documents

In hospitals, everything is important, vital even. The time at which a drug is administered? The exact moment vital signs are measured? Who did what and when? This information forms an integral part of a record that the medical team rely on to make decisions. As a result, time information can end up being critical data that is submitted to a judge or insurer as evidence. It originates from sources and equipment that timestamp their actions with their own clocks. For a record to have probative value, all of these clocks need to be synchronised.

When you are looking at a device in isolation, its internal time is enough. The need for synchronisation arises when several sources intersect to recreate a sequence of events. It is subsequently analysed, in the wake of an adverse event or a dispute. If equipment does not share the same time reference, the timeline created is wrong and the record loses its probative value.

What time precision is required?

To understand the level of precision called for in healthcare establishments, let’s take a look at medical imaging. The images of a scanner or an MRI are stored in DICOM format, which timestamps each shot. 

For this timestamping to remain consistent, DICOM relies on NTP, via the Consistent Time profile of the IHE. 

Good to know

The Consistent Time (CT) profile of the IHE (Integrating the Healthcare Enterprise) is a software interoperability profile that aims to ensure that all of a healthcare establishment’s information systems share a consistent and traceable time reference.

To go even further, a dedicated attribute indicates whether the timestamping of an image is actually aligned with an external time reference. This tells you whether a medical image has been reliably timestamped.

With external timestamping, the time information is reliable. It reconciles the timestamping of examinations carried out on different machines and establishes the precise timeline of a patient's care.

However, there is one point that sets healthcare apart from other sectors (for instance, finance). 
In finance, the MiFID II regulation imposes specific precision thresholds (up to 100 microseconds). In healthcare, there is no such regulatory precision threshold. 

This is counter-intuitive. But what matters for a piece of medical equipment is local stability and consistency at healthcare establishment level. Fine alignment, with an international benchmark, is less critical. The NTP millisecond therefore tends to be sufficient. The challenge for everyone is sharing the same reference time, reliably and continuously, in order to make the right decisions and demonstrate their timeline if necessary.

The HIS in view of DGOS requirements

DGOS (the General Directorate for Healthcare Services) has coordinated the digital strategy of establishments since 2012. The traceability of actions on the hospital information system (HIS) is part of it, and the atlas of HISs published by DGOS and ATIH (Technical Agency for Hospitalisation Information) reports that 97% of establishments can trace user actions.

This tracing enables hospitals to comply with instruction DGOS/MSIOS/2013/62, which establishes the requirement to be able to identify who has consulted or modified which medical data and when. 

To respond to this “when”, the traceability log must include timestamping just after each event. A few minutes’ difference between servers can generate an order or attribution error between two linked events. Therefore, synchronising all HISs with a single NTP source is the solution to ensure that traceability is admissible in the event of an audit.

The importance of cybersecurity in HISs

There is one issue that hospitals have in common with all industrial players: cybersecurity.
Healthcare establishments are regularly targeted by ransomware attacks. They are an easy target with staff always busy and infrastructure that is not always updated. 
ANSSI identified 30 public healthcare establishments that are affected, in the 2022-2023 period alone, which represents 10% of the incidents reported to it. 

In 2023, in its internet crime report, the FBI indicated that of the 1,193 ransomware cases processed by them that year, 249 were in the healthcare sector.

After an attack, it is the logging of the actions performed on the HISs that gives an understanding of how the intrusion happened and what has been affected. In practice, the logs of dozens of machines are cross-referenced: firewall, servers, workstations, access control, video surveillance. Only fine and precise synchronisation can explain how events unfolded. Without synchronisation, it becomes impossible to understand what has happened.
This is why ANSSI recommends putting in place an internal NTP time server.

However, there is still one problem: in its standard version, NTP does not authenticate its sources. An attacker that succeeds in injecting spoofed packets can shift the time of a piece of equipment and distort machine logs. The NTS (Network Time Security) protocol, defined by RFC 8915, corrects this concern by adding authentication and encryption to NTP. 

To take things a step further, it is recommended to put in place a time server that uses the NTS protocol.

Maintaining robust synchronisation

In general, an internal time server receives a GNSS time source (GPS, Galileo, etc.). What happens if this signal disappears, as a result of interference, antenna failure or maintenance? It all depends on the server’s internal oscillator. An OCXO or a rubidium oscillator holds over the reference time with a minimal drift over a period of up to several months (the time it takes for the source to re-establish itself). In a hospital, this holdover prevents the loss of a satellite signal desynchronising the entire establishment bit by bit.

Compliance

Beyond the information system, regulatory traceability covers medical acts, the administration of drugs, blood products and implantable devices. Without timestamping, traceability of these elements is lost. HAS certification and SUN-ES indicators (Ségur Usage Numérique en Établissements de Santé) led by DGOS incorporate these security and verifiability issues. A reliable synchronisation infrastructure is not a criterion explicitly demanded by these players, but it is an inherent consequence of their demands.