SlideShare a Scribd company logo
Certifying and Securing aTrusted Environment for Health
Informatics Research data
Dr Jonathan Monk, Director of IT, University of Dundee
1/11/2016
Health Informatics Centre
dundee.ac.uk/hic
Dr Jonathan Monk
Director of IT
University of Dundee
Certifying and Securing a Trusted
Environment for Health Informatics
Research data
Health Informatics Centre
dundee.ac.uk/hic
1. Overview of Health Informatics
2. Research Data Management Platform
3. Safe Haven Architecture
4. ISO27001 Certification
Health Informatics Centre
dundee.ac.uk/hic
Overview of Health
Informatics
Health Informatics Centre
dundee.ac.uk/hic
Geographic - Tayside And Fife Population of Scotland Time Period 1972 - 2016
Electronic Medical Data Coverage
Health Informatics Centre
dundee.ac.uk/hic
Parents Conception Birth Early Life Childhood Adulthood Late Life Death
Research Datasets
• GoDARTS Diabetes – 18K - Case/Controls
• TASC FORCE – 5000 - MRA Volunteers
• POPADAD – 1200 - Diabetes with no CVD
• TRACE RA – 3200 - Rheumatoid Arthritis/UK
Pre-consented Cohorts
 SHARE – 100+K
 Generation Scotland – 20K
SMR02
Maternity & Neonate
Walker
48,00 Births (1952-1966)
Health Care Data
 Primary Care : Community Prescribing
 Secondary Care : Out Patient Visits, Hospital Admissions, Accident & Emergency, Cancer Register, Psychiatric Episodes.
 Diagnostics : Radiology Events, Cardiology & Vascular Labs, Bowel Screening
 Laboratory - Biochemistry, Haematology, Immunology, Microbiology, Virology
 Diabetes Surveillance - BP,BMI, Smoking Alcohol, Amputations, Ulcers
 Diabetic Retinal Images – DRS Retinopathy Image Library (Go DARTS Population)
Disease Registers
• TARDIS Respiratory Disease
• SDCRN – Scottish Dementia Network
• SCI Diabetes
• Epilepsy
Child Health Pre-School/School
SIRS/CHSP
Register Of
Deaths
DataForLinkageExistingResearch
StudiesPhenotypic Data Available
Health Informatics Centre
dundee.ac.uk/hic
Data Linkage Through Family Generations
2004 - Community Prescribing (Dispensed)
2016
1986 - Acute Hospital Admission Tayside
1975 - Births and Neonatal Record
1986 - Laboratory ( Biochemistry, Haematology, Immunology, Microbiology)
1994 - Radiology Records
1952
Walker Dataset
1952 – 66
48,000
Dundee Births
Babies
Mothers
Fathers
1980 – Cancer Register
1990 – Diabetes Records
Cohort participants episodes recorded in dataset
Health Informatics Centre
dundee.ac.uk/hic
Health Informatics Centre
dundee.ac.uk/hic
Controls
 Ratio : 3:1
 Match on Age, Sex, SIMD
Feasibility Searches
Inclusion:
 Health Board : Tayside
 Status : Alive
 Conditions : Type 2 Diabetes
 Age: >= 65
 Prescribed : Insulin > 2yrs
Exclude:
 Prescribed: Statins
Researcher Supplies Search Criteria
Matches
570K
450K
120K
70K
9210
Health Informatics Centre
dundee.ac.uk/hic
Health Informatics Centre
dundee.ac.uk/hic
Demography
GRO ECHO
There was a
22% overall
reduction in all
cause mortality
with β blocker
use
Prescribing TARDIS
Biochemistry
MicrobiologyHaematology
Case Study # 1 - β blockers:
Their Effect in Managing Chronic Obstructive Pulmonary Disease (COPD)
Setting Tayside, Scotland (2001–2010)
Population 5977 patients aged >50 years
with a diagnosis of COPD.
BMJ. 2011; 342: d2549. 10.1136/bmj.d2549 P.M Short, S.I.W Lipworth, D.H.J Elder, S. Schembri, B.J. Lipworth.
Health Informatics Centre
dundee.ac.uk/hic
Hospital
admissions
GRO
More than 400 lives are being lost each year
because breast cancer patients fail to take
the full course of the drug Tamoxifen due to
"intolerable" side-effects
Prescribing
Br J Cancer. 2008 December 2; 99(11): 1763–1768. 10.1038/sj.bjc.6604758 McCowan, J Shearer, P T Donnan, J A Dewar, M Crilly, A M Thompson and T P Fahey
Researcher Supplied
Cohort
Cancer patients from a
Ninewells clinic
Case Study #2: Tamoxifen adherence:
Relationship to Mortality in Women with Breast Cancer
Health Informatics Centre
dundee.ac.uk/hic
Research Data Management Platform (RDMP)
‘Optimizing and Augmenting the Research Data Supply Chain`
Labs
SMR01
Prescribing
Raw Data Data Import Databases Custom Extractions & Export Formats
RDMP
Labs
SMR01
Prescribing
Raw Data Data Import Structured
Database
Extraction + Export
DataLoad
Engine
Research
Data Warehouse
Validate
Clean
Catalogue
QualityChecks
Project X
Data Marts
Validate
Clean
Catalogue
QualityChecks
Project Y
Data Marts
Validate
Clean
Catalogue
QualityChecks
DataExtraction
Engine
Health Informatics Centre
dundee.ac.uk/hic
Data
Set 1
Data
Set 6
Data
Set 2
Data
Set 3
Data
Set 4
Data
Set 5
Data Set 1
Pseudo-CHI
Data Set 2
Pseudo-CHI
Data Set 6
Pseudo-CHI
Data Set 3
Pseudo-CHI
Data Set 4
Pseudo-CHI
Data Set 5
Pseudo-CHI
CHI and All
Identifiable
Data
Data Set 1
Project -CHI
Data Set 4
Project -CHI
NHS Network University Network
Data Repository Function of Safe Haven Analytic Platform of Safe Haven
Virtual
Environment –
no data leaves
Health Informatics Centre
dundee.ac.uk/hic
• Extraction takes minutes
• Data released is standardised – the same regardless of Data Analyst that
completes the work
• A history is recorded of all changes to data over time
• Data released now will be in the same format as in 5 years from now
• Metadata has been added
• Methods for transforming and validations have been added across all data
sets
• Tools to manage and explore the data are available to Data Management
team and researchers
• Audit and Logging all automated
• Major work towards integration of image and genomic data
Health Informatics Centre
dundee.ac.uk/hic
Health Informatics Centre
dundee.ac.uk/hic
• Standard restrictive VDI solution
• VMWare View / Horizon
Health Informatics Centre
dundee.ac.uk/hic
• AppVolumes used for Applications
• Bring Your Own License
• Lots of Application Variations!
Health Informatics Centre
dundee.ac.uk/hic
• There are many types of ISO
Certification.
• We have 27001:2013 – Certificate
Number: 2016/2269
• ISO 27001:2013 is a specification for an
information security management
system (ISMS). An ISMS is a framework of
policies and procedures that includes all
legal, physical and technical controls
involved in an organisation's information
risk management processes.
What is ISO27001?
Health Informatics Centre
dundee.ac.uk/hic
Why ISO27001 certification?
• Independent set of standards – so rather than constantly having to
think what documents and processes we should have in place and
reinventing the wheel, ISO gives us this!
• Gives confidence to other organisations we work with e.g. NHS, main
University.
• Reduces other documentation requirements for governance, as we
can just reference ISO documentation.
• Improves the working practices of HIC. This has been particularly the
case with our hardware infrastructure.
• Key towards Scottish Government Safe Haven Accreditation.
Health Informatics Centre
dundee.ac.uk/hic
Scottish Government Safe Haven Accreditation
• 27001 standard controls PLUS some
additional ones specific to Safe Havens.
• Reviewed by Scottish Government
eHealth.
• Documentation Required:
• Risk Assessment Doc
• Mapping of Controls
Health Informatics Centre
dundee.ac.uk/hic
Health Informatics Centre
dundee.ac.uk/hic
Scope
“The provision of data to researchers via safe haven environment, secure
patient recruitment, data collection using software tools, data entry, the
development and operation of web based applications and all assets
underpinning the provision of those services from the locations of HIC premises
at Ninewells Hospital and data centres within the University of Dundee
Campus”
Health Informatics Centre
dundee.ac.uk/hic
ISMS Controls Status with Statement of
Applicability and Gaps
Health Informatics Centre
dundee.ac.uk/hic
ISO Controls – Made up of HIC specific ones
and University/NHS general controls
University of Dundee Security
Policies
University of Dundee HR Policies and
Procedures (and NHS where
appropriate as we have honorary
contracts)
HIC HR
Procedures/Training/Policies
HIC Security Policies
A7: Human Resource SecurityA5: Information Security Policies
A6: Organisation of
Information security
University of Dundee Security
Policies
HIC Security Policies,
SOPS, Procedures, Work
Instructions and Service
Descriptions
Health Informatics Centre
dundee.ac.uk/hic
Document Types and Review
Static & Formally Approved:
HIC Exec & HIC Information Governance Committee
• Policies
• Standard Operating Procedures (SOPs)
• Risk Management Doc
• Information Security Management System (ISMS)
Manual
• Business Continuity Plan
Just HIC Exec
• Procedures
Working Documents (technical):
Relevant Technical Manager
• Service Descriptions
• Work Instructions
• Asset and Responsibility Matrix
• Disaster Recovery Plans
• Infrastructure Diagrams
Health Informatics Centre
dundee.ac.uk/hic
Structure of Docs in Box Become aware of an
improvement of our
current procedure
Take a copy of Procedure from “Live” folder and move to
“Under Development”.
Draft change using tracked changes.
Ask Technical Manager to review.
Technical Manager moves the doc they have approved to
“Awaiting Approval Folder” and asks for it to be included in
HIC Exec Meeting Agenda for review.
If approved at HIC Exec either formally approved or sent to
HIC Information Governance Committee for additional
formal approval (if document type requires)
Approved doc is moved to
“Live” folder by HIC Admin
Procedure Changes
Health Informatics Centre
dundee.ac.uk/hic
Infrastructure comprised UoD, HIC & NHS
University of Dundee Network NHS Network
HIC Managed Hardware
HIC Managed Hypervisor Cluster
HIC Managed Operating Systems
HIC Managed Applications
UoD Hardware
UoD Hypervisor
UoD OS
UoD Applications
HIC and UoD use identical platform technology and share locations
Hardware & responsibility for management varies depending on specificity
University of Dundee Data Centres NHS Locations
Health Informatics Centre
dundee.ac.uk/hic
Timelines
• Help from University’s Information Security Officer (Graham McKay)
to get us up to the required standard.
• Passed our Stage 1 audit of our documentation in June 2015.
• Passed our Stage 2 audit of our systems (do we do what we say we do
in our documentation) in Jan 2016.
• Passed second Stage 2 audit July 2016
• Now have full audits every 6 months for the next 3 years!
Health Informatics Centre
dundee.ac.uk/hic
Phil Appleby
Jim Galloway
Chris Hall
Duncan HeatherEmily Jefferson
Claire JonesGordon
McAllister
Keith MilburnLeandro Tramma
Donald
Scobbie
Thomas Nind Guney Hanedan
Graham
McKay
Many thanks to the people that did all the work!
Health Informatics Centre
dundee.ac.uk/hic
Questions?

More Related Content

PDF
Connected health cities
PPTX
Strand 1: Connecting research and researchers: An introduction to ORCID by Ed...
PDF
Data discovery and sharing at UCLH
PDF
NHS SE presentation
PPTX
Open access progress and sustainability
PPTX
Jisc's new shared data centre
PPTX
Grampian safe haven, research data network
PPTX
EC Open Access Co-ordination workshop - 4th May 2011
Connected health cities
Strand 1: Connecting research and researchers: An introduction to ORCID by Ed...
Data discovery and sharing at UCLH
NHS SE presentation
Open access progress and sustainability
Jisc's new shared data centre
Grampian safe haven, research data network
EC Open Access Co-ordination workshop - 4th May 2011

What's hot (20)

PPTX
UK data management environment and support
PPTX
LEARN Conference - How to cost
PPTX
LEARN Final Conference: Tutorial Group | Using the LEARN Model RDM Policy
PPTX
Standardising research data policies, research data network
PPTX
Supporting the community-owned open scholarly communications ecosystem
PPTX
Why science needs open data – Jisc and CNI conference 10 July 2014
PDF
Digital transformation to enable a FAIR approach for health data science
PPTX
Towards Open Research
PPTX
LEARN Final Conference: Tutorial Group | Implementing the LEARN RDM Toolkit
PPTX
Making sense of open scholarly communications data - Jisc Digifest 2016
PPTX
Perspectives from the African Open Science Platform/Susan Veldsman
PPTX
Active research management and sharing
PPTX
Addressing the wicked problem of learning data privacy though principle and p...
PDF
Lessons from the UK: Data access, patient trust & real-world impact with heal...
PPTX
EPFL Open Research Data - a Jisc perspective
PPTX
H2020 open-data-pilot
PPTX
Paul Jeffreys - Research Integrity: Institutional Responsibility
PPTX
20160414 23 Research Data Things
PPTX
The fourth paradigm: data intensive scientific discovery - Jisc Digifest 2016
PPTX
UK Research Data Management: overview to ADBU congress, 19 Sep 2013 by Laura ...
UK data management environment and support
LEARN Conference - How to cost
LEARN Final Conference: Tutorial Group | Using the LEARN Model RDM Policy
Standardising research data policies, research data network
Supporting the community-owned open scholarly communications ecosystem
Why science needs open data – Jisc and CNI conference 10 July 2014
Digital transformation to enable a FAIR approach for health data science
Towards Open Research
LEARN Final Conference: Tutorial Group | Implementing the LEARN RDM Toolkit
Making sense of open scholarly communications data - Jisc Digifest 2016
Perspectives from the African Open Science Platform/Susan Veldsman
Active research management and sharing
Addressing the wicked problem of learning data privacy though principle and p...
Lessons from the UK: Data access, patient trust & real-world impact with heal...
EPFL Open Research Data - a Jisc perspective
H2020 open-data-pilot
Paul Jeffreys - Research Integrity: Institutional Responsibility
20160414 23 Research Data Things
The fourth paradigm: data intensive scientific discovery - Jisc Digifest 2016
UK Research Data Management: overview to ADBU congress, 19 Sep 2013 by Laura ...
Ad

Viewers also liked (20)

PPTX
Cyber Crime - "Who, What and How"
PPT
Role of the CISO in Higher Education
PPTX
Mitigation starts now
PDF
Protecting our customers - BT security
PPTX
Data and information governance: getting this right to support an information...
PPTX
GDPR: More reasons for information security
PPT
Working with students and ISO27001
PPTX
Information security at University of East London: the benefits (and pitfalls...
PPTX
Closing plenary and keynote from Lauren Sager Weinstein
PPTX
Archiving data from Durham to RAL using the File Transfer Service (FTS)
PPTX
110G networking within JASMIN
PPTX
Challenges in end-to-end performance
PPTX
Provisioning Janet
PPTX
Science DMZ
PDF
Science DMZ at Imperial
PPT
Solving Network Throughput Problems at the Diamond Light Source
PPTX
Enabling efficient movement of data into & out of a high-performance analysis...
PPTX
The Assessment Journey
PPTX
Data and disadvantaged students - using learning analytics for inclusion
PPTX
The Jisc UK ORCID consortium : Workshop 2
Cyber Crime - "Who, What and How"
Role of the CISO in Higher Education
Mitigation starts now
Protecting our customers - BT security
Data and information governance: getting this right to support an information...
GDPR: More reasons for information security
Working with students and ISO27001
Information security at University of East London: the benefits (and pitfalls...
Closing plenary and keynote from Lauren Sager Weinstein
Archiving data from Durham to RAL using the File Transfer Service (FTS)
110G networking within JASMIN
Challenges in end-to-end performance
Provisioning Janet
Science DMZ
Science DMZ at Imperial
Solving Network Throughput Problems at the Diamond Light Source
Enabling efficient movement of data into & out of a high-performance analysis...
The Assessment Journey
Data and disadvantaged students - using learning analytics for inclusion
The Jisc UK ORCID consortium : Workshop 2
Ad

Similar to Certifying and Securing a Trusted Environment for Health Informatics Research Data (20)

PPTX
Health informatics
PPTX
Health informatics
PPSX
Health informatics
PDF
List Of Figures And Functions Requirements
PDF
A Personal Health Record ( Ehr )
PPTX
An Introduction to Health Informatics
DOCX
DEADLINE FRIDAY 352021 BY 0800 PM ESTINSTRUCTIONS Res
PPTX
Hci capstone
PDF
Electronic Health Records 2nd Edition Jerome H. Carter
DOCX
Mh0053 hospital & healthcare information
DOCX
NURS FPX 4040 assessment 1 nursing informatics in health care.docx
PPT
informatics1.ppt
PDF
Introduction to Health Informatics
PDF
The role of biomedical engineers in the introduction and maintenance of healt...
PDF
Health Informatics for Clinical Research (November 25, 2021)
PDF
Health Informatics Labour Market Research
PPTX
Hcad600 group4presentationfinal
PDF
From Patient Data to Medical Knowledge The Principles and Practice of Health ...
PPTX
Health information management system by dr. protik.pptx
PPT
eHealth Governance, Security and Privacy a UK Perspective
Health informatics
Health informatics
Health informatics
List Of Figures And Functions Requirements
A Personal Health Record ( Ehr )
An Introduction to Health Informatics
DEADLINE FRIDAY 352021 BY 0800 PM ESTINSTRUCTIONS Res
Hci capstone
Electronic Health Records 2nd Edition Jerome H. Carter
Mh0053 hospital & healthcare information
NURS FPX 4040 assessment 1 nursing informatics in health care.docx
informatics1.ppt
Introduction to Health Informatics
The role of biomedical engineers in the introduction and maintenance of healt...
Health Informatics for Clinical Research (November 25, 2021)
Health Informatics Labour Market Research
Hcad600 group4presentationfinal
From Patient Data to Medical Knowledge The Principles and Practice of Health ...
Health information management system by dr. protik.pptx
eHealth Governance, Security and Privacy a UK Perspective

More from Jisc (20)

PPTX
Strengthening open access through collaboration: building connections with OP...
PPTX
Andrew-Brown-JUSP-showcase-20240730.pptx
PPTX
JUSP Showcase - Rebuilding Data presentation
PPTX
Adobe Express Engagement Webinar (Delegate).pptx
PPTX
FE Accessibility training matrix partnership - information session
PPTX
Procuring a research management system: why is it so hard?
PPTX
Adobe Express Engagement Webinar (Delegate).pptx
PPTX
How libraries can support authors with open access requirements for UKRI fund...
PPTX
Supporting (UKRI) OA monographs at Salford.pptx
PPTX
The approach at University of Liverpool.pptx
PPTX
Jisc's value to HE: the University of Sheffield
PPTX
Towards a code of practice for AI in AT.pptx
PPTX
Jamworks pilot and AI at Jisc (20/03/2024)
PPTX
Wellbeing inclusion and digital dystopias.pptx
PPTX
Accessible Digital Futures project (20/03/2024)
PPTX
Procuring digital preservation CAN be quick and painless with our new dynamic...
PPTX
International students’ digital experience: understanding and mitigating the ...
PPTX
Digital Storytelling Community Launch!.pptx
PPTX
Open Access book publishing understanding your options (1).pptx
PPTX
Scottish Universities Press supporting authors with requirements for open acc...
Strengthening open access through collaboration: building connections with OP...
Andrew-Brown-JUSP-showcase-20240730.pptx
JUSP Showcase - Rebuilding Data presentation
Adobe Express Engagement Webinar (Delegate).pptx
FE Accessibility training matrix partnership - information session
Procuring a research management system: why is it so hard?
Adobe Express Engagement Webinar (Delegate).pptx
How libraries can support authors with open access requirements for UKRI fund...
Supporting (UKRI) OA monographs at Salford.pptx
The approach at University of Liverpool.pptx
Jisc's value to HE: the University of Sheffield
Towards a code of practice for AI in AT.pptx
Jamworks pilot and AI at Jisc (20/03/2024)
Wellbeing inclusion and digital dystopias.pptx
Accessible Digital Futures project (20/03/2024)
Procuring digital preservation CAN be quick and painless with our new dynamic...
International students’ digital experience: understanding and mitigating the ...
Digital Storytelling Community Launch!.pptx
Open Access book publishing understanding your options (1).pptx
Scottish Universities Press supporting authors with requirements for open acc...

Recently uploaded (20)

PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PPTX
Cloud computing and distributed systems.
PDF
Modernizing your data center with Dell and AMD
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
cuic standard and advanced reporting.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
Review of recent advances in non-invasive hemoglobin estimation
PPTX
Big Data Technologies - Introduction.pptx
PDF
Encapsulation_ Review paper, used for researhc scholars
Advanced methodologies resolving dimensionality complications for autism neur...
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
The AUB Centre for AI in Media Proposal.docx
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Cloud computing and distributed systems.
Modernizing your data center with Dell and AMD
MYSQL Presentation for SQL database connectivity
Understanding_Digital_Forensics_Presentation.pptx
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Agricultural_Statistics_at_a_Glance_2022_0.pdf
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
NewMind AI Monthly Chronicles - July 2025
cuic standard and advanced reporting.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Review of recent advances in non-invasive hemoglobin estimation
Big Data Technologies - Introduction.pptx
Encapsulation_ Review paper, used for researhc scholars

Certifying and Securing a Trusted Environment for Health Informatics Research Data

  • 1. Certifying and Securing aTrusted Environment for Health Informatics Research data Dr Jonathan Monk, Director of IT, University of Dundee 1/11/2016
  • 2. Health Informatics Centre dundee.ac.uk/hic Dr Jonathan Monk Director of IT University of Dundee Certifying and Securing a Trusted Environment for Health Informatics Research data
  • 3. Health Informatics Centre dundee.ac.uk/hic 1. Overview of Health Informatics 2. Research Data Management Platform 3. Safe Haven Architecture 4. ISO27001 Certification
  • 5. Health Informatics Centre dundee.ac.uk/hic Geographic - Tayside And Fife Population of Scotland Time Period 1972 - 2016 Electronic Medical Data Coverage
  • 6. Health Informatics Centre dundee.ac.uk/hic Parents Conception Birth Early Life Childhood Adulthood Late Life Death Research Datasets • GoDARTS Diabetes – 18K - Case/Controls • TASC FORCE – 5000 - MRA Volunteers • POPADAD – 1200 - Diabetes with no CVD • TRACE RA – 3200 - Rheumatoid Arthritis/UK Pre-consented Cohorts  SHARE – 100+K  Generation Scotland – 20K SMR02 Maternity & Neonate Walker 48,00 Births (1952-1966) Health Care Data  Primary Care : Community Prescribing  Secondary Care : Out Patient Visits, Hospital Admissions, Accident & Emergency, Cancer Register, Psychiatric Episodes.  Diagnostics : Radiology Events, Cardiology & Vascular Labs, Bowel Screening  Laboratory - Biochemistry, Haematology, Immunology, Microbiology, Virology  Diabetes Surveillance - BP,BMI, Smoking Alcohol, Amputations, Ulcers  Diabetic Retinal Images – DRS Retinopathy Image Library (Go DARTS Population) Disease Registers • TARDIS Respiratory Disease • SDCRN – Scottish Dementia Network • SCI Diabetes • Epilepsy Child Health Pre-School/School SIRS/CHSP Register Of Deaths DataForLinkageExistingResearch StudiesPhenotypic Data Available
  • 7. Health Informatics Centre dundee.ac.uk/hic Data Linkage Through Family Generations 2004 - Community Prescribing (Dispensed) 2016 1986 - Acute Hospital Admission Tayside 1975 - Births and Neonatal Record 1986 - Laboratory ( Biochemistry, Haematology, Immunology, Microbiology) 1994 - Radiology Records 1952 Walker Dataset 1952 – 66 48,000 Dundee Births Babies Mothers Fathers 1980 – Cancer Register 1990 – Diabetes Records Cohort participants episodes recorded in dataset
  • 9. Health Informatics Centre dundee.ac.uk/hic Controls  Ratio : 3:1  Match on Age, Sex, SIMD Feasibility Searches Inclusion:  Health Board : Tayside  Status : Alive  Conditions : Type 2 Diabetes  Age: >= 65  Prescribed : Insulin > 2yrs Exclude:  Prescribed: Statins Researcher Supplies Search Criteria Matches 570K 450K 120K 70K 9210
  • 11. Health Informatics Centre dundee.ac.uk/hic Demography GRO ECHO There was a 22% overall reduction in all cause mortality with β blocker use Prescribing TARDIS Biochemistry MicrobiologyHaematology Case Study # 1 - β blockers: Their Effect in Managing Chronic Obstructive Pulmonary Disease (COPD) Setting Tayside, Scotland (2001–2010) Population 5977 patients aged >50 years with a diagnosis of COPD. BMJ. 2011; 342: d2549. 10.1136/bmj.d2549 P.M Short, S.I.W Lipworth, D.H.J Elder, S. Schembri, B.J. Lipworth.
  • 12. Health Informatics Centre dundee.ac.uk/hic Hospital admissions GRO More than 400 lives are being lost each year because breast cancer patients fail to take the full course of the drug Tamoxifen due to "intolerable" side-effects Prescribing Br J Cancer. 2008 December 2; 99(11): 1763–1768. 10.1038/sj.bjc.6604758 McCowan, J Shearer, P T Donnan, J A Dewar, M Crilly, A M Thompson and T P Fahey Researcher Supplied Cohort Cancer patients from a Ninewells clinic Case Study #2: Tamoxifen adherence: Relationship to Mortality in Women with Breast Cancer
  • 13. Health Informatics Centre dundee.ac.uk/hic Research Data Management Platform (RDMP) ‘Optimizing and Augmenting the Research Data Supply Chain` Labs SMR01 Prescribing Raw Data Data Import Databases Custom Extractions & Export Formats RDMP Labs SMR01 Prescribing Raw Data Data Import Structured Database Extraction + Export DataLoad Engine Research Data Warehouse Validate Clean Catalogue QualityChecks Project X Data Marts Validate Clean Catalogue QualityChecks Project Y Data Marts Validate Clean Catalogue QualityChecks DataExtraction Engine
  • 14. Health Informatics Centre dundee.ac.uk/hic Data Set 1 Data Set 6 Data Set 2 Data Set 3 Data Set 4 Data Set 5 Data Set 1 Pseudo-CHI Data Set 2 Pseudo-CHI Data Set 6 Pseudo-CHI Data Set 3 Pseudo-CHI Data Set 4 Pseudo-CHI Data Set 5 Pseudo-CHI CHI and All Identifiable Data Data Set 1 Project -CHI Data Set 4 Project -CHI NHS Network University Network Data Repository Function of Safe Haven Analytic Platform of Safe Haven Virtual Environment – no data leaves
  • 15. Health Informatics Centre dundee.ac.uk/hic • Extraction takes minutes • Data released is standardised – the same regardless of Data Analyst that completes the work • A history is recorded of all changes to data over time • Data released now will be in the same format as in 5 years from now • Metadata has been added • Methods for transforming and validations have been added across all data sets • Tools to manage and explore the data are available to Data Management team and researchers • Audit and Logging all automated • Major work towards integration of image and genomic data
  • 17. Health Informatics Centre dundee.ac.uk/hic • Standard restrictive VDI solution • VMWare View / Horizon
  • 18. Health Informatics Centre dundee.ac.uk/hic • AppVolumes used for Applications • Bring Your Own License • Lots of Application Variations!
  • 19. Health Informatics Centre dundee.ac.uk/hic • There are many types of ISO Certification. • We have 27001:2013 – Certificate Number: 2016/2269 • ISO 27001:2013 is a specification for an information security management system (ISMS). An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation's information risk management processes. What is ISO27001?
  • 20. Health Informatics Centre dundee.ac.uk/hic Why ISO27001 certification? • Independent set of standards – so rather than constantly having to think what documents and processes we should have in place and reinventing the wheel, ISO gives us this! • Gives confidence to other organisations we work with e.g. NHS, main University. • Reduces other documentation requirements for governance, as we can just reference ISO documentation. • Improves the working practices of HIC. This has been particularly the case with our hardware infrastructure. • Key towards Scottish Government Safe Haven Accreditation.
  • 21. Health Informatics Centre dundee.ac.uk/hic Scottish Government Safe Haven Accreditation • 27001 standard controls PLUS some additional ones specific to Safe Havens. • Reviewed by Scottish Government eHealth. • Documentation Required: • Risk Assessment Doc • Mapping of Controls
  • 23. Health Informatics Centre dundee.ac.uk/hic Scope “The provision of data to researchers via safe haven environment, secure patient recruitment, data collection using software tools, data entry, the development and operation of web based applications and all assets underpinning the provision of those services from the locations of HIC premises at Ninewells Hospital and data centres within the University of Dundee Campus”
  • 24. Health Informatics Centre dundee.ac.uk/hic ISMS Controls Status with Statement of Applicability and Gaps
  • 25. Health Informatics Centre dundee.ac.uk/hic ISO Controls – Made up of HIC specific ones and University/NHS general controls University of Dundee Security Policies University of Dundee HR Policies and Procedures (and NHS where appropriate as we have honorary contracts) HIC HR Procedures/Training/Policies HIC Security Policies A7: Human Resource SecurityA5: Information Security Policies A6: Organisation of Information security University of Dundee Security Policies HIC Security Policies, SOPS, Procedures, Work Instructions and Service Descriptions
  • 26. Health Informatics Centre dundee.ac.uk/hic Document Types and Review Static & Formally Approved: HIC Exec & HIC Information Governance Committee • Policies • Standard Operating Procedures (SOPs) • Risk Management Doc • Information Security Management System (ISMS) Manual • Business Continuity Plan Just HIC Exec • Procedures Working Documents (technical): Relevant Technical Manager • Service Descriptions • Work Instructions • Asset and Responsibility Matrix • Disaster Recovery Plans • Infrastructure Diagrams
  • 27. Health Informatics Centre dundee.ac.uk/hic Structure of Docs in Box Become aware of an improvement of our current procedure Take a copy of Procedure from “Live” folder and move to “Under Development”. Draft change using tracked changes. Ask Technical Manager to review. Technical Manager moves the doc they have approved to “Awaiting Approval Folder” and asks for it to be included in HIC Exec Meeting Agenda for review. If approved at HIC Exec either formally approved or sent to HIC Information Governance Committee for additional formal approval (if document type requires) Approved doc is moved to “Live” folder by HIC Admin Procedure Changes
  • 28. Health Informatics Centre dundee.ac.uk/hic Infrastructure comprised UoD, HIC & NHS University of Dundee Network NHS Network HIC Managed Hardware HIC Managed Hypervisor Cluster HIC Managed Operating Systems HIC Managed Applications UoD Hardware UoD Hypervisor UoD OS UoD Applications HIC and UoD use identical platform technology and share locations Hardware & responsibility for management varies depending on specificity University of Dundee Data Centres NHS Locations
  • 29. Health Informatics Centre dundee.ac.uk/hic Timelines • Help from University’s Information Security Officer (Graham McKay) to get us up to the required standard. • Passed our Stage 1 audit of our documentation in June 2015. • Passed our Stage 2 audit of our systems (do we do what we say we do in our documentation) in Jan 2016. • Passed second Stage 2 audit July 2016 • Now have full audits every 6 months for the next 3 years!
  • 30. Health Informatics Centre dundee.ac.uk/hic Phil Appleby Jim Galloway Chris Hall Duncan HeatherEmily Jefferson Claire JonesGordon McAllister Keith MilburnLeandro Tramma Donald Scobbie Thomas Nind Guney Hanedan Graham McKay Many thanks to the people that did all the work!

Editor's Notes

  • #9: Pre-Grant Application Service Feasibility Aggregates Inclusion & Exclusion breakdowns Cohort Identification Case Control Matching
  • #12: Changed the black font in the blue bubbles to white
  • #13: Changed the black font in the blue bubbles to white