SlideShare a Scribd company logo
Cloud Computing Enables
   Consumer-Centered
       Healthcare

     Eiji Sasahara, Ph.D., MBA
         Dan McGuire, MBA
       Hitoshi Iwashita, MBA
  Healthcare Cloud Initiative
        October 15, Intiative
         ©2009 Healthcare Cloud 2009   1
Agenda

•   1. Introduction
•   2. Understanding Cloud Computing
•   3. Cloud Computing in Healthcare
•   4. Case study in Life Science/Pharma
•   5. Case study in Healthcare provider




               ©2009 Healthcare Cloud Intiative   2
1. Introduction (1)

   • Speakers
     – Eiji Sasahara, Ph.D., MBA
       http://www.linkedin.com/in/esasahara


     – Dan McGuire, MBA
       http://www.linkedin.com/pub/dan-mcguire-japan-
       healthcare-network/1/970/329


     – Hitoshi Iwashita, MBA
       http://www.linkedin.com/pub/hitoshi-iwashita/0/34a/694


                      ©2009 Healthcare Cloud Intiative          3
1. Introduction (2)

   • Healthcare Cloud Initiative
     – Grass-root group to share knowledge
       about benefits and risks of cloud
       computing, and to promote new
       business development with ICT
       utilization in the healthcare industry
        • Life science & Pharmaceutical
        • Healthcare Provider
        • Healthcare Payer


                   ©2009 Healthcare Cloud Intiative   4
1. Introduction (3)

    • Healthcare Cloud Initiative
        – Focus areas in Healthcare Value Chain

  Patients                           Healthcare Communication              General
                 Academia
 & families                         Professionals  Media                  Consumers


            Opportunities and Risks of Cloud Computing
                               -New Business Development
                               -Technology Innovation


 Clinical       Relationship         Professional          Advertising   Direct-to-
 Trial          Development          Education             & Promotion   Consumer
 Supports       w/Opinion            & Advocacy                          Education
                Leaders                                                  & Advocacy

                               ©2009 Healthcare Cloud Intiative                  5
1. Introduction (4)

   • Cloud Security Alliance
      – Global, not-for-profit organization
      – Inclusive membership, supporting broad
        spectrum of subject matter expertise:
        cloud experts, security, legal,
        compliance, virtualization, and on and
        on…
      – We believe Cloud Computing has a
        robust future, we want to make it better
    “To promote the use of best practices for providing security assurance
     within Cloud Computing, and provide education on the uses of Cloud
           Computing to help secure all other forms of computing.”

                          ©2009 Healthcare Cloud Intiative              6
1. Introduction (5)

   • Cloud Security Alliance
        – Individual Members (LinkedIn Community)
 <Active Working Groups>                                <New Working Groups>
   -Editorial                                                -Healthcare
   -Educational Outreach                                     -Cloud Threat Analysis
   -Architecture                                             -US Federal Government
   -Governance, Risk Mgt, Compliance,                        -Financial Services
    Business Continuity
   -Legal & E-Discovery
   -Portability, Interoperability and Application Security
   -Identity and Access Mgt, Encryption & Key Mgt
   -Data Center Operations and Incident Response
   -Information Lifecycle Management & Storage
   -Virtualization and Technology Compartmentalization
                               ©2009 Healthcare Cloud Intiative                       7
1. Introduction (6)

   • Cloud Security Alliance
     – Resources
        • ”Security Guidance for Critical Areas of
          Focus in Cloud Computing”
          (http://www.cloudsecurityalliance.org/)
        • ”Cloud Security and Privacy: An Enterprise
          Perspective on Risks and Compliance”
          (http://oreilly.com/catalog/9780596802769/)




                   ©2009 Healthcare Cloud Intiative     8
2. Understanding Cloud Computing (1)

  • Definition of Cloud Computing
    by National Institute of Standards and Technology (V15)
    “Cloud computing is a model for enabling
    convenient, on-demand network access to
    a shared pool of configurable computing
    resources (e.g., networks, servers, storage,
    applications, and services) that can be
    rapidly provisioned and released with
    minimal management effort or service
    provider interaction.”
    (http://csrc.nist.gov/groups/SNS/cloud-
    computing/index.html)
                      ©2009 Healthcare Cloud Intiative        9
2. Understanding Cloud Computing (2)

  • Characteristics of Cloud Computing
    by NIST (V15)
     – On-demand self-service
     – Ubiquitous network access
     – Resource pooling
        • Location independence
        • Homogeneity
     – Rapid elasticity
     – Measured service
                ©2009 Healthcare Cloud Intiative   10
2. Understanding Cloud Computing (3)

  • Cloud Service Models by NIST (V15)
     – Cloud Software as a Service (SaaS)
       • Use provider’s applications over a network
     – Cloud Platform as a Service (PaaS)
       • Deploy customer-created applications to a cloud
     – Cloud Infrastructure as a Service (IaaS)
       • Rent processing, storage, network capacity, and
         other fundamental computing resources




                  ©2009 Healthcare Cloud Intiative    11
2. Understanding Cloud Computing (4)

  • Cloud Deployment Models by NIST (V15)
     – Private cloud
       • enterprise owned or leased
     – Community cloud
       • shared infrastructure for specific community
     – Public cloud
       • Sold to the public, mega-scale infrastructure
     – Hybrid cloud
       • composition of two or more clouds

                  ©2009 Healthcare Cloud Intiative   12
2. Understanding Cloud Computing (5)

  • Characteristics of Cloud Computing
    by Cloud Security Alliance
     – Abstraction of Infrastructure
     – Resource Democratization
     – Services Oriented Architecture
     – Elasticity/Dynamism
     – Utility Model of Consumption & Allocation

        Business requirements identify
         features of cloud computing
                 ©2009 Healthcare Cloud Intiative   13
2. Understanding Cloud Computing (6)

  • Difficulty in Cloud Computing
    by Cloud Security Alliance
     – Who manage it
     – Who owns it
     – Where it’s located
     – Who has access to it
     – How it’s accessed
    Big challenge: Security and risk control
    under the cloud computing environment
                 ©2009 Healthcare Cloud Intiative   14
2. Understanding Cloud Computing (7)

  • Architecture of Cloud Computing

  Business (e.g.)                     Healthcare       Healthcare
                     Life Science
  Layer                                 Payer           Provider


                    Software: Collaborative, Content, ERM, SCM, CRM,
  Application       Operations & Manufacturing, Engineering, Business     SaaS
  Layer             Intelligence, etc.

                    Software: Application Development, Quality & Life-
  Platform          Cycle Tools, Application Server/Integration &
                    Process Automation Middleware, Information & Data
                                                                          PaaS
  Layer
                    management, Systems & Network Management

                    Software: System & network management, Security,
  Infrastructure    Storage                                               IaaS
  Layer             Hardware: Healthcare Storage, Network, Clients
                        ©2009 Server, Cloud Intiative                    15
2. Understanding Cloud Computing (8)

  • What is Governance, Risk and
    Compliance (GRC) Management?
     – Governance: Activities to demonstrate
       strategy direction and systems to
       regulate and monitor corporate business
       management
     – Risk: Activities to identify, analyze and
       manage risks inside/outside the
       company
     – Compliance: Activities to adhere to rules
       and requirements set by laws, standards
       and code of ethics Cloud Intiative
                  ©2009 Healthcare               16
2. Understanding Cloud Computing (9)

  • GRC Management and ICT
     – Application Layer
        •   Compliance Management Solutions
        •   Business Assurance Analytic Solutions
        •   Financial Compliance and Reporting
        •   Compliance Process Automation
        •   Enterprise and Operational Risk Management
            Solutions
     – Platform and Infrastructure Layers
        • Compliance Infrastructure Solutions
             – Security Management Solutions
             – IT Governance Management Solutions
             – Records and Information Management Solutions
                       ©2009 Healthcare Cloud Intiative       17
2. Understanding Cloud Computing (10)

  • Architecture of GRC Management ICT
  Business                            Personal        Consumer
                       J-SOX
  Layer                              Information       Safety


                   Software: Compliance Management, Business
  Application      Assurance Analytic, Financial Compliance and          SaaS
  Layer            Reporting, Compliance Process Automation,
                   Enterprise and Operational Risk Management, etc.

                   Software: Application Development, Quality & Life-
  Platform         Cycle Tools, Application Server/Integration &
                   Process Automation Middleware, Information & Data
                                                                         PaaS
  Layer
                   management, Systems & Network Management

                   Software: System & network management, Security,
  Infrastructure   Storage                                               IaaS
  Layer            Hardware: Healthcare Storage, Network, Clients
                       ©2009 Server, Cloud Intiative                    18
2. Understanding Cloud Computing (11)
  • Impact of Consumer as a Stakeholder
     – Consumer-centered healthcare drives ICT utilization.
     – Consumerization of ICT drives cloud computing.
                                                                       Consumer-
  Business                          Healthcare            Healthcare
                                                                       Centered
                Life Science
  Layer                               Payer                Provider
                                                                       Movement

                   Software:
  Application                                                               SaaS
  Layer                             Healthcare              Cloud
                                       ICT                Computing
                   Software:
  Platform                                      GRC                         PaaS
  Layer                                      Management
                                                 Consumer
                   Software:                        as a
  Infrastructure                                Stakeholder                 IaaS
  Layer            Hardware: Healthcare Cloud Intiative
                       ©2009                                               19
3. Cloud Computing in Healthcare (1)

   • “Cloud Computing: A new business
     paradigm for biomedical information sharing”
      Rosenthal A, Mork P, Li MH, Stanford J, Koester D, Reynolds P.
       J Biomed Inform. 2009 Aug 26.
      (http://www.ncbi.nlm.nih.gov/pubmed/19715773)

     – For customers, cloud computing is
       primarily a new business paradigm, as
       opposed to a new technical paradigm.

      Who are “customers” in healthcare?
      = Consumers (Patients and families)
                       ©2009 Healthcare Cloud Intiative          20
3. Cloud Computing in Healthcare (2)

     – Features of Cloud Computing in
       Biomedical informatics
        • Resource outsourcing
        • Utility computing
        • Large number of machines
        • Automated resource management
        • Virtualization
        • Parallel computing
        Business requirements identify
         features ofHealthcare CloudComputing
                ©2009 Cloud Intiative           21
3. Cloud Computing in Healthcare (3)

   • “Security and privacy requirements for multi-
     institutional cancer research data grid”
      Manion FJ, Robbins RJ, Weems WA, Crowley RS.
      BMC Med Inform Decis Mak. 2009 Jun 15;9:31.
      (http://www.ncbi.nlm.nih.gov/pubmed/19527521)

     – Key Challenge is developing suitable
       models for authentication and
       authorization practices within federated
       environment.
     Healthcare cloud is based on federated
         environment (à Hybrid Cloud)
                      ©2009 Healthcare Cloud Intiative   22
3. Cloud Computing in Healthcare (4)

   • Recommendation for large scale federated sharing of data
     within a regulated environment
      – Necessity to construct separate legal or corporate entities for governance
        of federated sharing initiatives
      – Consensus on the treatment of foreign and commercial partnerships
      – Development of risk models and risk management processes
      – Development of technical infrastructure to support the credentia ling
        process associated with research including human subjects
      – Exploring the feasibility of developing large-scale, federated honest broker
        approaches
      – Development of suitable, federated identity provisioning processes to
        support federated authentication and authorization
      – Community development of requisite HIPAA and research ethics training
        modules by federation members
      – Recognition of the need for central auditing requirements and authority
      – Use of two-protocol data exchange models where possible in federation

                            ©2009 Healthcare Cloud Intiative                  23
3. Cloud Computing in Healthcare (5)

 • Summary
    – Cloud computing is primarily a new
      business paradigm.
    – Consumer-as-a-Stakeholder approach
      integrates cloud computing, GRC
      management and healthcare ICT.
    – GRC management should be the
      enabler of cloud computing in total
      healthcare value chain.
                ©2009 Healthcare Cloud Intiative   24

More Related Content

PDF
Cloud security and adoption
PDF
Cloud Security Strategy
PPTX
Getting Your IT Security Learners Ready for the Cloud with CCSK Certification
PDF
SECURE CLOUD ARCHITECTURE
PDF
Cloud Computing 28 Oct09 Research
PDF
Security architecture
PPTX
Ohm2013 cloud security 101 slideshare
PPT
2011 Digital Summit - Not So Cloudy - Agcaoili
Cloud security and adoption
Cloud Security Strategy
Getting Your IT Security Learners Ready for the Cloud with CCSK Certification
SECURE CLOUD ARCHITECTURE
Cloud Computing 28 Oct09 Research
Security architecture
Ohm2013 cloud security 101 slideshare
2011 Digital Summit - Not So Cloudy - Agcaoili

What's hot (19)

PDF
Qubole GDPR Security and Compliance Whitepaper
PDF
Manage risk by protecting apps, data and usage
PPTX
RSA: CSA GRC Stack Update for the CSA Atlanta Chapter
PPTX
Introduction to RESILIA and Cyber Resilience
PDF
Security Concerns in Cloud Computing
PPTX
CSA Atlanta and Metro Atlanta ISSA Chapter Meeting May 2014 - Key Threats to ...
PDF
Losing Control to the Cloud
PPTX
Cloud is not an option, but is security?
PDF
Cloud Security And Privacy
PPT
Securing your esi_piedmont
PPTX
Digital IQ in managing risk and cyber threats
PDF
Risk-driven and Business-outcome-focused Enterprise Security Architecture Fra...
PPTX
Security in Cloud Computing
PDF
___2360_SP_RBR_4pp_FINAL---Screen
PPTX
Ramnish Singh Platform Security Briefing
PDF
Cloud computing applications for e health
PPTX
Cloud computing
PDF
IBM Rational Software Conference 2009 Day 2 Keynote: Steve Mills
PDF
Information Security Shake-Up
 
Qubole GDPR Security and Compliance Whitepaper
Manage risk by protecting apps, data and usage
RSA: CSA GRC Stack Update for the CSA Atlanta Chapter
Introduction to RESILIA and Cyber Resilience
Security Concerns in Cloud Computing
CSA Atlanta and Metro Atlanta ISSA Chapter Meeting May 2014 - Key Threats to ...
Losing Control to the Cloud
Cloud is not an option, but is security?
Cloud Security And Privacy
Securing your esi_piedmont
Digital IQ in managing risk and cyber threats
Risk-driven and Business-outcome-focused Enterprise Security Architecture Fra...
Security in Cloud Computing
___2360_SP_RBR_4pp_FINAL---Screen
Ramnish Singh Platform Security Briefing
Cloud computing applications for e health
Cloud computing
IBM Rational Software Conference 2009 Day 2 Keynote: Steve Mills
Information Security Shake-Up
 
Ad

Similar to Cloud Computing Enables Consumer-Centered Healthcare (20)

PDF
Himss 2011 securing health information in the cloud -- feisal nanji
PDF
Cloud Computing Webinar - John Reza
PDF
Sukhbir jasuja digital_trends_11
PDF
Cloud Computing Building the foudation in Healthcare
PDF
Cloud Computing in Healthcare IT
PPT
Cloud Computing in Health
PDF
Cloud Security Alliance - Guidance
PDF
Info Sec 2010 Possibilities And Security Challenges Of Cloud Computing (Han...
PDF
Accenture Cloud Healthcare Po V
PDF
Accenture Cloud Healthcare Po V
PDF
Accenture Cloud Healthcare Po V
PPTX
CLOUD COMPUTING - Introduction -chapter-1
PPTX
2015 APHL Annual Meeting - Racing to the Clouds: How Cloud Computing is Advan...
PDF
Leaders in the Cloud: Identifying Cloud Business Value for Customers
PPTX
Aws jvaria e_collaborationforum
PPT
2012.06.07 - Marché et tendances du Cloud vus par des analystes et par IBM
PPTX
Impact of cloud computing on health industry
PPTX
Cloud computing arma_nnj
PDF
CFO Summit Series - Cloud Computing
PDF
Cscchealthcare110512
Himss 2011 securing health information in the cloud -- feisal nanji
Cloud Computing Webinar - John Reza
Sukhbir jasuja digital_trends_11
Cloud Computing Building the foudation in Healthcare
Cloud Computing in Healthcare IT
Cloud Computing in Health
Cloud Security Alliance - Guidance
Info Sec 2010 Possibilities And Security Challenges Of Cloud Computing (Han...
Accenture Cloud Healthcare Po V
Accenture Cloud Healthcare Po V
Accenture Cloud Healthcare Po V
CLOUD COMPUTING - Introduction -chapter-1
2015 APHL Annual Meeting - Racing to the Clouds: How Cloud Computing is Advan...
Leaders in the Cloud: Identifying Cloud Business Value for Customers
Aws jvaria e_collaborationforum
2012.06.07 - Marché et tendances du Cloud vus par des analystes et par IBM
Impact of cloud computing on health industry
Cloud computing arma_nnj
CFO Summit Series - Cloud Computing
Cscchealthcare110512
Ad

More from Eiji Sasahara, Ph.D., MBA 笹原英司 (20)

PDF
欧州セキュリティ認証制度(EUCC)と CSA STAR/CCM:イタリアのユースケースに学ぶ
PDF
クラウドネイティブな組込ソフトウェア開発手法とMLSecOpsへの進化 : 医療機器に学ぶ
PDF
「NISTIR 8320 ハードウェア対応セキュリティ: クラウド・エッジコンピューティングのユースケース向け プラットフォームセキュリティの階層型アプ...
PDF
クラウドワークロードセキュリティと 新興技術評価 -FedRAMP新ガイダンス-
PDF
「NISTIR 8320C ハードウェア対応セキュリティ:マシンアイデンティティ管理と保護」 初期公開草案概説
PDF
「NISTIR 8320D ハードウェア対応セキュリティ:ハードウェアベースの秘密計算」初期公開草案概説
PDF
医療/介護イノベーションの“砂場”に 変貌するシンガポール :シンガポールのクラウドセキュリティ管理手法
PDF
Metaverse and NFTs on the Healthcare Cloud
PPTX
米国大統領令を起点とする医療機器のゼロトラストとSBOM
PPTX
SDGs達成に向けたデジタルヘルスを支えるクラウドネイティブセキュリティ
PPTX
ロボット支援手術(RAS)システムの脅威モデリング ~医療ロボットから自動車への横展開~
PPTX
ゲノムデータのサイバーセキュリティとアクセス制御
PPTX
プライバシーエンジニアリング技術標準化の欧米比較
PPTX
医療におけるサードパーティベンダーリスク管理
PPTX
バイオ/医療サプライチェーンのサイバーセキュリティリスク管理
PPTX
最新事例に学ぶクラウドネイティブな医療AIのセキュリティ
PPTX
医療クラウドにおけるランサムウェア攻撃予防対策
PPTX
遠隔医療のクラウド利用とリスク管理
PDF
Landscape of Cloud-Driven Digital Health Platform Market in Japan 2023
PDF
バイオエコノミー産業の サイバーセキュリティ最新動向
欧州セキュリティ認証制度(EUCC)と CSA STAR/CCM:イタリアのユースケースに学ぶ
クラウドネイティブな組込ソフトウェア開発手法とMLSecOpsへの進化 : 医療機器に学ぶ
「NISTIR 8320 ハードウェア対応セキュリティ: クラウド・エッジコンピューティングのユースケース向け プラットフォームセキュリティの階層型アプ...
クラウドワークロードセキュリティと 新興技術評価 -FedRAMP新ガイダンス-
「NISTIR 8320C ハードウェア対応セキュリティ:マシンアイデンティティ管理と保護」 初期公開草案概説
「NISTIR 8320D ハードウェア対応セキュリティ:ハードウェアベースの秘密計算」初期公開草案概説
医療/介護イノベーションの“砂場”に 変貌するシンガポール :シンガポールのクラウドセキュリティ管理手法
Metaverse and NFTs on the Healthcare Cloud
米国大統領令を起点とする医療機器のゼロトラストとSBOM
SDGs達成に向けたデジタルヘルスを支えるクラウドネイティブセキュリティ
ロボット支援手術(RAS)システムの脅威モデリング ~医療ロボットから自動車への横展開~
ゲノムデータのサイバーセキュリティとアクセス制御
プライバシーエンジニアリング技術標準化の欧米比較
医療におけるサードパーティベンダーリスク管理
バイオ/医療サプライチェーンのサイバーセキュリティリスク管理
最新事例に学ぶクラウドネイティブな医療AIのセキュリティ
医療クラウドにおけるランサムウェア攻撃予防対策
遠隔医療のクラウド利用とリスク管理
Landscape of Cloud-Driven Digital Health Platform Market in Japan 2023
バイオエコノミー産業の サイバーセキュリティ最新動向

Recently uploaded (20)

PPTX
Electromyography (EMG) in Physiotherapy: Principles, Procedure & Clinical App...
PPTX
1 General Principles of Radiotherapy.pptx
PPT
Management of Acute Kidney Injury at LAUTECH
PPT
ASRH Presentation for students and teachers 2770633.ppt
PPTX
SKIN Anatomy and physiology and associated diseases
PPTX
NEET PG 2025: Memory-Based Recall Questions Compiled by Dr. Shivankan Kakkar, MD
PPTX
Gastroschisis- Clinical Overview 18112311
PPT
genitourinary-cancers_1.ppt Nursing care of clients with GU cancer
PPTX
Neuropathic pain.ppt treatment managment
PPT
Obstructive sleep apnea in orthodontics treatment
PPTX
Slider: TOC sampling methods for cleaning validation
PPT
1b - INTRODUCTION TO EPIDEMIOLOGY (comm med).ppt
PPT
Breast Cancer management for medicsl student.ppt
DOCX
RUHS II MBBS Microbiology Paper-II with Answer Key | 6th August 2025 (New Sch...
DOCX
NEET PG 2025 | Pharmacology Recall: 20 High-Yield Questions Simplified
PPTX
Neurotransmitter, Types of neurotransmitters,Neurotransmitter function, Neur...
PDF
Rheumatoid arthritis RA_and_the_liver Prof AbdelAzeim Elhefny Ain Shams Univ...
PDF
Khadir.pdf Acacia catechu drug Ayurvedic medicine
PDF
Therapeutic Potential of Citrus Flavonoids in Metabolic Inflammation and Ins...
PPTX
JUVENILE NASOPHARYNGEAL ANGIOFIBROMA.pptx
Electromyography (EMG) in Physiotherapy: Principles, Procedure & Clinical App...
1 General Principles of Radiotherapy.pptx
Management of Acute Kidney Injury at LAUTECH
ASRH Presentation for students and teachers 2770633.ppt
SKIN Anatomy and physiology and associated diseases
NEET PG 2025: Memory-Based Recall Questions Compiled by Dr. Shivankan Kakkar, MD
Gastroschisis- Clinical Overview 18112311
genitourinary-cancers_1.ppt Nursing care of clients with GU cancer
Neuropathic pain.ppt treatment managment
Obstructive sleep apnea in orthodontics treatment
Slider: TOC sampling methods for cleaning validation
1b - INTRODUCTION TO EPIDEMIOLOGY (comm med).ppt
Breast Cancer management for medicsl student.ppt
RUHS II MBBS Microbiology Paper-II with Answer Key | 6th August 2025 (New Sch...
NEET PG 2025 | Pharmacology Recall: 20 High-Yield Questions Simplified
Neurotransmitter, Types of neurotransmitters,Neurotransmitter function, Neur...
Rheumatoid arthritis RA_and_the_liver Prof AbdelAzeim Elhefny Ain Shams Univ...
Khadir.pdf Acacia catechu drug Ayurvedic medicine
Therapeutic Potential of Citrus Flavonoids in Metabolic Inflammation and Ins...
JUVENILE NASOPHARYNGEAL ANGIOFIBROMA.pptx

Cloud Computing Enables Consumer-Centered Healthcare

  • 1. Cloud Computing Enables Consumer-Centered Healthcare Eiji Sasahara, Ph.D., MBA Dan McGuire, MBA Hitoshi Iwashita, MBA Healthcare Cloud Initiative October 15, Intiative ©2009 Healthcare Cloud 2009 1
  • 2. Agenda • 1. Introduction • 2. Understanding Cloud Computing • 3. Cloud Computing in Healthcare • 4. Case study in Life Science/Pharma • 5. Case study in Healthcare provider ©2009 Healthcare Cloud Intiative 2
  • 3. 1. Introduction (1) • Speakers – Eiji Sasahara, Ph.D., MBA http://www.linkedin.com/in/esasahara – Dan McGuire, MBA http://www.linkedin.com/pub/dan-mcguire-japan- healthcare-network/1/970/329 – Hitoshi Iwashita, MBA http://www.linkedin.com/pub/hitoshi-iwashita/0/34a/694 ©2009 Healthcare Cloud Intiative 3
  • 4. 1. Introduction (2) • Healthcare Cloud Initiative – Grass-root group to share knowledge about benefits and risks of cloud computing, and to promote new business development with ICT utilization in the healthcare industry • Life science & Pharmaceutical • Healthcare Provider • Healthcare Payer ©2009 Healthcare Cloud Intiative 4
  • 5. 1. Introduction (3) • Healthcare Cloud Initiative – Focus areas in Healthcare Value Chain Patients Healthcare Communication General Academia & families Professionals Media Consumers Opportunities and Risks of Cloud Computing -New Business Development -Technology Innovation Clinical Relationship Professional Advertising Direct-to- Trial Development Education & Promotion Consumer Supports w/Opinion & Advocacy Education Leaders & Advocacy ©2009 Healthcare Cloud Intiative 5
  • 6. 1. Introduction (4) • Cloud Security Alliance – Global, not-for-profit organization – Inclusive membership, supporting broad spectrum of subject matter expertise: cloud experts, security, legal, compliance, virtualization, and on and on… – We believe Cloud Computing has a robust future, we want to make it better “To promote the use of best practices for providing security assurance within Cloud Computing, and provide education on the uses of Cloud Computing to help secure all other forms of computing.” ©2009 Healthcare Cloud Intiative 6
  • 7. 1. Introduction (5) • Cloud Security Alliance – Individual Members (LinkedIn Community) <Active Working Groups> <New Working Groups> -Editorial -Healthcare -Educational Outreach -Cloud Threat Analysis -Architecture -US Federal Government -Governance, Risk Mgt, Compliance, -Financial Services Business Continuity -Legal & E-Discovery -Portability, Interoperability and Application Security -Identity and Access Mgt, Encryption & Key Mgt -Data Center Operations and Incident Response -Information Lifecycle Management & Storage -Virtualization and Technology Compartmentalization ©2009 Healthcare Cloud Intiative 7
  • 8. 1. Introduction (6) • Cloud Security Alliance – Resources • ”Security Guidance for Critical Areas of Focus in Cloud Computing” (http://www.cloudsecurityalliance.org/) • ”Cloud Security and Privacy: An Enterprise Perspective on Risks and Compliance” (http://oreilly.com/catalog/9780596802769/) ©2009 Healthcare Cloud Intiative 8
  • 9. 2. Understanding Cloud Computing (1) • Definition of Cloud Computing by National Institute of Standards and Technology (V15) “Cloud computing is a model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.” (http://csrc.nist.gov/groups/SNS/cloud- computing/index.html) ©2009 Healthcare Cloud Intiative 9
  • 10. 2. Understanding Cloud Computing (2) • Characteristics of Cloud Computing by NIST (V15) – On-demand self-service – Ubiquitous network access – Resource pooling • Location independence • Homogeneity – Rapid elasticity – Measured service ©2009 Healthcare Cloud Intiative 10
  • 11. 2. Understanding Cloud Computing (3) • Cloud Service Models by NIST (V15) – Cloud Software as a Service (SaaS) • Use provider’s applications over a network – Cloud Platform as a Service (PaaS) • Deploy customer-created applications to a cloud – Cloud Infrastructure as a Service (IaaS) • Rent processing, storage, network capacity, and other fundamental computing resources ©2009 Healthcare Cloud Intiative 11
  • 12. 2. Understanding Cloud Computing (4) • Cloud Deployment Models by NIST (V15) – Private cloud • enterprise owned or leased – Community cloud • shared infrastructure for specific community – Public cloud • Sold to the public, mega-scale infrastructure – Hybrid cloud • composition of two or more clouds ©2009 Healthcare Cloud Intiative 12
  • 13. 2. Understanding Cloud Computing (5) • Characteristics of Cloud Computing by Cloud Security Alliance – Abstraction of Infrastructure – Resource Democratization – Services Oriented Architecture – Elasticity/Dynamism – Utility Model of Consumption & Allocation Business requirements identify features of cloud computing ©2009 Healthcare Cloud Intiative 13
  • 14. 2. Understanding Cloud Computing (6) • Difficulty in Cloud Computing by Cloud Security Alliance – Who manage it – Who owns it – Where it’s located – Who has access to it – How it’s accessed Big challenge: Security and risk control under the cloud computing environment ©2009 Healthcare Cloud Intiative 14
  • 15. 2. Understanding Cloud Computing (7) • Architecture of Cloud Computing Business (e.g.) Healthcare Healthcare Life Science Layer Payer Provider Software: Collaborative, Content, ERM, SCM, CRM, Application Operations & Manufacturing, Engineering, Business SaaS Layer Intelligence, etc. Software: Application Development, Quality & Life- Platform Cycle Tools, Application Server/Integration & Process Automation Middleware, Information & Data PaaS Layer management, Systems & Network Management Software: System & network management, Security, Infrastructure Storage IaaS Layer Hardware: Healthcare Storage, Network, Clients ©2009 Server, Cloud Intiative 15
  • 16. 2. Understanding Cloud Computing (8) • What is Governance, Risk and Compliance (GRC) Management? – Governance: Activities to demonstrate strategy direction and systems to regulate and monitor corporate business management – Risk: Activities to identify, analyze and manage risks inside/outside the company – Compliance: Activities to adhere to rules and requirements set by laws, standards and code of ethics Cloud Intiative ©2009 Healthcare 16
  • 17. 2. Understanding Cloud Computing (9) • GRC Management and ICT – Application Layer • Compliance Management Solutions • Business Assurance Analytic Solutions • Financial Compliance and Reporting • Compliance Process Automation • Enterprise and Operational Risk Management Solutions – Platform and Infrastructure Layers • Compliance Infrastructure Solutions – Security Management Solutions – IT Governance Management Solutions – Records and Information Management Solutions ©2009 Healthcare Cloud Intiative 17
  • 18. 2. Understanding Cloud Computing (10) • Architecture of GRC Management ICT Business Personal Consumer J-SOX Layer Information Safety Software: Compliance Management, Business Application Assurance Analytic, Financial Compliance and SaaS Layer Reporting, Compliance Process Automation, Enterprise and Operational Risk Management, etc. Software: Application Development, Quality & Life- Platform Cycle Tools, Application Server/Integration & Process Automation Middleware, Information & Data PaaS Layer management, Systems & Network Management Software: System & network management, Security, Infrastructure Storage IaaS Layer Hardware: Healthcare Storage, Network, Clients ©2009 Server, Cloud Intiative 18
  • 19. 2. Understanding Cloud Computing (11) • Impact of Consumer as a Stakeholder – Consumer-centered healthcare drives ICT utilization. – Consumerization of ICT drives cloud computing. Consumer- Business Healthcare Healthcare Centered Life Science Layer Payer Provider Movement Software: Application SaaS Layer Healthcare Cloud ICT Computing Software: Platform GRC PaaS Layer Management Consumer Software: as a Infrastructure Stakeholder IaaS Layer Hardware: Healthcare Cloud Intiative ©2009 19
  • 20. 3. Cloud Computing in Healthcare (1) • “Cloud Computing: A new business paradigm for biomedical information sharing” Rosenthal A, Mork P, Li MH, Stanford J, Koester D, Reynolds P. J Biomed Inform. 2009 Aug 26. (http://www.ncbi.nlm.nih.gov/pubmed/19715773) – For customers, cloud computing is primarily a new business paradigm, as opposed to a new technical paradigm. Who are “customers” in healthcare? = Consumers (Patients and families) ©2009 Healthcare Cloud Intiative 20
  • 21. 3. Cloud Computing in Healthcare (2) – Features of Cloud Computing in Biomedical informatics • Resource outsourcing • Utility computing • Large number of machines • Automated resource management • Virtualization • Parallel computing Business requirements identify features ofHealthcare CloudComputing ©2009 Cloud Intiative 21
  • 22. 3. Cloud Computing in Healthcare (3) • “Security and privacy requirements for multi- institutional cancer research data grid” Manion FJ, Robbins RJ, Weems WA, Crowley RS. BMC Med Inform Decis Mak. 2009 Jun 15;9:31. (http://www.ncbi.nlm.nih.gov/pubmed/19527521) – Key Challenge is developing suitable models for authentication and authorization practices within federated environment. Healthcare cloud is based on federated environment (à Hybrid Cloud) ©2009 Healthcare Cloud Intiative 22
  • 23. 3. Cloud Computing in Healthcare (4) • Recommendation for large scale federated sharing of data within a regulated environment – Necessity to construct separate legal or corporate entities for governance of federated sharing initiatives – Consensus on the treatment of foreign and commercial partnerships – Development of risk models and risk management processes – Development of technical infrastructure to support the credentia ling process associated with research including human subjects – Exploring the feasibility of developing large-scale, federated honest broker approaches – Development of suitable, federated identity provisioning processes to support federated authentication and authorization – Community development of requisite HIPAA and research ethics training modules by federation members – Recognition of the need for central auditing requirements and authority – Use of two-protocol data exchange models where possible in federation ©2009 Healthcare Cloud Intiative 23
  • 24. 3. Cloud Computing in Healthcare (5) • Summary – Cloud computing is primarily a new business paradigm. – Consumer-as-a-Stakeholder approach integrates cloud computing, GRC management and healthcare ICT. – GRC management should be the enabler of cloud computing in total healthcare value chain. ©2009 Healthcare Cloud Intiative 24