IS EHR BETTER OFF IN THE
         CLOUD?
                       BY
                  Joseph Benliro

    IS 307X , Information Security in Health Care
                  Dr. Stephen Rice
                  December 5, 2011




                                                    S
What is the Cloud?

S “This usage was originally derived from its common depiction in
   network diagrams as an outline of a cloud, used to represent the
   transport of data” – John Rittinghouse

S Provides the means through which everything from computing
   power to computing infrastructure, applications, business
   processes to personal collaboration can be delivered to you as a
   service wherever and whenever you need.

S Fluid and can easily expand and contract.

S Three basic service
  S SaaS, IaaS, and Paas

S Brief Cloud Explanation
Why EHR In the Cloud is a Bad Idea

S   Cloud EHR Systems are Prime Targets for Hackers
    S   Attacks on many of the top cloud providers

S   Not Knowing Exactly Who Has Access
    S   Applications and sensitive data are no longer protected by a secure perimeter.
    S   Medical professionals are accessing data from all types of devices and from diverse locations.
    S   The adoption of new cloud applications requires usernames and passwords and results in
        excess amounts of user credentials that can be lost, forgotten or stolen.
    S   Most audit and compliance solutions can track user access and activity only within the firewall,
        losing visibility when users access cloud-based applications.

S   The Problem With Trusting the Service Provider
    S   Cloud companies may change or completely disappear. As an example, in 2001, GE Healthcare
        bought health records provider Encounter EHR and eventually ended up shutting it down - giving
        records holders 30 days' notice to reclaim their data or lose it.
    S   Files are broken into chunks and may be stored on multiple data centers around the world.
    S   Cloud providers can monitor, data and communications at will.

S   EHR Cloud Services Are Subject to Poor Internet Service Quality
    S   If you do not have Internet connection, then you are not able to get to your data.
    S   patient care could be compromised.
Why EHR In the Cloud is a Great Idea

S The five essential characteristics of cloud computing, outlined in the
   National Institute of Standards and Technology’s NIST SP 800-145
   report

    S On-demand Self-service (Economic Benefits): A small provider
       can provision computing capabilities, such as server time and
       network storage, as needed.

    S Resource pooling: Providers can realize decreased costs
       because the underlying computing resources are pooled to serve
       multiple customers with different physical and virtual resources.

    S Rapid elasticity: Available capabilities can be scaled up or down
       at any time as demand for computing power dictates.

    S Measured service: Service and payment levels are established
       and monitored for consistency and violation. (e.g., a Distributed
       Denial of Service (DDoS) attack)
Why EHR In Cloud is a
           the          S The five essential characteristics
                           of cloud computing, outlined in the
     Great Idea            NIST SP 800-145 report
     (continued)           continued.

                            S Broad Network Access
                               (Data Portability and Mobility):
                               Cloud computing can provide
                               authorized access to records
                               from anywhere on any device.
                               The objective of the Health
                               Information Technology for
                               Economic and Clinical Health
                               Act (HITECH Act), enacted as
                               part of the American Recovery
                               and Reinvestment Act (ARRA)
                               in 2009.

                                S A perfect example was on
                                   the case of ClickCare - a
                                   HIPAA compliant SaaS
                                   and iPhone application.
                                   70 patients were treated
                                   solely over ClickCare with
                                   an overall healing rate of
                                   93% and an estimated
                                   savings of $24,000 in
                                   transportation costs.
Why EHR In the Cloud is a Great Idea
                    (continued)
S Additional Benefis/Advantages of Cloud Computing

   S Improved System Reliability: With everything being stored on
      redundant servers you would never again have to worry about
      losing data.

   S Freedom from Support and Maintenance Responsibilities:
      cloud providers are the ones who are responsible for all
      maintenance, infrastructure, and repair.

   S Infrastructure Flexibility and Scalability: Instead of buying,
      maintaining, and housing servers to meet those periods of peak
      demand, health care organizations can use the cloud to scale up
      or down as needed.
Conclusion
     In the health care environment, where a patient’s life depends on
easy and open access to patient records, access for need to know
personnel should be easy and unaffected by device or location and
unhampered by multiple, inconvenient and hard to remember methods
of authentication. In the Cloud, it is possible to Centralize
authentication thus allowing for a single strong password and
authentication policy for all cloud based applications, eliminating
access barriers and the security risks of managing multiple
passwords.

      Although there are many other security considerations when
moving regulated patient data to the cloud, I believe that appropriate
monitoring controls, layered with access management and strong
authentication will make health care organizations and their affiliates
realize that EHR is better off in the cloud.

More Related Content

PDF
Cloud Computing in Healthcare IT
PDF
Cloud Computing Stats - Cloud for Healthcare
PPTX
Impact of cloud computing on health industry
PPT
Harnessing and securing cloud in patient health monitoring
PDF
Cloud computing in healthcare
PPT
Cloud computing and health care - Facing the Future
PDF
Healthcare in the Clouds
PPTX
Cloud computing - Assessing the Security Risks - Jared Carstensen
Cloud Computing in Healthcare IT
Cloud Computing Stats - Cloud for Healthcare
Impact of cloud computing on health industry
Harnessing and securing cloud in patient health monitoring
Cloud computing in healthcare
Cloud computing and health care - Facing the Future
Healthcare in the Clouds
Cloud computing - Assessing the Security Risks - Jared Carstensen

What's hot (11)

PPT
Taking Healthcare to the Cloud
PDF
iCloudxchange Brochure
PDF
How to be hipaa compliant
DOCX
Scalable and secure sharing of personal health
PDF
Turn Your C-Suite Into Your A-Team
PDF
Iaetsd scalable and secure sharing of personal health
PPT
Healthcare IT Solutions Ensure Uptime, Security and Stability
PDF
Unlock the full potential of IoT
PDF
Dotnet scalable and secure sharing of personal health records in cloud compu...
PDF
ePlus Enabling a Total Healthcare IT Transformation to Deliver the Future of ...
Taking Healthcare to the Cloud
iCloudxchange Brochure
How to be hipaa compliant
Scalable and secure sharing of personal health
Turn Your C-Suite Into Your A-Team
Iaetsd scalable and secure sharing of personal health
Healthcare IT Solutions Ensure Uptime, Security and Stability
Unlock the full potential of IoT
Dotnet scalable and secure sharing of personal health records in cloud compu...
ePlus Enabling a Total Healthcare IT Transformation to Deliver the Future of ...
Ad

Similar to Why EHR in the Cloud is a good Idea (20)

PDF
Accenture Cloud Healthcare Po V
PDF
Accenture Cloud Healthcare Po V
PDF
Accenture Cloud Healthcare Po V
PPTX
Christoph thuemmler cloud computing
PDF
The Adoption of a National Cloud Framework for Healthcare Delivery in Nigeria
DOCX
McMahon and Associates Cloud Usage Policy Paper
PDF
Cloud computing applications for e health
DOCX
Cloud computing report
PDF
Cloud computing in healthcare industry.pdf
PDF
Benefits of Cloud-Based EHR ppt.pdf
PDF
Meaningful Use Forecast: Cloud Computing and Disaster Preparedness
PDF
Cloud computing: What is it and how it can benefit clinical research
PDF
Role of Cloud Computing in Healthcare Systems
PPTX
Cloud Disrupting Healthcare
PDF
ATTRIBUTE-BASED ACCESS CONTROL (ABAC) FOR EHR IN FOG COMPUTING ENVIRONMENT
PDF
Attribute Based Access Control (ABAC) for EHR in Fog Computing Environment
PDF
Cscchealthcare110512
PDF
FAST ALGORITHMS FOR UNSUPERVISED LEARNING IN LARGE DATA SETS
PDF
ATTRIBUTE-BASED ACCESS CONTROL (ABAC) FOR HER IN FOG COMPUTING ENVIRONMENT
PPTX
Building Future-Ready Healthcare IT Platforms: Get To The Cloud
Accenture Cloud Healthcare Po V
Accenture Cloud Healthcare Po V
Accenture Cloud Healthcare Po V
Christoph thuemmler cloud computing
The Adoption of a National Cloud Framework for Healthcare Delivery in Nigeria
McMahon and Associates Cloud Usage Policy Paper
Cloud computing applications for e health
Cloud computing report
Cloud computing in healthcare industry.pdf
Benefits of Cloud-Based EHR ppt.pdf
Meaningful Use Forecast: Cloud Computing and Disaster Preparedness
Cloud computing: What is it and how it can benefit clinical research
Role of Cloud Computing in Healthcare Systems
Cloud Disrupting Healthcare
ATTRIBUTE-BASED ACCESS CONTROL (ABAC) FOR EHR IN FOG COMPUTING ENVIRONMENT
Attribute Based Access Control (ABAC) for EHR in Fog Computing Environment
Cscchealthcare110512
FAST ALGORITHMS FOR UNSUPERVISED LEARNING IN LARGE DATA SETS
ATTRIBUTE-BASED ACCESS CONTROL (ABAC) FOR HER IN FOG COMPUTING ENVIRONMENT
Building Future-Ready Healthcare IT Platforms: Get To The Cloud
Ad

Recently uploaded (20)

PDF
STKI Israel Market Study 2025 version august
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PPT
Geologic Time for studying geology for geologist
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PDF
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
PPTX
The various Industrial Revolutions .pptx
PDF
August Patch Tuesday
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
A comparative study of natural language inference in Swahili using monolingua...
PDF
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
PDF
DP Operators-handbook-extract for the Mautical Institute
PDF
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
PDF
Getting started with AI Agents and Multi-Agent Systems
PPTX
Modernising the Digital Integration Hub
DOCX
search engine optimization ppt fir known well about this
PPTX
Final SEM Unit 1 for mit wpu at pune .pptx
PDF
Univ-Connecticut-ChatGPT-Presentaion.pdf
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
Architecture types and enterprise applications.pdf
PDF
Enhancing emotion recognition model for a student engagement use case through...
STKI Israel Market Study 2025 version august
Assigned Numbers - 2025 - Bluetooth® Document
Geologic Time for studying geology for geologist
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
The various Industrial Revolutions .pptx
August Patch Tuesday
1 - Historical Antecedents, Social Consideration.pdf
A comparative study of natural language inference in Swahili using monolingua...
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
DP Operators-handbook-extract for the Mautical Institute
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
Getting started with AI Agents and Multi-Agent Systems
Modernising the Digital Integration Hub
search engine optimization ppt fir known well about this
Final SEM Unit 1 for mit wpu at pune .pptx
Univ-Connecticut-ChatGPT-Presentaion.pdf
Group 1 Presentation -Planning and Decision Making .pptx
Architecture types and enterprise applications.pdf
Enhancing emotion recognition model for a student engagement use case through...

Why EHR in the Cloud is a good Idea

  • 1. IS EHR BETTER OFF IN THE CLOUD? BY Joseph Benliro IS 307X , Information Security in Health Care Dr. Stephen Rice December 5, 2011 S
  • 2. What is the Cloud? S “This usage was originally derived from its common depiction in network diagrams as an outline of a cloud, used to represent the transport of data” – John Rittinghouse S Provides the means through which everything from computing power to computing infrastructure, applications, business processes to personal collaboration can be delivered to you as a service wherever and whenever you need. S Fluid and can easily expand and contract. S Three basic service S SaaS, IaaS, and Paas S Brief Cloud Explanation
  • 3. Why EHR In the Cloud is a Bad Idea S Cloud EHR Systems are Prime Targets for Hackers S Attacks on many of the top cloud providers S Not Knowing Exactly Who Has Access S Applications and sensitive data are no longer protected by a secure perimeter. S Medical professionals are accessing data from all types of devices and from diverse locations. S The adoption of new cloud applications requires usernames and passwords and results in excess amounts of user credentials that can be lost, forgotten or stolen. S Most audit and compliance solutions can track user access and activity only within the firewall, losing visibility when users access cloud-based applications. S The Problem With Trusting the Service Provider S Cloud companies may change or completely disappear. As an example, in 2001, GE Healthcare bought health records provider Encounter EHR and eventually ended up shutting it down - giving records holders 30 days' notice to reclaim their data or lose it. S Files are broken into chunks and may be stored on multiple data centers around the world. S Cloud providers can monitor, data and communications at will. S EHR Cloud Services Are Subject to Poor Internet Service Quality S If you do not have Internet connection, then you are not able to get to your data. S patient care could be compromised.
  • 4. Why EHR In the Cloud is a Great Idea S The five essential characteristics of cloud computing, outlined in the National Institute of Standards and Technology’s NIST SP 800-145 report S On-demand Self-service (Economic Benefits): A small provider can provision computing capabilities, such as server time and network storage, as needed. S Resource pooling: Providers can realize decreased costs because the underlying computing resources are pooled to serve multiple customers with different physical and virtual resources. S Rapid elasticity: Available capabilities can be scaled up or down at any time as demand for computing power dictates. S Measured service: Service and payment levels are established and monitored for consistency and violation. (e.g., a Distributed Denial of Service (DDoS) attack)
  • 5. Why EHR In Cloud is a the S The five essential characteristics of cloud computing, outlined in the Great Idea NIST SP 800-145 report (continued) continued. S Broad Network Access (Data Portability and Mobility): Cloud computing can provide authorized access to records from anywhere on any device. The objective of the Health Information Technology for Economic and Clinical Health Act (HITECH Act), enacted as part of the American Recovery and Reinvestment Act (ARRA) in 2009. S A perfect example was on the case of ClickCare - a HIPAA compliant SaaS and iPhone application. 70 patients were treated solely over ClickCare with an overall healing rate of 93% and an estimated savings of $24,000 in transportation costs.
  • 6. Why EHR In the Cloud is a Great Idea (continued) S Additional Benefis/Advantages of Cloud Computing S Improved System Reliability: With everything being stored on redundant servers you would never again have to worry about losing data. S Freedom from Support and Maintenance Responsibilities: cloud providers are the ones who are responsible for all maintenance, infrastructure, and repair. S Infrastructure Flexibility and Scalability: Instead of buying, maintaining, and housing servers to meet those periods of peak demand, health care organizations can use the cloud to scale up or down as needed.
  • 7. Conclusion In the health care environment, where a patient’s life depends on easy and open access to patient records, access for need to know personnel should be easy and unaffected by device or location and unhampered by multiple, inconvenient and hard to remember methods of authentication. In the Cloud, it is possible to Centralize authentication thus allowing for a single strong password and authentication policy for all cloud based applications, eliminating access barriers and the security risks of managing multiple passwords. Although there are many other security considerations when moving regulated patient data to the cloud, I believe that appropriate monitoring controls, layered with access management and strong authentication will make health care organizations and their affiliates realize that EHR is better off in the cloud.