19 March 2012
Health Cloud Computing
March19th 2012
Danilo Cattaneo
Direttore Generale InfoCert
Interoperability standards in the various stages of the transition
to Cloud Computing: from Cloud to Trusted Cloud
19 March 2012
Health Cloud Computing
InfoCert at a glance
An implementation of Trusted Cloud Digital Archiving:
Azienda ULSS 8
From cloud to trusted cloud
19 March 2012
Health Cloud Computing
Our Company at a glance
Certification Authority for Digital Signature
Certified E-mail Provider
InfoCert
offers quality services and solutions for
digital
certification
and electronic
information management
InfoCert
implements and supplies
products and services
with experience in
consulting
,
design
and
development
in various sectors (portals, security, digital
certification and ICT regulations)
1
Main
Certification Authority
in Italy in
the Digit PA public list
2
Leader in
Registered E-Mail
3
Certified
player for document
management
to legally defined standards
4
Qualified
partner for business
management processes
19 March 2012
Health Cloud Computing
InfoCert Solution
Products Solutions
Registered e-mail
Document managementDigital preservation
Digital signature
Time stamp
Digital Signature on a
USB Token: for digital document subscription
OTP Remote
Signature : for online subscription without devices
Massive signature : automatic large number document subscription
Documents certified
date and time stamping
Certification Authority
certify the legal value
of the information stamped Ensures integrity, readability and authenticity of documents stored Document presentation maintain the legal value of the original paper document
Certified Digital communication
maintaining legal value of paper communication (not rejectable) Legal value of acceptance and delivery receipts Document workflow management
Digital process task automation and coordination
Information Copyright © InfoCert 2012
19 March 2012
Health Cloud Computing 5
Registered E-mail Digital document preservation Electronic
signature Archivistic digital file Workflow
Users
Emplyees
Back - End efficency Front - End efficency
Our vision for e-health
Perception
Internal :good, many areas involved
Users :good, they find new ways to communicate with the organization and perceived responsiveness
Perception
Internal: good, many affected areas
Users:excellent, have established a new relation channel with the organization and use mainly or exclusively web tools
Perception
Internal :low, only from the few areas more involved
Users : very low, they can begin to communicate by PEC and submitting digital documents.
Step 2:
Process automation Step 3:
Remote customer relation
Step 1:
Single tool implementation
Archiving: advanced use of archive information sets the foundation for electronic health dossier Workflow: processes becomes completely digital, with cost reduction and time saving
System Integration: vertical system integration disengages from phisical support
Electronic Medical Record: provides a common factor digital tools and process innovations introduced in the previous phases
Digital request: shows on the web portal forms to start and interact with internal workflows.
REGISTERED E_MAIL: trusted communication with users and healthcare agencies
SIGNATURE: paperless reports LONG TERM ARCHIVING: document long term archiving
Digital request
100% paperless
100% paper… Electronic Patient Record System integrationInformation Copyright © InfoCert 2012
19 March 2012
Health Cloud Computing 6
The project in Azienda ULSS 8
Consolidation of document assets (clinical, diagnostic, administrative…)
Management of digital signatures (preservation of validity)
Archival for full legal validity and long-term preservation
1
2
3
Targets:
The solution:
A cloud based document preservation system with
9 connectors to clinical systems
1 connector to PACS; reconciliation between studies and records
2 connectors to administative systems
flow Monitoring console
local/Remote Archive browsing facilities
statistics
archived data might offer“disaster recovery” service
Information Copyright © InfoCert 2012
19 March 2012
Health Cloud Computing 7
ULSS8 Asolo: main benefits
BEFORE
Traditional on-site services
AFTER
CLOUDTrusted
services
redundant, secure, resilient services
delegated adherence to norms and
standards
delegation of liability
best-of-breed approach
control
flexibility, customizability
scalability
cost saving
Information Copyright © InfoCert 2012
19 March 2012
Health Cloud Computing 8
HealthCare and Trusted Cloud
HealthCare has strong need for
trusted services
:
Check of documents, possibly including digital signature
Consolidation (time stamping)
Archival for full legal validity and long-term preservation
Identity management for proper document access
1
2
3
4
standards and law compliance
quality certification
accreditation (whenever needed)
Security & Trust culture
1
2
3
4
Trusted services imply:
Information Copyright © InfoCert 2012
19 March 2012
Health Cloud Computing 9
The interoperability issues for a trusted cloud
Standard presidium
• InfoCert operates with established standards in HealthCare (DICOM, HL7, XSD)
Compliance presidium
• Certified, strict compliance with legal standards for Digital Signature, security, identity management
Infrastructure investments
• Secured premises with access control 24hx365, access control, business continuity
Third party certification
• ISO 27001 and ISO 9001 Certification , Adeherence to DigitPA guidelines for Certification Authorities and Registered E-Mail providers
Issues at the
“CLOUD”
LEVEL
:
InfoCert operates with established
standards in HealthCare:
DICOM
HL7
XDS
Issues at the
“TRUSTED CLOUD”
LEVEL
:
Certified, strict compliance with legal
standards
Digital Signature formats and verification
Standard security requirements
Identity management , strong authentication
March 2012
Information Copyright © InfoCert 2012
Health Cloud Computing 10
850.000
registered mailbox (PEC –
Legalmail)
100 million
of certified mail
message (PEC ) in 2011
450 million
of document in legal
storage
4.5 million
of digital signature
certification emitted
Key data
20 M
€
turnover 2010
30 M
€
turnover 2011
25 M
€
share capital
Economics certification as a formal assumption of company’s committment on data and information management
compliance on quality processes
integrity, reliability, openess and
transparency
Values
Membership ETSI (European
Telecommunication Standards Institute), contributing to standards definition
CEN/ISSS Member:
E-Invoicing
Interoperability Interfaces for public procurement in Europe (CEN WS/ BII)
International Regulatory Organization
How do we guarantee what we do?
Technical committee of Assocertificatori for digital signature
Technical committee for Registered e-mail
“E-Invoicing Observatory” (Politecnico di Milano)
working group on Electronic Document promoted by ABI Lab
National Regulatory Organization
ISO 27001 Certification
ISO 9001 Certification
Adeherence to DigitPA guidelines for Certification Authorities and Registered E-Mail providers
19 March 2012
Health Cloud Computing