challenges of securing clinical data in a cloud-centric world

19
Challenges of Securing Clinical Data in a Cloud- centric World Patty Furukawa – Assistant Dean for IT University of California-Irvine School of Law Doug Edmunds – Assistant Dean for IT University of North Carolina School of Law

Upload: alair

Post on 22-Feb-2016

38 views

Category:

Documents


0 download

DESCRIPTION

Challenges of Securing Clinical Data in a Cloud-centric World. Patty Furukawa – Assistant Dean for IT University of California-Irvine School of Law Doug Edmunds – Assistant Dean for IT University of North Carolina School of Law. UC Irvine School of Law. Founded in 2009 - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Challenges of Securing Clinical Data in a Cloud-centric World

Challenges of Securing

Clinical Data in a Cloud-

centric WorldPatty Furukawa – Assistant Dean for IT

University of California-Irvine School of Law

Doug Edmunds – Assistant Dean for IT

University of North Carolina School of Law

Page 2: Challenges of Securing Clinical Data in a Cloud-centric World

UC Irvine School of LawFounded in 2009Clinical program began in Fall 2011Deployed Time Matters in Spring 2012Switched to Clio in Fall 2012

Page 3: Challenges of Securing Clinical Data in a Cloud-centric World

Academic Year 2012-2013

5 clinics – “firm” policy for information security4 clinics – not under our “firm” policyApproximately 140 students8 full-time faculty7 adjunct faculty1 clinic administrator

Page 4: Challenges of Securing Clinical Data in a Cloud-centric World

UNC School of LawFounded in 1845Clinical program optional for 3LsCase Master used circa 1999-2005Time Matters used from 2005 – 2011 (fall)Clio deployed fall 2011

Page 5: Challenges of Securing Clinical Data in a Cloud-centric World

Academic Year 2012-2013

6 clinics all operating under same “firm” policies1 center for civil rights, non-clinical, needs varyApproximately 70 students (only 3Ls)8 full-time faculty3 full-time staff

Page 6: Challenges of Securing Clinical Data in a Cloud-centric World

Survey ResultsConducted via Teknoids listserv – May 2013Responses from most US geographic regions + 1 from CanadaIndicative of hesitation toward a move to the cloudConcerns mainly about data control

Page 7: Challenges of Securing Clinical Data in a Cloud-centric World
Page 8: Challenges of Securing Clinical Data in a Cloud-centric World
Page 9: Challenges of Securing Clinical Data in a Cloud-centric World
Page 10: Challenges of Securing Clinical Data in a Cloud-centric World
Page 11: Challenges of Securing Clinical Data in a Cloud-centric World
Page 12: Challenges of Securing Clinical Data in a Cloud-centric World

Do you have any formal procedures in place to monitor how clinical data are being stored?

13 out of 14 institutions answered no.Yes - “We utilize encryption on the server and have full logging turned on for all clinical data.”

No - “We need to develop better policies for monitoring this. Although almost all of our data are stored within Clio, some users are still saving data to their network drive (I recently learned), which is not what we would like.”

Page 13: Challenges of Securing Clinical Data in a Cloud-centric World

What types of tools, if any does your IT unit provide and support to help secure clinical information? (institutions w/ local storage)

Main campus ITS Security departmentTime Matters passwords & port limitationDocumentation on disk encryption Limiting access to clinical data only to workstations in the clinicStrict e-mail policiesVPN for faculty Separate server for clinical data

Page 14: Challenges of Securing Clinical Data in a Cloud-centric World

What types of tools, if any does your IT unit provide and support to help secure clinical information? (institutions w/ cloud storage)

Encryption (flash drives, laptop HDs)Password protection (at file level)Data scanning software DLP (data loss prevention) through McAfee Virtualization (Citrix)Secure e-mail through middlewareLogoff script to remove temp files

Page 15: Challenges of Securing Clinical Data in a Cloud-centric World
Page 16: Challenges of Securing Clinical Data in a Cloud-centric World

Information Security TopicsOrganizational and personal risksStolen credentials (phishing attempts, malware)Socially engineered threatsMobile devices Physical securityCloud services

Page 17: Challenges of Securing Clinical Data in a Cloud-centric World

Best PracticesNot all cloud-providers are created equal – differentiation is crucial!Educate your users on the various risksDevelop written SOP and security policiesInvolve your university counsel and security officersCarefully review SLAs and contractsBackup your data

Page 18: Challenges of Securing Clinical Data in a Cloud-centric World

References & ResourcesCisco IronPort (secure e-mail) –http://tinyurl.com/n99l36pWatchdox - http://www2.watchdox.com/Citrix ShareFile – http://www.sharefile.comApple Forum (scripting temp file removal) –http://tinyurl.com/l8vk7pg