SlideShare uma empresa Scribd logo
1 de 57
Networking Breakfast
Presentations Start at 9AM ET
Logistics &
Agenda
Grant Elliott
CEO, Ostendio, Inc.
@HCCColaition
#HC3
@HCCCoalition #HC3
Event Sponsors
@HCCCoalition #HC3
Agenda
8:30am Networking breakfast (sponsored by Davis Wright Tremaine LLP)
9:00am HC3 Overview Adam Greene
9:30am What is the Cloud? Hemant Pathak
10:00am The Disruptive Cloud Anish Sebastian
10:20am The Practical Cloud Pete Celano
10:40am Panel Discussion & QA Moderated by Shahid Shah
(Hemant Pathak, Chad Kissinger, Sandeep Pulim, Adam Greene)
11:30am HC3 Wrap up Adam Greene
Noon End
@HCCCoalition #HC3
Questions & Comments
Send questions to @HCCCoalition #HC3
Addressing Regulatory
Challenges of Bringing Health
Care to the Cloud
Adam H. Greene, JD, MPH
Partner, Davis Wright Tremaine LLP
@HCCCoalition #HC3
The Challenges
Cloud computing and
cloud-based mobile
technology can improve
health care and reduce
costs, but…
@HCCCoalition #HC3
The Challenges
Health care is not fully
leveraging cloud
technology because of lack
of trust in information
security
@HCCCoalition #HC3
The Challenges
Where health care
entities leverage cloud
computing, there are too
many inefficiencies:
A sea of different information
security questionnaires
Confusion and disagreement
over business associate
agreement terms
Confusion over information
security responsibilities
@HCCCoalition #HC3
The Challenges
A lack of HHS
guidance on how
HIPAA applies to
cloud computing:
What if cloud vendor was
unaware it was hosting PHI for a
covered entity?
No guidance or audit protocols
specific to business associates
How to handle patients rights
and breaches when you may not
know what information you have
@HCCCoalition #HC3
The Challenges
The price of entry for
small companies into
health care is too high
because of this
confusion.
@HCCCoalition #HC3
The Mission of HC3
Reduce obstacles to the health care sector
leveraging cloud computing technology.
Promote innovation by reducing health care
compliance burdens on health care technology
companies.
@HCCCoalition #HC3
The Objectives of HC3
1. Understanding – Create an accepted
framework for health care and cloud computing
@HCCCoalition #HC3
The Objectives of HC3
Develop internal
guidance on how
HIPAA applies to cloud
computing.
@HCCCoalition #HC3
The Objectives of HC3
Develop
tools,
such as:
Sample business associate agreement
provisions, to address unique cloud
computing issues
Notices that clearly identify each party’s
security responsibilities
A self-audit protocol for cloud computing
providers
@HCCCoalition #HC3
The Objectives of HC3
Work with health care providers and other
associations (e.g., HIMSS, Cloud Security
Alliance) to obtain feedback and promote
the tools and guidance.
@HCCCoalition #HC3
The Objectives of HC3
2. Trust – Build trust in cloud computing and
regulatory compliance through an accepted
accreditation/certification process or other
programs.
@HCCCoalition #HC3
The Objectives of HC3
Certification
needs to be:
Focused on health care (e.g., HIPAA,
Alcohol and Substance Abuse
Treatment Confidentiality)
Focused on cloud computing
Scalable (e.g., works for both large IaaS
provider and small SaaS provider that
does not host its own data)
@HCCCoalition #HC3
The Objectives of HC3
Not looking to reinvent the wheel.
 Adopt and promote any existing or upcoming
certifications/accreditations that meet our needs.
 Tweak any existing certifications/accreditations
that get us 90% of the way there.
@HCCCoalition #HC3
The Objectives of HC3
3. Government Outreach – Seek regulatory
guidance from HHS and other relevant
agencies. Maintain outreach and
transparency with the government.
@HCCCoalition #HC3
The Objectives of HC3
4. What else?
@HCCCoalition #HC3
Next Steps?
Learn from others today about the benefits and
challenges of cloud computing in health care.
Discuss the scope of what HC3 will initially
take on.
Incorporate and set up structure for
membership dues.
Volunteers
Health Care Cloud Coalition
Legal considerations with cloud
computing
A View From The Cloud Vendor.
Insight on the HIPAA Omnibus Rule,
Cloud Privacy & Security, and HIPAA
Enforcement
Hemant Pathak, Assistant General Counsel, Microsoft
@HCCCoalition #HC3
What are the types of cloud model we
are going to discuss today?
 Enterprise Cloud
 Three types of cloud services: SaaS, PaaS, IaaS
 Public, Private, Hybrid
 Always available
 Per user, consumption buying model
 Data and services with a common delivery model in
shared data centers
 Different from traditional “outsourcing”
@HCCCoalition #HC3
Why do customers choose cloud
services?
 On demand scalability, reliability and flexibility of
computing resources, updates, interoperability and tech
support
 Reduction of infrastructure costs & complexities at very
large economies of scale across the board (electricity,
network bandwidth, operations, SW & HW).
 Organizations can “get out” of the Data Center business
 The right vendor can address state of the art security &
privacy protocols to help customers address their
compliance requirements in a highly regulated industry
@HCCCoalition #HC3
From the cloud service provider (CSP) perspective
– what are contracting expectations?
 Cloud services are configurable, but generally not
customizable
 SLA, Service Descriptions, Security Descriptions
 Contract terms that require unique requirements for
service for one individual subscriber are not scalable
 Pre-Sales CSP & customer partnership and due
diligence on contract terms and solution alignment
reduces risk now and in the future for both parties
 Ensure compliance with laws and corporate policies
 Protect brand and reputation for both parties
@HCCCoalition #HC3
From the customer perspective – what
are contracting expectations?
Where and how is data stored?
 Clear data maps and geographic boundary information Data
must be encrypted wherever possible
Who has access and what is accessed?
 Core customer data must be accessed only for service
delivery, troubleshooting, migration and malware prevention
purposes on an exception basis and all access should be
logged
Who owns data?
 The Customer. Data must be fully portable and retrievable
Who pays for costs related to security breaches?
 Commercial term addressed by the parties
@HCCCoalition #HC3
Security & Privacy – How do you get
assurances?
 Security
 Physical Data Center standards
 Secure Networks
 Automated operations
 Robust breach prevention, detection and mitigation
 Compliance -Cloud Service Providers (CSP) should address
regulatory standards
 E.g. - ISO 27001, HIPAA BAA
 Federal Trade Commission
 Watchdog groups
 Healthcare agencies
 DHHS
 Independent Audit & Verification
@HCCCoalition #HC3
What are questions Customers ask a
potential CSP?
 Security & Privacy Compliance
 Does the cloud vendor offer a BAA
 Does the BAA contain all required HIPAA terms
 Does the CSP stipulate to comply with breach notification rule, timely reporting,
appropriate and transparent limitations on use & disclosure and “minimum
necessary”
 Embedded technical, physical and administrative safeguards in support of HIPAA
 Data mining – will my cloud provider use my data for advertising, marketing or
other commercial purpose w/o my consent
 Does CSP have transparent and robust process on addressing third party
requests for data?
 Clinical centered care strategies
 Compliance across collaboration modes through audio, video & messaging
 HealthCare Enterprise Ready
@HCCCoalition #HC3
What are consequences of non-
compliance?
 Phoenix Cardiac Surgery
 Fined $100,000 by DHHS for failure to obtain a BAA
“Covered Entity failed to obtain satisfactory assurances in business
associates agreements from the Internet-based calendar and from the
Internet-based public email providers that these entities would appropriately
safeguard the ePHI received from Covered Entity.”
 Oregon Health & Science University
 Negative PR stemming from breach involving storing a spreadsheet of
patient data with cloud service which was not a business associate.
 DHHS Regulator Quotes
“If you use a cloud service, it should be your business associate. If they
refuse to sign a business associate agreement, don't use the cloud service.”
“…cloud services [are] under direct regulations of HIPAA…,"
@HCCCoalition #HC3
Conclusion
 Health Care Providers moving to the cloud want to
choose a CSP that has been proven trustworthy and that
they can trust.
 Transparency about compliance, security and privacy
practices and use of data is the key to trust.
 Transparency allows customers to determine whether
using a given cloud offering helps them to be compliant
with applicable regulations and corporate policy.
@HCCCoalition #HC3
QUESTIONS?
The Disruptive Cloud –
How the cloud is helping
me drive innovation
Anish Sebastian Co-founder 1EQ
@HCCCoalition #HC3
The Cloud
@HCCCoalition #HC3
The Cloud = 10X Improvement!
 Ease of Use
 Scalability
 Risk and Reliability
 Cost
 Security
 Connectivity
@HCCCoalition #HC3
Ease of Use
@HCCCoalition #HC3
Ease of Use
 Deploy infrastructure quickly
with no need for system
admin
 No cabling, racking,
unboxing or buying
 Software now controls the
infrastructure
 Control your servers with
the click of a mouse
@HCCCoalition #HC3
Scalability
@HCCCoalition #HC3
Scalability
 Can adjust to min by min
variation in demand
 Nothing to purchase and
take delivery
 Increase innovation, by
removing “too scared to try”
syndrome
 Go global in a matter of
seconds (co-location)
@HCCCoalition #HC3
Risk and Reliability
 Cancel immediately
 Change instantly, even OS
 Rebuilt instantly
 No long term contracts
 Based on enterprise grade
hardware
 Employ best practices in IT:
 Design for failure
 Control framework
 Disaster recovery
@HCCCoalition #HC3
Cost
 Pay for only what you use –
nothing up front and pay as you
go
 Zero cap Ex = lower burn rate =
happy investors!
 Cloud has economies of scale,
business model based on
volume not margin
 Since we started using amazon,
prices have gone down
@HCCCoalition #HC3
Security
 Architected for enterprise security
requirements
 More than likely more secure than
what you can normally build
yourself
 AWS White paper on HIPPA
 Ability to quickly fix security holes
and keep up with new compliance
standards.
@HCCCoalition #HC3
Being an “aaS”
SaaS – Software as a Service
PaaS – Platform as a Service
IaaS – Infrastructure as a Service
@HCCCoalition #HC3
The Cloud Pyramid
Broad
Niche
@HCCCoalition #HC3
The cloud Pyramid
Developers
Users
Network Engineers
@HCCCoalition #HC3
The cloud Pyramid
Google Apps, Heroku,
Salesforce
Windows Azure
SendGrid, Mailchip, Twilllio
Zendesk, ……..a lot more
Amazon, Racksapce
@HCCCoalition #HC3
The cloud Pyramid – Applications long
tail effect.
• The long tail
is directly an
impact of the
cloud.
• They all talk
to each
other.
@HCCCoalition #HC3
Connectivity
 This long tail of products
connect to the cloud via API
 It has fueled a new era of API
 Allows for various SaaS
companies to stitch together a
whole series of services
generally via API
 Everything is connected to
everyone
@HCCCoalition #HC3
Differentiation
 Bottom Line:
 The cloud allows you to focus on what
truly makes you different
 Let’s you outsource commoditized
services and services that are not your
core competencies.
@HCCCoalition #HC3
What does the future look like?
The Answer is in the Cloud
Pete Celano
MedStar Institute for Innovation
www.mi2.org
@HCCCoalition #HC3
Mission
 Extend Access to the Poor/Rural
 Reduce Costs
 Better Outcomes
 New Revenue
@HCCCoalition #HC3
New World
 Old World: EMR(s) is
what you have
 New World: Innovate
“north” of the EMR.
And bolt-in.
@HCCCoalition #HC3
Focus Areas
1. Capacity Utilization
2. Extending the Site of
Service
3. Flowing Data to Docs
@HCCCoalition #HC3
5-Step Process
1. What problem are we trying to solve, and RoI?
2. Balance Sheet Test
3. Our BAA
4. Pilot Fast
5. Take it Wide if Pilot Works & Economics are Verified
@HCCCoalition #HC3
Five Predictions
1. Only more inventors will run-not-walk to
healthcare
2. EMR vendors will be acquiring right & left in 2015
and beyond
3. Solutions will start breaking Provider-only and
Provider-Payer (“Provayer?”)
4. Virtual Visits will take off like a rocket
5. Apple’s HealthKit et al will finally make Remote
Patient Monitoring relevant.
Panel Discussion and Q&A
10:40AM – 11:30AM
• Hemant Pathak (Microsoft)
• Chad Kissinger (OnRamp)
• Sandeep Pulim (@Point of Care 360)
• Adam Greene (Davis Wright Tremaine LLP)
- Moderated by Shahid Shah, Netspective

Mais conteúdo relacionado

Mais procurados

Asean 1017 ezine_14pp
Asean 1017 ezine_14ppAsean 1017 ezine_14pp
Asean 1017 ezine_14ppPekerja lepas
 
The realist’s guide to quantum technology and national security
The realist’s guide to quantum technology and national securityThe realist’s guide to quantum technology and national security
The realist’s guide to quantum technology and national securityDeloitte United States
 
Softchoice Security Consolidation Survey Results
Softchoice Security Consolidation Survey ResultsSoftchoice Security Consolidation Survey Results
Softchoice Security Consolidation Survey ResultsSoftchoice Corporation
 
The three technology trends that will make medical breakthroughs possible: bi...
The three technology trends that will make medical breakthroughs possible: bi...The three technology trends that will make medical breakthroughs possible: bi...
The three technology trends that will make medical breakthroughs possible: bi...Brandon Jones
 
Getting to grips with a Service Level Agreement and how SLA-Ready can help
Getting to grips with a Service Level Agreement and how SLA-Ready can helpGetting to grips with a Service Level Agreement and how SLA-Ready can help
Getting to grips with a Service Level Agreement and how SLA-Ready can helpSLA-Ready Network
 
FUTURE-PROOFING CONSUMER IDENTITY AND ACCESS MANAGEMENT
FUTURE-PROOFING CONSUMER IDENTITY AND ACCESS MANAGEMENTFUTURE-PROOFING CONSUMER IDENTITY AND ACCESS MANAGEMENT
FUTURE-PROOFING CONSUMER IDENTITY AND ACCESS MANAGEMENTForgeRock
 
Extending the Power of Consent with User-Managed Access & OpenUMA
Extending the Power of Consent with User-Managed Access & OpenUMAExtending the Power of Consent with User-Managed Access & OpenUMA
Extending the Power of Consent with User-Managed Access & OpenUMAkantarainitiative
 
Rental, HOA, Insurance, Consumer Loans Markets Overview
Rental, HOA, Insurance, Consumer Loans Markets OverviewRental, HOA, Insurance, Consumer Loans Markets Overview
Rental, HOA, Insurance, Consumer Loans Markets OverviewChristopher "Dain" Hall
 
Towards Better Patient Outcomes and Staying Well: The Promise of Cloud Comput...
Towards Better Patient Outcomes and Staying Well: The Promise of Cloud Comput...Towards Better Patient Outcomes and Staying Well: The Promise of Cloud Comput...
Towards Better Patient Outcomes and Staying Well: The Promise of Cloud Comput...accacloud
 
Cloud computing
Cloud computingCloud computing
Cloud computinghundejibat
 
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_CloudPerspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_CloudCheryl Goldberg
 
The Rise of Data Ethics and Security - AIDI Webinar
The Rise of Data Ethics and Security - AIDI WebinarThe Rise of Data Ethics and Security - AIDI Webinar
The Rise of Data Ethics and Security - AIDI WebinarEryk Budi Pratama
 
Kantara a Global Context 2011
Kantara a Global Context 2011Kantara a Global Context 2011
Kantara a Global Context 2011kantarainitiative
 
Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™
Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™
Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™Intralinks
 
Maximising Technology and Information Solutions Through "Interoperability"
Maximising Technology and Information Solutions Through "Interoperability"Maximising Technology and Information Solutions Through "Interoperability"
Maximising Technology and Information Solutions Through "Interoperability"Louise Sinclair
 
Drones: The Insurance Industry's Next Game-Changer?
Drones: The Insurance Industry's Next Game-Changer?Drones: The Insurance Industry's Next Game-Changer?
Drones: The Insurance Industry's Next Game-Changer?Cognizant
 
Kantara - Consent & Information Sharing WG Update
Kantara - Consent & Information Sharing WG UpdateKantara - Consent & Information Sharing WG Update
Kantara - Consent & Information Sharing WG Updatekantarainitiative
 
Data Sovereignty, Security, and Performance Panacea: Why Mastercard Sets the ...
Data Sovereignty, Security, and Performance Panacea: Why Mastercard Sets the ...Data Sovereignty, Security, and Performance Panacea: Why Mastercard Sets the ...
Data Sovereignty, Security, and Performance Panacea: Why Mastercard Sets the ...Dana Gardner
 
Regulatory and compliance forum cloud computing for law firms
Regulatory and compliance forum   cloud computing for law firmsRegulatory and compliance forum   cloud computing for law firms
Regulatory and compliance forum cloud computing for law firmsDatabarracks
 

Mais procurados (20)

Asean 1017 ezine_14pp
Asean 1017 ezine_14ppAsean 1017 ezine_14pp
Asean 1017 ezine_14pp
 
180926 ihan webinar 2
180926 ihan webinar 2180926 ihan webinar 2
180926 ihan webinar 2
 
The realist’s guide to quantum technology and national security
The realist’s guide to quantum technology and national securityThe realist’s guide to quantum technology and national security
The realist’s guide to quantum technology and national security
 
Softchoice Security Consolidation Survey Results
Softchoice Security Consolidation Survey ResultsSoftchoice Security Consolidation Survey Results
Softchoice Security Consolidation Survey Results
 
The three technology trends that will make medical breakthroughs possible: bi...
The three technology trends that will make medical breakthroughs possible: bi...The three technology trends that will make medical breakthroughs possible: bi...
The three technology trends that will make medical breakthroughs possible: bi...
 
Getting to grips with a Service Level Agreement and how SLA-Ready can help
Getting to grips with a Service Level Agreement and how SLA-Ready can helpGetting to grips with a Service Level Agreement and how SLA-Ready can help
Getting to grips with a Service Level Agreement and how SLA-Ready can help
 
FUTURE-PROOFING CONSUMER IDENTITY AND ACCESS MANAGEMENT
FUTURE-PROOFING CONSUMER IDENTITY AND ACCESS MANAGEMENTFUTURE-PROOFING CONSUMER IDENTITY AND ACCESS MANAGEMENT
FUTURE-PROOFING CONSUMER IDENTITY AND ACCESS MANAGEMENT
 
Extending the Power of Consent with User-Managed Access & OpenUMA
Extending the Power of Consent with User-Managed Access & OpenUMAExtending the Power of Consent with User-Managed Access & OpenUMA
Extending the Power of Consent with User-Managed Access & OpenUMA
 
Rental, HOA, Insurance, Consumer Loans Markets Overview
Rental, HOA, Insurance, Consumer Loans Markets OverviewRental, HOA, Insurance, Consumer Loans Markets Overview
Rental, HOA, Insurance, Consumer Loans Markets Overview
 
Towards Better Patient Outcomes and Staying Well: The Promise of Cloud Comput...
Towards Better Patient Outcomes and Staying Well: The Promise of Cloud Comput...Towards Better Patient Outcomes and Staying Well: The Promise of Cloud Comput...
Towards Better Patient Outcomes and Staying Well: The Promise of Cloud Comput...
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_CloudPerspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
 
The Rise of Data Ethics and Security - AIDI Webinar
The Rise of Data Ethics and Security - AIDI WebinarThe Rise of Data Ethics and Security - AIDI Webinar
The Rise of Data Ethics and Security - AIDI Webinar
 
Kantara a Global Context 2011
Kantara a Global Context 2011Kantara a Global Context 2011
Kantara a Global Context 2011
 
Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™
Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™
Direct Edge and BATS Global Markets Trusts Intralinks Dealspace™
 
Maximising Technology and Information Solutions Through "Interoperability"
Maximising Technology and Information Solutions Through "Interoperability"Maximising Technology and Information Solutions Through "Interoperability"
Maximising Technology and Information Solutions Through "Interoperability"
 
Drones: The Insurance Industry's Next Game-Changer?
Drones: The Insurance Industry's Next Game-Changer?Drones: The Insurance Industry's Next Game-Changer?
Drones: The Insurance Industry's Next Game-Changer?
 
Kantara - Consent & Information Sharing WG Update
Kantara - Consent & Information Sharing WG UpdateKantara - Consent & Information Sharing WG Update
Kantara - Consent & Information Sharing WG Update
 
Data Sovereignty, Security, and Performance Panacea: Why Mastercard Sets the ...
Data Sovereignty, Security, and Performance Panacea: Why Mastercard Sets the ...Data Sovereignty, Security, and Performance Panacea: Why Mastercard Sets the ...
Data Sovereignty, Security, and Performance Panacea: Why Mastercard Sets the ...
 
Regulatory and compliance forum cloud computing for law firms
Regulatory and compliance forum   cloud computing for law firmsRegulatory and compliance forum   cloud computing for law firms
Regulatory and compliance forum cloud computing for law firms
 

Destaque

Scale-on-Scale : Part 3 of 3 - Disaster Recovery
Scale-on-Scale : Part 3 of 3 - Disaster RecoveryScale-on-Scale : Part 3 of 3 - Disaster Recovery
Scale-on-Scale : Part 3 of 3 - Disaster RecoveryScale Computing
 
Webinar: Is Convergence right for you? – 4 questions to ask
Webinar: Is Convergence right for you? – 4 questions to askWebinar: Is Convergence right for you? – 4 questions to ask
Webinar: Is Convergence right for you? – 4 questions to askStorage Switzerland
 
Taneja grouptechnologyvalidation scalecomputing
Taneja grouptechnologyvalidation scalecomputingTaneja grouptechnologyvalidation scalecomputing
Taneja grouptechnologyvalidation scalecomputingAccenture
 
Scale-on-Scale : Part 1 of 3 - Production Environment
Scale-on-Scale : Part 1 of 3 - Production EnvironmentScale-on-Scale : Part 1 of 3 - Production Environment
Scale-on-Scale : Part 1 of 3 - Production EnvironmentScale Computing
 
Nutanix NEXT on Tour - Maarssen, Netherlands
Nutanix NEXT on Tour - Maarssen, Netherlands  Nutanix NEXT on Tour - Maarssen, Netherlands
Nutanix NEXT on Tour - Maarssen, Netherlands NEXTtour
 
Nutanix Fundamentals The Enterprise Cloud Company
Nutanix Fundamentals The Enterprise Cloud CompanyNutanix Fundamentals The Enterprise Cloud Company
Nutanix Fundamentals The Enterprise Cloud CompanyNEXTtour
 
Nutanix overview
Nutanix overviewNutanix overview
Nutanix overviewamoreland
 

Destaque (7)

Scale-on-Scale : Part 3 of 3 - Disaster Recovery
Scale-on-Scale : Part 3 of 3 - Disaster RecoveryScale-on-Scale : Part 3 of 3 - Disaster Recovery
Scale-on-Scale : Part 3 of 3 - Disaster Recovery
 
Webinar: Is Convergence right for you? – 4 questions to ask
Webinar: Is Convergence right for you? – 4 questions to askWebinar: Is Convergence right for you? – 4 questions to ask
Webinar: Is Convergence right for you? – 4 questions to ask
 
Taneja grouptechnologyvalidation scalecomputing
Taneja grouptechnologyvalidation scalecomputingTaneja grouptechnologyvalidation scalecomputing
Taneja grouptechnologyvalidation scalecomputing
 
Scale-on-Scale : Part 1 of 3 - Production Environment
Scale-on-Scale : Part 1 of 3 - Production EnvironmentScale-on-Scale : Part 1 of 3 - Production Environment
Scale-on-Scale : Part 1 of 3 - Production Environment
 
Nutanix NEXT on Tour - Maarssen, Netherlands
Nutanix NEXT on Tour - Maarssen, Netherlands  Nutanix NEXT on Tour - Maarssen, Netherlands
Nutanix NEXT on Tour - Maarssen, Netherlands
 
Nutanix Fundamentals The Enterprise Cloud Company
Nutanix Fundamentals The Enterprise Cloud CompanyNutanix Fundamentals The Enterprise Cloud Company
Nutanix Fundamentals The Enterprise Cloud Company
 
Nutanix overview
Nutanix overviewNutanix overview
Nutanix overview
 

Semelhante a HC3 Kickoff presentations - June 19, 2014

EMC Perspective: What Customers Seek from Cloud Services Providers
EMC Perspective: What Customers Seek from Cloud Services ProvidersEMC Perspective: What Customers Seek from Cloud Services Providers
EMC Perspective: What Customers Seek from Cloud Services ProvidersEMC
 
New Era in Insurance - Cloud Computing
New Era in Insurance - Cloud ComputingNew Era in Insurance - Cloud Computing
New Era in Insurance - Cloud ComputingNIIT Technologies
 
Opportunities and Challenges in Data Innovation
Opportunities and Challenges in Data InnovationOpportunities and Challenges in Data Innovation
Opportunities and Challenges in Data InnovationCharles Mok
 
Smart and Secure Healthcare Administration over Cloud Environment
Smart and Secure Healthcare Administration over Cloud EnvironmentSmart and Secure Healthcare Administration over Cloud Environment
Smart and Secure Healthcare Administration over Cloud EnvironmentIRJET Journal
 
How cloud computing is beneficial for the Healthcare industry.pdf
How cloud computing is beneficial for the Healthcare industry.pdfHow cloud computing is beneficial for the Healthcare industry.pdf
How cloud computing is beneficial for the Healthcare industry.pdfLaura Miller
 
Cloud computing Risk management
Cloud computing Risk management  Cloud computing Risk management
Cloud computing Risk management Padma Jella
 
How secure is the cloud? and Amazon vs Walmart which giant will dominant?
How secure is the cloud? and Amazon vs Walmart which giant will dominant?How secure is the cloud? and Amazon vs Walmart which giant will dominant?
How secure is the cloud? and Amazon vs Walmart which giant will dominant?Mohammad Mydul Islam
 
Cloud computing - Assessing the Security Risks - Jared Carstensen
Cloud computing - Assessing the Security Risks - Jared CarstensenCloud computing - Assessing the Security Risks - Jared Carstensen
Cloud computing - Assessing the Security Risks - Jared Carstensenjaredcarst
 
Law Practice Management in the Cloud
Law Practice Management in the CloudLaw Practice Management in the Cloud
Law Practice Management in the CloudCourtney Fisk
 
Cloud computing & service level agreements
Cloud computing & service level agreementsCloud computing & service level agreements
Cloud computing & service level agreementsCade Zvavanjanja
 
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110guestd7fc9c
 
Cloud Computing - A future prerogative
Cloud Computing - A future prerogativeCloud Computing - A future prerogative
Cloud Computing - A future prerogativeWayne Poggenpoel
 
Data Privacy And Security Issues In Cloud Computing.pdf
Data Privacy And Security Issues In Cloud Computing.pdfData Privacy And Security Issues In Cloud Computing.pdf
Data Privacy And Security Issues In Cloud Computing.pdfCiente
 
Future of Cloud Computing in Healthcare.pdf
Future of Cloud Computing in Healthcare.pdfFuture of Cloud Computing in Healthcare.pdf
Future of Cloud Computing in Healthcare.pdfMarie Weaver
 
cloud computing in health care.pptx
cloud computing in health care.pptxcloud computing in health care.pptx
cloud computing in health care.pptxamanyosama12
 
Procurement Of Software And Information Technology Services
Procurement Of Software And Information Technology ServicesProcurement Of Software And Information Technology Services
Procurement Of Software And Information Technology ServicesPeister
 
SLA Based Information Security Metric for Cloud Computing from COBIT 4.1 Fram...
SLA Based Information Security Metric for Cloud Computing from COBIT 4.1 Fram...SLA Based Information Security Metric for Cloud Computing from COBIT 4.1 Fram...
SLA Based Information Security Metric for Cloud Computing from COBIT 4.1 Fram...ijcncs
 

Semelhante a HC3 Kickoff presentations - June 19, 2014 (20)

EMC Perspective: What Customers Seek from Cloud Services Providers
EMC Perspective: What Customers Seek from Cloud Services ProvidersEMC Perspective: What Customers Seek from Cloud Services Providers
EMC Perspective: What Customers Seek from Cloud Services Providers
 
New Era in Insurance - Cloud Computing
New Era in Insurance - Cloud ComputingNew Era in Insurance - Cloud Computing
New Era in Insurance - Cloud Computing
 
Healthcare Cloud Adoption – HIPAA Still the Major Priority
Healthcare Cloud Adoption – HIPAA Still the Major PriorityHealthcare Cloud Adoption – HIPAA Still the Major Priority
Healthcare Cloud Adoption – HIPAA Still the Major Priority
 
Opportunities and Challenges in Data Innovation
Opportunities and Challenges in Data InnovationOpportunities and Challenges in Data Innovation
Opportunities and Challenges in Data Innovation
 
Cloud services and it security
Cloud services and it securityCloud services and it security
Cloud services and it security
 
Impact of Cloud Computing on Healthcare v2.0
Impact of Cloud Computing on Healthcare v2.0Impact of Cloud Computing on Healthcare v2.0
Impact of Cloud Computing on Healthcare v2.0
 
Smart and Secure Healthcare Administration over Cloud Environment
Smart and Secure Healthcare Administration over Cloud EnvironmentSmart and Secure Healthcare Administration over Cloud Environment
Smart and Secure Healthcare Administration over Cloud Environment
 
How cloud computing is beneficial for the Healthcare industry.pdf
How cloud computing is beneficial for the Healthcare industry.pdfHow cloud computing is beneficial for the Healthcare industry.pdf
How cloud computing is beneficial for the Healthcare industry.pdf
 
Cloud computing Risk management
Cloud computing Risk management  Cloud computing Risk management
Cloud computing Risk management
 
How secure is the cloud? and Amazon vs Walmart which giant will dominant?
How secure is the cloud? and Amazon vs Walmart which giant will dominant?How secure is the cloud? and Amazon vs Walmart which giant will dominant?
How secure is the cloud? and Amazon vs Walmart which giant will dominant?
 
Cloud computing - Assessing the Security Risks - Jared Carstensen
Cloud computing - Assessing the Security Risks - Jared CarstensenCloud computing - Assessing the Security Risks - Jared Carstensen
Cloud computing - Assessing the Security Risks - Jared Carstensen
 
Law Practice Management in the Cloud
Law Practice Management in the CloudLaw Practice Management in the Cloud
Law Practice Management in the Cloud
 
Cloud computing & service level agreements
Cloud computing & service level agreementsCloud computing & service level agreements
Cloud computing & service level agreements
 
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110C:\Fakepath\Cloud Computing   Mitigating Risk   Fmb   0110
C:\Fakepath\Cloud Computing Mitigating Risk Fmb 0110
 
Cloud Computing - A future prerogative
Cloud Computing - A future prerogativeCloud Computing - A future prerogative
Cloud Computing - A future prerogative
 
Data Privacy And Security Issues In Cloud Computing.pdf
Data Privacy And Security Issues In Cloud Computing.pdfData Privacy And Security Issues In Cloud Computing.pdf
Data Privacy And Security Issues In Cloud Computing.pdf
 
Future of Cloud Computing in Healthcare.pdf
Future of Cloud Computing in Healthcare.pdfFuture of Cloud Computing in Healthcare.pdf
Future of Cloud Computing in Healthcare.pdf
 
cloud computing in health care.pptx
cloud computing in health care.pptxcloud computing in health care.pptx
cloud computing in health care.pptx
 
Procurement Of Software And Information Technology Services
Procurement Of Software And Information Technology ServicesProcurement Of Software And Information Technology Services
Procurement Of Software And Information Technology Services
 
SLA Based Information Security Metric for Cloud Computing from COBIT 4.1 Fram...
SLA Based Information Security Metric for Cloud Computing from COBIT 4.1 Fram...SLA Based Information Security Metric for Cloud Computing from COBIT 4.1 Fram...
SLA Based Information Security Metric for Cloud Computing from COBIT 4.1 Fram...
 

Último

Evidence-based resources -2023-PRUH SS.pptx
Evidence-based resources -2023-PRUH SS.pptxEvidence-based resources -2023-PRUH SS.pptx
Evidence-based resources -2023-PRUH SS.pptxMrs S Sen
 
Back care and back massage. powerpoint presentation
Back care and back massage. powerpoint presentationBack care and back massage. powerpoint presentation
Back care and back massage. powerpoint presentationpratiksha ghimire
 
Mental Health for physiotherapy and other health students
Mental Health for physiotherapy and other health studentsMental Health for physiotherapy and other health students
Mental Health for physiotherapy and other health studentseyobkaseye
 
Importance of Assessing Level of Consciousness in Medical Care | The Lifescie...
Importance of Assessing Level of Consciousness in Medical Care | The Lifescie...Importance of Assessing Level of Consciousness in Medical Care | The Lifescie...
Importance of Assessing Level of Consciousness in Medical Care | The Lifescie...The Lifesciences Magazine
 
Medisep insurance policy , new kerala government insurance policy for govrnm...
Medisep insurance policy , new  kerala government insurance policy for govrnm...Medisep insurance policy , new  kerala government insurance policy for govrnm...
Medisep insurance policy , new kerala government insurance policy for govrnm...LinshaLichu1
 
lupus quiz.pptx for knowing lupus thoroughly
lupus quiz.pptx for knowing lupus thoroughlylupus quiz.pptx for knowing lupus thoroughly
lupus quiz.pptx for knowing lupus thoroughlyRitasman Baisya
 
Immediate care of newborn, midwifery and obstetrical nursing
Immediate care of newborn, midwifery and obstetrical nursingImmediate care of newborn, midwifery and obstetrical nursing
Immediate care of newborn, midwifery and obstetrical nursingNursing education
 
Advance Directives and Advance Care Planning: Ensuring Patient Voices Are Heard
Advance Directives and Advance Care Planning: Ensuring Patient Voices Are HeardAdvance Directives and Advance Care Planning: Ensuring Patient Voices Are Heard
Advance Directives and Advance Care Planning: Ensuring Patient Voices Are HeardVITASAuthor
 
Preventing Common Nutritional Deficiencies In Poultry Flocks (PPT).pdf
Preventing Common Nutritional Deficiencies In Poultry Flocks (PPT).pdfPreventing Common Nutritional Deficiencies In Poultry Flocks (PPT).pdf
Preventing Common Nutritional Deficiencies In Poultry Flocks (PPT).pdfAditiAlishetty
 
TEENAGE PREGNANCY PREVENTION AND AWARENESS
TEENAGE PREGNANCY PREVENTION AND AWARENESSTEENAGE PREGNANCY PREVENTION AND AWARENESS
TEENAGE PREGNANCY PREVENTION AND AWARENESSPeterJamesVitug
 
EMS Response to Terrorism involving Weapons of Mass Destruction
EMS Response to Terrorism involving Weapons of Mass DestructionEMS Response to Terrorism involving Weapons of Mass Destruction
EMS Response to Terrorism involving Weapons of Mass DestructionJannelPomida
 
EHR Market Growth is The Boom Over - Jasper Colin
EHR Market Growth is The Boom Over - Jasper ColinEHR Market Growth is The Boom Over - Jasper Colin
EHR Market Growth is The Boom Over - Jasper ColinJasper Colin
 
Subconjunctival Haemorrhage,causes,treatment..pptx
Subconjunctival Haemorrhage,causes,treatment..pptxSubconjunctival Haemorrhage,causes,treatment..pptx
Subconjunctival Haemorrhage,causes,treatment..pptxvideosfildr
 
arpita 1-1.pptx management of nursing service and education
arpita 1-1.pptx management of nursing service and educationarpita 1-1.pptx management of nursing service and education
arpita 1-1.pptx management of nursing service and educationNursing education
 
ANTIGEN- SECTION IMMUNOLOGY DEPARTMENT OF MICROBIOLOGY
ANTIGEN- SECTION IMMUNOLOGY  DEPARTMENT OF MICROBIOLOGYANTIGEN- SECTION IMMUNOLOGY  DEPARTMENT OF MICROBIOLOGY
ANTIGEN- SECTION IMMUNOLOGY DEPARTMENT OF MICROBIOLOGYDrmayuribhise
 
Exploring the Integration of Homeopathy and Allopathy in Healthcare.pdf
Exploring the Integration of Homeopathy and Allopathy in Healthcare.pdfExploring the Integration of Homeopathy and Allopathy in Healthcare.pdf
Exploring the Integration of Homeopathy and Allopathy in Healthcare.pdfDharma Homoeopathy
 

Último (20)

Dr Sujit Chatterjee Hiranandani Hospital Kidney.pdf
Dr Sujit Chatterjee Hiranandani Hospital Kidney.pdfDr Sujit Chatterjee Hiranandani Hospital Kidney.pdf
Dr Sujit Chatterjee Hiranandani Hospital Kidney.pdf
 
DELIRIUM psychiatric delirium is a organic mental disorder
DELIRIUM  psychiatric  delirium is a organic mental disorderDELIRIUM  psychiatric  delirium is a organic mental disorder
DELIRIUM psychiatric delirium is a organic mental disorder
 
Evidence-based resources -2023-PRUH SS.pptx
Evidence-based resources -2023-PRUH SS.pptxEvidence-based resources -2023-PRUH SS.pptx
Evidence-based resources -2023-PRUH SS.pptx
 
Back care and back massage. powerpoint presentation
Back care and back massage. powerpoint presentationBack care and back massage. powerpoint presentation
Back care and back massage. powerpoint presentation
 
Mental Health for physiotherapy and other health students
Mental Health for physiotherapy and other health studentsMental Health for physiotherapy and other health students
Mental Health for physiotherapy and other health students
 
Importance of Assessing Level of Consciousness in Medical Care | The Lifescie...
Importance of Assessing Level of Consciousness in Medical Care | The Lifescie...Importance of Assessing Level of Consciousness in Medical Care | The Lifescie...
Importance of Assessing Level of Consciousness in Medical Care | The Lifescie...
 
Medisep insurance policy , new kerala government insurance policy for govrnm...
Medisep insurance policy , new  kerala government insurance policy for govrnm...Medisep insurance policy , new  kerala government insurance policy for govrnm...
Medisep insurance policy , new kerala government insurance policy for govrnm...
 
lupus quiz.pptx for knowing lupus thoroughly
lupus quiz.pptx for knowing lupus thoroughlylupus quiz.pptx for knowing lupus thoroughly
lupus quiz.pptx for knowing lupus thoroughly
 
Immediate care of newborn, midwifery and obstetrical nursing
Immediate care of newborn, midwifery and obstetrical nursingImmediate care of newborn, midwifery and obstetrical nursing
Immediate care of newborn, midwifery and obstetrical nursing
 
Advance Directives and Advance Care Planning: Ensuring Patient Voices Are Heard
Advance Directives and Advance Care Planning: Ensuring Patient Voices Are HeardAdvance Directives and Advance Care Planning: Ensuring Patient Voices Are Heard
Advance Directives and Advance Care Planning: Ensuring Patient Voices Are Heard
 
Kidney Transplant At Hiranandani Hospital
Kidney Transplant At Hiranandani HospitalKidney Transplant At Hiranandani Hospital
Kidney Transplant At Hiranandani Hospital
 
Preventing Common Nutritional Deficiencies In Poultry Flocks (PPT).pdf
Preventing Common Nutritional Deficiencies In Poultry Flocks (PPT).pdfPreventing Common Nutritional Deficiencies In Poultry Flocks (PPT).pdf
Preventing Common Nutritional Deficiencies In Poultry Flocks (PPT).pdf
 
TEENAGE PREGNANCY PREVENTION AND AWARENESS
TEENAGE PREGNANCY PREVENTION AND AWARENESSTEENAGE PREGNANCY PREVENTION AND AWARENESS
TEENAGE PREGNANCY PREVENTION AND AWARENESS
 
Check Your own POSTURE & treat yourself.pptx
Check Your own POSTURE & treat yourself.pptxCheck Your own POSTURE & treat yourself.pptx
Check Your own POSTURE & treat yourself.pptx
 
EMS Response to Terrorism involving Weapons of Mass Destruction
EMS Response to Terrorism involving Weapons of Mass DestructionEMS Response to Terrorism involving Weapons of Mass Destruction
EMS Response to Terrorism involving Weapons of Mass Destruction
 
EHR Market Growth is The Boom Over - Jasper Colin
EHR Market Growth is The Boom Over - Jasper ColinEHR Market Growth is The Boom Over - Jasper Colin
EHR Market Growth is The Boom Over - Jasper Colin
 
Subconjunctival Haemorrhage,causes,treatment..pptx
Subconjunctival Haemorrhage,causes,treatment..pptxSubconjunctival Haemorrhage,causes,treatment..pptx
Subconjunctival Haemorrhage,causes,treatment..pptx
 
arpita 1-1.pptx management of nursing service and education
arpita 1-1.pptx management of nursing service and educationarpita 1-1.pptx management of nursing service and education
arpita 1-1.pptx management of nursing service and education
 
ANTIGEN- SECTION IMMUNOLOGY DEPARTMENT OF MICROBIOLOGY
ANTIGEN- SECTION IMMUNOLOGY  DEPARTMENT OF MICROBIOLOGYANTIGEN- SECTION IMMUNOLOGY  DEPARTMENT OF MICROBIOLOGY
ANTIGEN- SECTION IMMUNOLOGY DEPARTMENT OF MICROBIOLOGY
 
Exploring the Integration of Homeopathy and Allopathy in Healthcare.pdf
Exploring the Integration of Homeopathy and Allopathy in Healthcare.pdfExploring the Integration of Homeopathy and Allopathy in Healthcare.pdf
Exploring the Integration of Homeopathy and Allopathy in Healthcare.pdf
 

HC3 Kickoff presentations - June 19, 2014

  • 2. Logistics & Agenda Grant Elliott CEO, Ostendio, Inc. @HCCColaition #HC3
  • 4. @HCCCoalition #HC3 Agenda 8:30am Networking breakfast (sponsored by Davis Wright Tremaine LLP) 9:00am HC3 Overview Adam Greene 9:30am What is the Cloud? Hemant Pathak 10:00am The Disruptive Cloud Anish Sebastian 10:20am The Practical Cloud Pete Celano 10:40am Panel Discussion & QA Moderated by Shahid Shah (Hemant Pathak, Chad Kissinger, Sandeep Pulim, Adam Greene) 11:30am HC3 Wrap up Adam Greene Noon End
  • 5. @HCCCoalition #HC3 Questions & Comments Send questions to @HCCCoalition #HC3
  • 6. Addressing Regulatory Challenges of Bringing Health Care to the Cloud Adam H. Greene, JD, MPH Partner, Davis Wright Tremaine LLP
  • 7. @HCCCoalition #HC3 The Challenges Cloud computing and cloud-based mobile technology can improve health care and reduce costs, but…
  • 8. @HCCCoalition #HC3 The Challenges Health care is not fully leveraging cloud technology because of lack of trust in information security
  • 9. @HCCCoalition #HC3 The Challenges Where health care entities leverage cloud computing, there are too many inefficiencies: A sea of different information security questionnaires Confusion and disagreement over business associate agreement terms Confusion over information security responsibilities
  • 10. @HCCCoalition #HC3 The Challenges A lack of HHS guidance on how HIPAA applies to cloud computing: What if cloud vendor was unaware it was hosting PHI for a covered entity? No guidance or audit protocols specific to business associates How to handle patients rights and breaches when you may not know what information you have
  • 11. @HCCCoalition #HC3 The Challenges The price of entry for small companies into health care is too high because of this confusion.
  • 12. @HCCCoalition #HC3 The Mission of HC3 Reduce obstacles to the health care sector leveraging cloud computing technology. Promote innovation by reducing health care compliance burdens on health care technology companies.
  • 13. @HCCCoalition #HC3 The Objectives of HC3 1. Understanding – Create an accepted framework for health care and cloud computing
  • 14. @HCCCoalition #HC3 The Objectives of HC3 Develop internal guidance on how HIPAA applies to cloud computing.
  • 15. @HCCCoalition #HC3 The Objectives of HC3 Develop tools, such as: Sample business associate agreement provisions, to address unique cloud computing issues Notices that clearly identify each party’s security responsibilities A self-audit protocol for cloud computing providers
  • 16. @HCCCoalition #HC3 The Objectives of HC3 Work with health care providers and other associations (e.g., HIMSS, Cloud Security Alliance) to obtain feedback and promote the tools and guidance.
  • 17. @HCCCoalition #HC3 The Objectives of HC3 2. Trust – Build trust in cloud computing and regulatory compliance through an accepted accreditation/certification process or other programs.
  • 18. @HCCCoalition #HC3 The Objectives of HC3 Certification needs to be: Focused on health care (e.g., HIPAA, Alcohol and Substance Abuse Treatment Confidentiality) Focused on cloud computing Scalable (e.g., works for both large IaaS provider and small SaaS provider that does not host its own data)
  • 19. @HCCCoalition #HC3 The Objectives of HC3 Not looking to reinvent the wheel.  Adopt and promote any existing or upcoming certifications/accreditations that meet our needs.  Tweak any existing certifications/accreditations that get us 90% of the way there.
  • 20. @HCCCoalition #HC3 The Objectives of HC3 3. Government Outreach – Seek regulatory guidance from HHS and other relevant agencies. Maintain outreach and transparency with the government.
  • 21. @HCCCoalition #HC3 The Objectives of HC3 4. What else?
  • 22. @HCCCoalition #HC3 Next Steps? Learn from others today about the benefits and challenges of cloud computing in health care. Discuss the scope of what HC3 will initially take on. Incorporate and set up structure for membership dues. Volunteers
  • 23. Health Care Cloud Coalition Legal considerations with cloud computing A View From The Cloud Vendor. Insight on the HIPAA Omnibus Rule, Cloud Privacy & Security, and HIPAA Enforcement Hemant Pathak, Assistant General Counsel, Microsoft
  • 24. @HCCCoalition #HC3 What are the types of cloud model we are going to discuss today?  Enterprise Cloud  Three types of cloud services: SaaS, PaaS, IaaS  Public, Private, Hybrid  Always available  Per user, consumption buying model  Data and services with a common delivery model in shared data centers  Different from traditional “outsourcing”
  • 25. @HCCCoalition #HC3 Why do customers choose cloud services?  On demand scalability, reliability and flexibility of computing resources, updates, interoperability and tech support  Reduction of infrastructure costs & complexities at very large economies of scale across the board (electricity, network bandwidth, operations, SW & HW).  Organizations can “get out” of the Data Center business  The right vendor can address state of the art security & privacy protocols to help customers address their compliance requirements in a highly regulated industry
  • 26. @HCCCoalition #HC3 From the cloud service provider (CSP) perspective – what are contracting expectations?  Cloud services are configurable, but generally not customizable  SLA, Service Descriptions, Security Descriptions  Contract terms that require unique requirements for service for one individual subscriber are not scalable  Pre-Sales CSP & customer partnership and due diligence on contract terms and solution alignment reduces risk now and in the future for both parties  Ensure compliance with laws and corporate policies  Protect brand and reputation for both parties
  • 27. @HCCCoalition #HC3 From the customer perspective – what are contracting expectations? Where and how is data stored?  Clear data maps and geographic boundary information Data must be encrypted wherever possible Who has access and what is accessed?  Core customer data must be accessed only for service delivery, troubleshooting, migration and malware prevention purposes on an exception basis and all access should be logged Who owns data?  The Customer. Data must be fully portable and retrievable Who pays for costs related to security breaches?  Commercial term addressed by the parties
  • 28. @HCCCoalition #HC3 Security & Privacy – How do you get assurances?  Security  Physical Data Center standards  Secure Networks  Automated operations  Robust breach prevention, detection and mitigation  Compliance -Cloud Service Providers (CSP) should address regulatory standards  E.g. - ISO 27001, HIPAA BAA  Federal Trade Commission  Watchdog groups  Healthcare agencies  DHHS  Independent Audit & Verification
  • 29. @HCCCoalition #HC3 What are questions Customers ask a potential CSP?  Security & Privacy Compliance  Does the cloud vendor offer a BAA  Does the BAA contain all required HIPAA terms  Does the CSP stipulate to comply with breach notification rule, timely reporting, appropriate and transparent limitations on use & disclosure and “minimum necessary”  Embedded technical, physical and administrative safeguards in support of HIPAA  Data mining – will my cloud provider use my data for advertising, marketing or other commercial purpose w/o my consent  Does CSP have transparent and robust process on addressing third party requests for data?  Clinical centered care strategies  Compliance across collaboration modes through audio, video & messaging  HealthCare Enterprise Ready
  • 30. @HCCCoalition #HC3 What are consequences of non- compliance?  Phoenix Cardiac Surgery  Fined $100,000 by DHHS for failure to obtain a BAA “Covered Entity failed to obtain satisfactory assurances in business associates agreements from the Internet-based calendar and from the Internet-based public email providers that these entities would appropriately safeguard the ePHI received from Covered Entity.”  Oregon Health & Science University  Negative PR stemming from breach involving storing a spreadsheet of patient data with cloud service which was not a business associate.  DHHS Regulator Quotes “If you use a cloud service, it should be your business associate. If they refuse to sign a business associate agreement, don't use the cloud service.” “…cloud services [are] under direct regulations of HIPAA…,"
  • 31. @HCCCoalition #HC3 Conclusion  Health Care Providers moving to the cloud want to choose a CSP that has been proven trustworthy and that they can trust.  Transparency about compliance, security and privacy practices and use of data is the key to trust.  Transparency allows customers to determine whether using a given cloud offering helps them to be compliant with applicable regulations and corporate policy.
  • 33. The Disruptive Cloud – How the cloud is helping me drive innovation Anish Sebastian Co-founder 1EQ
  • 35. @HCCCoalition #HC3 The Cloud = 10X Improvement!  Ease of Use  Scalability  Risk and Reliability  Cost  Security  Connectivity
  • 37. @HCCCoalition #HC3 Ease of Use  Deploy infrastructure quickly with no need for system admin  No cabling, racking, unboxing or buying  Software now controls the infrastructure  Control your servers with the click of a mouse
  • 39. @HCCCoalition #HC3 Scalability  Can adjust to min by min variation in demand  Nothing to purchase and take delivery  Increase innovation, by removing “too scared to try” syndrome  Go global in a matter of seconds (co-location)
  • 40. @HCCCoalition #HC3 Risk and Reliability  Cancel immediately  Change instantly, even OS  Rebuilt instantly  No long term contracts  Based on enterprise grade hardware  Employ best practices in IT:  Design for failure  Control framework  Disaster recovery
  • 41. @HCCCoalition #HC3 Cost  Pay for only what you use – nothing up front and pay as you go  Zero cap Ex = lower burn rate = happy investors!  Cloud has economies of scale, business model based on volume not margin  Since we started using amazon, prices have gone down
  • 42. @HCCCoalition #HC3 Security  Architected for enterprise security requirements  More than likely more secure than what you can normally build yourself  AWS White paper on HIPPA  Ability to quickly fix security holes and keep up with new compliance standards.
  • 43. @HCCCoalition #HC3 Being an “aaS” SaaS – Software as a Service PaaS – Platform as a Service IaaS – Infrastructure as a Service
  • 44. @HCCCoalition #HC3 The Cloud Pyramid Broad Niche
  • 45. @HCCCoalition #HC3 The cloud Pyramid Developers Users Network Engineers
  • 46. @HCCCoalition #HC3 The cloud Pyramid Google Apps, Heroku, Salesforce Windows Azure SendGrid, Mailchip, Twilllio Zendesk, ……..a lot more Amazon, Racksapce
  • 47. @HCCCoalition #HC3 The cloud Pyramid – Applications long tail effect. • The long tail is directly an impact of the cloud. • They all talk to each other.
  • 48. @HCCCoalition #HC3 Connectivity  This long tail of products connect to the cloud via API  It has fueled a new era of API  Allows for various SaaS companies to stitch together a whole series of services generally via API  Everything is connected to everyone
  • 49. @HCCCoalition #HC3 Differentiation  Bottom Line:  The cloud allows you to focus on what truly makes you different  Let’s you outsource commoditized services and services that are not your core competencies.
  • 50. @HCCCoalition #HC3 What does the future look like?
  • 51. The Answer is in the Cloud Pete Celano MedStar Institute for Innovation www.mi2.org
  • 52. @HCCCoalition #HC3 Mission  Extend Access to the Poor/Rural  Reduce Costs  Better Outcomes  New Revenue
  • 53. @HCCCoalition #HC3 New World  Old World: EMR(s) is what you have  New World: Innovate “north” of the EMR. And bolt-in.
  • 54. @HCCCoalition #HC3 Focus Areas 1. Capacity Utilization 2. Extending the Site of Service 3. Flowing Data to Docs
  • 55. @HCCCoalition #HC3 5-Step Process 1. What problem are we trying to solve, and RoI? 2. Balance Sheet Test 3. Our BAA 4. Pilot Fast 5. Take it Wide if Pilot Works & Economics are Verified
  • 56. @HCCCoalition #HC3 Five Predictions 1. Only more inventors will run-not-walk to healthcare 2. EMR vendors will be acquiring right & left in 2015 and beyond 3. Solutions will start breaking Provider-only and Provider-Payer (“Provayer?”) 4. Virtual Visits will take off like a rocket 5. Apple’s HealthKit et al will finally make Remote Patient Monitoring relevant.
  • 57. Panel Discussion and Q&A 10:40AM – 11:30AM • Hemant Pathak (Microsoft) • Chad Kissinger (OnRamp) • Sandeep Pulim (@Point of Care 360) • Adam Greene (Davis Wright Tremaine LLP) - Moderated by Shahid Shah, Netspective

Notas do Editor

  1. (1) Hi good morning everyone, my name is Anish Sebastian I am one of the founders of a start up called 1EQ – we are startup focused on improving pre-natal care. (2) But I am not here to talk about my startup, I am here today to talk about how disruptive the cloud can be especially for startup’s like myself. (3) I think the end that I am going to drive toward is that while the cloud truly is disruptive, it does signify a new era when it comes to privacy and compliance.
  2. (1) Ok, everyone talk about the cloud. Its probably one of the most cliched term these days. (2) Its now gone passed that stage of being an cartoon on a meme  which means it is now officially mainstream.
  3. So why ? Why is the cloud so powerful ? Why is it so disruptive to every industry and especially. Well most technologies to be called disruptive – have to at least provide 10X improvement and cloud certainly shows that. I bucket them into these categories -
  4. I think this the most simples way to get across the ease of use point. Normally, without a cloud based/ virtualized technology – I’d be doing that on the left hand side (clearly not enticing) Now with a sign in and with very little training, I am up and running.
  5. Generally contracts are on an as needed basis and can be cancelled as demand goes down Linux, Windows - deploy in any server technology With the ability to create virtual environment you can compartmentalize the entire thing, in other words