Wk 4 Team Assignment: IT Project Implementation Failures

profilemisha42000
1.BibliU-Print-9781449648008.pdf

1114237 - Jones & Bartlett Learning ©

CHAPTER 4 HIS Application Systems and Technology

LEARNING OBJEC TIV ES By the end of this chapter, the student will be able to:

• Understand how the software development life cycle is used to develop health information systems (HIS) applications.

• Determine the relationship between HIS programming languages, applications, and databases. • Identify the benefit of application integration over application interfaces. • Describe the inpatient and outpatient clinical and administrative HIS applications in use today. • Explain how computer networks work, their importance in supporting HIS applications, and the different

network architectures in use today (e.g., local area networks, wireless local area networks, wide area networks, wireless wide area networks, and storage area networks).

• Understand how emerging technologies such as voice over Internet Protocol, unified communications, and video/web conferencing are affecting HIS initiatives.

• Identify why data center infrastructure, cloud computing, backups, and disaster recovery are critical to properly maintain HIS applications.

• Define the essential components of modern server computing, including unified computing systems, server virtualization, and single sign-on.

• Describe the key benefits of client, device, and mobile computing that are being used specifically to enhance HIS deployments.

• Understand the importance of technologies that deliver privacy and security benefits to HIS applications.

INTRODUCTION In this chapter, we examine the applications and technology requirements needed to support the health information systems (HIS) and technology environment. There is little doubt that healthcare delivery is complex and that HIS can deliver considerable value in improving the quality of care and reducing the costs of care. However, the technology being used to support HIS has been viewed as complicated and, in many instances, well beyond the understanding of nontechnical individuals. As sophisticated as HIS applications and technology may appear to be, when they are examined at their more fundamental levels, HIS can be readily understood.

Understanding how HIS applications are developed is essential to ensuring they produce the desired functionality. In this chapter, we review one of the primary HIS application development methods in use today—the software development life cycle. We also look at the relationships between HIS programming languages, applications, and databases. The benefits of application integration over application interfaces are also reviewed. To clearly understand HIS, we discuss the clinical and administrative HIS applications being used by healthcare organizations today.

1114237 - Jones & Bartlett Learning ©

HIS applications require a robust, high-performing, and highly available underlying technical infrastructure. Unless this technology is deployed correctly, HIS users will not be able to access their systems to perform their work—the HIS applications will perform slowly, be inaccessible, or experience data corruption. In this chapter, we examine how computer networks work, consider their importance in supporting HIS applications, and outline the different network architectures in use today. We review emerging technologies that are affecting HIS applications, such as Voice over Internet Protocol, unified communications, and video/web conferencing. Data center infrastructure, cloud computing, backups, and disaster recovery—all aspects that are critical to properly maintain HIS applications—are discussed as well. The essential components of modern server computing, including unified computing systems, server virtualization, and single sign-on, are analyzed, along with other key client, device, and mobile technologies. Finally, this chapter highlights the importance of technologies that deliver privacy and security benefits to HIS applications.

HIS APPLICATIONS An important concept to understand is that all HIS applications are developed using a programming language, which allows them to operate by executing programming code. Data can be created or modified by programs based on input received from end-user input devices or other software programs and are stored in computer-based files. Large instances of data are normally stored in a database, which offers distinct advantages over other file types, such as documents, spreadsheets, and various forms of graphic and multimedia files. Some of these benefits include support for very large file sizes, the ability of multiple users to edit data at the same time, advanced data recoverability security, and data normalization (i.e., organizing and distilling data). While responsibilities for process redesign and implementation depend on resources within organizations, in healthcare environments, the technical work of developing and maintaining application programming is most often delegated to the vendors who own the application product or to consultants who focus specifically on application programming. Relying on the software vendor to manage software application development, upgrades, and customization allows healthcare organizations to focus on their core business objective of delivering quality health care.

Traditionally, healthcare organizations have purchased licenses for many of these vendor applications, or commercial off-the-shelf (COTS) products, causing healthcare data centers to be filled with many “best of breed” applications. Although best-of-breed applications provide healthcare organizations with advanced application functionality for specific service lines or departments, they are generally not developed to integrate or interoperate with other applications. Today, application integration is one way to eliminate application and data silos, and to help organizations achieve efficiencies and healthcare reform criteria. For those healthcare environments large enough to require their own customized application development, programmers are typically added to the internal information technology (IT) department to build customized applications that are specific to their organizations. Web services, Microsoft’s .NET, and Sun’s Java development platform are three prevalent programming languages in use at many health systems today.

Regardless of the programming platform used to develop application programs, one of the standard development frameworks in use today is the software development life cycle (SDLC) methodology. When applied to the development of HIS applications, the SDLC process is designed to ensure end-state solutions meet user requirements in support of the healthcare organization’s strategic goals and objectives. The SDLC methodology includes seven stages (Figure 4.1)1:

1. Conceptual Planning. This phase involves the identification and assessment of the system requirements and enhancements, feasibility, costs, and risks.

2. Planning and Requirements Definition. This phase involves identifying functional, support, and training requirements, as well as developing the initial life-cycle management plans, the project plans, and other operations requirements.

3. Design. This phase comprises developing the preliminary and detailed designs, including how the system will meet functional requirements.

4. Development and Testing. This phase includes the system development, testing, and validation activities, which are designed to ensure the system works as expected and that the project sponsor’s (i.e., customer’s) requirements are satisfied.

1114237 - Jones & Bartlett Learning ©

5. Implementation. In this phase, the system is installed in the production environment, the training of users is completed, data conversions and system issues are resolved, and the newly designed system is turned over to the project sponsor.

6. Operations and Maintenance. During this phase, the new or upgraded system is operationalized, with routine maintenance, upgrades, feature enhancements, and bug fixes completed.

7. Disposition. This phase represents the end of the system’s life cycle, when the system is scheduled to be decommissioned and retired. The emphasis of this phase is to ensure that the system is disposed of in accordance with proper procedures.

HIS applications are software programs of similar functionality that are used to support and facilitate work in a given area within a healthcare setting. HIS applications have historically been developed according to the healthcare organization’s functional departments, divisional areas, or service lines, as opposed to being developed for the organization as a whole. Some of these applications include laboratory systems, nursing systems, patient billing and accounting systems, payroll and time and attendance systems, and human resources information systems. As a result, most of the early HIS applications were specific to the functional unit for which they were developed, causing the proliferation of many non-integrated systems operating within the same organization.

FIGURE 4.1 Software Development Life Cycle

The development of application interfaces was the initial attempt to bridge these various systems in hopes that common data sets could be leveraged by multiple departments and functional areas. However, maintaining interfaces—essentially data-translation programs—between disparate applications proved to be expensive, time consuming, and inefficient. System developers soon found that application integration, the process that brings data or functions from different application programs together at the point when the applications themselves are first being developed so that they share common data elements and use a common data base, is much more efficient. Essentially, integration avoids building applications in silos, which in turn eliminates the need to build and maintain

1114237 - Jones & Bartlett Learning ©

interfaces on a regular basis after the initial development. Application programs that are integrated use data from the same shared data repository, whereas application programs that are interfaced exchange and maintain data repositories between separate databases for each application using one- or two-way data transfers. Middleware is a type of software that is designed to provide application integration by interfacing between two existing application programs that are already fully developed and in use.

Clinical Applications One of the most important types of applications in healthcare organizations is clinical applications. A clinical application can be defined as any system that supports clinical care (e.g., electronic health record systems), ancillary clinical support processes (e.g., laboratory testing, radiology), clinicians (e.g., computerized physician order entry, clinical decision support), and patient flow (e.g., registration, scheduling). Clinical applications are designed to improve the quality of care; increase efficiency; provide better patient services; reduce medical record transportation costs; and improve a number of processes, including workflow, patient communications, accuracy for coding evaluation and management, drug refill capabilities, charge capture, and claims submissions.

An electronic health record (EHR) application is an example of a clinical application that supports clinical care. EHR applications enhance communication and enable the computerized documentation of patient care activities and health services from myriad settings. Key functions supported by EHR applications include electronic capture of data for subsequent storage in a data repository, real-time order entry and results reporting, administrative processes linked with clinical activities, electronic data interchange (EDI) with agencies and partners, clinical decision support for diagnosis and care management, performance reporting internally and to external agencies, and individual patients’ access to their own records.2,3

Another clinical application commonly found in healthcare organizations is a clinical information system (CIS). A CIS application is a computerized system that supports clinical diagnosis, treatment planning, and medical outcomes evaluations. This computerized system organizes, stores, and double- checks all of a patient’s medical information. Such an application keeps health history, prescriptions, doctor’s notes and dictation, and all other information together electronically, and replaces the paper charts of the past. Examples of departmental and service lines systems that are considered CIS applications include quality management, laboratory testing, radiology, endoscopy, nursing, surgery, operating room, and pharmacy. Nursing and physician documentation are also CIS applications. CIS systems include embedded clinical guidelines and treatment protocols, establish rules and alerts, and provide evidence-based treatment plans. An important success factor for achieving future CIS viability and integration throughout the organization’s HIS applications is the need for enterprise-wide strategic HIS planning.

A laboratory information system (LIS) is a CIS application that supports chemistry, pathology, blood bank, instrumentation, calculations, calibrations, and results management areas within clinical settings. Core functions of a lab system include test requisition processing, scheduling and cataloging specimen collection, and test processing; delivering results of completed tests that have been verified and recorded, and results reporting directly into patient records; identifying abnormal results and alerts; providing statistical reports for lab management and patient summary reports; performing quality control and charge capture functions; and supporting lab operations management.

A pharmacy information system (PIS) is a complex CIS application that is tightly integrated with clinical care, particularly with nursing personnel and workflows. Because medication errors are always a concern with pharmacy systems, integration to ensure the proper delivery of care is a high priority. Workflow redesign is especially important when implementing medication administration management processes; pharmacy system automation requires a different approach than automation of paper- based processes. It is critical that pharmacy applications are tightly integrated with nursing medication administration records (MARs) and other order processes such as computerized physician order entry (CPOE) to ensure patient safety. Additional areas that pharmacy systems automate as part of their effort to improve the quality of care and patient safety are drug inventory management, charges, medication error tracking, profile orders, performance management, drug–drug interactions, allergies, and other screenings.

1114237 - Jones & Bartlett Learning ©

Radiology information systems (RISs), medical imaging systems (MISs), and picture archiving and communication systems (PACSs) are all CIS applications that provide clinical support processes. MISs support image management, image processing, enhancement, visualization, and storage. RISs provide functionality that manages test requisitions, schedules procedures, manages test results, identifies charges, and delivers patient test and department management reports. In addition, radiology systems are capable of performing image enhancements, computed tomography (CT) scans, ultrasound imaging, angiography, magnetic resonance imaging (MRI) scans, nuclear medicine functions, radiation therapy, computerized patient-specific treatment planning programs, and surgery. PACS applications manage image storage, local and remote retrievals, and distribution and presentation of PACS files. Recent advances with PACS applications have added features such as improved turnaround time for results, elimination of film loss, support for teleradiology, and reduction of physical space requirements for storage.

Outpatient systems are CIS applications designed to assist in the delivery of care for patients who are hospitalized for less than 24 hours. These ambulatory care systems are CIS applications that assist caregivers in performing consultations, treatments, or interventions in an outpatient setting, such as a medical clinic. Examples of the types of procedures that are performed in this environment include minor surgical and medical procedures, dental services, dermatology services, and diagnostic procedures such as blood tests and X-rays. Ambulatory care settings have needs similar to those served by inpatient clinical and business applications, but slightly different priorities. Two important areas of emphasis in ambulatory care settings are financial and administrative systems—which include billing, eligibility determinations and authorizations, claims processing, general financial, human resources, and materials management applications—and clinical systems—which support scheduling, appointment reminders, EHRs and personal health records (PHRs), transcription, prescription management, disease management, and patient communications.

Long-term care (LTC) systems are CIS applications designed to aid in the delivery of care for patients who are older than age 65 or who have a chronic or disabling condition that needs constant supervision. LTC facilities can provide nursing home care, home health care, and personal or adult day care for individuals. LTC systems include clinical, financial, and administrative management functionality that is designed to address the unique requirements of the LTC environment. Adoption of CIS applications in LTC settings has been slow to date, but transitioning to computerized systems in these environments has been shown to improve care delivery. Two special challenges are encountered in LTC environments: (1) They are not tightly integrated with health systems and (2) physicians are not routinely present at LTC facilities.

CPOE systems are CIS applications that directly support clinician workflow requirements. CPOE comprises the electronic entry of medical practitioner instructions, referred to as “orders,” for the treatment of patients under that practitioner’s care. Typically, these orders are communicated within and through an EHR application to departments such as pharmacy, laboratory testing, or radiology, where they will then be filled. CPOE applications have the benefit of decreasing delays in order completion, reducing errors related to handwriting translation or transcription, allowing order entry at the point of care or off-site, enabling error checking for incorrect or duplicate doses or tests, and streamlining the posting of charges and inventory management.

CIS applications have many benefits for both healthcare organizations and patients. These advantages include reduction of staffing requirements over the long term, attaining eligibility for pay- for-performance payments, recruiting and retaining physicians, enhancing the legibility of clinical documentation notes, reducing spelling errors within CIS applications, improving access to medical charts, reducing costs associated with transcription and facilities used for storing paper, and improved recovery of medical data following a disaster. Additional benefits include allowing multiple clinicians to simultaneously access medical charts, having lab and X-ray results returned automatically, checking for drug–drug and drug–allergy interactions, integrating physician dispensing software, and improving patient safety. Figure 4.2 summarizes the key CIS applications that healthcare organizations are seeking to deploy in their efforts to achieve technology adoption and meaningful use of EHRs.4

Administrative Applications Historically, health care has lagged behind other industries in the development of robust administrative and financial systems. Healthcare reform has brought increased pressure on healthcare organizations

1114237 - Jones & Bartlett Learning ©

to take a more strategic approach to managing these systems. In response, healthcare providers and payers are now deploying systems that integrate administrative and financial systems. These include EHRs, along with enterprise resources planning (ERP) systems, customer resource management (CRM) systems, and supply chain management (SCM) systems. Patient accounting is an administrative application that manages billing and accounts receivable, and is often integrated into a health provider EHR application. ERP systems are bundled applications that manage a healthcare organization’s financial and accounting applications. They can include general ledger, accounts payable, material management, human resources management, and facilities management applications, which have been traditionally installed at healthcare organizations as separate or “point” solutions (silos).

FIGURE 4.2 Healthcare Provider Technology Adoption Map

In the Robert Wood Johnson Foundation’s annual report, Health Information Technology in the United States: Better Information Systems for Better Care (2013), 44% of hospitals reported having a basic EHR system as of 2012.5 This was a 17% increase from 2011, demonstrating that hospitals, physicians, and other providers have made significant strides in the adoption of health information technology and the integration of healthcare data. Physicians were reported to have also made substantial progress, with 38.2% having adopted basic EHR functionalities by 2012. Despite these advances, many organizations have not taken steps to achieve an integrated ERP solution and, therefore, may face challenges in generating comprehensive reports due to the existence of data silos and data integrity issues.

Home health care is an evolving method of care delivery that is increasingly using administrative applications of HIS. With the advent of healthcare reform and technology advances, including mobile devices that are being used by nurses in the field, delivery of care outside of traditional hospitals and clinics is becoming more feasible and widespread. With a laptop computer and broadband card, a nurse can make home visits, enter updates into his or her laptop, and automatically update central medical office systems. Home healthcare organizations require the same types of administrative, financial management, and clinical applications as other healthcare organizations. The only difference is that home health HIS applications need to be customized to meet the unique requirements found in the home health environment. This functionality includes monitoring patients for specific conditions, developing treatment plans, identifying measures that can be taken and communicated to the home health site, and communicating with caregivers in homes between visits using mobile technology. Home health care is a highly regulated arena of healthcare delivery, so automation saves caregivers the time associated with filling out the many required forms by hand, leaving more opportunity for caregiver–patient interaction, an outcome that is satisfactory for caregivers and patients alike.

1114237 - Jones & Bartlett Learning ©

TECHNOLOGY Essential to the success of an HIS deployment is first ensuring that the basic building blocks of data communication are architected and maintained properly. Many HIS implementations risk failure or high user dissatisfaction if the infrastructure supporting the transfer of voice and data is outdated, unstable, or not managed efficiently. Two related important areas that we will cover are telecommunications and networking. Each of these technology areas is one of the most complex topics in the computer-related field.

Telecommunications and Networking Telecommunications is defined as the electrical transmission of data among systems, whether through analog, digital, or wireless media. Data transmissions can occur across a variety of media types, such as copper wires, coaxial cable, fiber, or airwaves. Both large and small healthcare organizations today utilize these data transmission types and mediums. Data communication networks consist of three basic hardware components: servers, clients, and circuits. A server is a host computer that stores data or software and is accessed by clients. While a server resides at one end of a communication circuit, a client is the input/output hardware device at the user’s end of a communication circuit. A client typically provides end users with access to the network and a server. A circuit is the pathway by which messages between servers and/or clients travel. Copper wire, fiberoptic cable, and wireless transmissions are three of the most common circuit types deployed today, with switches, routers, and gateways being three of the many devices used to enable circuits to transmit information.

An example of these three components in a healthcare setting can be seen with an LIS. The LIS servers hosting the data and providing the application processing will be located in the organization’s data center. The doctors and nurses who need to access the LIS information will use their client computers—usually a personal computer (PC) or mobile device. The hospital or clinic’s wireless or wired network, along with the Internet, can be considered the circuit that is used to transfer data between the client and the server.

Types of Networks Networks are commonly categorized into four different types: local area networks (LANs), backbone networks (BNs), metropolitan area networks (MANs), and wide area networks (WANs). LANs are groups of devices located within the same geographical area, such as one or more floors within a building, or multiple buildings in close proximity to each other. BNs are designed to connect LANs, WANs, and other BNs at high data transfer speeds and typically span several miles. MANs connect LANs, BNs, and WANs that are usually located within 3 to 30 miles of each other, and are often referred to as campus networks. WANs connect BNs and MANs and can connect devices that are located around the world. Whereas healthcare organizations can create and maintain their own LAN, BN, and MAN infrastructure, commercial carriers are the primary providers of WAN infrastructure, which consists of fiber-optic cable, switching equipment, and microwave towers or satellite equipment. LANs, BNs, MANs, and WANs support data transmission speeds of up to 10 gigabits per second (Gbps) between each other, with higher speeds currently being developed. Data transfer rates via devices connected to LANs can range from 10 megabits per second (Mbps) or 10 million bits per second to 1 Gbps or 1 billion bits per second.

Networks may also be classified as intranets or extranets. Intranets are LANs that function similar to the Internet, providing web-based technologies that are accessible only to internal users of an organization. Vendor-developed and internally customized web-based applications can be found on an intranet. Examples of web-based applications that are often found in healthcare organization intranets include company directories, user account request systems, collaboration and file sharing sites, human resources information systems, purchasing systems, and help desk ticketing systems. Extranets are similar to Intranets but provide web-based content and access to applications and databases for users who are outside of the organization—for example, business partners, patients, vendors, and students/faculty.

Both intranet and extranet content are most efficiently maintained using enterprise web content management (EWCM) systems, which allow individual departments to easily update their content made available on the network without knowledge of HTML programming or use of webdesign skills. In many cases, health organizations are leveraging remote hosting by engaging a third-party web-

1114237 - Jones & Bartlett Learning ©

hosting company to manage their external web content. This is often done by entering into a contract with a professional EWCM vendor, which then supplies all the necessary hardware, software, website address information, and website development. The healthcare customer simply needs to provide the Internet connectivity to the external website, along with supplying the web content.

Network Models Networks perform the basic function of transferring data from a sending device to a receiving device. To make this process efficient and modular, the various functions necessary to complete the data transfer operation are divided into network layers. The two most important network models useful to describe these network layers are the Open Systems Interconnection model (OSI) and the Internet model. The OSI model was developed in 1984 and defines seven network layers (Figure 4.3(a))6:

• Layer 1: Physical Layer. The physical layer is designed primarily to transmit data bits (0s and 1s signifying positive and negative electrical charges) over a communication circuit.

• Layer 2: Data Link Layer. The data link layer is responsible for the physical transmission circuit in layer 1 and converts it into a circuit, ensuring the transmission is error free.

• Layer 3: Network Layer. The network layer is responsible for routing—that is, identifying the best path through which to send the data—and ensuring the message arrives to the destination address.

•  Layer 4: Transport Layer. The transport layer manages end-to-end network issues, such as procedures for entering and departing from the network. This layer establishes and manages the logical connections between the sending device and the receiving device, performs error checking, and, if necessary, breaks up the data packet into smaller packets for more efficient transmission.

• Layer 5: Session Layer. The session layer is responsible for initiating, maintaining, and terminating the logical sessions between end users. These functions can be best explained by considering how a telephone call is made: A phone generates a dial tone, a number is dialed, and the receiving phone answers the call, creating the logical call session where both parties can talk to each other. The session layer also manages security checks and file transfers. Again, this can be best explained by comparing the process to a telephone call: Picking up the phone and dialing to connect to another phone initiates the session; the session is then maintained until it is terminated by one of the parties hanging up.

1114237 - Jones & Bartlett Learning ©

FIGURE 4.3 (a) The Seven Layers of the OSI Model (b) The Four Layers of the Internet Model

•  Layer 6: Presentation Layer. The presentation layer manages the formatting of the data being transferred so that it can be presented to the end user, regardless of the type of device the end user is using. Layer 6 is also responsible for compressing the data, if necessary.

• Layer 7: Application Layer. The application layer is designed to manage the end user’s access to the network. This includes the applications and programs used by the end user. In addition, network monitoring and network management are two important functions that are performed at the application layer. Both of these functions keep track of how the network is operating and allow network administrators to ensure that the network is working optimally.

Although the OSI model is the primary model used to describe how networks work, the Transmission Control Protocol/Internet Protocol (TCP/IP) or Internet model is a simpler model that is used with today’s hardware and software; it is also the model that defines the Internet. Understanding both the OSI and Internet models is important for healthcare professionals, as they are wonderful examples of how complex HIS are made of multiple independent layers or modules, each functioning autonomously within their own context, yet working together with other self-contained modules to create a fully functional, multifaceted HIS. The Internet model (Figure 4.3(b)) keeps the same OSI model for layers 1–4, but combines the OSI model layers 5–7 into the Internet model layer 4, which is labeled the application layer.

It is also common to further classify the OSI model and the Internet model into the following groups of layers7:

•  Application Group Layer. The application group layer consists of the OSI model session, presentation, and application layers, and the Internet model application layer.

•  Internetwork Group Layer. The internetwork group layer comprises the OSI model and Internet model transport and network layers.

• Hardware Group Layer. The hardware group layer includes the OSI model and Internet model data link and physical layers.

1114237 - Jones & Bartlett Learning ©

Finally, it is important to understand how each network layer communicates with the other layers. When two computers are transmitting data to each other, both the sending computer and the receiving computer will use software to perform different functions at each network layer. As such, each network layer uses a formal language or protocol that defines how it will operate at each layer.

To see how this works, imagine an end user creates a message (an email, for example) using a web browser and sends that message to another user, who will also receive and read the message using a web browser. In this example and using the Internet model, the Hypertext Transfer Protocol (HTTP) is used at the application layer to create an HTTP request packet, which includes the message from the sender. The Transmission Control Protocol (TCP) is used at the transport layer to break the HTTP packet into one or more smaller-sized HTTP packets, place each of these smaller HTTP packets into TCP packets, determine the destination server address, and then open a connection to the destination server for the transfer of the TCP packets. The Internet Protocol (IP) at the network layer then determines the next stop on the way to the destination server, packages the TCP packet into an IP packet, and sends the IP packet to the next stop. The Ethernet protocol is used at the data link layer to format the message, provide error checking, add the IP packet into an Ethernet packet, and then instruct the physical hardware to transmit the Ethernet packet to the next stop. The physical layer takes the Ethernet packet and transmits it over the network cable as a series of positive and negative electrical impulses.

When the destination server receives these electrical impulses, the preceding steps are carried out in reverse order: The physical layer translates the electrical impulses into Ethernet packets, the data link layer converts the Ethernet packets into IP packets and checks for errors, the network layer converts the IP packets into TCP packets, the transport layer converts the TCP packets into HTTP packets, and finally the application layer presents the request (or webpage) from the HTTP packet to the end user.

This example demonstrates both the complexity and the elegance involved in sending a simple message between computers over a network. On the one hand, many different software programs and languages are used at the various layers, which allows applications to be built in a modular fashion. Such an approach requires that software and hardware vendors use the same standards when developing their products. On the other hand, the different and multiple layers of the protocol stack can create a level of inefficiency that slows down the transmission of data. This example also highlights the importance of technical standards that ensure common protocols for transmitting data along the various steps between layers.

Local Area Networks Local area networks are the primary networks used by desktops, servers, and network and other devices to communicate when they are in close proximity with each other. LANs are used for two reasons: information sharing, which enables users to exchange data, files, emails, and other types of information; and resource sharing, which refers to a computer sharing an attached device or software application such as a printer or fax application. LANs can be set up to operate in a client–server or peer-to-peer configuration. In a peer-to-peer network, computers share information and resources equally, and there are no dedicated network servers in place. In a client–server network, one or more dedicated servers provide the client computers with various types of network services, such as web services, application services, and database services.

LANs are composed of a number of components. A network interface card (NIC) is a hardware component in each computer that enables that computer to physically connect to the network and transfer data over a network cable. Network cables connect the NIC to a wall jack or directly to a network switch using a copper or fiber-optic cable. Desktop computers typically connect using a Category 5 (CAT5) or higher copper cable, and server computers or other networking devices can be connected with either copper or fiber-optic cables. Copper cables, as the name implies, are constructed with universal twisted pair (UTP) or standard twisted pair (STP) copper wires, can be twisted or bent, and support transmission speeds between 10 Mbps and 100 Mbps. Fiberoptic cables are made of very fine layers of glass and use light to transmit data at speeds of 10 Gbps and higher; unfortunately, they are more apt to malfunction if bent or twisted. Due to cabling length restrictions, LANs must be interconnected by using hubs or switches.

LANs are the basic building blocks that interconnect desktops, servers, and other devices. When setting up a new LAN, it is important to ensure that the LAN is designed to operate at high speeds, the

1114237 - Jones & Bartlett Learning ©

network traffic is optimized and controlled, and redundancy and high availability are built into the architecture. Having an unstable or slow-performing LAN will negatively affect end-user computer performance. When designing a new LAN, attention should be given to assessing and remediating any shortcomings with how the LAN is configured. This is vital to healthcare organizations, as end-user satisfaction with HIS application depends on the network connectivity being robust and available on a 24/7 basis. Several areas to consider in this regard include replacing old, legacy network hubs with modern network switches, installing network patch panels to reduce lengthy cabling runs, eliminating “daisy-chained” network switches, replacing slower copper network cabling with higher-speed fiber- optic cabling between intermediate distribution frame (IDF) and main distribution frame (MDF) network closets, upgrading desktop computer network connections from 10 Mbps or 100 Mbps speeds to 1 Gbps speeds, replacing “flat” or statically addressed network segments with virtual local area networks (VLANs) using dynamic addressing, and implementing advanced LAN management and monitoring tools.

Wireless LANs Wireless local area networks (WLANs) are perhaps one of the fastest-growing network technologies in today’s healthcare environment. Clinicians and other healthcare workers are increasingly seeking to use mobile workstations on wheels (WOWs), laptop computers, tablet computers, smart phones, and other wireless devices to do their jobs faster, more efficiently, and with greater flexibility. WLANs operate by transmitting data from a wireless access point (WAP) through the medium of air using radio frequencies. WAPs are typically distributed on or inside the rooms and hallway ceilings requiring wireless coverage, but are physically connected to network switches using CAT5 or higher cabling. Of the various wireless technologies in use today, the Institute of Electrical and Electronics Engineers (IEEE) technologies known as IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, and IEEE 802.11n are four of the most widely adopted WLAN technologies, with IEEE 802.11n being the most recent technology developed that supports the highest speeds and the largest ranges.

WLANs have the benefits of faster, easier, and less costly deployment requirements, as there is no need to go through the time-consuming and expensive process of deploying cabling to each computer. Important WLAN implementation considerations include replacing old and legacy IDF switches with power-over-Ethernet (POE) switches; ensuring POE switches have ample available and unused ports to support future growth; resisting the temptation to configure stationary computers for wireless access, thereby avoiding the additional performance limitations and complexities involved with wireless protocols; performing WLAN site surveys and staggered WAP placement to eliminate dropped- or low- coverage areas, as well as WAP contention; deploying redundant and properly distributed wireless access controllers; and implementing wireless network access control technology to support the increasing demand for guest, physician group, vendor, patient, and other non-employee access.

Wide Area Networks Wide area networks connect users on LANs to other LANs or other WANs. As healthcare reform continues to drive healthcare organizations toward greater reliance on EHR and other computerized HIS, various configurations are increasingly necessary to connect with other computers over greater distances. Many healthcare organizations encompass facilities at multiple locations. A WAN is used to connect the LANs at this disparate locations to each other. If an organization is large enough to have multiple WANs, these can also be linked together to form an even larger WAN. The largest WAN in existence today is the Internet. WANs are interconnected using high-speed fiber-optic cabling and typically support data transmission rates of 10 Gbps or higher. They utilize network devices called routers to connect or route data traffic from one LAN or WAN to another LAN or WAN. Routers send information through network devices called gateways.

A reliable WAN with sufficient bandwidth or capacity to handle end-user network traffic is critical for the successful operation of HIS implementations. Important areas to review to attain a high- performing WAN include replacing slower, legacy WAN circuits, such as T1 lines (also referred to T- carrier lines), asynchronous transfer mode (ATM) lines, or other copper-wire point-to-point telecommunications with high-speed fiber-optic multiprotocol label switching (MPLS) circuits8; using multiple commercial carriers and redundant pairs of networking devices for high availability; eliminating

1114237 - Jones & Bartlett Learning ©

all single points of failure along the WAN physical path; and implementing network link-load balancing (NLLB) and WAN optimization technology.

Wireless Wide Area Networks Another wireless technology increasingly used within healthcare environments is wireless wide area networks (WWANs), often referred to as broadband or cellular network technology. WWANs are wide area networks that provide service to large geographic areas through separate areas of coverage, referred to as cells. Cell phones, smart phones, tablet computers, and hot spots are mobile devices commonly used to connect to WWANs. Three families of WWAN technologies are prevalent today: (1) Global System for Mobile Communications (GSM) and Universal Mobile Telecommunications System (UMTS); (2) Code-Division Multiple Access (CDMA) One, CDMA2000, and Wideband CDMA (WCDMA); and (3) Worldwide Interoperability for Microwave Access (WiMAX) and Long-Term Evolution (LTE). The GSM/UMTS and CDMA One/CDMA 2000/WCDMA standards are referred to as second-generation (2G) and third-generation (3G) technologies, as they were designed to replace the slower, more limited analog cellular networks with higher-speed, digital cellular networks. The WiMAX and LTE standards are high-speed fourth-generation (4G) technologies that are now gaining increasing market share on a global scale. T-Mobile, AT&T, Sprint, and Verizon are four major WWAN service providers.

The consumerization of IT has given rise to the bring-your-own-device (BYOD) phenomenon, in which increasing numbers of end users seek to use their personal smart phones and/or tablets for both personal and work use.9 Many healthcare organizations have responded to the complexities involved in supporting both personal and corporate data on a personally owned mobile device by deciding to officially support only corporate-owned mobile devices. Other organizations have developed appropriate BYOD policies and deployed mobile device management technology. Many organizations have recognized the need to provide uninterrupted cellular network coverage to doctors, nurses, and other healthcare workers for functions such as voice, texting, web browsing, and other mobile applications; for those organizations, distributed antennae system (DAS) technology can eliminate dead spots and other areas of poor cellular signal coverage within hospital buildings.

Storage Area Networks Storage area networks (SANs) are dedicated back-end computer systems designed to efficiently and cost-effectively store and transfer a healthcare organization’s server data. These high-speed networks are dedicated to centrally storing and providing access to data from multiple server systems. They have the distinct benefit of providing high availability, with no one single hardware component (a so-called single point of failure) being able to disrupt access to data. Traditional methods of storing data involve using directly attached storage, where each server stores its associated data to hard disk drives (HDDs) directly attached to itself. This method has many limitations in today’s environment, where end users are demanding ever-greater storage capacity and performance. Directly attached storage systems still exist today, but they are largely giving way to SAN systems, which boast higher capacity, faster access, greater availability, and stronger security at less cost. The different types of SANs in use today include fiber channel (FC) SANs and network attached storage (NAS) devices.

At a basic level, data are stored on a HDD and can be written or read. To ensure that the data will be available in the event the hard disk fails, hard drives can be placed into a redundant array of independent drives (RAID) configuration, with the data copied across multiple drives. A RAID controller is a computing peripheral that keeps the disks in the array in synchronization and manages all the write and read (input/output [I/O]) operations to and from the disks. Four RAID configurations widely used today are RAID 1, RAID 5, RAID 5 with a spare, and RAID 10.

• RAID 1 configurations, also called mirrored disks, use two HDDs: one as the primary HDD and the other as the secondary HDD. This configuration provides redundancy if a HDD fails and boasts fast read performance, as the data can be read from either disk. Unfortunately, it has slow write speeds to the HDD and is more expensive because two HDDs are required.

•  RAID 5 distributes the common or redundant information (called parity) to all HHDs in the configuration. If a block or HDD fails, the parity information ensures that the lost information can be restored when a replacement HDD is inserted into the array. RAID 5 requires a minimum of three HDDs, and has the advantage of performing fast HDD reads.

1114237 - Jones & Bartlett Learning ©

•  RAID 5 with a spare configuration contains an additional HDD, called a hot spare; it remains unused until a HDD in configuration fails, at which time the array automatically rebuilds the failed HDD to the spare HDD. This scheme has the advantage of providing an additional layer of redundancy should a HDD fail.

• RAID 10 is a combination of RAID 1 and RAID 5, giving it the fastest performance and highest availability, albeit with the highest cost, because only half of the HHD capacity is used for the actual storage of data.

In healthcare server systems today, RAID 1 is often used to configure stand-alone server operating system drives, while RAID 5 is used as a cost-effective and acceptably performing configuration for both directly attached and SAN data storage environments. RAID 10 is used for SANs that require very high performance and availability. Most mission critical databases are stored on RAID 10, as it provides higher levels of availability and write access. However, it costs almost twice as much as RAID5 because it has almost twice the number of disks.

SANs can be used to support very large amounts of data. To do so efficiently, they allow for the creation of disk pools that vary in size, speed, and cost by using different RAID configurations, HDD sizes, and HDD access times. When a server needs new or additional storage, based on what is needed and how expensive the storage needs to be, logical volumes (LUNs) can be provisioned and presented to the server as a local HDD. SANs communicate with each other using either the Ethernet (also referred to as IP), FC, Fiber Channel over Ethernet (FCoE), or Internet Small Computer System Interface (iSCSI) protocol; they also use high-speed fiberoptic cabling and network switches that support the IP, FCoE, or iSCSI protocols. Modern SAN deployments typically use either 10 Gbps FCoE Ethernet or 16 Gbps FC. With the application of aggregation technology, both Ethernet and FC SAN connections can be increased to higher speeds to support increased traffic loads and higher data transfer requirements.

SANs that may have medium to high storage capacity requirements but do not have high performance requirements, such as file servers, can be configured as NAS devices. NAS systems use the Ethernet (IP) protocol over standard LAN switches to present storage to servers and other devices on the network. This approach has the benefit of being less expensive than FC-based SANs because it uses less costly LAN switches and cabling, and cheaper and larger HDDs. SAN and NAS vendors are continuing to develop easier-touse management consoles for SAN administrators, reducing the learning curve and skill set needed to troubleshoot and maintain the various SAN technologies.

Voice and Communications Voice over Internet Protocol (VoIP) and unified communications (UC) are emerging technologies that healthcare organizations are beginning to leverage and implement at their facilities. VoIP comprises a family of technologies that enable IP networks to be used for voice applications such as telephony, messaging, and collaboration. With greater reliance on robust data networks, traditional analog-based PBX office phone systems that operate over public switched telephone networks (PSTNs) telecommunication circuits are now being replaced with more cost-effective VoIP solutions that run over existing IP networks. With high-speed, robust LAN and WAN connections in place, and with the Internet being capable of supporting voice traffic over data circuits, voice calls no longer need dedicated analog circuits and can leverage the existing data network. This approach requires a VoIP- enabled phone or a computer and headset. Analog voice calls are converted to packets of data, which are then sent over the data network, and converted back to analog signals. The addition of voice to a data network allows organizations to reduce costs, improve productivity, and enhance collaboration.

Voice over wireless local area network (VoWLAN) is a technology designed to integrate mobile devices using the WLAN. It is proving particularly advantageous as more clinical applications are developed for use with smart phones, tablets, and portable computers. Use of VoWLAN offers the following benefits:

• Improves workflow and productivity by delivering ubiquitous, robust coverage • Enables roaming of voice clients and high-quality voice communications by using real-time radio-

frequency scanning and monitoring to minimize interference • Minimizes roam time and client connectivity issues • Provides advanced quality of service (QoS),

extended talk-time, and call security

1114237 - Jones & Bartlett Learning ©

UC is another evolving technology that involves the integration of real-time communication services, such as instant messaging and presence, VoIP and VoWLAN, video conferencing, and web conferencing. Digital signage and wayfinding, and IP television (IPTV), are also considered part of the UC family of services. UC is designed to use a single, consistent user interface to provide one or more of these services, along with transferring data over the IP network. An example of UC in an HIS setting can be seen when virtual meetings are conducted with products such as Cisco WebEx, Citrix Go-To-Meeting, or Microsoft Lync web conferencing software. Although healthcare workers and partners might be located around the world, they can meet via an online session, sharing voice, video, presentations, chat, and other forms of collaboration—all while using only a web browser and computer or mobile device.

Instant messaging or chat is used often in healthcare environments as the real-time communication needs of clinicians and IT personnel expand. Instant messaging allows users to send messages or files to each other. In a healthcare setting, a secured instant messaging application is required to avoid issues with electronic protected health information (ePHI) or other sensitive information traveling over unsecured networks, such as the Internet. Instant messaging has the additional benefit of giving others notice of an individual’s presence or status, such as whether he or she is online, offline, busy, or in a meeting.

Figure 4.4 illustrates the multiple components in the WLAN protocol that securely support data and voice traffic.

Video conferencing enables two or more individuals to talk and see each other by transmitting audio and video signals. Although this technology has existed for many years, it has not been widely adopted due to the complexity and high costs involved in using analog circuits and deploying proprietary video conferencing equipment. UC, however, enables video conferencing to be performed over IP data networks with significantly reduced costs and complexity. Popular applications of this technology in healthcare environments include video conferencing over desktop computers and mobile devices, video conferencing in conference rooms using large-screen monitors (which eliminates the need for travel and other expenses involved in face-to-face meetings), and cloud-based video conferencing services (which eliminate the need to buy and maintain expensive equipment).

FIGURE 4.4 VoWLAN Protocol

Web conferencing is used frequently in healthcare organizations because of its simplicity, convenience, and low cost. It enables users at multiple locations to hold audio meetings and share desktop computer applications or applications from their mobile devices over the IP network. Given the never-ending quest to reduce costs, web conferencing is being widely embraced as a solution that enables organizations to reduce employee travel requirements while increasing collaboration between all stakeholders. Web conferencing solutions can be cloud based or deployed using an on-premises architecture.

Digital signage and digital wayfinding are other UC technologies that are being deployed in healthcare organizations. Digital signage uses server technology and IP networks to electronically display information, such as organizational training or news, advertising, or other healthcare-related

1114237 - Jones & Bartlett Learning ©

messages, using liquid crystal displays (LCDs) or plasma displays that are placed in various public or internal locations within hospitals and work areas. Digital wayfinding uses digital signage technology, but adds touch-screen technology to allow users to interact with the LCD-presented information.10 Examples of digital wayfinding technology commonly found in hospitals include interactive touchscreen LCDs that allow patients to obtain directions to various departments, find information about their physician, see cafeteria information, and look up healthcare education information.

Data Centers and Cloud Computing Ensuring that HIS applications and data are protected, secured, and always accessible to the end users who need to use them is a very important aspect to HIS. Data centers are the facilities where HIS are located and are vital to the successful implementation and ongoing support of providing healthcare applications. With the ever-growing reliance on electronic information, healthcare organizations must ensure that their data centers can provide high availability for their computer systems, are secure and modernized to remain cost-effective, and have ample capacity for growth and expansion. One of the first decisions facing healthcare organizations is whether they will maintain their own data center facilities, lease one or more commercially owned colocation data center facilities, or outsource (remote host) both their data center facility and computing equipment to a third party. Due to the high costs and complexities involved in an organization maintaining its own data center facility, contracting with a co-location facility and remote hosting are increasingly popular options with many healthcare organizations.

Another important decision organizations need to address involves data center consolidation. Newer servers, networking devices, and other equipment located inside data centers are increasing in capacity and performance (referred to as computer density) while requiring less cabinet, rack, and floor space. Organizations are discovering that they no longer need multiple data centers but rather can consolidate their IT infrastructure into a single facility. At the same time, to ensure high availability and disaster recovery capability, healthcare organizations need a secondary data center. This is typically a smaller facility that can support running the mission-critical applications (at a minimum) and is often remotely hosted by a third-party data center vendor.

A third important question is how the organization will position itself with the evolving technology of cloud computing. Cloud computing, a recent emergent technology, followed in the footsteps of mainframe, client–server, web, and service-oriented architecture (SOA), all of which were popular at some point in the past. Cloud computing is a general term associated with delivering hosted services, with the goal of providing easy, scalable access to computing resources and IT services. As depicted in Figure 4.5, these services are organized into three categories: infrastructure-as-a-service (IaaS), platform-as-a-service (PaaS), and software-as-a-service (SaaS), with some healthcare proponents now discussing EMR-as-a-service (EaaS) as a future possibility.11 An IaaS-hosted solution involves a vendor supplying a data center with all the server hardware and network connectivity needed to support HIS applications. The HIS customer then needs to install and manage its server operating systems, applications, and databases itself. A PaaS-hosted solution is similar to an IaaS-hosted solution, except that the cloud vendor also supplies the server operating systems. With a SaaS-hosted solution, the cloud vendor installs and manages all previously mentioned components. With an EaaS- hosted solution, the cloud vendor fully hosts the EMR solution. In all four scenarios, the HIS customer still manages the processes of entering and extracting data from the service.

A cloud can also be categorized as private or public. Public clouds, such as Amazon Web Services, sell services to anyone on the Internet, typically consumers. Private clouds are proprietary networks and data centers that supply secure, hosted services for use within a particular organization; these are being increasingly adopted among healthcare organizations.

1114237 - Jones & Bartlett Learning ©

FIGURE 4.5 Cloud Computing Components

Data center facilities have a number of critical components that must be managed appropriately. The most costly operational expense related to a data center, other than the high capital costs required for building or upgrading the facility itself, is electrical power consumption. The green data center concept is an initiative designed to improve the environment by reducing power usage. In a data center, this goal can be accomplished by using energy-efficient equipment and reducing the amount of physical equipment inside the data center by leveraging technologies such as virtualization and consolidation.

Data centers receive their primary power, called utility power, from commercial utility companies. Ideally, this should be supplied by two separate physical paths (or feeds) into the building’s main distribution unit to provide redundancy. The typical power path is 1–10 megawatts (MW) or greater. Through a series of electrical transformers, high-voltage electricity is reduced or “stepped down” so that facilities and computing equipment can be supplied with appropriate voltages. Utility power is routed to power distribution units (PDUs), which are distributed throughout the data center. In large data

1114237 - Jones & Bartlett Learning ©

centers, remote power panels (RPPs) route power to one or more data center cabinets. Power is then distributed to each cabinet, which can directly connect to computing equipment or a set of smaller cabinet power strips. Most servers and data center equipment will plug into these data center cabinet PDUs, which can be remotely monitored over the network using a branch circuit monitoring system (BCMS) application. Larger facility equipment uses 480- or 220-volt capacities, while computing equipment uses 220- or 110-volt capacities.

In the event that the utility power feeds fail, data centers should be configured to automatically fail over to use backup power, in a battery-supported form. The typical power path is an uninterruptable power supply (UPS), a flywheel-driven continuous power source (CPS), or a combination of the two. Backup power is important to ensure that HIS applications remain available and accessible, as inevitably electrical components suffer outages from time to time. Any disruption in power will translate into these critical HIS applications going offline, in turn negatively impacting patient care. UPS backup systems use batteries to provide electricity and have the advantages of being less expensive and starting up faster than non-battery backup systems, such as CPS systems. However, UPS systems are not considered environmentally friendly and the batteries require regular maintenance and replacement. CPS systems use a continuously spinning flywheel driven by high-speed turbines to generate electricity. They are robust and considered environmentally friendly, but are more expensive and slower to assume the primary load than UPS systems. Generators, using diesel or gasoline fuel, are needed to provide power to both UPS and CPS systems. Due to the high levels of noise generated by CPS equipment, data center personnel must use earplugs to minimize ear damage.

Data centers should have service level agreements (SLAs) with fuel companies to deliver fuel until the utility power is restored, and they often are equipped with local storage tanks capable of holding tens of thousands of gallons of fuel. In many data centers that are large enough to use CPS backup systems, UPS systems are also installed to ensure the primary load is assumed quickly.

In addition to a continuous power supply, cooling is essential to reliably support HIS. Many computer systems are located in densely configured data centers, where a tremendous amount of heat is produced within a confined space. To provide ambient or room cooling, heating, ventilating, and air- conditioning (HVAC) systems are used. HVAC systems utilize water to absorb excess heat: Computer room air handlers (CRAH) draw in the hot air, and then cold water traveling through large pipes absorbs the heat. Subsequently, roof or wall condensers release the heat outside the data center and large, heavy-duty water chillers cool and recirculate the water. As a contingency in case commercial or utility water sources become unavailable, many data centers have wells that can hold tens of thousands of gallons of water.

To protect a data center from damage by fire, fire suppression systems, such as water-based dry- pipe preaction sprinklers or gas-based FM200 fire suppression systems, are used. Dry-pipe systems fill the pipes with water if a fire occurs. They are less expensive than the gas-based FM200 systems but have the disadvantage of potentially damaging computer systems in the event of a fire. However, because individual sprinkler heads open only after a temperature fuse breaks—normally at a temperature of approximately 175°F—water damage will be limited to just the computer equipment directly below the specific sprinkler head where the fire is occurring. FM200 systems contain a fire retardant that will not damage computer equipment, but tend to cost more and require data center personnel to evacuate the area being treated. To help provide early warning detection of a potential fire, very early smoke detection apparatus (VESDA) systems monitor for smoke particles and sound alerts when they are detected.

If a catastrophic and life-threatening event does occur within a data center, in which terminating all electricity is the only option to resolve the situation, an emergency power off (EPO) switch should be available. Once this button is pressed, all electricity to the data center is shut off.

BCMS can be deployed in data centers to monitor and manage electrical circuits, and provide data center staff with the ability to ensure that data center equipment has sufficient electrical capacity. Data center management systems (DCMSs) are hardware and software systems that allow data center personnel to design and proactively manage these and additional data center technologies; they can help reduce unplanned system downtime caused by poor planning or a lack of standardized and documented processes and procedures. A DCMS may include power protection and distribution management, air-conditioning and environmental controls, intelligent cable management, cabinet

1114237 - Jones & Bartlett Learning ©

space management, server and network device remote access, and asset management and tracking (Figure 4.6).

Business Continuity and Disaster Recovery Another area associated with data centers is business continuity and disaster recovery. “Business continuity” describes the processes and steps a healthcare organization puts in place to ensure that its essential business functions will continue during and after a disaster.12 One of the most important areas of business continuity planning is disaster recovery planning, which comprises the planning, process, policy, and procedures undertaken to prevent interruption of missioncritical IT services, and to reestablish full IT functioning as swiftly and smoothly as possible.

FIGURE 4.6 Components of a Data Center Management System

Key: KVM, Kernel-based Virtual Machine.

As EHRs and other HIS technologies become more commonplace in healthcare environments, it is critical that the risk of a system outage or data center disaster be mitigated. Many health organizations today have not fully developed their business continuity plan (BCP) or disaster recovery plan (DRP); these organizations should consider performing a BCP or DRP assessment to determine the level of risk that is acceptable. In preparing a BCP, the organization should first identify and prioritize the criticality of the various HIS components and then determine the appropriate recovery time objective (RTO) and recovery point objective (RPO) for each HIS in the event of a disaster or unplanned system outage. RTO refers to the total time (in minutes, hours, or days) during which a server or service can remain unavailable before it is restored to full functionality, while RPO refers to the total time (in minutes, hours, or days) for which data might be lost. Keeping BCP and DRP at the same level of priority as other projects within HIS is often challenging for healthcare organizations to accomplish, but it is critical to do so. The increasing dependence on HIS and technology throughout health care necessitates investment of time and effort to establish and maintain these protective capabilities.

An examination of important DRP concepts will demonstrate the various steps that organizations can take to reduce this risk. Redundancy is one of the simplest concepts that should be implemented at all levels of DRP. Where possible, having two instances of server, storage, or network system components, such as central processing units (CPUs), HDDs, NICs, storage host bus adaptor (HBA)

1114237 - Jones & Bartlett Learning ©

cards, system controllers, and cabling, will enable the hardware system to support the HIS and remain operational should a failure occur that is restricted to any one of the components.

At the next level, servers, storage, and network systems themselves should be clustered, load balanced, or mirrored such that if the primary system fails, the secondary system will continue to provide service. Clustering is typically used with applications and databases, while load balancing is used with web servers, file servers, and various network devices. Mirroring is used to replicate and maintain synchronous copies of data between two or more SANs.

Moving to the highest level of redundancy, data centers themselves should be redundant. To accomplish this in today’s environment, each primary data center should be associated with a corresponding secondary or backup data center. Secondary data centers can be configured as cold sites, tepid sites, warm sites, or hot sites, such that they can provide different levels of service in the event that the primary site is unavailable.

• Cold sites are facilities that have hardware and software available for use, but are shared with other organizations and contain no data from the primary data center. Should a disaster occur, the cold site systems would need to be configured and the backup data restored to the cold site location. This is the least costly DRP option and has no distance limitation between data centers, but it can take several days to bring an organization’s critical systems back online.

•  Tepid sites are similar to cold sites, but have the data from the organization’s critical systems copied over using basic SAN replication. This is the third most costly DRP option, has a distance limitation of 1000 miles or less, and takes only 2 to 3 hours to bring an organization’s critical systems back online.

• Warm sites improve on the tepid site capability, with the difference being that all systems and data from the primary site are copied over, although noncritical systems will operate in a degraded mode. This is a very costly DRP option, has the same distance limitation of 1000 miles or less as tepid sites, and requires only 1 hour or less to bring an organization’s systems back online.

• Hot sites can provide rapid, automated and full system and data recovery in less than a minute, but are the most expensive option. They have a distance limitation of either 200 miles or a data transfer round-trip time of 10 milliseconds.

Backup systems are another key technology that healthcare organizations can leverage to ensure HIS and data availability. Tape-based backup systems, such as digital linear tape (DTL) and linear tape- open (LTO) models, use magnetic tape, tape drive systems, and stand-alone or centralized backup application software to make backup copies of computer data on tape. Tape backup systems have been used in data centers for many years but suffer from limitations such as unacceptably slow backup and restore transfer times, limited capacity to address the exponential storage growth found in modern HIS, the risk of losing tapes that are stored at remote locations, and the inability to store data indefinitely. Additionally, tape backup systems lack support for advanced features such as encryption- at-rest capabilities.

Disk-based backup systems address many of the shortcomings of tape backups by backing up system and application data to disk. These systems have the benefits of being able to reduce the amount of data that must be backed up by as much as 90% through a process called data deduplication. Data deduplication eliminates the need to back up redundant or already backed-up data. As a result, disk-based backup systems have higher backup storage capacities and faster backup and restore times. They more easily move and store data to disparate locations using network and cloud- based technologies and are designed to use advanced security features and both encryption-at-rest and encryption-in-transit.

Virtual tape libraries (VTLs) are backup systems that use disk-based arrays to emulate tape libraries. With these systems, the storage medium can be switched from tapes to disks while continuing to use the existing tape backup software. VTLs lack the advanced features of disk-based backup systems.

Server Computing Servers are specialized computers that are designed to process or “serve” computing requests, such as requests for database information, application processing, or file transfers and storage. Although they

1114237 - Jones & Bartlett Learning ©

have the basic components found in client or desktop computers, they are architected differently. Servers are designed with multiple high-speed CPUs, large amounts of random access memory (RAM), redundant and high-capacity I/O, internal bus systems, and access to high-speed storage, network, and backup systems. These computers are inserted or “racked” in computer cabinets to allow for high density, and they do not require the individual directly connected monitors, keyboards, mice, or other devices that are common with client or desktop computers. As many as 10 to 12 rack-mounted servers may be stored in a single computer cabinet (Figure 4.7). A highcapacity server is so large that it requires an entire computer cabinet on its own.

Keyboard, video, and mouse over IP (KVMoIP) devices are centralized systems that give system administrators keyboard, monitor, and mouse access over the network, eliminating the requirement and additional cost to provide these peripheral devices for each server.

Blade server technology represents an advancement in increasing server density and reducing server costs. Blade servers are stored in a compact enclosure called a blade chassis, which has a reduced size and uses less energy. These types of servers boast higher availabilities achieved by sharing common components, such as network, storage, cabling, and power infrastructure. Three to four times more blade servers can fit in the same cabinet space as rack-mounted servers. Unified computing system (UCS) technology is a next-generation data center platform that increases server density, performance, availability, management, and efficiency beyond blade server technology by uniting multiple blade server chassis, networks, and storage infrastructures into a single cohesive system.

FIGURE 4.7 Data Center Class Servers

Virtualization is another technology advance that has significantly reduced the amount of server infrastructure needed to support today’s healthcare environments, thereby greatly smoothing the way for healthcare organization server consolidation initiatives. Physical servers or hosts generally use only 10% or less of their processing ability. The virtualization feature takes advantage of a server’s unused processing power by creating multiple virtual server instances, which typically increases server density by a factor of 10 to 15. A hypervisor or virtual machine monitor (VMM) is a piece of computer software, firmware, or hardware that creates and runs virtual machines. These virtual server instances, called virtual machines (VMs), run on servers running Windows, Linux, and Solaris operating systems, and on

1114237 - Jones & Bartlett Learning ©

logical partition arrays (LPARs) in UNIX-based servers, such as the Advanced Interactive eXecutive (AIX) operating system.

Servers that run one or more VMs are called hypervisors, and are defined as host machines. Individual VMs are called guest machines. Hypervisors present and manage the operation of the guest operating systems within the virtual operating platform. By combining or clustering multiple host computers into redundant and highly available server farms so that VMs and LPARs can automatically move between physical hosts, server virtualization significantly reduces server downtime due to hardware failure or planned maintenance. Figure 4.8 illustrates how virtualization is designed to maximize server hardware and software resources.

FIGURE 4.8 Diagram of a Virtualized Server

Data from Nash Networks, Inc. (2009). Virtualization: A small business perspective. Executive Summary. http://www.nashnetworks.ca/virtualization-a-small-business-perspective.htm

Despite the many advantages of server virtualization, including the ability to rapidly and easily deploy servers, reduced costs per server, and simplified server management, several challenges need to be addressed when moving forward with this technology. Server sprawl or large numbers of servers may occur due to the relative ease with which systems can be deployed. New charge-back models and processes must be put in place when this approach is used, as most of the server infrastructure must be procured and deployed prior to identifying the need for a new server. Additional care must be given to server architecture and change management because there is increased risk that multiple systems might be negatively affected by any design flaw or problematic configuration change or upgrade.

Servers can be classified in additional ways. Servers that are fully supported and managed by a vendor (usually installed with a proprietary operating system and software) are called appliances. Appliances are typically self-contained, requiring only a network connection; are easy and fast to deploy; and can be a preferred method for delivering a server application, as healthcare organizations or customers do not have to address all the complications and delays involved in setting up the server themselves. Servers are also classified as production, development, or test types, with all three types being stored in secured, highly available data centers.

Infrastructure Servers Infrastructure servers provide core services that support server system functionality and that need to be implemented properly if a healthcare organization expects to rely on its business and clinical applications. A poorly implemented underlying server infrastructure environment will cause significant

1114237 - Jones & Bartlett Learning ©

issues with HIS application deployments. Understanding the following infrastructure servers and applications will provide insight needed to establish a robust and stable environment that reliably supports HIS applications.

Dynamic Host Configuration Protocol (DHCP) servers assign a unique address to each computer on the network. A misconfigured or inaccessible DHCP server can cause both servers and end users’ computers to receive duplicate or incorrect addresses, making them unable to function. Domain Name System (DNS) servers enable users and servers to contact websites and other servers by maintaining a directory listing of server and website names. It is important for organizations to ensure that their DNS servers are properly configured, and if an update or modification is required, thorough testing must be performed. Should the DNS service be disrupted, end-user web browsing via the Internet and server-to- server communications can be inhibited. Active directory (AD) servers maintain lists of users, computers, and printers, along with any associated passwords and security settings. A misconfigured or inaccessible AD server can cause users and computers to have access, connectivity, and password issues. Identity and access management (IAM) servers automate and streamline the management of user, computer, and application accounts and passwords; their use can significantly reduce the number of help desk or IT staff needed for these tasks.

Additional infrastructure servers include enterprise monitoring servers, which are used to monitor servers, applications, storage, and network services. Such servers can send alerts or resolve failed services, thereby greatly increasing system uptime. Systems management servers provide comprehensive management of applications, services, physical resources, hypervisors, and networks. They also provide centralized services such as desktop imaging and software deployment, antivirus and antimalware protection, application security patching and upgrades, and computer configuration and asset management. Endpoint encryption servers are systems that install and manage encryption on client computers.

Database servers maintain a healthcare organization’s database instances; they are frequently clustered or configured with multiple servers to support large database sizes. Most HIS and administrative/clinical applications use transactional databases, such as Oracle 11G, IBM DB2, or Microsoft SQL, whereas EHRs may use high-speed object databases, such as Intersystems Cache.

Enterprise web content management (EWCM) servers enable departments to easily update and manage web-based content on the corporate intranet and, in some cases, on the organization’s externally facing website. Finally, application virtualization servers enable users to run applications that are installed on centrally located servers, eliminating the need to install the application locally and, in most cases, improving the performance of the application and overall end-user experience. Application virtualization is being widely adopted in healthcare settings due to its tangible benefits.

Client Computing Client computing describes the computers and devices used by end users. These can be categorized as either stationary or mobile devices, with mobile computing needs on the rise. Nevertheless, the standard client computer issued today is a PC directly connected to the organization’s network using a wired or copper cable network connection. Recent advances in technology have significantly reduced the size and cost of PCs, but additional improvements in wireless technology are needed to transition to a fully wireless environment.

Other stationary computers found in a healthcare setting include all-in-one (AIO) computers, wall- mounted computers, thin- and zero-client computers, and electronic tracking board systems. AIOs are often needed in clinical areas with space constraints, such as in operating room (OR) or emergency room (ER) locations, and are designed with all the computer system components (except for the keyboard and mouse) integrated with the monitor, which is typically a 24- to 27-inch LCD plasma screen. Wall-mounted computers are frequently deployed in patient rooms and other locations where space constraints exist. In patient rooms, care must be taken to ensure that these computers are optimally situated to enhance the caregiver–patient experience, as maintaining eye contact between both parties is vital for the proper delivery of care. In some cases, special construction must be undertaken to create stationary workstation areas in the center of rooms that support multiple patients.

Thin-client computers are increasing in use in healthcare settings. These small machines rely on a server to perform and store all data processing, and can be likened to client dumb terminals from the

1114237 - Jones & Bartlett Learning ©

mainframe era. Thin-client computers typically have a small amount of RAM, a reduced-size CPU, a small hard drive that runs a modified version of the Windows operating system (called Windows Embedded), and a NIC. The benefits of thin-client computing include improved maintenance and security due to central administration of the hardware and software in the data center, and reduced client hardware and energy costs.

Zero-client computers are similar to thin-client computers, but offer the additional advantage of having no local hard drive or operating system to secure or maintain.13 Like thin clients, zero clients are gaining in popularity in healthcare settings, as they are well suited to furthering desktop virtualization and integrating with WOWs due to their light weight, small form factor, and ease of management.

Electronic tracking board systems support the real-time tracking of critical information pertinent to the flow of care for individual patients. Tracking board systems consist of room-sized LCD or plasma computer monitors connected to an EHR or another clinical application. They are often used in ERs.

Mobile computers frequently used in healthcare settings include WOWs, laptops, tablets, and smartphones. WOWs, which are also referred to as computers-on-wheels (COWs) or mobile workstations, are mobile carts that integrate with client computers and peripherals. They can function as either a mobile system or, by locking the wheels at the base of the cart, a stationary system. WOWs are often used in clinical areas such as nursing stations, patient rooms, hallways, and other rooms; due to their larger size, however, it is not always possible to deploy them in smaller or crowded areas. WOWs vary in cost, with the more expensive carts having advanced battery power capabilities, lockable drawers or bins for medication administration and other supplies, power assistance, and advanced cart software. Specialized medical-grade keyboards and mice are often deployed with WOWs to improve infection control. WOWs are often deployed using thin-client computers, zero-client computers, or AIOs.

In some cases, healthcare organizations elect to use laptops and medical-grade tablets with docking stations when deploying WOWs. Laptops and tablets can be readily disconnected from WOWs for easy portability because they have their own battery and operating systems; once disconnected, they can be used as stand-alone devices, and later reconnected to WOWs. Tablets are easier to carry than laptops when making rounds but are not as well suited for clinical documentation as laptops and standard PCs. As a result, iPad and medical-grade tablet usage in clinical settings has seen mixed adoption rates. In a healthcare setting, smartphones are used primarily for communication-related activities such as email, alerting, scheduling, texting, web-based searches, and viewing clinical application data.

Other important client devices and peripherals needed to provide patient care include bar-code scanners, signature pads, printers, document scanners, and identification (ID) badge and access control systems. Bar-code scanners are used to automate the input of patient and medical information, including patient identification from bar-coded wristbands or identification tags, and medication administration that uses pharmacy bar-coded labels. Bar-code scanners are manufactured in wired or wireless configurations, with the wireless modality being both more popular and more expensive. Signature pads are designed to electronically accept patient and clinician signatures, and are frequently deployed at hospital admission and patient accounting areas. Both bar-code scanners and signature pads are among the peripherals often found on a WOW.

Printing and electronic document management (EDM) are two final client computing areas that are critical to a healthcare organization. For large healthcare organizations, centralized print servers can be deployed in the organization’s data center; these computers typically support as many as 500 printers. EDM is seeing more adoption in health care due to the transition from paper records to electronic records. It involves scanning paper documents and using intelligent optical character recognition (OCR) technology to convert the image into editable text. Low-speed, medium-speed, and high-speed scanners—listed here in order of increasing costs but also better scanning speeds and capacities—are essential EDM devices in today’s healthcare environment, particularly in health information management (HIM) departments. Portable scanners are commonly used in various clinical areas, such as admissions and nursing stations.

ID badge and access control systems are increasingly widespread in healthcare environments. The important components of badge and access control systems include the ID badge media, radio frequency identification (RFID) badge readers, badge printers and cameras, and badge access control hardware and software. Smart-card ID badges uniquely identify individuals who work in a healthcare

1114237 - Jones & Bartlett Learning ©

setting and are now frequently used to log in and out of computers, gain access to restricted areas within a hospital or healthcare facility, and record start and end times of work shifts. Proximity, iClass, and multi-Class smart-card ID badge technologies are pervasive in healthcare environments, with the latter two having the advantage of not requiring any physical contact between the badge media and the reader. In addition to displaying the user’s photo and work information, smart-card ID badges can be configured to hold embedded information, such as an employee number or medication administration identifier. Use of smart-card ID badges by clinicians to dispense medications reduces the risk of medical errors. RFID badge readers are often deployed on WOWs or other client computers to allow users to quickly log in and out of their computer session. Specialized badge printers and camera equipment are needed to take individual user photos and print the smart-card ID badges. Badge access control hardware and software is required to maintain the list of users who have been assigned a smart-card ID badge, along with their user and access-level information. Such hardware and software are usually deployed with the server system and database installed in the organization’s primary data center, with individual servers or appliances installed in a distributed fashion at each facility that has a geographically disparate location.

Virtual desktop infrastructure (VDI) technology is gaining increased acceptance in healthcare settings, largely due to its direct impact in improving patient care delivery. Desktop virtualization is defined as a client’s desktop operating system that is hosted within a VM running on a centralized server in the data center. Thin- or zero-client computers are the most prevalent desktop computers running in VDI environments. However, because VDI desktop client hardware requirements are minimal, legacy PCs can be repurposed with a VDI desktop and used for several additional years. It is also common for organizations to deploy VDI software to mobile devices, such as laptops and tablets, which gives them the ability to operate their local desktop or a VDI desktop. Another strategy used in healthcare organizations is to deploy VDI desktops to PC workstations, thereby giving the users of these computers the option to run either both the local desktop and the VDI desktop, or only the VDI desktop. Server computers hosting VDI desktop VMs require a different configuration than host systems running server- and application-based VMs. VDI VMs demand large amounts of RAM, CPUs, and high-speed SAN storage to provide an acceptable end-user experience. In contrast, VDI desktops generally use a standard desktop image that has all the applications and programs preinstalled. A user’s personal settings, such as wallpaper and browser shortcuts, along with information on which desktop applications the user has permission to access, can be maintained centrally. Files and documents used during a VDI desktop session can be stored centrally on a file server.

VDI desktops are categorized as either persistent desktops or nonpersistent desktops. When a user logs in to a persistent desktop, he or she receives a new desktop installation each time, along with the user’s current personal settings and file sharing information copied to the desktop. If the user then experiences a difficulty with a desktop application or the desktop freezes or crashes, he or she simply needs to log off and then log back in, as doing so will create a new or “fresh” desktop. In healthcare settings, this setup can greatly reduce queries to the help desk. Also, because all users receive the same standard desktop image, significantly less server storage and ongoing maintenance are needed. A downside to persistent desktops is that when the desktop image is upgraded with new applications, care must be taken to ensure that the upgrade will work correctly with the existing applications installed to the desktop.

Nonpersistent desktops function much like a non-VDI experience, except that dedicated server storage for each VDI desktop and the user’s VDI desktop is not recreated or refreshed when logging in. This approach is not as effective when addressing end-user help desk requests regarding problematic VDI desktop issues, but does more closely simulate the traditional user desktop experience.

Single sign-on (SSO) and tap ’n go technologies can provide significant benefits to healthcare organizations that are deploying VDI desktops. SSO has the benefit that users have to remember just one username and password for their desktop session and all applications. It works by requiring users to log in to their desktop session with their username and password. Once in the desktop session, the SSO technology automatically logs the user in to each of the various applications without requiring the user to remember or enter application-specific passwords. In a healthcare setting where many different applications are used, each requiring the use of a separate password, this is a significant time saver and user satisfier.

1114237 - Jones & Bartlett Learning ©

Tap ’n go technology enables users to quickly log in and out of computers with just the “tap” of their ID badge. When moving from computer to computer, the user’s desktop session is transferred seamlessly based on proximity of the ID badge to a work station, bringing it over to the next computer exactly as it was left in the previous computer. If an application was opened on one computer, the same application remains open when the user moves to the next computer.

In short, VDI desktops have the potential to improve the desktop experience, reduce desktop support costs, simplify desktop management, increase desktop standardization, and strengthen remote access and data security. Drawbacks to VDI technology are the relatively high up-front capital costs, the more advanced system administrator skill sets needed, the limitations encountered when working offline, and the challenges associated with supporting video and other bandwidth-intensive applications.

Mobile Computing Mobile computing in health care has emerged as a leading driver for improving the quality, accessibility, and safety of care, as well as increasing the cost-effectiveness of care. For many years, technology adoption in health care has lagged behind that in other industries such as the financial, manufacturing, and retail industries. With the recent development of mHealth (i.e., mobile health), there are now significant opportunities to improve how healthcare professionals deliver care. An important benefit of mobile computing can be seen with how it improves the real-time delivery of care. In addition, with the rapid adoption of smart phones and tablets among clinicians, consumers, and employees, the BYOD phenomenon is gaining acceptance within healthcare settings. Providers of care, who traditionally have been slow to respond to technology innovation, are now taking steps to transform how they deliver health care through the use of mobile computing.

To ensure that mobile computing is successfully deployed in an HIS environment, it is vital that healthcare managers understand how an effective mobile computing strategy can be developed. The steps should be considered when developing a mobile computing strategy.14

1. Identify the Key Stakeholders Four key groups of stakeholders who have unique mobile computing requirements are end users, clinicians, management, and IT staff. To appropriately determine each of these stakeholders’ requirements, their input is needed prior to selecting and deploying the mobile solution. End-user concerns typically center on if and how they can use their device, how to obtain assistance or training, what their password requirements will be, what they should do if they lose their device, what the rules are for personal versus company data on the device, and what, if any, reimbursement policy exists.

Physicians and nurses need secure point-of-care mobile technology that will allow them to communicate with each other rapidly and in real time to efficiently do their jobs. Secure text messaging functionality and the ability to integrate with Wi-Fi to provide coverage in areas where cellular signals are weak are two critical areas gaining traction in healthcare settings. Recent research indicates that clinician involvement in technology decision making and use of a single mobile device (instead of multiple mobile devices) improve the quality of care they can provide and increase physician and nurse efficiency.

Management will be concerned about the liabilities, costs, insurance, and changing legal and vendor landscape that are associated with mobile computing. In addition, the ownership and protection of corporate data and assets, along with the ability to measure user patterns, will be an area of management interest. Finally, the focus of the IT staff will be on mobile computing device and application deployment, support, and management; application and data configuration and standardization; and ways to address mobile computing incidents and lost/stolen device issues.

2. Create Policies, Procedures, and an End-User Acceptance Agreement It is vital that healthcare organizations develop a comprehensive mobile computing policy, including language clearly defining their BYOD strategy. An acceptable use agreement detailing the terms and conditions of mobile computing expectations for end users should be developed by the healthcare organization and signed by each end user prior to that person being given access to organizational resources via his or her mobile device. Typically, this can be implemented by including the user acceptance agreement when deploying the mobile computing software to the end-user mobile devices.

1114237 - Jones & Bartlett Learning ©

Incorporating mobile computing into security awareness training is also an important step toward ensuring ongoing compliance.

3. Understand Regulatory, Legal, and Compliance Requirements A successful healthcare mobile computing strategy must include all pertinent local, state, and federal regulatory, privacy and security, legal, and compliance requirements. Important legislation such as HIPAA and the HITECH Act at the national level, as well as state-level regulations, such as California Senate Bill (SB) 13863, which includes notification rules that outline requirements for disclosure of breaches, are important regulations that need to be considered before and monitored after implementing mobile computing in HIS environments.

4. Develop Mobile Management Strategies A number of mobile management strategies have emerged, with mobile device management (MDM) being the most mature in its development. MDM encompasses managing mobility at the mobile device level, with secure email, calendaring, contacts, web browsing, and application store management being standard areas that are typically covered. Enrollment and automatic profile/application capabilities; remote administration; screen passcode settings, remote wipe for lost or stolen devices, and encryption at rest and in transit; secure web browser capability; persistent push email delivery; and compliance/auditing, asset, device, location, and network tracking are additional features that are found in MDM products.

Another mobile computing area that is critical in healthcare environments is mobile content management (MCM), which provides encryption for files and attachments, content expiration, screen capture controls, and online/offline access to secure content. Some MCM products have advanced functionality that restricts data from being physically stored on a mobile device, yet provides full access and functionality to the content. Mobile application management (MAM) gives organizations control over mobile application delivery and app store management, blacklist/whitelist functionality, application tracking, and application security. In addition, it provides a framework for managing a healthcare organization’s internal customized mobile applications.

5. Define the Technical Architecture Four important technical areas must be considered as part of the mobile computing strategy: (1) what the mobile platform will be; (2) whether enterprise directory integration will be needed; (3) which devices and native applications will be supported; and (4) which telecommunications management capabilities and restrictions will be applied. The benefits of cloud computing, including more robust security and reduced costs, have made hosted or SaaS solutions attractive alternatives to on-premises virtual or appliance mobile computing solutions. Other areas to review are perpetual versus monthly licensing, single- versus multitenancy architecture, role-based access control (RBAC) support, web-based administrative features, and self-service capabilities.

Medium to large healthcare providers typically require AD, Certificate Authority (CA), and Secure Socket Layer (SSL) virtual private network (VPN) and WLAN integration. The ability to support a wide range of mobile devices using their native applications, particularly for email, calendaring, and contact management, is a necessity, especially for users participating in a BYOD program. It is not uncommon for employers to limit company-issued mobile devices to one or two vendor device lines, with the Apple IOS iPad and iPhone tablets and smart phones having a notably large market share among physicians.

As BYOD gains in popularity, telecommunications management functionality is becoming of increasing importance. This includes controlling and tracking voice and data roaming, cellular and Wi-Fi network data usage and signal strength, and phone call history. Finally, it is important to ensure an optimal and successful end-user experience, avoiding scenarios such as requiring an end user to change his or her existing carrier data plan to a more costly plan to participate in a BYOD program.

Information Security Ensuring and maintaining the security of HIS data, applications, and supporting technical infrastructure is vital to the long-term viability of healthcare organizations. Without appropriate security program, policies, and corresponding controls in place to (1) define how users and computer systems should behave and (2) protect valuable assets such as computers, applications, databases,

1114237 - Jones & Bartlett Learning ©

networks, and data centers, organizations will be vulnerable to data, financial, and reputational loss. Such losses can be the result of unintentional occurrences, such as unplanned system outages due to poor configuration or a lack of change management. They can also result from intentional acts, such as cybercrime, computer hacking, or malware, which target systems that are not updated or lack appropriate security controls. When designing or implementing HIS, security should be considered at the outset—not just after the systems have been developed and deployed in a production environment. Of course, security controls need to be incorporated in all aspects of technology, including mobile devices, client computers, servers and applications, network devices, and data center infrastructure. In addition to taking security considerations into account in the system planning stages, security needs to be reviewed and adjusted on an ongoing basis to properly protect the ever-evolving technology environment.

Many information security-related systems and technologies can be deployed to protect modern healthcare environments. Firewalls are network devices that limit access and protect an organization’s internal network from unauthorized users and external systems. Traditional firewalls use “stateful” network packet inspection to determine whether a network packet should be allowed through the firewall. A network packet’s “state” is related to its source and destination address, but does not indicate whether the data inside the network packet are good or bad. Stateful firewalls are becoming obsolete for this reason, as they are unable to determine the kind of traffic or the data inside the network packet. Next-generation (NG) firewalls address the traffic inspection and application awareness drawbacks of stateful inspection firewalls and are now replacing those traditional firewalls. Two of the most important features of NG firewalls are deep network packet inspection and application awareness. Deep packet inspection examines the network packet payload for anomalies and known malware, while application awareness is a feature that enables NG firewalls to better identify and manage web application traffic. Enterprise class firewalls include other advanced network security features.

VPNs allow remote users to connect to applications or services that are accessible only from computers on the internal or corporate network. VPN connections are secure, encrypted remote-access sessions that use either the Internet Protocol Security (IPSEC) or SSL VPN tunnels to encrypt all data traffic that travels between the remote computer and the internal network. Intrusion detection systems (IDSs) and intrusion prevention systems (IPSs) are intelligent monitoring and analysis systems that detect irregular or inappropriate data traffic occurring on the corporate network; they generate alerts to network and system administrators describing the offending system or device.

Despite the many benefits provided by network firewalls, additional security technologies are needed to thoroughly protect healthcare organization networks, servers, applications, databases, desktops, and other devices. Web security systems are designed to monitor end-user Internet activity; they block or greatly reduce users’ ability to access inappropriate and malicious websites, and restrict usage of unauthorized web services, such as unsecured document/file sharing and music/video streaming services. Web security systems can use the Web Cache Communication Protocol to ensure that no end users can bypass the web security system. In addition, most web security systems have data loss prevention (DLP) capability, which is designed to restrict confidential or unauthorized data from leaving the internal network. A current limitation with DLP technology is that it is unable to inspect encrypted traffic traveling about the Internet.

Encryption-in-transit is an important control that ensures the security of all data traffic containing confidential or ePHI information, such as network traffic, web activity, email messaging, file transfers, text messaging, and instant messaging. Encryption-at-rest is a similar security control that protects data stored in databases, applications, storage and backup systems, and laptops and mobile devices. One of the most often cited reasons that healthcare organizations receive fines for HIPAA violations is lost or stolen laptops containing ePHI that was not encrypted. As such, healthcare organizations need to give attention to encrypting all of their laptops.

Two-factor authentication is an easy-to-deploy technology that can be used to provide secure access to remote systems as well as to critical servers or network devices. It works by requiring two forms of identification. The most common form of single-factor authentication in use today is a username and password; this falls under the category of something a user knows. Two-factor authentication commonly includes a username and password, plus something a user has in his or her possession, such as a smart card or a randomly generated personal identification number (PIN) that is

1114237 - Jones & Bartlett Learning ©

sent to a small device or mobile phone. Two-factor authentication can also include something a user is. Although not widespread in healthcare organizations, this technology is found in biometric devices, such retinal or fingerprint readers.

Security information event management (SIEM) is a critical technology that is designed to automate and intelligently analyze system logs for anomalies and inappropriate activity. With increasing reliance on EHRs and other HIS applications, and hundreds of thousands of system log entries to review for inappropriate user activity, thereby ensuring that access to confidential or sensitive data is restricted to only those who have a need to know, SIEM technology is often the only practical method by which a healthcare organization can detect these types of violations.

System hardening, vulnerability assessments, and penetration testing are three ongoing security activities that are designed to ensure that network, server, application, and database systems are configured in a highly secure manner, fully up-to-date with security patches, and free from vulnerabilities that can exploited to negatively impact the confidentiality, integrity, and availability of production systems.

As seen in Figure 4.9, managed security services are costeffective information security services provided to healthcare organizations by consulting or vendor companies. These services typically manage many of the healthcare organization’s information security technologies, such as IDS/IPS, SIEM, vulnerability assessments, and security incident response. Such services provide value by reducing the number of information security personnel needed by the healthcare organization, thereby allowing the organization to spend more time and resources concentrating on its core mission of delivering quality health care.

FIGURE 4.9 Managed Security Services

1114237 - Jones & Bartlett Learning ©

SUMMARY HIS applications and their supporting underlying technology infrastructure are complex, yet easily understood when examined through the lens of their smaller, core components (or building blocks). HIS applications are developed using programming languages to define how data will be processed. HIS data are stored in databases that provide advanced processing and reporting functionality. Application integration has been found to be a more superior process for connecting HIS applications than developing and maintaining application interfaces. To develop such applications, the software development life cycle (SDLC) methodology is typically used as the programming development framework. Healthcare organizations are relying increasingly on vendors to develop HIS applications, thereby allowing them to focus on their core competency—that of delivering quality patient care.

HIS applications are categorized as delivering clinical care (e.g., EHRs), clinical support processes (e.g., lab testing, pharmacy, radiology), clinicians (e.g., computerized physician order entry, clinical decision support), and patient flow (e.g., registration, scheduling). Clinical information system (CIS) applications can be either inpatient or outpatient systems. Examples of outpatient CIS applications include ambulatory care systems, personal health records, long-term care systems, and CPOE systems. HIS applications also encompass administrative applications, such as enterprise resources planning, customer relationship management, supply chain management, and home health care. Critical to the success of HIS applications is a smoothly running, properly configured underlying technical infrastructure. This includes technologies such as networks, data centers, server/client computers, and other devices.

Understanding how computer networks operate is essential to ensuring a high level of performance and efficiency for HIS environments. The most important types of computer networks are local area networks (LANs), wireless LANs (WLANs), wide area networks (WANs), wireless WANs (WWANs), and storage area networks (SANs). The Internet is a well-known WAN that is being increasing leveraged by HIS applications due to its robust, highly available platform and pervasiveness. For example, many healthcare organizations are now leveraging the Internet as they strive to improve their communication with patients, develop new marketing strategies, and educate their health plan members. Emerging technologies, such as Voice over Internet Protocol, unified communications, video/web conferencing, and mobile computing are providing new ways for clinicians to collaborate with each other and patients.

The sizes of healthcare data centers are decreasing due to advances in server and storage consolidation, virtualization, and cloud computing. Remote-hosting EHR applications are now more commonplace, with many healthcare organizations becoming increasingly reliant on co-location or vendor-supported data centers to host their HIS infrastructure. As organizations struggle to develop acceptable business continuity and disaster recovery plans, they are discovering that remote-hosted data centers and cloud computing boast high service level agreements and lower costs. But no matter where the systems are housed, they must be protected by viable business continuity and disaster recovery plans. Virtualization and single sign-on advances in client computing have benefited HIS application usability, greatly increasing end-user satisfaction. Wireless workstations on wheels and other peripheral devices are continuing to expand their footprints in hospitals as demands for mobility by clinicians increase. The consumerization of IT and bring-your-owndevice models are steadily gaining acceptance in healthcare environments. Finally, challenges with privacy and security remain, but advances in technology are positioning healthcare organizations to mitigate many of these vulnerabilities, with the promise of successfully delivering and maintaining efficient, secure, and high- performing HIS applications.

KEY TERMS Circuit Client Clinical information system (CIS) Commercial off-the-shelf (COTS) Continuous power source (CPS) Customer resource management (CRM) system Data centers

1114237 - Jones & Bartlett Learning ©

Distributed antennae system (DAS) Electronic data interchange (EDI) Electronic document management (EDM) Extranet Health information management (HIM) Infrastructure-as-a-service (IaaS) Integration Interface Intranet Local area network (LAN) Medical administration record (MAR) Open Systems Interconnection model (OSI) Personal health record (PHR) Picture archiving and communication system (PACS) Platform-as-a-service (PaaS) Remote hosting Security information event management (SIEM) Server Single sign-on (SSO) Software-as-a-service (SaaS) Software development life cycle (SDLC) Storage area network (SAN) Supply chain management (SCM) Transmission Control Protocol/Internet Protocol model (TCP/IP) Unified communications (UC) Uninterruptable power supply (UPS) Virtual desktop infrastructure (VDI) Voice over Internet Protocol (VoIP) Voice over wireless local area network (VoWLAN) Wide area network (WAN) Wireless local area network (WLAN) Wireless wide area network (WWAN)

Discussion Questions

1. Describe the seven stages of the software development life cycle (SDLC) methodology and explain which functions are performed in each phase.

2. Discuss the pros and cons of using application integration versus application interfaces. 3. Identify the various clinical applications (Quadrant I) that support clinical care, clinical support processes,

clinicians, and patient flow, and describe how they differ from one another. 4. List three major inpatient clinical information systems and explain how technology enables these systems

to deliver improved care. 5. Identify two outpatient clinical information systems, and explain how these systems differ from inpatient

clinical information systems. 6. What are the benefits of a computerized physician/provider order entry (CPOE) system? 7. Explain the differences between the various computer networks supporting HIS applications today (e.g.,

LANs, WLANs, WANs, WWANs, and SANs). 8. Identify some of the emerging technologies being used to support HIS, and describe how they are benefiting

the delivery of care. 9. Which technologies are being utilized today in computer networks, data centers, servers, and applications to

provide increased availability and allow HIS to remain accessible, even in the event of a hardware or component failure?

1114237 - Jones & Bartlett Learning ©

10. Discuss the benefits of server virtualization, and describe how it is affecting HIS applications. 11. Identify the various types of client computing devices that are being deployed in hospitals today, and explain

which types of advantages they bring. 12. How can ID badge and virtual desktop infrastructure technology improve the delivery of care? 13. What are the important steps a healthcare organization should consider before implementing a mobile

computing strategy such as bring-your-own-device technology? 14. Why is security information event management an important technology for managing the security of EHRs

and other HIS applications?

REFERENCES 1. StudyMode.com. (2008–2009). The seven phases of the systems development life cycle.

http://www.studymode.com/essays/Seven-Phases-Systems-Development-Life-Cycle-163461.html 2. Institute of Medicine. (1991). The computer-based patient record: An essential technology for health care.

Edited by R. S. Dick & E. B. Steen. Washington, DC: National Academies Press. 3. Institute of Medicine. (1997). The computer-based patient record: An essential technology for health care.

Edited by R. S. Dick, E. B. Steen, & D. E. Detmer. Washington, DC: National Academies Press. 4. Hanover, J. (2010). Building the right foundation for long term meaningful use. IDC Health Insights, p. 21.

http://download.microsoft.com/download/D/5/A/D5A9EBCA-3856-4386-B79D- EA497964B9D2/BuildingTheRightFoundationforLongTermMeaningfulUse.pdf

5. Stalley, S., & DesRoches, C. M. (2013). Progress on adoption of electronic health records. In Robert Wood Johnson Foundation, Health information technology in the United States: Better information systems for better care. Princeton NJ: Author.

6. Information processing systems—Open Systems Interconnection—Basic Reference Model, Addendum 1: Connectionless-mode transmission, Ref. No. ISO 7498: Add.1: 1987(E). (1984).

7. Outcome 1: IP addressing. The TCP/IP Protocol Suite. HN Computing http://www.sqa.org.uk/e- learning/NetInf101CD/page_15.htm

8. Internet Engineering Task Force. (n.d.). Multiprotocol label switching. Charter for working group. http://datatracker.ietf.org/wg/mpls/charter/

9. Bent, K. (2012, October 19). How the BYOD phenomenon is shaping the next era in managed print services. CRN. http://www.mpsconnect.com/articles/437690/how-the-byod-phenomenon-is-shaping-the-next-era-in/

10. Dern, D. P. (2013, December 9). The benefits of integrating wayfinding with digital signage and who’s using it now. Campus Safety Magazine. http://www.campussafetymagazine.com/article/The-Benefits-of-Integrating- Wayfinding-with-Digital-Signage-and-Who-s-Using

11. Ontario MD, Inc. (2013). EMR as a service. https://www.ontariomd.ca/idc/groups/public/documents/omd_file_content_item/omd012523.pdf

12. Barnes, J. C. (2004). Business continuity planning and HIPAA: Business continuity management in the health care environment. Brookfield, CT: Rothstein Associates, pp. 13–24.

13. Kleyman, B. (2013, October 11). The zero-client: The next-generation in client computing. Data Center Knowledge. http://www.datacenterknowledge.com/archives/2013/10/11/the-zero-client-the-next-generation-in- client-computing/

14. Mobile Security Work Group. (2013). 20 questions to ask about bring your own device (BYOD). HIMSS. http://www.himss.org/ResourceLibrary/ContentTabsDetail.aspx?ItemNumber=21437