Please wait while the page is being loaded Skip this advertisement >
Saturday | 22 November, 2008
CIO
Avoid Pitfalls of Health-care Wi-Fi Networks
With the security and privacy requirements of the US federal Health Insurance Portability and Accountability Act being a constant concern, Herrin was all too aware of the potential problems
Bert Latamore (Computerworld (US)) 04 June, 2007 11:50:41

In health-care, network dependability can literally be a matter of life and death, and US federal law mandates security and privacy levels beyond those needed in any other vertical industry outside finance and national security. And many health-care providers operate on shoestring budgets, in part because of the large population of uninsured individuals.

So when US-based Tuality Healthcare, a 90-year-old not-for-profit integrated health-care provider serving the western suburbs of Portland, designed its Wi-Fi network it moved carefully. "We, as an industry, are not early adapters of unstable technology," says Chris Herrin, Tuality's network services manager. For instance, the provider is only now upgrading from its Cerner Classic Clinical Information System, a dumb-terminal architecture, to the Cerner Millennium client/server architecture.

The health-care provider operates Tuality Community Hospital, a 167-bed facility, as well as a 48-bed satellite hospital nearby and clinics throughout the area.

We still have some doctors resisting computers, but the mainstream is well versed and is encouraging and, in some cases, pushing us to use the latest and greatest
Chirs Herrin — Tuality network services manager

Tuality, however, is heavily networked on the wired side. "We are a Cisco shop with a multi-gigabyte backplane built on six Model 6500 routers that can take transmission speeds to tens of gigs," Herrin says. "Right now, we are running at 6 to 8 gigs, and throughput is fabulous."

Tuality needs that speed to support its networked Picture Archival Computing System (PACS), which has become its lead application. With it the provider is replacing some of its traditional film images throughout its facilities, including operating theatres. It delivers images directly to doctors' offices, which, Herrin says, the doctors love and which has helped change the minds of some physicians about using computers.

It allows radiologists to read images at home, providing coverage for the emergency room evenings until 9pm, after which an outsourcer, Virtual Radiological Consultants, takes over for overnight emergencies. The radiologists access the images transmitted to them directly from the modality - X-ray, CAT or MRI - and either call or fax their reads to the emergency room.

Cutting costs

PACS saves Tuality money by eliminating film and developing costs and cutting second-and third-shift personnel costs, and it has improved morale among the radiologists. But medical images are big and put heavy demands on the network. "We ran T1s to the radiologists' homes because the service agreement with our Internet provider was not sufficient to handle the uptime," Herrin says. That's why a 1200-member organization has such a heavy-duty network infrastructure.

"The PACS application broke through the barrier of computer resistance to the extent that our neurosurgeons and orthopedic surgeons wanted it in the ORs in place of film," Herrin says. "We still have some doctors resisting computers, but the mainstream is well versed and is encouraging and, in some cases, pushing us to use the latest and greatest."

This has paved the way for the next step, layering an Aruba Networks wireless edge network onto the environment to serve Tuality's Hillsboro main campus. While this will allow the provider to support mobile computing for its staff - most of whom spend the majority of their day away from desks and nurses' stations - and potentially may allow it to provide pass-through Internet service to patients and visitors, it also introduces a new security exposure. With the security and privacy requirements of the US federal Health Insurance Portability and Accountability Act being a constant concern, Herrin was all too aware of the potential problems.

Avoiding a nightmare

"We looked at all the news stories about the guys who lost laptops full of people's personal information," he says. "That turns into a nightmare for a staff, so we want to come out of the gate strong with our initial wireless implementation."

He decided to implement the Aruba firewall but was not satisfied with Aruba's access control. Instead, he chose Network Chemistry's RFprotect, including:

  • RFprotect Scanner, a network-based vulnerability management solution for rogue wireless AP detection and remediation.

  • RFprotect Mobile, a portable, laptop-based analyzer for automating site surveys, security assessments and incident response.

  • RFprotect Distributed, a 24/7 wireless monitoring and intrusion-prevention system.

Tuality first looked at Network Chemistry because Gartner gives it a high rating, Herrin says. Then "users I talked to were unanimously enthusiastic about the products and the vendor's responsiveness," he adds.

"So we are working directly with Network Chemistry now, and so far it is going very well," he says. "With the strength of Network Chemistry's products and their ability to integrate, there is just no question that we will be ready to protect our assets and sensitive patient information when we go live."

Bert Latamore is a journalist with 10 years' experience in daily newspapers and 25 in the computer industry. He has written for several computer industry and consumer publications.

Featured Whitepaper Sponsors
Market Place
 
Featured Whitepapers

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    Chris Hoff on Virtualization and Cloud Computing 20 November, 2008 10:55:00

    Chris Hoff, chief security architect for the systems and technology division at Unisys and an advisor on the Skybox Security customer advisory board, is one of the biggest critics of virtualization security out there. Not because it isn't important - but rather because it is vital and needs to mature rapidly.
  • +

    Cybersecurity is focus of new start-up incubator 20 November, 2008 07:19:00

    Texas uni announces the Institute for Cyber Security.
    The University of Texas at San Antonio Tuesday announced a technology incubator aimed at fostering IT security-based start-ups within the state.
  • +

    Dilip Sarangan on Physical Security M&A 20 November, 2008 11:18:00

    Dilip Sarangan tracks physical security companies for Frost & Sullivan. He expects the industry's "need to have" products to weather the economic storm well, with the big players (now including IBM and Cisco) looking for value-priced acquisitions.
  • +

    International Challenges in PCI Security 20 November, 2008 09:15:00

    In a country that's seen many regulatory compliance challenges this decade, the headaches of PCI security tend to be analyzed from a largely American perspective.
  • +

    PCI council sharpens oversight of security auditors 19 November, 2008 10:53:00

    Quality assurance plan targets security assessors and scanning vendors
    The PCI Security Standards Council Monday unveiled a plan to sharpen oversight of the hundreds of security-service providers now authorized to evaluate merchant networks under the organization's Payment Card Industry data standards.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

Enterprise Wireless WLAN Security

Learn more about the security challenges to be faced when defining and implementing security mechanisms within diverse wired and wireless network environments. Download this must-read guide to plan your wireless data protection strategy now.