Risks of Hosting Practice Data on the Cloud Vs. Locally

Similar documents
Information Security: Cloud Computing

Your complete guide to Cloud Computing

Making the leap to the cloud: IS my data private and secure?

Client Security Risk Assessment Questionnaire

Cloud Computing Overview & Security Issues

A 123Together.com White Paper. Microsoft Exchange Server: To Outsource Or Not To Outsource The affordable way to bring Exchange to your company.

Electronic Records Storage Options and Overview

Take Your Vision to the Cloud

Bringing the Cloud into Focus. A Whitepaper by CMIT Solutions and Cadence Management Advisors

Software as a Service (SaaS)

Three Things to Consider Before Implementing Cloud Protection

White Paper: Introduction to Cloud Computing

AVAILABILITY SERVICES CLouD SECuRITY

Software as a Service (SaaS)

HOW TO CHOOSE A FUNDRAISING DATABASE

Cloud Computing; is it right for my business?

IT Best Practices Audit TCS offers a wide range of IT Best Practices Audit content covering 15 subjects and over 2200 topics, including:

Protecting Your Data On The Network, Cloud And Virtual Servers

Understanding Financial Cloud Services

Deltek First - The Business Case

How to Practice Safely in an era of Cybercrime and Privacy Fears

Credit Unions and The Cloud. By: Chris Sachse

Virginia Government Finance Officers Association Spring Conference May 28, Cloud Security 101

HARNESSING THE POWER OF THE CLOUD

Quick guide: Using the Cloud to support your business

Future- Building a. Business: The Ultimate Guide. Business to

Nine Steps to Smart Security for Small Businesses

On-boarding the Cloud in Your Workforce

Internet Security Protecting Your Business. Hayden Johnston & Rik Perry WYSCOM

TENDER NOTICE No. UGVCL/SP/III/608/GPRS Modem Page 1 of 6. TECHNICAL SPECIFICATION OF GPRS based MODEM PART 4

Cloud Computing; What is it, How long has it been here, and Where is it going?

nwstor Storage Security Solution 1. Executive Summary 2. Need for Data Security 3. Solution: nwstor isav Storage Security Appliances 4.

Looking for the right technology partner for your business?

Office Technologies Managed Services Professional Services. SERVING OVER 18,000 CUSTOMERS IN THE NYC & TRI-STATE AREA tomorrowsoffice.

Cloud Computing Secured. Thomas Mitchell CISSP. A Technical Communication

The Specialized Cloud for Accounting Professionals

DATABASE SECURITY, INTEGRITY AND RECOVERY

Cbeyond Cloud Server Packages

MAXIMUM DATA SECURITY with ideals TM Virtual Data Room

Remote Services. Managing Open Systems with Remote Services

Why Managed Hosted Hosted Solutions in the Cloud Are Critical to Their Survival

What Dropbox Can t Do For Your Business

Hosted Desktop for Business

Security Threat Risk Assessment: the final key piece of the PIA puzzle

Everything You Need to Know About Effective Mobile Device Management. mastering the mobile workplace

Is your business still wasting time and money on PCs and Servers?

Protecting Official Records as Evidence in the Cloud Environment. Anne Thurston

Ensuring security the last barrier to Cloud adoption

4 Critical Risks Facing Microsoft Office 365 Implementation

Private vs. Public Cloud Solutions

State IT Management Initiative - Standardization and Centralization

The Cloud. IIA Seminar, York April 30 th


Choosing the Right Cloud Service Provider. A guide to asking the right questions

Kaseya IT Automation Framework

Enabling Business Beyond the Corporate Network. Secure solutions for mobility, cloud and social media

Tier3 Remote Monitoring System. Peace of Mind for Less Than a Cup of Coffee a Day

Healthcare IT Compliance Service. Services > Overview MaaS360 Healthcare IT Compliance Service

Move your business into the Cloud with one single, easy step.

Your business in the 21 st Century. Understanding Cloud

How To Protect Your Data From Being Hacked

Real Time Monitoring: Features, Functions & Benefits. Technology for the way you do Business!

Are You in Control? MaaS360 Control Service. Services > Overview MaaS360 Control Overview

How cloud computing can transform your business landscape

Asigra Cloud Backup V13 Delivers Enhanced Protection for Your Critical Enterprise Data


8 BEST PRACTICES FOR MAKING YOUR PROJECT COSTING EASY 1. 8 Best Practices for Making Your Project Costing Easy

Migrate, Manage, Monitor SQL Server 2005: How Idera s Tools for SQL Server Can Help

Cloud Computing: Security Risks and Compliance Implications

IT Support Day FREE Trial. Free Site Survey & Network Health Report

Comprehensive Agentless Cloud Backup and Recovery Software for the Enterprise

USER-MANAGED FILE SERVER BACKUP:

F G F O A A N N U A L C O N F E R E N C E

Cloud Computing Security Issues and Controls

Central Agency for Information Technology

What Every User Needs To Know Before Moving To The Cloud. LawyerDoneDeal Corp.

NAREIM Session: Dangers and challenges of The Cloud. President, NiceNets Consulting, LLC

Mapping Your Path to the Cloud. A Guide to Getting your Dental Practice Set to Transition to Cloud-Based Practice Management Software.

GETTING THE MOST FROM THE CLOUD. A White Paper presented by

Cloud computing. Advantages and disadvantages

All can damage or destroy your company s computers along with the data and applications you rely on to run your business.

Cloud Computing Thunder and Lightning on Your Horizon?

LAWYERING IN THE CLOUD CRIB NOTES 2012 Charles F. Luce, Jr. coloradolegalethics.com/ (alpha release)

INFOSTOR. Cloud Poised to Be Most Popular Backup Medium. Executive Brief. In This Paper

Managed IT Secure Infrastructure Flexible Offerings Peace of Mind

Rajan R. Pant Controller Office of Controller of Certification Ministry of Science & Technology rajan@cca.gov.np

Why Consider Cloud-Based Applications?

Reach for the sky NEW SMAR T RELIABLEFAST RELIABLESHARE SOLUTION ACCESS CONNECT TEAMCONNECT SURF

Cloud Computing and Records Management

Negotiating Contracts That Will Keep our Clouds Afloat: You re going to put THAT in a cloud? Meteorologist: Daniel T. Graham

Assessing the Security Risks of Cloud Computing

Disaster Recovery Strategies

Effective Storage Management for Cloud Computing

The Outsourced IT Hiring Guide

Top Cloud Solutions For SMBs

TITUS Data Security for Cloud Identify and Control Sensitive Data Sent to the Cloud

Storing and securing your data

( and how to fix them )

PART I: The Pros and Cons of Public Cloud Computing

What You Need to Know About Cloud Backup: Your Guide to Cost, Security, and Flexibility

Transcription:

Risks of Hosting Practice Data on the Cloud Vs. Locally Software involving the cloud is becoming ever more popular amongst health professions due to the myriad of benefits it delivers. This concept is not new, twenty years ago the internet was represented on flow charts as a cloud, primarily because its took information in and routed it somewhat invisibly to another destination. More recently this concept has become very specialized and now consumers can take advantage of cloud computing through hosted systems that store photographs, files (e.g. Google Docs), and even information via the web. Today, the 14th largest software company by market capitalization (Salesforce.com) operates almost entirely in the cloud and this sector is predicted to grow to over $200B (US) worldwide by the end of 2013 (Source: Merrill Lynch). Despite the growth and technical advancement in cloud computing many companies resist the temptation to join the cloud due the perceived risks, instead maintaining control locally. As we know, cloud based practice management providers offer many benefits, most notably the scalable and flexible access to computing resources anywhere at anytime (i.e. mobile). So with this increased amount of business data and computing power come increased security risks, requiring special considerations and attention. This article will outline some of the risks involved in hosting your data locally versus on the cloud, along with some helpful questions to consider prior to subscribing to a cloud based software provider. Risks and Responsibilities of Hosting Data Locally Commonly clinics in the past have installed a Windows or Microsoft software application locally on their computers/servers to retain client information. This could also refer to paper files in a filing cabinet (your server/database). So have you ever considered by doing this there are a number of responsibilities involved here if you continue to resist cloud software/practice management systems? Consider that your responsibilities when storing the information locally are

1. Anti-virus software a. Do you maintain the security of your servers/computer anti-virus system? b. Do you undertake virus scans on a regular basis? c. Is the virus software up to date? d. Is every computer in the network covered? e. Does it protect your email system? 2. Operating system a. Is the operating system you are currently using stable (e.g. windows, Lion/Mac osx etc)? Are your aware of its weaknesses? 3. Firewalls a. Is there a firewall for your server? 4. Back-up s a. Do you back-up the data on a regular basis? b. Are they stored off site? Is that site secure? c. Do you test the back-up is the information on them recoverable? 5. Remote access Do you access your clinic database remotely? a. Is the connection secure? b. Is it over a Virtual Private Network (VPN)? 6. Is your clinic secure? a. Do you have an alarm system? b. What steps have you put in place to prevent your computers from being stolen? If they are stolen would you be able to practice the next day? (With a cloud system you could purchase a new computer and plug into the internet and be up and running within minutes). 7. Is your Practice management software up to date? a. Have you installed the latest version of your practice management software with security features? b. Do you have to do this manually every time?

c. Do you have to pay for this upgrade? d. Is it a hassle to undertake does an IT expert have to login remotely and do this for you? So there are probably a few things going through your mind right now that you might not have considered? As we know a completely cloud based system takes care of many of the hassles for you to allow you to focus on managing your clients care. However by passing over this responsibility to a cloud-based provider there are a number of risks to consider. The Risk of hosting your practice data on the cloud So the question is: If I change to a cloud based system what are the possible risks and responsibilities of the cloud providers? These risks include - 1. Security, Privacy and Confidentiality While cloud technically offers a higher level of security than local servers (due to IT expects managing these environments), as they become more popular they also become a more attractive target for hackers. The probability of an attack is relatively low, but even if only one is successful, the impact could be significant. 2. Loss of Data By transferring your sensitive practice data over to a third party provider you risk the possibility of them going out of business, mismanaging your data or even their cloud environment crashing all resulting in loss of your practice data. 3. Compliance Issues A host of IT compliance issues arise when a company decides to migrate to the cloud. These are often industry-specific regulatory issues, such as Medicare Integration, Health Funds Compliance or even Government regulations (e.g. DVA online claiming).

4. Hidden Costs Ensure that you have all costs quoted up front to avoid potential financial damage to your company resulting from a reduction in productivity. Despite these risks there can be significant cost savings that can be realized via the cloud. Questions to ask your potential provider In order to mitigate the risk it s important to ask your potential vender the following questions 1. Demand transparency and avoid vendors that refuse to provide detailed information on security programs. Ask questions related to the staff, risk-control processes and technical mechanisms that identify unanticipated problems. 2. Ensure that there is privileged user access. Ask providers who has access and control over the data. Who in the organization can access it? 3. Regulatory compliance. Customers are ultimately responsible for the security and integrity of their own data, even when a cloud service provider holds it, however ensure that your provider complies with security certifications and audits as required. 4. Data location. When you use the cloud, you probably won't know exactly where your data is hosted. In fact, you might not even know what country it will be stored in. Ask providers if they will commit to storing and processing data in specific jurisdictions. 5. Data segregation and encryption. Ensure your data is encrypted and separated from the rest of files in the data center. 6. Recovery. Even if you don't know where your data is, a cloud provider should tell you what would happen to your data and service in case of a disaster. Ask if the provider has the ability to do a complete restoration, and how long it will take?

7. Long-term viability. Ideally, your cloud computing provider will never go broke or get acquired and swallowed up by a larger company. But you must be sure your data will remain available even after such an event. "Ask potential providers how you would get your data back and if it would be in a format that you could import into a replacement application. In Conclusion ask yourself are you doing everything possible to secure your data (either locally or via the cloud) containing sensitive client information. As outlined above your cloud provider has a lot of responsibility and if they are doing their job well then a secure cloud based practice management system is, in many facets, more secure and offers more flexibility to manage your business than a locally based system. Ensure that you do your due diligence and ask the appropriate questions of your software provider before taking the plunge into the cloud. By Darren Rieck Darren Rieck is a physiotherapist and founder of Nookal. Nookal is a provider of practice management software for the allied health industry. They offer practice management solutions to help health clinics streamline their administration systems, effectively manage their business and improve efficiency and productivity. To learn more, visit www.nookal.com or call 1300 NOOKAL.