Marc Desgrousilliers CTO at Clinovo Clinical Trials in the Cloud: A New Paradigm? Marc Desgrousilliers CTO at Clinovo
What is a Cloud? (1 of 3) "Cloud computing is a model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. Source: http://www.nist.gov/itl/cloud/
What is a Cloud? (2 of 3) Mandated by the US Government under the Federal Cloud Computing Strategy in Feb-2011 Defined by the NIST A Cloud must exhibit 5 characteristics: On-demand self service Ubiquitous network access Resource pooling Elasticity Measured services (SLA)
What is a Cloud? (3 of 3)
Example of Clouds Around Us Consumer Enterprise
Types of Clouds (1 of 2) Public Private Hybrid Community Private/Community Clouds Public Clouds
Types of Clouds (2 of 2) Public Private Community Hosted by Service Provider Sponsor/CRO -or- Service Provider Tenancy Multi-tenancy Available to the public Sponsor/CRO -or- Service Provider Single tenancy Multi-tenancy Available to members of community Infrastructure Shared Dedicated to single tenant Network access Internet VPN -or- LAN Can store clinical data? L J Dedicated to community VPN J
Cloud Service Layers (1 of 2) Infrastructure-as-a-Service Fully outsourced hardware infrastructure Rent a server billed per hour or minute Give your full control for changes, data protection, etc. Platform-as-a-Service Provides a platform to develop cloud-based applications Provider controls changes to the environment and data protection Not recommended for Clinical Trials Software-as-a-Service Provides a consumable application running in the cloud Software vendor must demonstrate adherence to 21 CFR Part II and evidence of validation
Cloud Services Layers (2 of 2) Infrastructure as a Service Platform as a Service Software as a Service Self Service OK OK OK Reduced Cost Ubiquitous Access Automated System On-demand Scalability Expensive for large deployment OK OK OK Caution with mobile platforms Caution with auto updates OK OK OK OK OK OK Can Store Clinical Data? K L J
Clearing up the Cloudiness Infrastructure-as-a-Service OK to use for clinical trial in both Private and Community Clouds. For large deployments, make sure to model cost vs. onsite Software-as-a-Service OK to use for Clinical Trials in both Private and Community Clouds. SaaS on Public Cloud is not recommended for Clinical Trials data, but if considered, in-depth vendor audit is required. Cost Infrastructure as a Service Private Cloud K Software as a Service J Community Cloud Infrastructure as a Service K Software as a Service J Can Store Clinical Data? J J J J
Regulatory Considerations All 21 CFR Part 11 rules apply regardless if system is cloud-based, hosted or on-site Data security & privacy Data protection Hosting facility controls Change management Validation Your organization (not the Service Provider) is ultimately responsible to ensure the GxP system is validated, compliant and performs as intended on the Cloud.
Regulatory Recommendations (1 of 3) Step 1: Evaluate vendor capabilities Does vendor have existing customers running GxP applications? Does vendor s staff have all necessary qualification and training? Does vendor have a validated instance/template for their hosted application? Can the vendor show proof of validation documentation? Does the vendor provide 24x7 application support?
Regulatory Recommendations (2 of 3) Step 2: Evaluate data security Where exactly will the data be stored and processed? Does vendor have sufficient physical and electronic security? Is the data communication encrypted over the network? Are passwords encrypted when stored? Does vendor use a 3 rd party data center? If so, can they also be audited? Does data center have recent SSAE 16 or SAS-70 audit reports? Does vendor have a data backup procedure and a credible disaster recovery plan in place? In case of breach of contract, will the data still be available? How are other tenants and applications isolated from each other? Who owns and has access to your data?
Regulatory Recommendations (3 of 3) Step 3: Conduct an onsite audit to verify the answers you received from the pre-qualified vendor Any Service Provider who refuses to be audited or can t properly answer these questions should be disqualified
Examples of Clouds for Clinical Trials
eclinical Forecast for the Next Few Years Definitely cloudy with chances of changing winds! J
Questions? Thank You! Marc Desgrousilliers CTO Clinovo marc.desgrousilliers@clinovo.com