Maj Todd Roman, SM Project Officer Mr. Andrew Jake Jacobs, Strategy Officer 2014 Defense Health Information Technology Symposium Cloud Computing in the Defense Health Agency 1
DHA Vision A joint, integrated, premier system of health, supporting those who serve in the defense of our country. 2
Learning Objectives Understand the Fundamental Benefits of Cloud Computing Realize Challenges for Cloud Adoption Identify Compliance with DoD Requirements for Entering the Cloud Recognize Contractual Concerns with DoD Cloud 3 3
Agenda Learning Objectives Benefits of Cloud Computing Exchanging Data with Partners Challenges of Cloud Computing within Healthcare DoD Cloud Computing Requirements Reaching the Cloud Med-COI FOC State Contractual Concerns with DoD Cloud 4 4
Benefits of Cloud Computing Cloud computing offers the government an opportunity to be more efficient, agile, and innovative through more effective use of IT investments. *Source: FY 2012 President's Budget position for DHP O&M Includes Normal Cost contributions to the Medicare Eligible Retiree Health Care Fund (MERHCF) The government can use cloud computing to rid itself of billions annually in duplicative IT spending. 5
Exchanging Data with Partners Department of Veteran Affairs (VA) Department of Health and Human Services (HHS) Centers for Medicare and Medicaid (CMS) Federal Drug Administration (FDA) HIE Health Information Exchanges (HIE) (created by ACA) -More than 100 across the country -No Industry Standard Interfaces Additional requirements to meet Office of National Coordinator (ONC) for Health Information 6
Challenges of Cloud Computing within Healthcare Federal Cloud Computing Strategy Security Controls Compliance Cloud Brokerage 7
DoD Cloud Computing Requirements DISA ECSB Security Model 1 U-Public NA-L-x 2 U-Limited Access 3 CUI L-M-x 4 CUI M-M-x 5 CUI H-H-x 6 Classified The DoD is currently operating between level 4 & 5 of the DISA ECSB Security model. 8
HITECH Act Health Information Technology for Economic and Clinical Health (HITECH) Data Ownership Office of the General Council (OGC) Privacy Office While increasing the use of electronic health records, securing patient health Information (PHI) remains a major component of the HITECH. 9
Reaching the Cloud Creating an enterprise-wide digital backbone Increase Speed, Mobility and Collaboration of Healthcare Encourage the healthcare industry to meet DoD specific security requirements Separate the Healthcare Network from the DoD Information Network (DoDIN) Establish the Medical Community of Interest (MEDCOI) Support the Joint Information Environment (JIE) 10
Cloud Adoption Catalyzing Cloud Adoption Leveraging cloud computing accelerators Ensuring a secure, trustworthy environment Streamlining procurement process Establishing cloud computing standards Recognizing the international dimensions of cloud computing Laying a solid governance foundation *Source: http://csrc.nist.gov/groups/sns/cloud-computing/, http://www.nist.gov/itl/cloud/index.cfm 11
Medical Community of Interest (Med-COI) FOC State OV-1 Medical Community of Interest Network (Med-COI) Final Operation Configuration (proposed) Legend: Connected Via MPGs Security/Access Gateways Med IPNs/SSPNs Med-COI Intranet/ Extranet Gateway VA-IdMS MVI DMDC PDR/DEERS VistA RDCs (1 of 8) DoD MTF (CONUS) MPLS-VPN over DISN** VAMCs (1 of 135) VA Austin Information Technology Center (AITC) Trusted EHR/CSPs OneVA WAN DoD MTF (CONUS) Notes: * Sharing Sites and extension to Sites in Joint Market Areas Post Phase 3 ** Confidentiality Service (IP-SEC) maintained for PHI/PII Data Types VAMC (DoD/VA Sharing Site)* FedRAMP Certified Provider VA Enterprise Gateway (TIC 2.0) (1 of 4) CONUS IdM & Federated Directory Service (mjad) Kaiser Quest Permanente Labs Nationwide Health Information Network (NwHIN) Core and Regional Data Centers (CONUS) N+1 Data Centers DHS/ DHMSM EHR Pacific (RPC) DoD DoD MTF MTF OCONUS OCONUS HIE Enabled Business Partner Extranets (BPEs) United Healthcare Virtual Connect over DISN-COI transport - MPGs to TIC/Fed G/Ws LabCorp (supports non-medical Mission Partner connections) DoD Service Enterprise Service Base/Post Services Base/Post Enclave (JIE) Enclave JIE (NIPRNet & Other DoD-COIs) Mission DoD-DMZ Partner IAP Gateway MHSi/Med-COI Enterprise (1 of 5) Gateways CONUS & (1 of 9) OCONUS Internet DoD MTF OCONUS EHR Europe (RPC) DoD MTF OCONUS EUCOM EHR Theater Site Med-COI Other DoD COIs SWA Regional and Intranets Gateways EHR (1 of 4) Theater OCONUS Site EHR Theater CENTCOM PACOM Site DoD / VA Data Interoperability Commercial Business Partners and Service Providers JIE Common / Core Services DoD Mission Partners
Contractual Concerns with DoD Cloud Business Associates Agreements (BAAs) - need to be evaluated down to the lowest subcontractor to support Privacy Impact Assessment (PIA) Service Level Agreement (SLAs) - need to be reviewed down to the lowest subcontractor level for PIA Federal Risk and Authorization Management Program (FedRAMP) - certifications need to be validated Ongoing Monitoring What will you do to ensure monitoring according to FedRAMP/DoD requirements? Private or Public Cloud considerations FedRAMP, NIST, and ECSB all require Private for PHI. Cloud is NOT outsourced IT full Infrastructure, Platform and Software Security compliance needs to be assessed Data Ownership Who owns the data within the system and what is it used for? What happens to the data when you terminate this contract? What happens if a subcontractor goes out of business? 13
Come see us if You re already operating in the cloud You plan to be in the cloud 14
Evaluations Please don't forget to submit your evaluations! 15
Speaker Info Andrew Jake Jacobs ITILv3, Net +, CHSP, CEP, VEP Acting Branch Chief, Strategy and Planning, Innovation and Advanced Technology Development (IATD) Division Andrew.Jacobs@dha.mil 703-681-6759 MAJ Todd Roman, USAF MSC, CAAMA Project Officer, Secure Messaging Defense Health Services Systems (DHSS) Todd.Roman@dha.mil 703-681-9634 16
QUESTIONS 17