Disaster Avoidance and Resilient IT for Business Continuity in Medical Practice : Proven strategies and procedures to assist with planning, implementation and testing of medical practice IT for business continuity MIROSLAV DONCEVIC MANAGING DIRECTOR DIGITAL MEDICAL SYSTEMS IGITAL MEDICAL SYSTEMS
IGITAL MEDICAL SYSTEMS The End Goal for Medical Practice IT is Business Continuity October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 3
IGITAL MEDICAL SYSTEMS How Business Continuity is attained: October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 4
Begin with the end in mind IGITAL MEDICAL SYSTEMS What is your business cost per hour if all IT and communication systems are unavailable? (What is your maximum IT pain threshold?) Base your target Recovery Time Objective on cost per hour October 2015 5 COPYRIGHT2015 IGITAL MEDICAL SYSTEMS CONFIDENTI.T. CALL1300 865 977
Begin with the end in mind IGITAL MEDICAL SYSTEMS Work out your dollar generation / pure income loss: Total billings per day / hours (Averaged over five days) You could also work out the hourly cost per doctor Example : (provided by Gary Smith at Tindale Family Practice in Penrith NSW) 10 consulting rooms: IT Downtime Cost = $2,800 per hour October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 6
Begin with the end in mind IGITAL MEDICAL SYSTEMS Also consider the inefficiencies of poor performing systems and the other risks: Medico-Legal Compliance Reputational damage - with patients with doctors October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS EASIER MEDICAL I.T. CALL 1300 865 977 7
Some Definitions IGITAL MEDICAL SYSTEMS No Single Point of Failure Redundancy High Availability Rapid Disaster Recovery Resilience Disaster Avoidance Business Continuity October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 8
IGITAL MEDICAL SYSTEMS Do you know your current systems specifications / configurations? Management guru Peter Drucker is often quoted as saying that "you can't manage what you can't measure. If you can't measure it, you can't improve it. Peter Drucker October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 9
Audit the current systems configuration IGITAL MEDICAL SYSTEMS Policy, Procedures and Systems Documentation: Is it accurate, comprehensive and compliant? Hardware systems: Network components Server systems Backup systems Communications components PCs, including all peripheral components Software systems: Network Operating System (ie Windows Server) Backup software & configuration Clinical & Practice Management software Critical utility software eg pathology download s/w, secure messaging PCs Operating Systems Security Peripheral components, ie printers Do your systems comply with standards and IT best practices? Do your systems have a Standard Operating Environment? October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 10
Software Redundancy & High Availability with Virtualization: IGITAL MEDICAL SYSTEMS No Virtualization: Single Operating System per physical machine Software and Hardware tightly coupled Running multiple applications on same machine often creates conflicts Underutilized resources (CPU cores, RAM etc.) Inflexible and costly infrastructure Disaster Recovery takes significant time No High Availability With Virtualization: Hardware independence of Operating System and physical machine and applications Virtual machines can be provisioned to any system Can manage OS and application as a single unit by encapsulating them into virtual machines Efficiently utilize all resources (CPU cores, RAM etc.) Sandbox application conflicts from each other High Availability - Rapid Disaster Recovery now possible within minutes October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 14
ICT Standards for GP Medical Clinics IGITAL MEDICAL SYSTEMS Are you compliant with the new RACGP CISS Second Edition standard? Is your clinic IT safe? What do the guidelines mean? http://www.racgp.org.au/your-practice/standards/computer-and-information-security-standards/ October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 15
RACGP CISS 2 ND Ed. for GP Medical Clinics The key points in plain English: IGITAL MEDICAL SYSTEMS 1. ICT Policy and Procedures Does your policy documentation stack up for accreditation and compliance? 2. Are your practice ICT systems and data secure? and available? Do you have high security access controls? Are they actively maintained and updated? Are the backups working? (Can you prove it? i.edo you test restore regularly?) How far back do you keep archives of critical data and system configurations? Can you really restore your systems when disaster strikes? Can you prove it? How long will it take to recover? Is Rapid Disaster Recovery possible? Do you have timely access to business & clinical information? UPS? High Availability? Is physical, hardware, software & OS up to date, managed & regularly maintained? Really? By whom? 3. Network, Internet, Web and Remote Access Security? Are you reallyprotected from external and internal threats? Are you protected from Mobile devices? Are your Mobile devices protected? 4. Is your sharing of confidential information secure? Is Secure Messaging correctly configured and tested? Are digital certificates managed? Is the practice website secure? October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 17
Backup, Disaster Recovery & Business Continuity: IGITAL MEDICAL SYSTEMS Backups are important only if you value the work that you do on your computer. If you use you computer as a paperweight, then you don t need to make backups Simson Garfinkel, Gene Spafford, Alan Schwartz Practical UNIX and Internet Security data backup or data recovery can mean the difference between a slight computer setback and living through your own electronic apocalypse... TopTenreviews.com in a study of companies that experienced a major data loss without having a solid Business Continuity/Disaster Recovery Plan in place, 43% never reopened, 51% closed within two years and only 6% survived long term Susan Snedaker Business Continuity and Disaster Recovery Planning for IT Professionals October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 19
IGITAL MEDICAL SYSTEMS Cloud Computing threat: communications network down example Telstra internet back after four-day outage in Victoria's west October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 21
IGITAL MEDICAL SYSTEMS Internet Security - Is your clinic IT secure? 1. A top brand name business level hardware based Firewall installed between the internet modem and the network 2. A top brand name business level Anti Virus and Security Suite such as Webroot End Point Security including A/V, Spam, Web and Mobile security as essential for medical clinics to protect against external and internal threats 3. Very tight policy rules on internet access 4. Real Time Security Monitoring& Management October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 23
IGITAL MEDICAL SYSTEMS Internet Security: You have mail! In the NEWS!! Security Alert! Crypto-ransomware attack! ABC News Report, 8 October 2014 Crypto-ransomware is a relatively new and increasingly pervasive type of ransomware that aims to collect personal and financial information or install a malicious virus which can "take over" your PC Recovery of infected systems is virtually impossible without clean backups October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 24
Internet Security: You have mail! 2 IGITAL MEDICAL SYSTEMS October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 25
Internet Security: You have mail! 3 IGITAL MEDICAL SYSTEMS October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 26
Intelligent Cloud based Security: Webroot IGITAL MEDICAL SYSTEMS For the tech s at DMS its easy currently Webroot Inc. products offer our clients the best cyber security solutions compared to most of the competing business grade internet and web security brands. October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 28
In summary: IGITAL MEDICAL SYSTEMS How do we attain Disaster Avoidance and Resilient IT? Implement Risk Management Systems: 1. Compliant IT Policy & Procedures 2. Staff Training 3. Redundant Systems Design - No Single Point of Failure 4. High Availability Systems with Automatic Failover via Virtualization 5. Data Backup and Rapid Disaster Recovery Systems 6. Fully Managed Endpoint and Internet Security 7. Fully Managed and Automated IT Services, with Real Time Monitoring and Alerting October 2015 COPYRIGHT 2015 IGITAL MEDICAL SYSTEMS CALL 1300 865 977 29
Thank you for your time. Any Questions? Miroslav Doncevic miroslav@dgs.com.au www.dgs.com.au/dms IGITAL MEDICAL SYSTEMS Call 1300 865 977 40