3 ms·
From what I know of enterprise software it's basically an MSSQL or MySQL box having all the data in the end and IT has to back up it, so they have db admin lmao
by rejectfinite 3y ago
From what I know of enterprise software it's basically an MSSQL or MySQL box having all the data in the end and IT has to back up it, so they have db admin lmao
Yes very secure.
- theGnuMe 3y agoEpic is something entirely different.
- Urist-Green 3y agoNot a lawyer, but my understanding is the main issue with healthcare services on the cloud is auditing physical access to the machines. If any questions come up then the service provider "should" be able to tell a court exactly where a healthcare company's data is and what technicians had access at different times. Microsoft, Google, etc are still totally happy to sell that service, but there is a separate legal agreement that has to signed to say "we care about healthcare privacy".
- kstrauser 3y agoSpecifically, you have to get them to sign a HIPAA Business Associate Agreement (BAA). The good news is that Amazon makes this an automated process in their compliance portal, so you can knock that out in 5 minutes and then go on with the rest of the planning.
- haldujai 3y agoAlso worth noting that not every resource and instance type is covered by a BAA so there’s a bit more to it than just signing an agreement and doing whatever you want. The responsibility remains with the user rather than the cloud provider to ensure compliance but they will do their part if you set things up correctly.
- haldujai 3y agoYou’re missing at least an order of magnitude of complexity here. For starters the data generated by a single hospital EHR is something like 10-20 TB/year. The data is stored (essentially indefinitely) in multiple databases of varying availability, formats and interfaces. It is generally on prem, with multiple failover systems as well as long term backup and a read-only failover usually in the cloud. Somewhere in this process the data is stored in a non-clinical use data warehouse which has strict physical and digital access restrictions and detailed logs. Backups are obviously automated. Logs cannot disclose protected health information. IT accessing individual records would always be flagged to the CIO and CPO offices and audited. A % of providers are randomly audited by the same offices and certain accesses automatically trigger an audit (for example if I open my own chart, or if I open the chart of a patient who has restricted access - this is audited even if I’m part of their care team and state so in the prompt that comes up when I open the chart). Physical access by infra providers is disclosed and audited as well. It’s actually quite secure largely because the fines for failing to do so are quite hefty for the hospital.