SlideShare a Scribd company logo
Certifying and Securing aTrusted Environment for Health
Informatics Research data
Dr Jonathan Monk, Director of IT, University of Dundee
1/11/2016
Health Informatics Centre
dundee.ac.uk/hic
Dr Jonathan Monk
Director of IT
University of Dundee
Certifying and Securing a Trusted
Environment for Health Informatics
Research data
Health Informatics Centre
dundee.ac.uk/hic
1. Overview of Health Informatics
2. Research Data Management Platform
3. Safe Haven Architecture
4. ISO27001 Certification
Health Informatics Centre
dundee.ac.uk/hic
Overview of Health
Informatics
Health Informatics Centre
dundee.ac.uk/hic
Geographic - Tayside And Fife Population of Scotland Time Period 1972 - 2016
Electronic Medical Data Coverage
Health Informatics Centre
dundee.ac.uk/hic
Parents Conception Birth Early Life Childhood Adulthood Late Life Death
Research Datasets
• GoDARTS Diabetes – 18K - Case/Controls
• TASC FORCE – 5000 - MRA Volunteers
• POPADAD – 1200 - Diabetes with no CVD
• TRACE RA – 3200 - Rheumatoid Arthritis/UK
Pre-consented Cohorts
 SHARE – 100+K
 Generation Scotland – 20K
SMR02
Maternity & Neonate
Walker
48,00 Births (1952-1966)
Health Care Data
 Primary Care : Community Prescribing
 Secondary Care : Out Patient Visits, Hospital Admissions, Accident & Emergency, Cancer Register, Psychiatric Episodes.
 Diagnostics : Radiology Events, Cardiology & Vascular Labs, Bowel Screening
 Laboratory - Biochemistry, Haematology, Immunology, Microbiology, Virology
 Diabetes Surveillance - BP,BMI, Smoking Alcohol, Amputations, Ulcers
 Diabetic Retinal Images – DRS Retinopathy Image Library (Go DARTS Population)
Disease Registers
• TARDIS Respiratory Disease
• SDCRN – Scottish Dementia Network
• SCI Diabetes
• Epilepsy
Child Health Pre-School/School
SIRS/CHSP
Register Of
Deaths
DataForLinkageExistingResearch
StudiesPhenotypic Data Available
Health Informatics Centre
dundee.ac.uk/hic
Data Linkage Through Family Generations
2004 - Community Prescribing (Dispensed)
2016
1986 - Acute Hospital Admission Tayside
1975 - Births and Neonatal Record
1986 - Laboratory ( Biochemistry, Haematology, Immunology, Microbiology)
1994 - Radiology Records
1952
Walker Dataset
1952 – 66
48,000
Dundee Births
Babies
Mothers
Fathers
1980 – Cancer Register
1990 – Diabetes Records
Cohort participants episodes recorded in dataset
Health Informatics Centre
dundee.ac.uk/hic
Health Informatics Centre
dundee.ac.uk/hic
Controls
 Ratio : 3:1
 Match on Age, Sex, SIMD
Feasibility Searches
Inclusion:
 Health Board : Tayside
 Status : Alive
 Conditions : Type 2 Diabetes
 Age: >= 65
 Prescribed : Insulin > 2yrs
Exclude:
 Prescribed: Statins
Researcher Supplies Search Criteria
Matches
570K
450K
120K
70K
9210
Health Informatics Centre
dundee.ac.uk/hic
Health Informatics Centre
dundee.ac.uk/hic
Demography
GRO ECHO
There was a
22% overall
reduction in all
cause mortality
with β blocker
use
Prescribing TARDIS
Biochemistry
MicrobiologyHaematology
Case Study # 1 - β blockers:
Their Effect in Managing Chronic Obstructive Pulmonary Disease (COPD)
Setting Tayside, Scotland (2001–2010)
Population 5977 patients aged >50 years
with a diagnosis of COPD.
BMJ. 2011; 342: d2549. 10.1136/bmj.d2549 P.M Short, S.I.W Lipworth, D.H.J Elder, S. Schembri, B.J. Lipworth.
Health Informatics Centre
dundee.ac.uk/hic
Hospital
admissions
GRO
More than 400 lives are being lost each year
because breast cancer patients fail to take
the full course of the drug Tamoxifen due to
"intolerable" side-effects
Prescribing
Br J Cancer. 2008 December 2; 99(11): 1763–1768. 10.1038/sj.bjc.6604758 McCowan, J Shearer, P T Donnan, J A Dewar, M Crilly, A M Thompson and T P Fahey
Researcher Supplied
Cohort
Cancer patients from a
Ninewells clinic
Case Study #2: Tamoxifen adherence:
Relationship to Mortality in Women with Breast Cancer
Health Informatics Centre
dundee.ac.uk/hic
Research Data Management Platform (RDMP)
‘Optimizing and Augmenting the Research Data Supply Chain`
Labs
SMR01
Prescribing
Raw Data Data Import Databases Custom Extractions & Export Formats
RDMP
Labs
SMR01
Prescribing
Raw Data Data Import Structured
Database
Extraction + Export
DataLoad
Engine
Research
Data Warehouse
Validate
Clean
Catalogue
QualityChecks
Project X
Data Marts
Validate
Clean
Catalogue
QualityChecks
Project Y
Data Marts
Validate
Clean
Catalogue
QualityChecks
DataExtraction
Engine
Health Informatics Centre
dundee.ac.uk/hic
Data
Set 1
Data
Set 6
Data
Set 2
Data
Set 3
Data
Set 4
Data
Set 5
Data Set 1
Pseudo-CHI
Data Set 2
Pseudo-CHI
Data Set 6
Pseudo-CHI
Data Set 3
Pseudo-CHI
Data Set 4
Pseudo-CHI
Data Set 5
Pseudo-CHI
CHI and All
Identifiable
Data
Data Set 1
Project -CHI
Data Set 4
Project -CHI
NHS Network University Network
Data Repository Function of Safe Haven Analytic Platform of Safe Haven
Virtual
Environment –
no data leaves
Health Informatics Centre
dundee.ac.uk/hic
• Extraction takes minutes
• Data released is standardised – the same regardless of Data Analyst that
completes the work
• A history is recorded of all changes to data over time
• Data released now will be in the same format as in 5 years from now
• Metadata has been added
• Methods for transforming and validations have been added across all data
sets
• Tools to manage and explore the data are available to Data Management
team and researchers
• Audit and Logging all automated
• Major work towards integration of image and genomic data
Health Informatics Centre
dundee.ac.uk/hic
Health Informatics Centre
dundee.ac.uk/hic
• Standard restrictive VDI solution
• VMWare View / Horizon
Health Informatics Centre
dundee.ac.uk/hic
• AppVolumes used for Applications
• Bring Your Own License
• Lots of Application Variations!
Health Informatics Centre
dundee.ac.uk/hic
• There are many types of ISO
Certification.
• We have 27001:2013 – Certificate
Number: 2016/2269
• ISO 27001:2013 is a specification for an
information security management
system (ISMS). An ISMS is a framework of
policies and procedures that includes all
legal, physical and technical controls
involved in an organisation's information
risk management processes.
What is ISO27001?
Health Informatics Centre
dundee.ac.uk/hic
Why ISO27001 certification?
• Independent set of standards – so rather than constantly having to
think what documents and processes we should have in place and
reinventing the wheel, ISO gives us this!
• Gives confidence to other organisations we work with e.g. NHS, main
University.
• Reduces other documentation requirements for governance, as we
can just reference ISO documentation.
• Improves the working practices of HIC. This has been particularly the
case with our hardware infrastructure.
• Key towards Scottish Government Safe Haven Accreditation.
Health Informatics Centre
dundee.ac.uk/hic
Scottish Government Safe Haven Accreditation
• 27001 standard controls PLUS some
additional ones specific to Safe Havens.
• Reviewed by Scottish Government
eHealth.
• Documentation Required:
• Risk Assessment Doc
• Mapping of Controls
Health Informatics Centre
dundee.ac.uk/hic
Health Informatics Centre
dundee.ac.uk/hic
Scope
“The provision of data to researchers via safe haven environment, secure
patient recruitment, data collection using software tools, data entry, the
development and operation of web based applications and all assets
underpinning the provision of those services from the locations of HIC premises
at Ninewells Hospital and data centres within the University of Dundee
Campus”
Health Informatics Centre
dundee.ac.uk/hic
ISMS Controls Status with Statement of
Applicability and Gaps
Health Informatics Centre
dundee.ac.uk/hic
ISO Controls – Made up of HIC specific ones
and University/NHS general controls
University of Dundee Security
Policies
University of Dundee HR Policies and
Procedures (and NHS where
appropriate as we have honorary
contracts)
HIC HR
Procedures/Training/Policies
HIC Security Policies
A7: Human Resource SecurityA5: Information Security Policies
A6: Organisation of
Information security
University of Dundee Security
Policies
HIC Security Policies,
SOPS, Procedures, Work
Instructions and Service
Descriptions
Health Informatics Centre
dundee.ac.uk/hic
Document Types and Review
Static & Formally Approved:
HIC Exec & HIC Information Governance Committee
• Policies
• Standard Operating Procedures (SOPs)
• Risk Management Doc
• Information Security Management System (ISMS)
Manual
• Business Continuity Plan
Just HIC Exec
• Procedures
Working Documents (technical):
Relevant Technical Manager
• Service Descriptions
• Work Instructions
• Asset and Responsibility Matrix
• Disaster Recovery Plans
• Infrastructure Diagrams
Health Informatics Centre
dundee.ac.uk/hic
Structure of Docs in Box Become aware of an
improvement of our
current procedure
Take a copy of Procedure from “Live” folder and move to
“Under Development”.
Draft change using tracked changes.
Ask Technical Manager to review.
Technical Manager moves the doc they have approved to
“Awaiting Approval Folder” and asks for it to be included in
HIC Exec Meeting Agenda for review.
If approved at HIC Exec either formally approved or sent to
HIC Information Governance Committee for additional
formal approval (if document type requires)
Approved doc is moved to
“Live” folder by HIC Admin
Procedure Changes
Health Informatics Centre
dundee.ac.uk/hic
Infrastructure comprised UoD, HIC & NHS
University of Dundee Network NHS Network
HIC Managed Hardware
HIC Managed Hypervisor Cluster
HIC Managed Operating Systems
HIC Managed Applications
UoD Hardware
UoD Hypervisor
UoD OS
UoD Applications
HIC and UoD use identical platform technology and share locations
Hardware & responsibility for management varies depending on specificity
University of Dundee Data Centres NHS Locations
Health Informatics Centre
dundee.ac.uk/hic
Timelines
• Help from University’s Information Security Officer (Graham McKay)
to get us up to the required standard.
• Passed our Stage 1 audit of our documentation in June 2015.
• Passed our Stage 2 audit of our systems (do we do what we say we do
in our documentation) in Jan 2016.
• Passed second Stage 2 audit July 2016
• Now have full audits every 6 months for the next 3 years!
Health Informatics Centre
dundee.ac.uk/hic
Phil Appleby
Jim Galloway
Chris Hall
Duncan HeatherEmily Jefferson
Claire JonesGordon
McAllister
Keith MilburnLeandro Tramma
Donald
Scobbie
Thomas Nind Guney Hanedan
Graham
McKay
Many thanks to the people that did all the work!
Health Informatics Centre
dundee.ac.uk/hic
Questions?

More Related Content

What's hot (20)

PPTX
UK data management environment and support
Jisc
 
PPTX
LEARN Conference - How to cost
Jisc RDM
 
PPTX
LEARN Final Conference: Tutorial Group | Using the LEARN Model RDM Policy
LEARN Project
 
PPTX
Standardising research data policies, research data network
Jisc RDM
 
PPTX
Supporting the community-owned open scholarly communications ecosystem
Jisc
 
PPTX
Why science needs open data – Jisc and CNI conference 10 July 2014
Jisc
 
PDF
Digital transformation to enable a FAIR approach for health data science
Varsha Khodiyar
 
PPTX
Towards Open Research
Jisc RDM
 
PPTX
LEARN Final Conference: Tutorial Group | Implementing the LEARN RDM Toolkit
LEARN Project
 
PPTX
Making sense of open scholarly communications data - Jisc Digifest 2016
Jisc
 
PPTX
Perspectives from the African Open Science Platform/Susan Veldsman
African Open Science Platform
 
PPTX
Active research management and sharing
Jisc
 
PPTX
Addressing the wicked problem of learning data privacy though principle and p...
Jisc
 
PDF
Lessons from the UK: Data access, patient trust & real-world impact with heal...
Varsha Khodiyar
 
PPTX
EPFL Open Research Data - a Jisc perspective
Christopher Brown
 
PPTX
H2020 open-data-pilot
Sarah Jones
 
PPTX
Paul Jeffreys - Research Integrity: Institutional Responsibility
Jisc
 
PPTX
20160414 23 Research Data Things
Katina Toufexis
 
PPTX
The fourth paradigm: data intensive scientific discovery - Jisc Digifest 2016
Jisc
 
PPTX
UK Research Data Management: overview to ADBU congress, 19 Sep 2013 by Laura ...
L Molloy
 
UK data management environment and support
Jisc
 
LEARN Conference - How to cost
Jisc RDM
 
LEARN Final Conference: Tutorial Group | Using the LEARN Model RDM Policy
LEARN Project
 
Standardising research data policies, research data network
Jisc RDM
 
Supporting the community-owned open scholarly communications ecosystem
Jisc
 
Why science needs open data – Jisc and CNI conference 10 July 2014
Jisc
 
Digital transformation to enable a FAIR approach for health data science
Varsha Khodiyar
 
Towards Open Research
Jisc RDM
 
LEARN Final Conference: Tutorial Group | Implementing the LEARN RDM Toolkit
LEARN Project
 
Making sense of open scholarly communications data - Jisc Digifest 2016
Jisc
 
Perspectives from the African Open Science Platform/Susan Veldsman
African Open Science Platform
 
Active research management and sharing
Jisc
 
Addressing the wicked problem of learning data privacy though principle and p...
Jisc
 
Lessons from the UK: Data access, patient trust & real-world impact with heal...
Varsha Khodiyar
 
EPFL Open Research Data - a Jisc perspective
Christopher Brown
 
H2020 open-data-pilot
Sarah Jones
 
Paul Jeffreys - Research Integrity: Institutional Responsibility
Jisc
 
20160414 23 Research Data Things
Katina Toufexis
 
The fourth paradigm: data intensive scientific discovery - Jisc Digifest 2016
Jisc
 
UK Research Data Management: overview to ADBU congress, 19 Sep 2013 by Laura ...
L Molloy
 

Viewers also liked (20)

PPTX
Cyber Crime - "Who, What and How"
Jisc
 
PPT
Role of the CISO in Higher Education
Jisc
 
PPTX
Mitigation starts now
Jisc
 
PDF
Protecting our customers - BT security
Jisc
 
PPTX
Data and information governance: getting this right to support an information...
Jisc
 
PPTX
GDPR: More reasons for information security
Jisc
 
PPT
Working with students and ISO27001
Jisc
 
PPTX
Information security at University of East London: the benefits (and pitfalls...
Jisc
 
PPTX
Closing plenary and keynote from Lauren Sager Weinstein
Jisc
 
PPTX
Archiving data from Durham to RAL using the File Transfer Service (FTS)
Jisc
 
PPTX
110G networking within JASMIN
Jisc
 
PPTX
Challenges in end-to-end performance
Jisc
 
PPTX
Provisioning Janet
Jisc
 
PPTX
Science DMZ
Jisc
 
PDF
Science DMZ at Imperial
Jisc
 
PPT
Solving Network Throughput Problems at the Diamond Light Source
Jisc
 
PPTX
Enabling efficient movement of data into & out of a high-performance analysis...
Jisc
 
PPTX
The Assessment Journey
Jisc
 
PPTX
Data and disadvantaged students - using learning analytics for inclusion
Jisc
 
PPTX
The Jisc UK ORCID consortium : Workshop 2
Jisc
 
Cyber Crime - "Who, What and How"
Jisc
 
Role of the CISO in Higher Education
Jisc
 
Mitigation starts now
Jisc
 
Protecting our customers - BT security
Jisc
 
Data and information governance: getting this right to support an information...
Jisc
 
GDPR: More reasons for information security
Jisc
 
Working with students and ISO27001
Jisc
 
Information security at University of East London: the benefits (and pitfalls...
Jisc
 
Closing plenary and keynote from Lauren Sager Weinstein
Jisc
 
Archiving data from Durham to RAL using the File Transfer Service (FTS)
Jisc
 
110G networking within JASMIN
Jisc
 
Challenges in end-to-end performance
Jisc
 
Provisioning Janet
Jisc
 
Science DMZ
Jisc
 
Science DMZ at Imperial
Jisc
 
Solving Network Throughput Problems at the Diamond Light Source
Jisc
 
Enabling efficient movement of data into & out of a high-performance analysis...
Jisc
 
The Assessment Journey
Jisc
 
Data and disadvantaged students - using learning analytics for inclusion
Jisc
 
The Jisc UK ORCID consortium : Workshop 2
Jisc
 
Ad

Similar to Certifying and Securing a Trusted Environment for Health Informatics Research Data (20)

PPT
UCSF Informatics Day 2014 - Sorena Nadaf, "Translational Informatics OnCore C...
CTSI at UCSF
 
PPTX
International perspective for sharing publicly funded medical research data
ARDC
 
PPT
Clinical trial data wants to be free: Lessons from the ImmPort Immunology Dat...
Barry Smith
 
PPTX
A standards-based approach to development of clinical registries
Health Informatics New Zealand
 
PPTX
A Standards-based Approach to Development of Clinical Registries - Initial Le...
Koray Atalag
 
PPTX
Clinical Data Management Process Overview_Katalyst HLS
Katalyst HLS
 
PPTX
Shifting the goal post – from high impact journals to high impact data
CGIAR Research Program on Dryland Systems
 
PPTX
Accessing data for research: data publishing pathways and the Five Safes
Louise Corti
 
PDF
Development_data_standards_data_integration_tools
Rafael Romero
 
PDF
Data Virtualization Modernizes Biobanking
Denodo
 
PDF
CDM_Process_Overview_Katalyst HLS
Katalyst HLS
 
PPTX
AllTrials AAAS 2015 - Opportunities and Challenges for ClinicalTrials.gov
SenseAboutSci
 
PPTX
dkNET Webinar: Creating and Sustaining a FAIR Biomedical Data Ecosystem 10/09...
dkNET
 
PPTX
ANDS health and medical data webinar 16 May. Storing and Publishing Health an...
ARDC
 
PDF
Registry Participation 101: A Step-by-Step Guide to What You Really Need to K...
Wellbe
 
PPTX
McGrath Health Data Analyst SXSW
Robert McGrath
 
PPTX
A Stocktake of New Zealand’s Healthcare Datasets
Health Informatics New Zealand
 
PDF
Spitzer datawarehouse
Mitzi Santiago
 
PPTX
Current ONC Standards Activities
Jitin Asnaani
 
UCSF Informatics Day 2014 - Sorena Nadaf, "Translational Informatics OnCore C...
CTSI at UCSF
 
International perspective for sharing publicly funded medical research data
ARDC
 
Clinical trial data wants to be free: Lessons from the ImmPort Immunology Dat...
Barry Smith
 
A standards-based approach to development of clinical registries
Health Informatics New Zealand
 
A Standards-based Approach to Development of Clinical Registries - Initial Le...
Koray Atalag
 
Clinical Data Management Process Overview_Katalyst HLS
Katalyst HLS
 
Shifting the goal post – from high impact journals to high impact data
CGIAR Research Program on Dryland Systems
 
Accessing data for research: data publishing pathways and the Five Safes
Louise Corti
 
Development_data_standards_data_integration_tools
Rafael Romero
 
Data Virtualization Modernizes Biobanking
Denodo
 
CDM_Process_Overview_Katalyst HLS
Katalyst HLS
 
AllTrials AAAS 2015 - Opportunities and Challenges for ClinicalTrials.gov
SenseAboutSci
 
dkNET Webinar: Creating and Sustaining a FAIR Biomedical Data Ecosystem 10/09...
dkNET
 
ANDS health and medical data webinar 16 May. Storing and Publishing Health an...
ARDC
 
Registry Participation 101: A Step-by-Step Guide to What You Really Need to K...
Wellbe
 
McGrath Health Data Analyst SXSW
Robert McGrath
 
A Stocktake of New Zealand’s Healthcare Datasets
Health Informatics New Zealand
 
Spitzer datawarehouse
Mitzi Santiago
 
Current ONC Standards Activities
Jitin Asnaani
 
Ad

More from Jisc (20)

PPTX
Strengthening open access through collaboration: building connections with OP...
Jisc
 
PPTX
Andrew-Brown-JUSP-showcase-20240730.pptx
Jisc
 
PPTX
JUSP Showcase - Rebuilding Data presentation
Jisc
 
PPTX
Adobe Express Engagement Webinar (Delegate).pptx
Jisc
 
PPTX
FE Accessibility training matrix partnership - information session
Jisc
 
PPTX
Procuring a research management system: why is it so hard?
Jisc
 
PPTX
Adobe Express Engagement Webinar (Delegate).pptx
Jisc
 
PPTX
How libraries can support authors with open access requirements for UKRI fund...
Jisc
 
PPTX
Supporting (UKRI) OA monographs at Salford.pptx
Jisc
 
PPTX
The approach at University of Liverpool.pptx
Jisc
 
PPTX
Jisc's value to HE: the University of Sheffield
Jisc
 
PPTX
Towards a code of practice for AI in AT.pptx
Jisc
 
PPTX
Jamworks pilot and AI at Jisc (20/03/2024)
Jisc
 
PPTX
Wellbeing inclusion and digital dystopias.pptx
Jisc
 
PPTX
Accessible Digital Futures project (20/03/2024)
Jisc
 
PPTX
Procuring digital preservation CAN be quick and painless with our new dynamic...
Jisc
 
PPTX
International students’ digital experience: understanding and mitigating the ...
Jisc
 
PPTX
Digital Storytelling Community Launch!.pptx
Jisc
 
PPTX
Open Access book publishing understanding your options (1).pptx
Jisc
 
PPTX
Scottish Universities Press supporting authors with requirements for open acc...
Jisc
 
Strengthening open access through collaboration: building connections with OP...
Jisc
 
Andrew-Brown-JUSP-showcase-20240730.pptx
Jisc
 
JUSP Showcase - Rebuilding Data presentation
Jisc
 
Adobe Express Engagement Webinar (Delegate).pptx
Jisc
 
FE Accessibility training matrix partnership - information session
Jisc
 
Procuring a research management system: why is it so hard?
Jisc
 
Adobe Express Engagement Webinar (Delegate).pptx
Jisc
 
How libraries can support authors with open access requirements for UKRI fund...
Jisc
 
Supporting (UKRI) OA monographs at Salford.pptx
Jisc
 
The approach at University of Liverpool.pptx
Jisc
 
Jisc's value to HE: the University of Sheffield
Jisc
 
Towards a code of practice for AI in AT.pptx
Jisc
 
Jamworks pilot and AI at Jisc (20/03/2024)
Jisc
 
Wellbeing inclusion and digital dystopias.pptx
Jisc
 
Accessible Digital Futures project (20/03/2024)
Jisc
 
Procuring digital preservation CAN be quick and painless with our new dynamic...
Jisc
 
International students’ digital experience: understanding and mitigating the ...
Jisc
 
Digital Storytelling Community Launch!.pptx
Jisc
 
Open Access book publishing understanding your options (1).pptx
Jisc
 
Scottish Universities Press supporting authors with requirements for open acc...
Jisc
 

Recently uploaded (20)

PPTX
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
PPTX
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
PPTX
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
PDF
Economic Impact of Data Centres to the Malaysian Economy
flintglobalapac
 
PDF
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
PDF
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
PPTX
AI Code Generation Risks (Ramkumar Dilli, CIO, Myridius)
Priyanka Aash
 
PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
PDF
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
PDF
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
PDF
Generative AI vs Predictive AI-The Ultimate Comparison Guide
Lily Clark
 
PDF
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
PDF
Peak of Data & AI Encore - Real-Time Insights & Scalable Editing with ArcGIS
Safe Software
 
PDF
GDG Cloud Munich - Intro - Luiz Carneiro - #BuildWithAI - July - Abdel.pdf
Luiz Carneiro
 
PPTX
Simple and concise overview about Quantum computing..pptx
mughal641
 
PPTX
Agentic AI in Healthcare Driving the Next Wave of Digital Transformation
danielle hunter
 
PDF
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
PDF
Researching The Best Chat SDK Providers in 2025
Ray Fields
 
PPTX
AVL ( audio, visuals or led ), technology.
Rajeshwri Panchal
 
PDF
Build with AI and GDG Cloud Bydgoszcz- ADK .pdf
jaroslawgajewski1
 
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
Economic Impact of Data Centres to the Malaysian Economy
flintglobalapac
 
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
AI Code Generation Risks (Ramkumar Dilli, CIO, Myridius)
Priyanka Aash
 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
Generative AI vs Predictive AI-The Ultimate Comparison Guide
Lily Clark
 
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
Peak of Data & AI Encore - Real-Time Insights & Scalable Editing with ArcGIS
Safe Software
 
GDG Cloud Munich - Intro - Luiz Carneiro - #BuildWithAI - July - Abdel.pdf
Luiz Carneiro
 
Simple and concise overview about Quantum computing..pptx
mughal641
 
Agentic AI in Healthcare Driving the Next Wave of Digital Transformation
danielle hunter
 
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
Researching The Best Chat SDK Providers in 2025
Ray Fields
 
AVL ( audio, visuals or led ), technology.
Rajeshwri Panchal
 
Build with AI and GDG Cloud Bydgoszcz- ADK .pdf
jaroslawgajewski1
 

Certifying and Securing a Trusted Environment for Health Informatics Research Data

  • 1. Certifying and Securing aTrusted Environment for Health Informatics Research data Dr Jonathan Monk, Director of IT, University of Dundee 1/11/2016
  • 2. Health Informatics Centre dundee.ac.uk/hic Dr Jonathan Monk Director of IT University of Dundee Certifying and Securing a Trusted Environment for Health Informatics Research data
  • 3. Health Informatics Centre dundee.ac.uk/hic 1. Overview of Health Informatics 2. Research Data Management Platform 3. Safe Haven Architecture 4. ISO27001 Certification
  • 5. Health Informatics Centre dundee.ac.uk/hic Geographic - Tayside And Fife Population of Scotland Time Period 1972 - 2016 Electronic Medical Data Coverage
  • 6. Health Informatics Centre dundee.ac.uk/hic Parents Conception Birth Early Life Childhood Adulthood Late Life Death Research Datasets • GoDARTS Diabetes – 18K - Case/Controls • TASC FORCE – 5000 - MRA Volunteers • POPADAD – 1200 - Diabetes with no CVD • TRACE RA – 3200 - Rheumatoid Arthritis/UK Pre-consented Cohorts  SHARE – 100+K  Generation Scotland – 20K SMR02 Maternity & Neonate Walker 48,00 Births (1952-1966) Health Care Data  Primary Care : Community Prescribing  Secondary Care : Out Patient Visits, Hospital Admissions, Accident & Emergency, Cancer Register, Psychiatric Episodes.  Diagnostics : Radiology Events, Cardiology & Vascular Labs, Bowel Screening  Laboratory - Biochemistry, Haematology, Immunology, Microbiology, Virology  Diabetes Surveillance - BP,BMI, Smoking Alcohol, Amputations, Ulcers  Diabetic Retinal Images – DRS Retinopathy Image Library (Go DARTS Population) Disease Registers • TARDIS Respiratory Disease • SDCRN – Scottish Dementia Network • SCI Diabetes • Epilepsy Child Health Pre-School/School SIRS/CHSP Register Of Deaths DataForLinkageExistingResearch StudiesPhenotypic Data Available
  • 7. Health Informatics Centre dundee.ac.uk/hic Data Linkage Through Family Generations 2004 - Community Prescribing (Dispensed) 2016 1986 - Acute Hospital Admission Tayside 1975 - Births and Neonatal Record 1986 - Laboratory ( Biochemistry, Haematology, Immunology, Microbiology) 1994 - Radiology Records 1952 Walker Dataset 1952 – 66 48,000 Dundee Births Babies Mothers Fathers 1980 – Cancer Register 1990 – Diabetes Records Cohort participants episodes recorded in dataset
  • 9. Health Informatics Centre dundee.ac.uk/hic Controls  Ratio : 3:1  Match on Age, Sex, SIMD Feasibility Searches Inclusion:  Health Board : Tayside  Status : Alive  Conditions : Type 2 Diabetes  Age: >= 65  Prescribed : Insulin > 2yrs Exclude:  Prescribed: Statins Researcher Supplies Search Criteria Matches 570K 450K 120K 70K 9210
  • 11. Health Informatics Centre dundee.ac.uk/hic Demography GRO ECHO There was a 22% overall reduction in all cause mortality with β blocker use Prescribing TARDIS Biochemistry MicrobiologyHaematology Case Study # 1 - β blockers: Their Effect in Managing Chronic Obstructive Pulmonary Disease (COPD) Setting Tayside, Scotland (2001–2010) Population 5977 patients aged >50 years with a diagnosis of COPD. BMJ. 2011; 342: d2549. 10.1136/bmj.d2549 P.M Short, S.I.W Lipworth, D.H.J Elder, S. Schembri, B.J. Lipworth.
  • 12. Health Informatics Centre dundee.ac.uk/hic Hospital admissions GRO More than 400 lives are being lost each year because breast cancer patients fail to take the full course of the drug Tamoxifen due to "intolerable" side-effects Prescribing Br J Cancer. 2008 December 2; 99(11): 1763–1768. 10.1038/sj.bjc.6604758 McCowan, J Shearer, P T Donnan, J A Dewar, M Crilly, A M Thompson and T P Fahey Researcher Supplied Cohort Cancer patients from a Ninewells clinic Case Study #2: Tamoxifen adherence: Relationship to Mortality in Women with Breast Cancer
  • 13. Health Informatics Centre dundee.ac.uk/hic Research Data Management Platform (RDMP) ‘Optimizing and Augmenting the Research Data Supply Chain` Labs SMR01 Prescribing Raw Data Data Import Databases Custom Extractions & Export Formats RDMP Labs SMR01 Prescribing Raw Data Data Import Structured Database Extraction + Export DataLoad Engine Research Data Warehouse Validate Clean Catalogue QualityChecks Project X Data Marts Validate Clean Catalogue QualityChecks Project Y Data Marts Validate Clean Catalogue QualityChecks DataExtraction Engine
  • 14. Health Informatics Centre dundee.ac.uk/hic Data Set 1 Data Set 6 Data Set 2 Data Set 3 Data Set 4 Data Set 5 Data Set 1 Pseudo-CHI Data Set 2 Pseudo-CHI Data Set 6 Pseudo-CHI Data Set 3 Pseudo-CHI Data Set 4 Pseudo-CHI Data Set 5 Pseudo-CHI CHI and All Identifiable Data Data Set 1 Project -CHI Data Set 4 Project -CHI NHS Network University Network Data Repository Function of Safe Haven Analytic Platform of Safe Haven Virtual Environment – no data leaves
  • 15. Health Informatics Centre dundee.ac.uk/hic • Extraction takes minutes • Data released is standardised – the same regardless of Data Analyst that completes the work • A history is recorded of all changes to data over time • Data released now will be in the same format as in 5 years from now • Metadata has been added • Methods for transforming and validations have been added across all data sets • Tools to manage and explore the data are available to Data Management team and researchers • Audit and Logging all automated • Major work towards integration of image and genomic data
  • 17. Health Informatics Centre dundee.ac.uk/hic • Standard restrictive VDI solution • VMWare View / Horizon
  • 18. Health Informatics Centre dundee.ac.uk/hic • AppVolumes used for Applications • Bring Your Own License • Lots of Application Variations!
  • 19. Health Informatics Centre dundee.ac.uk/hic • There are many types of ISO Certification. • We have 27001:2013 – Certificate Number: 2016/2269 • ISO 27001:2013 is a specification for an information security management system (ISMS). An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation's information risk management processes. What is ISO27001?
  • 20. Health Informatics Centre dundee.ac.uk/hic Why ISO27001 certification? • Independent set of standards – so rather than constantly having to think what documents and processes we should have in place and reinventing the wheel, ISO gives us this! • Gives confidence to other organisations we work with e.g. NHS, main University. • Reduces other documentation requirements for governance, as we can just reference ISO documentation. • Improves the working practices of HIC. This has been particularly the case with our hardware infrastructure. • Key towards Scottish Government Safe Haven Accreditation.
  • 21. Health Informatics Centre dundee.ac.uk/hic Scottish Government Safe Haven Accreditation • 27001 standard controls PLUS some additional ones specific to Safe Havens. • Reviewed by Scottish Government eHealth. • Documentation Required: • Risk Assessment Doc • Mapping of Controls
  • 23. Health Informatics Centre dundee.ac.uk/hic Scope “The provision of data to researchers via safe haven environment, secure patient recruitment, data collection using software tools, data entry, the development and operation of web based applications and all assets underpinning the provision of those services from the locations of HIC premises at Ninewells Hospital and data centres within the University of Dundee Campus”
  • 24. Health Informatics Centre dundee.ac.uk/hic ISMS Controls Status with Statement of Applicability and Gaps
  • 25. Health Informatics Centre dundee.ac.uk/hic ISO Controls – Made up of HIC specific ones and University/NHS general controls University of Dundee Security Policies University of Dundee HR Policies and Procedures (and NHS where appropriate as we have honorary contracts) HIC HR Procedures/Training/Policies HIC Security Policies A7: Human Resource SecurityA5: Information Security Policies A6: Organisation of Information security University of Dundee Security Policies HIC Security Policies, SOPS, Procedures, Work Instructions and Service Descriptions
  • 26. Health Informatics Centre dundee.ac.uk/hic Document Types and Review Static & Formally Approved: HIC Exec & HIC Information Governance Committee • Policies • Standard Operating Procedures (SOPs) • Risk Management Doc • Information Security Management System (ISMS) Manual • Business Continuity Plan Just HIC Exec • Procedures Working Documents (technical): Relevant Technical Manager • Service Descriptions • Work Instructions • Asset and Responsibility Matrix • Disaster Recovery Plans • Infrastructure Diagrams
  • 27. Health Informatics Centre dundee.ac.uk/hic Structure of Docs in Box Become aware of an improvement of our current procedure Take a copy of Procedure from “Live” folder and move to “Under Development”. Draft change using tracked changes. Ask Technical Manager to review. Technical Manager moves the doc they have approved to “Awaiting Approval Folder” and asks for it to be included in HIC Exec Meeting Agenda for review. If approved at HIC Exec either formally approved or sent to HIC Information Governance Committee for additional formal approval (if document type requires) Approved doc is moved to “Live” folder by HIC Admin Procedure Changes
  • 28. Health Informatics Centre dundee.ac.uk/hic Infrastructure comprised UoD, HIC & NHS University of Dundee Network NHS Network HIC Managed Hardware HIC Managed Hypervisor Cluster HIC Managed Operating Systems HIC Managed Applications UoD Hardware UoD Hypervisor UoD OS UoD Applications HIC and UoD use identical platform technology and share locations Hardware & responsibility for management varies depending on specificity University of Dundee Data Centres NHS Locations
  • 29. Health Informatics Centre dundee.ac.uk/hic Timelines • Help from University’s Information Security Officer (Graham McKay) to get us up to the required standard. • Passed our Stage 1 audit of our documentation in June 2015. • Passed our Stage 2 audit of our systems (do we do what we say we do in our documentation) in Jan 2016. • Passed second Stage 2 audit July 2016 • Now have full audits every 6 months for the next 3 years!
  • 30. Health Informatics Centre dundee.ac.uk/hic Phil Appleby Jim Galloway Chris Hall Duncan HeatherEmily Jefferson Claire JonesGordon McAllister Keith MilburnLeandro Tramma Donald Scobbie Thomas Nind Guney Hanedan Graham McKay Many thanks to the people that did all the work!

Editor's Notes

  • #9: Pre-Grant Application Service Feasibility Aggregates Inclusion & Exclusion breakdowns Cohort Identification Case Control Matching
  • #12: Changed the black font in the blue bubbles to white
  • #13: Changed the black font in the blue bubbles to white