Healthcare as an industry has the most to gain from a progressive approach to identity both in physical and logical security. Few other industries have the baseline need of assuring identity: whether it’s accessing doors leading to the emergency room or accessing a patient’s electronic medical record. This whitepaper will explore identity from the physical perimeter through the logical network; and, will promote a concept of unified identity. We will discuss the importance of a common architecture which is easily managed and audited. And, we will explore newer technologies and architectures which enable dynamic exchange of health information, but demand non-repudiation of identity.
IAM Health, a division of IAM Technology, is pleased to support the dynamic healthcare industry with our Advanced Security Group, experts in advanced access control and security integration in healthcare. Let us be your guide through this rapidly changing industry.
Earlier this year President Obama signed into law the American Recovery and Reinvestment Act, equally known as ARRA or the Stimulus Act, providing over $38 Billion dollars to the advancement of electronic health records. This investment will transform the healthcare industry. Under the ARRA, physicians will receive a reimbursement premium on Medicaid payments for the use of electronic health records or will be penalized on Medicaid reimbursement beginning in 2015 if they fail to implement electronic health records.
The growth of electronic medical records raises the question of how we trust the integrity of the record: who updated the record, when, who’s liable for misuse, and who has rights to access to the record? It is time for the healthcare industry to embrace a new identity blueprint, an identity proven, flexible and secure. A Blueprint modeled after the success of a similar identity framework instituted throughout the United States federal government.
Building a Unified Path
Whether you are a CIO, CSO, or a Facilities Manager, beginning the process of review, scoping the needs for your future, and developing an identity plan is timely. In fact, you may find your existing access control credentials/cards weak by today’s standards. The vast majority of identity credentials for access control are first generation cards: proximity cards or MiFare Classic Cards. These radio frequency cards simple lack the hardened cryptographic protections to assure security in your healthcare facility. In fact, proximity cards and MiFare Classic Cards have been knowingly compromised by security researchers.
See a MiFare 4K attack in action: http://www.youtube.com/watch?v=NW3RGbQTLhE
Newer smart cards are developed with advanced cryptographic properties and better communication protocols. What this means is a more secure and effective card, one capable of securely authenticating to multiple applications. In fact, newer smart cards actually have a processor, enabling on card computing and advanced access control challenges. This is the case with all United States Federal government identity credentials by law. The Homeland Security Presidential Directive (HSPD) 12 instructed the National Institute of Science and Technology (NIST) to create Federal Information Processing Standard (FIPS) 201, a framework for the vetting, issuance, management and accreditation of identity products throughout the federal government. FIPS 201 is a contact and contactless smart card security framework that standardizes multi-tiered access and authentication. For advance authentication, one or more digital keys are stored on an advanced smart card processor. This is known as a Public Key Infrastructure or PKI, a security infrastructure based on unique private keys issued by a trusted server.
The Emerging Standard
The FIPS 201 standard provides Federal agencies with a blueprint for designing and implementing a comprehensive smart card credentialing program, and also provides the healthcare industry a standard for credentialing and security. The signing of HSPD-12 and the subsequent creation of FIPS 201 has been termed a landmark event for identity worldwide. For the first time, a formal standard now exists for governments and industry to purchase biometric and credentialing solutions with the assurance of interoperability and accredited trust. In conjunction with other federal ID programs like TWIC (the Transportation Worker Identification Credential), Registered Traveler and the FRAC (First Responder Access Card), the healthcare industry can now reliable implement enhanced credentials without fear of non-compliance to either Federal, State, or industry standards.
Progressive healthcare organizations are moving to FIPS 201 compatible architectures as a means of achieving a more holistic approach to security, incorporating personnel review (vetting, background checks, security training and awareness), logical security (network and application access), physical security (facility access), audit, and compliance reviews.
While there are many benefits to an advanced smart card credentialing framework in the near term, the majority of benefits will be gained as the electronic health record standards are implemented in the next three to five years. Today, we know the future standard of security on the health record exchange; this has been clearly established by the standards committees. To identify the creator of the record the healthcare standard is SAML (Security Assertion Mark-up Language). SAML is an authentication assertion that provides assurance of the provenance and integrity of the message (we will explore further below). An advanced identity framework similar in scope to FIPS 201 is not simply the right technical answer; it’s the right economic answer. Today, FIPS 201 shows us how to managed identity from a single card, a smart card.
Electronic Medical Records
The National Health Information Network (nHIN) embraces WS-Security (Web Services Security) as an internal message security protocol. WS-Security provides for XML Signature and XML Encryption, two elements that bind identity and encryption to elements of the message itself. In layman’s terms, the doctor can “notarize” her additions to a health record. She, in turn, can encrypt those additions for select recipients to decrypt. While this reaches beyond a traditional discussion of identity, it begins to reveal the scope of your healthcare institutions identity framework.
An advanced smart card architecture is the foundation for this architecture. It is easily audited and streamlines compliance checks. A common identity architecture that is used system-wide and integrated to HR systems, ERP systems, Active Directory , and physical access systems begins with the next generation of card architecture.
Summary
So we have gone on a journey from the security perimeter through the electronic exchange of medical records. We have highlighted the structural benefits of the United States federal standards for identity and credentialing; standards we believe the United States federal government will recommend for the healthcare industry. We believe there are compelling business drivers: ease of management, integration to ERP systems, convergence of identity physical and logical, lower OPEX (operational expense), possible CAPEX savings (capital expense), stronger cryptographic assurance of identity, multi-factor authentication, seamless integrity with electronic medical system, compliance to international and United States federal standards, federated trust between institutions, among others.
Is it time to explore the benefits of a common identity architecture? We certainly are encouraging our clients to explore the benefits of addressing identity, physical and logical, as one common solution. We have seen firsthand the success of the Federal Government with FIPS 201, and we believe this provides the ideal identity framework for your future. When properly designed, we believe an advanced identity architecture drives business process improvement throughout your institution and will have many institutional benefits. Our biggest obstacle is often not the technology, but getting disparate departments within the institution to work together.
Finally, the greatest benefit of all may be a common compliance and audit trail. When we rely on a unique identifier (a private key) tied to an ID Card with multi-factor authentication, we have a trusted architecture. From that point on, we are not auditing multiple systems, nor fighting weak authentication methods; we simply wear the answer to trusted identity around our neck.
The United States federal government through the Department of Homeland Security and the Federal Emergency Management Agency are also promoting the use of FIPS 201 in healthcare. Properly designed, a healthcare identity architecture would assure proper accreditation of healthcare specialties and training in the case of a natural disaster. Building a national first responder identity framework may be one of the most important things we do to protect our Nation.
