<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Chakraborty Software &#187; Healthcare &amp; Medical</title>
	<atom:link href="http://www.chakraborty.ch/category/healthcare-medical/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.chakraborty.ch</link>
	<description>Information Security Consulting Services</description>
	<lastBuildDate>Tue, 18 Oct 2011 09:12:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Protected: Pre-Emptive Medical Device Network Security</title>
		<link>http://www.chakraborty.ch/healthcare-medical/pre-emptive-medical-device-network-security/</link>
		<comments>http://www.chakraborty.ch/healthcare-medical/pre-emptive-medical-device-network-security/#comments</comments>
		<pubDate>Mon, 06 Nov 2006 21:39:48 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[Architecture & Design]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Healthcare & Medical]]></category>
		<category><![CDATA[Network Security]]></category>

		<guid isPermaLink="false">http://www.chakraborty.ch/wordpress/?p=10</guid>
		<description><![CDATA[There is no excerpt because this is a protected post.]]></description>
			<content:encoded><![CDATA[<form action="http://www.chakraborty.ch/wp-pass.php" method="post">
<p>This post is password protected. To view it please enter your password below:</p>
<p><label for="pwbox-10">Password:<br />
<input name="post_password" id="pwbox-10" type="password" size="20" /></label><br />
<input type="submit" name="Submit" value="Submit" /></p></form>
]]></content:encoded>
			<wfw:commentRss>http://www.chakraborty.ch/healthcare-medical/pre-emptive-medical-device-network-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IT Security of In Vitro Diagnostic Instruments and Software Systems</title>
		<link>http://www.chakraborty.ch/development/it-security-of-in-vitro-diagnostic-instruments-and-software-systems/</link>
		<comments>http://www.chakraborty.ch/development/it-security-of-in-vitro-diagnostic-instruments-and-software-systems/#comments</comments>
		<pubDate>Sun, 05 Nov 2006 16:38:53 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[Healthcare & Medical]]></category>
		<category><![CDATA[Standards]]></category>

		<guid isPermaLink="false">http://www.chakraborty.ch/wordpress/?p=9</guid>
		<description><![CDATA[Standard issued by the Clinical Laboratory Standards Institute (CLSI), document ID &#8220;Auto-11P&#8221;. One of several recent attempts to specify standards for IT security in medical devices. Covers network security, separation of privileges, development best practices, as well as review techniques. Many of its elements are very basic (e.g. explanations of encryption and authentication technology, what <a href='http://www.chakraborty.ch/development/it-security-of-in-vitro-diagnostic-instruments-and-software-systems/'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p>Standard issued by the Clinical Laboratory Standards Institute (CLSI), document ID &#8220;Auto-11P&#8221;.  One of several recent attempts to specify standards for IT security in medical devices.  Covers network security, separation of privileges, development best practices, as well as review techniques.  Many of its elements are very basic (e.g. explanations of encryption and authentication technology, what is a firewall, etc.) and rely on common sense, but then again the medical and IVD fields are about 10 years behind the technology curve as security is concerned.</p>
<p>The doc is targeted at 3 sensible groups; vendors (i.e. R&#038;D and support staff), end-users and customer IT managers.  There is provision made for the idea of protecting against data theft, although the prime issue in this area is data corruption by malware and other attacks.  As you are probably aware, the main problem facing medical device manufacturers is the inability to consistently patch systems to respond to newly discovered threats and vulnerabilities; every &#8220;change&#8221; to the nature of a system requires a complex and expensive re-validation process.</p>
<p>Naturally, the solution to this is &#8220;don&#8217;t develop purely oriented towards functionality&#8221;.  In plain English, don&#8217;t scrounge around for technology that just happens to be available, such as Windows XP, without proper design criteria and a fundamental evaluation and risk assessment process (what will the long-term cost be due to the fact that we used crappy technology to start out with&#8230;)  I&#8217;m hoping that the suggestions and requirements in this doc will narrow down the solutions chosen for development platforms such as diagnostic data stations to technologies considered secure and reliable by other industries&#8211;which have more experience in secure development.</p>
<p>Unfortunately, as it&#8217;s a commercial document I can&#8217;t post the text here, but it is available at <a target="_blank" href="http://webstore.ansi.org/ansidocstore/dept.asp?dept_id=57">http://webstore.ansi.org/ansidocstore/dept.asp?dept_id=57</a> and via CD-ROM subscription from CLSI.</p>
<p>From the press release at <a href="http://www.clsi.org">http://www.clsi.org</a>:<br />
<em>&#8220;Newly proposed Clinical and Laboratory Standards Institute (CLSI, formerly NCCLS) document IT Security of In Vitro Diagnostic Instruments and Software Systems; Proposed Standard (AUTO11-P) specifies technical and operational requirements, as well as technical implementation procedures related to security of IVD systems (devices, analytical instruments, data management systems, etc.) installed at a healthcare organization.  This document provides a framework for communication of IT security issues between the IVD system vendor and the healthcare organization.&#8221;</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.chakraborty.ch/development/it-security-of-in-vitro-diagnostic-instruments-and-software-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Health IT Security Wiki</title>
		<link>http://www.chakraborty.ch/healthcare-medical/the-health-it-security-wiki/</link>
		<comments>http://www.chakraborty.ch/healthcare-medical/the-health-it-security-wiki/#comments</comments>
		<pubDate>Fri, 03 Nov 2006 14:24:29 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[Healthcare & Medical]]></category>

		<guid isPermaLink="false">http://www.chakraborty.ch/wordpress/?p=7</guid>
		<description><![CDATA[The health IT security wiki is a community portal with links to and information about standardization groups, laws, and other interesting bits related to healthcare and medical IT security. It&#8217;s a pretty good starting resource and incorporates pointers to a lot of the compliance-relevant and technical standards in this field, which is pretty far behind <a href='http://www.chakraborty.ch/healthcare-medical/the-health-it-security-wiki/'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p>The health IT security wiki is a community portal with links to and information about standardization groups, laws, and other interesting bits related to healthcare and medical IT security.  It&#8217;s a pretty good starting resource and incorporates pointers to a lot of the compliance-relevant and technical standards in this field, which is pretty far behind financial services and other areas in terms of having a firm grasp on information security.</p>
<p>Many of the topics are ones I have worked on in recent projects, and as such I will be posting more links to related groups, as well as descriptions of what they do (I got to write a little tiny bit of the CLSI Standard for IVD IT Security, whee!)</p>
<p><a target="_blank" href="http://www.healthitsecurity.net/wiki/index.php?title=Main_Page">http://www.healthitsecurity.net/wiki/index.php?title=Main_Page </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.chakraborty.ch/healthcare-medical/the-health-it-security-wiki/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: basic

Served from: www.chakraborty.ch @ 2012-02-06 03:38:00 -->
