ellen_messmer
Senior Editor, Network World

An Rx for security

News
Jun 19, 20065 mins

Hospitals get creative by using facial-image passwords, RFID, network-access control systems.

Passwords for network security are out and faces are in at ParadigmHealth. The Upper Saddle River, N.J., provider of care to seriously ill patients is adopting a Web-based authentication method that requires doctors, nurses and other users to remember images of nine faces to gain access to patient records through ParadigmHealth’s Web portal.

Passwords for network security are out and faces are in at ParadigmHealth.

The Upper Saddle River, N.J., provider of care to seriously ill patients is adopting a Web-based authentication method that requires doctors, nurses and other users to remember images of nine faces to gain access to patient records through ParadigmHealth’s Web portal.


Hospital finds a bloody good RFID application

“There’s a huge advantage in this high-security face recognition” over easily shared and compromised passwords, says Tom Hagen, CEO of the healthcare company, which is using technology from PassFaces.

Healthcare providers, not often viewed as IT innovators, are becoming increasingly aggressive and creative about network security. Their efforts go hand in hand with regulatory requirements to safeguard patient data, and recognize that wireless and other technologies fit the mobile jobs of doctors and nurses.

Kettering Medical Center Network in Dayton, Ohio, has embraced wireless for staff and patients. It is adopting fingerprint biometrics to secure patient data.

The organization, which includes five major hospitals and numerous smaller facilities for a total of about 7,000 employees, last month began installing Cisco-based wireless LAN (WLAN) technology. The rollout will provide nurses and doctors with laptops on carts and mounted on walls that will require fingerprint biometrics for authentication for access to patient data.

The Sentillion single-sign-on software used for the project will let authorized staff bring up electronic records from where they’re stored in Kettering’s primary data center, says Bob Burritt, director of technology.

Once the network is up, Kettering will provide wireless hot spots for patients seeking Internet access.

Memorial Healthcare, a 1,000-employee hospital in Owosso, Mich., is a few steps ahead. It already has a segmented WLAN for use by patients and staff. The hospital also has put about 100 computers in hospital rooms for use by staff caring for patients. The latest round of innovation at Memorial came in January when nurses were given RFID-based badges to wear that automatically lock computers when they walk away from them. (Read about how another hospital is using RFID to safeguard blood transfusions, above.)

“There’s now a USB antenna in the computer, and they walk a certain distance, it locks,” says Project Manager Frank Fear, citing Memorial’s use of software from Ensure Technologies.

Hospital staff have to authenticate with a fingerprint biometric to gain access to computers. To simplify electronic-records access for the nurses, Memorial, with help from Citrix and single-sign-on firm Imprivata, added a way to have the nurses’ electronic patient records roam with them from room to room.

“Before, they had to go pull up each patient’s record from several databases each time they entered a new patient room,” Fear says. “Our philosophy in this project is security needs to be coupled with convenience.”

One challenge Memorial has encountered in using the radio frequency-based proximity badges is that nurses easily adapt to them, but physicians find it harder because their schedules more frequently have them on the go outside the hospital.

New York Presbyterian Hospital also is taking IT security seriously, adopting the sort of network access control technology that many organizations are still only thinking about using.

New York Presbyterian has a system that includes 8,000 associated physicians and 14,000 other network users who can access records in databases in a mid-town data center connecting the organization’s two main hospitals via private-line dark fiber in Manhattan and the Bronx.

Earlier this year New York Presbyterian deployed appliances from start-up CounterStorm that plug into a switch to monitor traffic and shut down port access to infected machines. The appliances use anomaly detection rather than signature-based recognition to spot infected machines or attacks and shut off access to ports.

“We wanted to move to the prevention side,” says Soumitra Sengupta, information security officer at the hospital. “We had been using intrusion-detection systems but we were getting a large amount of fake positives in terms of alerts.”

Hospital finds a bloody good use for RFID

RFID tags and readers most commonly are associated with tracking goods in manufacturing and warehousing, but hospitals are starting to apply RFID for a new purpose: tracking blood.

At Italian hospital Ospedale Maggiore in Bologna, Dr. Daniele Luppi says patients last month began wearing RFID-based wristbands, each containing a unique alphanumeric code.

“A similar RFID module embedded in adhesive labels is used for identifying the request form for blood units and operators,” the transfusion specialist says.

A pocket-based computer called the Palmed, an RFID reader that can be used only after a fingerprint-based biometric authentication is completed, can read the identifications of the patient and the blood unit being used in any transfusion.

If the unique identifiers on the patient and the blood unit are a match, a wireless electronic seal on the blood unit is released, permitting the transfusion to occur. The check for the correct match is made through a server running software from Italian firm Tiomed, which designed the system for the hospital using RFID technology from U.S.-based SkyeTek.

Using RFID as a fail-safe mechanism in blood transfusion improves security because in the past, accuracy has always relied on “the attention of the operator,” Luppi says. “Human attention does not remain constant over time.” The RFID-based mechanism prevents human error that can turn into “serious incidents,” she says.

Sonia Rubertelli, operations manager at Tiomed, says European laws require the tracking of blood transfusions from donor and blood bank to patient, and the Tiomed’s RFID-based transfusion safety system also helps in automating information related to tracking the blood supply.