IT managers implement new technology to make sure law is on their side.
Overseeing data and telecom installations isn’t about technology for technology’s sake. Choices that IT managers make have to satisfy legal requirements, and the impact of simply following the law can be a catalyst for change in business.
At times, companies spend huge sums in the name of regulatory compliance. Take the Philadelphia Stock Exchange (PSE). According to Bernie Donnelly, vice president of quality assurance and control, PSE spent millions to automate how stockbrokers place trades to comply with Securities and Exchange Commission (SEC) rules.
“It’s a highly regulated industry to start with,” Donnelly says. “The SEC dictates what we have to do.”
In this case, the SEC has asked regulated firms to use industry-developed guidelines for electronic stock-quote processing by next year. At PSE, where options traders were accustomed to shouting out quotes on the exchange floor and placing orders over the phone, this has meant a shift to handheld computers and a Nortel-based 802.11b wireless network to share trading information.
“We had to take manual systems and make them automatic,” Donnelly says. Re-designing internal applications and networks to support wireless electronic data cost about $2 million to make sure the new stock-trading management system, which is ramping up now, fit in with the SEC guidelines. The trading floor is now much more quiet, he says.
PSE isn’t under legal obligation to follow another set of SEC guidelines instituted after Congress passed the Sarbanes-Oxley Act in the wake of the 2002 accounting scandals that rocked the stock markets. But Donnelly says PSE voluntarily is seeking to comply with Sarbanes-Oxley, which requires corporations to document internal controls and be able to rapidly disclose financial irregularities.
IT staff has met with in-house lawyers and audit teams to understand what technology changes might further compliance with Sarbanes-Oxley. “You’ve got to get the lawyers involved,” Donnelly notes. “You can’t do it on your own.”
NiSource, an energy utility in Merrillville, Ind., is obliged to comply with Sarbanes-Oxley.
“On the financial side, [Sarbanes-Oxley] wants to make sure access controls are well defined and that audit controls are in place,” says Pete White, senior security analyst at NiSource.
As one means to comply with Sarbanes-Oxley, NiSource has deployed Consul’s InSight Security Manager server-based audit and compliance-monitoring software to collect log data from about four dozen servers and other devices. “Consul is pulling in data from Unix, the [Cisco firewall] PIX and Windows, and then massaging it to give us information on what’s going on,” White says. “I have data going back to April in a 140-gigabit drive.”
Hospitals face their own set of regulatory demands.
“There are 52 regulatory agencies we have to deal with on the state and federal level,” notes Ken Bixel, CIO at Mount Nittany Medical Center in State College, Pa.
The U.S. Department of Health & Human Services regulations known as the Health Insurance Portability and Accountability Act (HIPAA) for privacy and security of patient data are paramount in the minds of hospital IT administrators.
“HIPAA has been my life,” Bixel says. The effort to understand complex HIPAA regulations has involved him in extensive discussion with lawyers and the hospital’s executive and administrative groups as they prepare for the April deadline.
“I don’t have a clinical background, so I have two people working for me who are health practitioners,” Bixel says. “One has a degree in clinical informatics and can translate what doctors say when we’re looking at technology to meet regulations.”
The hospital also has turned to outside consultants specializing in HIPAA, including Phoenix Health Systems of Gaithersburg, Md., for guidance.
“They can translate HIPAA into policy,” Bixel says. “Basically, you have to look at medical records and how secure they are.” In the end, he says it boils down to security best practices and common sense.
Another hospital, Denver Health, appointed a “HIPAA compliance employee,” a nurse whose job is solely to study HIPAA and guide the IS department on how to protect and secure data, says David Boone, the hospital’s IT manager.
HIPAA is leading to technology changes. Denver Health, for instance, switched from having its doctors and nurses use simple passwords for network authentication to using smart cards with digital certificates.
“HIPAA says you have to have a secure password, and the reason we went to smart cards is that it takes us a step beyond what the regulations mean,” Boone says. The hospital uses the Gemplus smart card combined with Microsoft-based digital certificates for authentication on what Boone says is a largely Microsoft-based LAN infrastructure.
As part of its effort on HIPAA, Community Health Network, a hospital group in Indianapolis, deployed the Vericept Acceptable Use Manager at its Internet gateway to watch for any sensitive patient information that might be sent out electronically, whether inadvertently or not.
The intention is to work with employees to ensure necessary data sharing is done with the patient’s privacy in mind, says Dave McClain, IS security manager at Community Health Network. He adds the Central Indiana HIPAA Working Group, which holds monthly meetings for area hospitals, has helped him understand the regulation.
HIPAA isn’t the only regulatory elephant in the room.
The national hospital accreditation organization known as the Joint Commission of Accreditation of Healthcare Organizations (JCAHO) sends in an inspection team at least once every few years to give hospitals a thorough check-up.
“They also look at your medical records and how secure they are,” Mount Nittany Medical Center’s Bixel says. The accreditation organization wants hospitals to have centralized nurse and doctor call systems. And they check to make sure refrigerators for storing medicines and patient lab specimens are at certain temperatures and that data is logged periodically.
That’s done manually today in a labor-intensive process, but JCAHO requirements have Mount Nittany’s IT staff pondering how to automate the process. If the hospital can figure out how to do that with wireless LANs, it will be another example of regulation driving technology adoption.




