Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Health Care Pros Find Rx for Secure Portal

    Written by

    David Spark
    Published August 15, 2005
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Sue Merk keeps an Excel spreadsheet of compliments. As they come in, she appends them to the file. “I absolutely LOVE the fact that we never have to change our password!! Thank you!!” reads one compliment.

      If she likes a compliment, shell move it up on the Microsoft Corp. application and highlight it in yellow. “I rely on it daily and save a lot of time since I dont have to sit on hold with insurance companies for basic questions. I love it!” reads another compliment.

      These quotes come from users of OneHealthPort, the Seattle-based one-stop online security portal that facilitates medical professionals access to a network of more than 6,500 health care organizations in the Pacific Northwest. Merk is OHPs vice president of product management and business development.

      Before OHP launched three years ago, Merk said, some health care service providers were going through the costly experience of building and promoting a portal. Others just looked on and asked, “Wouldnt it be nice if we didnt all have to do this?”

      /zimages/4/28571.gifSome clinical trials are putting portals to use as well. Click here to read more.

      So in an effort to tackle a security project collectively and noncompetitively, a group called the Washington Healthcare Forum, comprising CEOs from many of Washington states health plans and large health systems, established OHP with the goal of creating a single portal for health care professionals.

      OHP wanted one place where doctors, nurses, insurance providers and vendors could get secure access to claims submissions, clinical information, prescriptions and other health care services that traditionally required phone calls and faxes for accreditation.

      “If we do it together, we share the costs and create something the community only has to use once,” Merk said.

      “Use once” turned into a recurring theme for OHP. The Forum wanted to construct a security portal that requires one registration, one agreement to sign and one log-on that gives users access to all participating sites. That objective raised questions. Could OHP do this? Does something like this already exist? Will it work with every organizations varying policies and restrictions?

      Not knowing the answers, Merk said, OHP put out an RFI (request for information) to see what might be possible.

      Building security

      Betrusted Inc., of Columbia, Md., answered the RFI and won the bid to build out OHPs infrastructure and maintain its system on an outsourced basis. (In November 2004, Betrusted joined with other security organizations to form Cybertrust Inc., of Herndon, Va.)

      Bob Bryan, head of identity and access management services for Cybertrust, had built a similar security portal, Transact Washington, the official state government Web site. Bryan knew what it was like to build security in a heterogeneous environment.

      “Were dealing with developing a piece of security infrastructure that had to play with multiple systems that were being independently developed by the other players in the community,” Bryan said.

      Unlike Bryans government effort, OHP was a commercial project and required a balance among security, ease of use and fast deployment. Merk said OHP wanted a solution that was loosely coupled, allowing participants to keep their existing architecture while still being able to grow with it.

      Security also had to have room to develop, Merk said. At launch, single-factor password log-ons would be sufficient, but in the future, participants wanted the option to layer on additional factors such as smart cards and USB tokens. But to get the project off the ground, OHP wanted to launch with a security offering that could be delivered with zero footprint on the desktop, meaning access could be had without having to install any software or hardware on each workstation. Merk said Betrusted delivered on all the demands, with the zero footprint being the one factor that really won the project for the integrator.

      Hybrid security

      OHP had to be designed so that health care professionals wanted to use it. An overly complicated registration and security procedure, for example, might limit participation. While OHP leaned toward a user ID/password system, it was wary of using strong passwords that required special characters and had to be changed every 90 days.

      “What [strong passwords] really do is, they drive people to write them down and post them on the front of their machine or some place you can find them. So they destroyed the security by making it too difficult to use,” said Merk.

      The other log-in option was to create a full-blown PKI (public-key infrastructure)-based digital certificate system, but that would have required installing software and possibly hardware on the desktop. Either need was eliminated when Betrusted found a hybrid solution from TriCipher Inc., of San Mateo, Calif.

      Next page: TriCipher to the rescue.

      TriCipher to the Rescue

      With the TriCipher system, users can choose a password that contains any number of characters, doesnt require special characters and never needs to be changed. When users enter their ID and password, an algorithm generates a coded hash of the password. That hash, not the password, is sent encrypted via an SSL (Secure Sockets Layer) connection to a secure appliance, where the second half of the key is waiting. The password is never stored. It just launches a chain of events.

      “It allowed us to use a system that looks like a standard user ID and password to the user, but it uses PKI in the background—which eliminates the need to actually store passwords on our central server,” Bryan said.

      In an effort to quickly deploy the system, reduce management and minimize security concerns, OHP didnt require every participant to maintain a database of users, said Merk.

      Instead of using a database, said Bryan, the TriCipher appliance would send a users authentication information one at a time via SAML (Security Assertion Markup Language) at the moment of log-on. When a participating health care provider or vendor receives a users validated credentials, it then chooses how much access it wants to grant to its particular site.

      The No. 1 problem in building out the system was finding the right people to register, said Barry Gordon, senior project director at GroupHealth Cooperatives Health Informatics division, in Seattle. At each contracted organization, there needs to be a coordination point. Finding that person wasnt easy, and it was always changing.

      “Some providers balked,” said Gordon as he retold an example of such an interaction: “Youre not the first guy whos come to me about Web sites. And I dont want to have to manage eight accounts for this billing person in my office. We want one.”

      After nine months of plugging away with a very manual registration process, Health Informatics was only able to set up about 700 accounts. Conversely, OHP has a delegated administrator model that allows an in-house person to set up accounts locally, allowing users to choose either online or offline registration.

      OHP had far greater success signing up users. Within just 18 months of its July 2003 launch, OHP signed up nearly 12,000 users. After the launch, Health Informatics slowly transitioned all its users to OHP and turned off its security infrastructure, opting to stand solely behind the OHP shell.

      Premera Blue Cross and Regence BlueShield, two of the largest health plans in the Northwest, were the first two to join. Group Health Cooperative joined two months later, and, as a result, their business reportedly tripled in just two weeks.

      “It was almost as if we drafted right behind Regence and Premera, and we benefited from all of the work that they did in setting up accounts,” said Gordon. “Because the [OHP] application has that value proposition to a provider, that when a provider gets set up based on Premera targeting them, not only do they get to use Premera, they get to use all these other sites. All of those positive externalities that result from just getting an account, we saw immediately.”

      OHPs Merk was stunned as well. “Who would guess that focusing on security, a fairly benign area that most people dont really like to deal with, would become such a great thing for a community.”

      Bryan said he believed it was the elimination of the central database that helped the community feel more comfortable about participating.

      “Its one thing if youre just an enterprise, because you can maintain all the control, but when you have to extend it out to a large community consisting of multiple entities, it was nice to get rid of that central risk point,” said Bryan.

      David Spark is a freelance writer in San Francisco. He can be reached at [email protected].

      Check out eWEEK.coms for the latest news, views and analysis of technologys impact on health care.

      David Spark
      David Spark

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.