Download PDF
Medical Information Protected by Barracuda NG Firewall
Technology Category
- Cybersecurity & Privacy - Network Security
- Cybersecurity & Privacy - Security Compliance
Applicable Industries
- Healthcare & Hospitals
- Education
Applicable Functions
- Business Operation
- Facility Management
Services
- System Integration
- Testing & Certification
The Challenge
An essential element of the scientific work at the INM is storage and processing of person and patient-related information. Very tight legal stipulations defined by the Bavarian and Federal Data Protection Acts must be adhered to when dealing with this sensitive data. All data protective measures must stand up to an intensive discussion and examination with the controller for data protection at the University Hospital in Munich. It soon became clear to those responsible for IT at the Institute that the existing firewall solution—a pure packet filter solution—could no longer satisfy the current technical security requirements under the existing conditions. The four-man IT department at INM managed by Dr. Marc Lazarovici, M.D. began searching for a suitable alternative. The IT Team initially defined the core requirements for a new solution at the beginning of the evaluation phase. The following criteria had to be fulfilled: Increasing security standards: In addition to meeting the strict data protection law stipulations, an effective solution was required to counter the diverse attack attempts and malicious code activities. It was clear at this point that the route which the Institute for Emergency Medicine had to follow was to move away from a pure packet solution and onto an application level firewall. Secured access to the Institute’s network via VPN: The 30 full-time employees and their external colleagues should have easy access from outside onto the Institute’s network, without compromising the security. Increasing failsafe security: The new system should have a redundant concept. Several physical computers in distributed premises should be used here.
About The Customer
The first organization in a German-speaking university with a focus on teaching and researching emergency medicine and medicine management was founded in 2002. The INM, Institute for Emergency Medicine and Medicine Management was established as an interdisciplinary clinical organization at the Munich University Hospital by the Bavarian Ministry for Science, Research and Art. This research work involves the analysis and assessment of high volumes of patients’ data, so protecting this is a matter of the highest priority. This can only be guaranteed by a security solution that meets rigorous standards.
The Solution
Following an intensive evaluation phase, Dr. Lazarovici’s IT department decided in favor of using a Barracuda solution. The Institute required a solution that would reliably guarantee that communications could continue running, even under difficult circumstances. The requirements also covered administrative efficiency increases with adapted management concepts. The Barracuda NG Firewall was clearly the best solution in all areas. The implementation of the Barracuda NG Firewall ran smoothly, despite some specific special issues which were inherent to the project. The transition to Barracuda NG Firewall took place simultaneously with a move to new premises by both the Institute and the computing center. However, the entire system had to remain constantly accessible and available throughout the entire transition. It was inconceivable that the system be down for a period of several hours. On the one hand, employees and students work continuously with the Internet and on the other, a high number of web servers were hosted in the Institute’s computing center, including the main server for teaching at the faculty of medicine. The old solution was still in operation while the new system was initially activated for selected parts of the network. Some VPN clients were also assigned to some testers. Since no problems arose during this test phase, the new system was transferred to the entire system in one major conversion process. This took place with a downtime of just a few minutes. The entire process, from the conception to the final transition, took three weeks.
Operational Impact
Quantitative Benefit
Related Case Studies.
Case Study
Hospital Inventory Management
The hospital supply chain team is responsible for ensuring that the right medical supplies are readily available to clinicians when and where needed, and to do so in the most efficient manner possible. However, many of the systems and processes in use at the cancer center for supply chain management were not best suited to support these goals. Barcoding technology, a commonly used method for inventory management of medical supplies, is labor intensive, time consuming, does not provide real-time visibility into inventory levels and can be prone to error. Consequently, the lack of accurate and real-time visibility into inventory levels across multiple supply rooms in multiple hospital facilities creates additional inefficiency in the system causing over-ordering, hoarding, and wasted supplies. Other sources of waste and cost were also identified as candidates for improvement. Existing systems and processes did not provide adequate security for high-cost inventory within the hospital, which was another driver of cost. A lack of visibility into expiration dates for supplies resulted in supplies being wasted due to past expiry dates. Storage of supplies was also a key consideration given the location of the cancer center’s facilities in a dense urban setting, where space is always at a premium. In order to address the challenges outlined above, the hospital sought a solution that would provide real-time inventory information with high levels of accuracy, reduce the level of manual effort required and enable data driven decision making to ensure that the right supplies were readily available to clinicians in the right location at the right time.
Case Study
Gas Pipeline Monitoring System for Hospitals
This system integrator focuses on providing centralized gas pipeline monitoring systems for hospitals. The service they provide makes it possible for hospitals to reduce both maintenance and labor costs. Since hospitals may not have an existing network suitable for this type of system, GPRS communication provides an easy and ready-to-use solution for remote, distributed monitoring systems System Requirements - GPRS communication - Seamless connection with SCADA software - Simple, front-end control capability - Expandable I/O channels - Combine AI, DI, and DO channels
Case Study
Driving Digital Transformations for Vitro Diagnostic Medical Devices
Diagnostic devices play a vital role in helping to improve healthcare delivery. In fact, an estimated 60 percent of the world’s medical decisions are made with support from in vitrodiagnostics (IVD) solutions, such as those provided by Roche Diagnostics, an industry leader. As the demand for medical diagnostic services grows rapidly in hospitals and clinics across China, so does the market for IVD solutions. In addition, the typically high cost of these diagnostic devices means that comprehensive post-sales services are needed. Wanteed to improve three portions of thr IVD:1. Remotely monitor and manage IVD devices as fixed assets.2. Optimizing device availability with predictive maintenance.3. Recommending the best IVD solution for a customer’s needs.
Case Study
HaemoCloud Global Blood Management System
1) Deliver a connected digital product system to protect and increase the differentiated value of Haemonetics blood and plasma solutions. 2) Improve patient outcomes by increasing the efficiency of blood supply flows. 3) Navigate and satisfy a complex web of global regulatory compliance requirements. 4) Reduce costly and labor-intensive maintenance procedures.
Case Study
Harnessing real-time data to give a holistic picture of patient health
Every day, vast quantities of data are collected about patients as they pass through health service organizations—from operational data such as treatment history and medications to physiological data captured by medical devices. The insights hidden within this treasure trove of data can be used to support more personalized treatments, more accurate diagnosis and more advanced preparative care. But since the information is generated faster than most organizations can consume it, unlocking the power of this big data can be a struggle. This type of predictive approach not only improves patient care—it also helps to reduce costs, because in the healthcare industry, prevention is almost always more cost-effective than treatment. However, collecting, analyzing and presenting these data-streams in a way that clinicians can easily understand can pose a significant technical challenge.