Hajar Sabuur Johnson & Johnson Worldwide Information Security June 16, 2005

Slides:



Advertisements
Similar presentations
Electronic Health Records for Clinical Research EHR/CR – Functional Profile.
Advertisements

Yukiko Ko Binding Corporate Rules – Global Implications Conference on Cross Border Data Flows and Privacy October 16, 2007.
ELTSS Alignment to Nationwide Interoperability Roadmap DRAFT: For Stakeholder Consideration in response to public comment.
EDUCAUSE 2001, Indianapolis IN Securing e-Government: Implementing the Federal PKI David Temoshok Federal PKI Policy Manager GSA Office of Governmentwide.
Federal PKI Architecture Update
Education Session: Healthcare Track July 2013 “Is the role of the Meeting Manager evolving into a Data Statistician?”
SLIDE 1 Westbrook Technologies from Fortis: A Healthcare Solution for Medical Records, Billing and HIPAA.
Identity Assurance at Virginia Tech CSG January 13, 2010 Mary Dunker
FIPS 201 Personal Identity Verification For Federal Employees and Contractors National Institute of Standards and Technology Information Technology Laboratory.
SAFE-BioPharma: Industry’s Digital Identity and Signature Standard Practical Use Cases Cindy Cullen CTO Oct. 1, 2008.
SAFE Implementation Toolkit How to use it. Implementation toolkit Overview Log-in Contents Search Toolkit Use Log-out.
SAFE BioPharma Association CONFIDENTIAL1 SAFE Public Key Infrastructure (PKI) 2005 EDUCAUSE/Dartmouth PKI Deployment Summit.
August 2004 Providing Industry-wide Security and Identity Management Solutions.
The Cape Town Convention’s International Registry: Decoding the Secrets of Success in Global Electronic Commerce Roksana Moore Soton Oxford University.
Identity Management Realities in Higher Education NET Quarterly Meeting January 12, 2005.
Page 1 Issues in and perspectives on electronic authentication of health professionals Pascal POITEVIN Marketing and Communication manager GIP-CPS e-Health.
EDUCAUSE Fed/Higher ED PKI Coordination Meeting
Health and Wellness for all Arizonans azdhs.gov Arizona Association for Home Care Presentation Arizona Department of Health Services July 25, 2015.
The Business of Identity Management Barry R. Ribbeck Director Systems Architecture & Infrastructure Rice University
Session 6: Data Integrity and Inspection of e-Clinical Computerized Systems May 15, 2011 | Beijing, China Kim Nitahara Principal Consultant and CEO META.
1. 2 ECRF survey - Electronic signature Mr Yves Gonner Luxembourg, June 12, 2009.
SAFE is a member-governed, not-for-profit enterprise that: Manages and promotes the SAFE standard Provides a legal and contractual framework Provides technical.
The 4BF The Four Bridges Forum The SAFE-BioPharma Digital Identity and Signature Standard.
GEORGE MILLER BLUE TEAM CS 410 Mobile Digital Signatures A Mobile Access Defense Health System (MADHS)
Regulatory Update Ellen Leinfuss SVP, Life Sciences.
Clinical Trials Market in Russia 17 October 2008 ROTOBO - ACTO.
Stakeholders In Clinical Research Government and Regulatory Bodies Professor Phil Warner.
The InCommon Federation The U.S. Access and Identity Management Federation
A Framework for Rational Decision Making. 2 Health Companies Alcon Abbott Laboratories Fund Baxter BD Boehringer Ingelheim Cares Foundation Bristol-Myers.
Johnson & Johnson’s Public Key Infrastructure Bob Stahl
Trusted Federated Identity and Access Management to provide the Cornerstone for Cyber Defense.
Health Records in Other Settings Ambulatory CareRehabilitation Long Term CareHome Care Mental Health Hospice.
Local Public Health System Assessment using the NPHPSP Local Instrument Essential Service 6 Enforce Laws and Regulations that Protect Health and Ensure.
1 EAP and EAI Alignment: FiXs Pilot Project December 14, 2005 David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
ECE Lecture 1 Security Services.
Chapter 6 – Data Handling and EPR. Electronic Health Record Systems: Government Initiatives and Public/Private Partnerships EHR is systematic collection.
1 June Richard Guida Stephanie Evans Johnson & Johnson Director, WWIS WWIS SAFE Infrastructure Overview.
CRIX: toward a secure, standards-based, clinical research information exchange.
+ National and Institutional Guidelines on Conflict of Interest in Physician-Industry Relationships.
1 7 th CACR Information Workshop Vulnerabilities of Multi- Application Systems April 25, 2001 MAXIMUS.
Lori Warrens The Partnership for Quality Medical Donations PQMD July 21,
Robert Guerra Director, CryptoRights Foundation Implementing Privacy Implementing Privacy: Rules of the Game for Developers Mac-Crypto Conference on Macintosh.
FDA Public Meeting on Electronic Records and Signatures June 11, 2004 Presentation of the Industry Coalition on 21CFR Part 11 Alan Goldhammer, PhD Chair.
Identity Management Working Group 2006 Member Meeting Tempe, AZ Barry Ribbeck Rice University.
International E-Health Conference “E-Health:around the clock care for everyone, everywhere” Quality in Health Care and Medical care E-Health in Friuli.
Transforming Government Federal e-Authentication Initiative David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
Overview of US PKI Peter Alterman, Ph.D. Chair, Federal PKI Policy Authority and Asst. CIO E-Authentication, NIH.
Chapter © 2012 Pearson Education, Inc. Publishing as Prentice Hall.
Legal, Regulations, Investigations, and Compliance Chapter 9 Part 2 Pages 1006 to 1022.
Content Introduction History What is Digital Signature Why Digital Signature Basic Requirements How the Technology Works Approaches.
Pfizer’s SAFE Use Case Michael Lavoie, CISSP, PMP Member, SAFE Board of Directors 24-FEB-2016.
The Federal E-Authentication Initiative David Temoshok Director, Identity Policy GSA Office of Governmentwide Policy February 12, 2004 The E-Authentication.
Cancer Clinical Trials Office Clinical Trials & Research Training Oct2014.
Contingent Workforce: Cerner Quality System & Regulations
Paperless & Cashless Poland Program overview
The Information Professional’s Role in Product Safety
ICH-GCP Avinash Kondawar M. Pharm Lead CRA
Microsoft 365 Get help with regulatory compliance
Digital Signature.
Building A Community of Trust to Transform Medicines Development
U.S. Federal e-Authentication Initiative
Introduction to TransCelerate
Employee Privacy and Privacy of Employee Information
EDUCAUSE Fed/Higher ED PKI Coordination Meeting
Overview of US PKI Peter Alterman, Ph.D.
FDA 21 CFR Part 11 Overview June 10, 2006.
Introduction to TransCelerate
HIMSS National Conference New Orleans Convention Center
E-Lock ProSigner ProSigner means “Professional Signer” signifying the software that can apply legally enforceable Advanced electronic signatures to electronic.
Global Politics: Regionalism and the EU Key terms
Presentation transcript:

Hajar Sabuur Johnson & Johnson Worldwide Information Security June 16,

What is SAFE? SAFE – Secure Access for Everyone – is a Standard Specifies technical, legal, and regulatory compliance standards A non-profit association (SAFE-Biopharma, Association) to manage the SAFE Standard The SAFE Standard delivers.. unique electronic identity credentials for legally enforceable & regulatory compliant access control and digital signatures across the global bio-pharmaceutical environment The SAFE Standard applies to all.. business to business, and business to government / regulator transactions © The New Yorker Collection 1993 Peter Steiner from cartoonlink.com. All rights reserved.

Impact of Today’s Environment The pharmaceutical industry spends over $1 billion per year on independent identity credentialing models –Over 200,000 clinical investigators sites, 1,500 CRO’s, 1,000 university medical centers, and 1,000 medical labs (the total amounts to ~700,000 individual users) all use Independent proprietary credentials for remote access to information systems Paper-based processes –Approximately 40% of all R&D costs are attributed to paper based business processes ($9 Billion in the US alone) –With global geographic locations & time zones, it can take between several days to even months to just obtain one signature on a paper document Paperwork = 31% of all health costs / $500 billion this year –Emergency Department: 1 hr. care/1 hr. of paperwork –Surgery & Inpatient Acute Care: 1 hr. care/36 min. paperwork –Skilled Nursing Care: 1 hr. care / 30 min. of paperwork –Home Health Care: 1 hr. care / 48 min. of paperwork Without a legally enforceable and interoperable identity and digital signature solution, the health care industry cannot eliminate or reduce the loss in time or financial impact of paper-based processes * New England Journal of Medicine, 2004

Key Points on SAFE SAFE Provides: –Common credential for access control to internal or business partner systems –Replaces hand-written signatures with digital signatures creating legally enforceable electronic records –Ensures data integrity of digitally signed documents Basis: –Hardware based solution (smart card or other device) 2-Factor security: something you have and something you know –Closed user community based on mutually agreed legal rules to ensure global enforceability among participating entities Bridges local and regional differences in digital signature laws (state, federal, European, etc)

One hardware device per person, which holds the digital identity Simplified user environment Common implementation standard across all biopharmaceutical companies Clinical Site Example Pharma A Pharma B NCI/caBIGPharma C Site ID Pharma D User ID/ Password Current Environment Goal SAFE Environment

SAFE Participants SAFE Members/Full Members: –Existing Members: Abbott Labs, AstraZeneca, Bristol Myers-Squibb, GlaxoSmithKline, INC Research, Johnson & Johnson, Pfizer, Procter & Gamble, Merck, Sanofi-Aventis –Ongoing Discussions: Eli Lilly, Schering Plough, Novartis, Genzyme, Wyeth, Quintiles, Akzo-Nobel/Organon Government entity memberships in discussion: –National Cancer Institute (NCI), EMEA, and various EU Member State Agencies Partners & Agencies –PhRMA (sponsor), EFPIA (sponsor), FDA (Reviewers for compliance), EMEA (will sponsor SAFE Pilot)

SBCA Update SBCA will be operational by mid July 2005 –Cybertrust acting as the SBCA Operational Authority (OA) –The SBCA directory LDAP only –The SBCA OCSP Responder SBCA test environment is available for SAFE Issuers. Cross certification with the SBCA –Indicate the issuer is SAFE complaint - SAFE Accredited Issuer –Request for Cross Certification after July 2005 SAFE 2.0 –Many SAFE Issuers will cross certify with the SBCA by end of year or early next year