Government & Policy
NHS Scotland has signed a new agreement with Microsoft to deploy Office 365 and migrate all systems to Windows 10 E5 during the next three years in an effort to boost cyber resilience and mitigate any potential threats.
"We're creating the environment and the tools to allow staff and services to flourish. At the moment they are too often hampered by systems that don't join up or make collaboration easy,” said Jeane Freeman, who was appointed as Scotland’s Health Secretary in June this year.
Freeman explained this included the development of a new national digital platform and setting out “common standards and approaches for healthcare systems”. HITN sister publication MobiHealthNews reported in August that Dr Alistair Hann, former Skyscanner Chief Technology Officer, had joined the NHS Digital Service, based within the national health board NHS Education for Scotland, to help build the new platform, working with Geoff Huggins, Director of the NES Digital Service, and Liz Elliot, former Chief Operating Officer at the Health Data Research UK institute.
Webinar: How Cybersecurity Leaders Avoid Data Breaches in Healthcare
Commenting on today’s announcement, Huggins told HITN:
"We're building a joined-up health and social care system, based on a National Digital Platform, so that people can get the best care, regardless of where they are. Moving to 365 is a fundamental building-block in that process."
Earlier this year, the Department of Health and Social Care agreed a centralised deal with Microsoft, enabling all NHS organisations to use Windows 10 and strengthen their cyber defence capabilities, nearly a year after the WannaCry attack disrupted operations at around one-third of NHS hospital trusts in England and 603 primary care and other NHS organisations.
NHS Scotland has the option to extend its three-year agreement with Microsoft for a further 24 months under similar terms.
Twitter: @1Leontina
Contact the author: lpostelnicu@himss.org
NHS Digital will cut around 500 jobs in a major restructure expected to "change the skills and capability of its workforce", Health and Social Care Secretary Matt Hancock has said.
Hancock confirmed earlier reports that the reconfiguration of NHS Digital would be delivered in a “series of waves”, set to be completed by 2020/21.
“At this stage, NHS Digital estimates that a net overall reduction in headcount of circa 500 full time equivalents is expected. A programme of staff engagement and discussions with staff representatives is in place. All staff will be affected by the restructuring and will be required to apply for posts in the new organisation structure,” the secretary told Parliament this week.
NHS Digital employs more than 2,500 staff around the country, including in London, Southport, and Southampton, while its head office is based in Leeds.
Computer Weekly reported earlier this year that NHS Digital organised several meetings with its staff to inform them of the restructure, with documents sent to employees indicating that those not be appointed by December this year would be offered the option to consider voluntary redundancy, according to an email seen by the publication.
Hancock said the agency would “provide every facility to help staff secure suitable alternate employment”.
“A professional outplacement service has been secured to work with displaced staff and NHS Digital is seeking opportunities with other public and private sector employers in the areas affected,” he explained.
Sean Walsh, NHS Digital Director of Regions and Professions, said:
“This restructure is about skilling up our workforce and rethinking our structure. This will ensure that we have the deep skills and technical expertise to deliver the best service for both patients and customers, and that our structure allows us to flex according to the needs of the health and care sector.
“We estimate that the restructure will lead to a net reduction of around 500 full time equivalent roles across the organisation. Where possible, this will be through a combination of redeployment, natural turnover and suitable alternative employment.
“It is important to note that we cannot be precise about the exact numbers at this stage because they may change to reflect the outcomes of the proposals for change, as well as external influences which may affect us.
“This is understandably a difficult and challenging time for our hardworking employees and we are taking every possible step to provide them with all the help and support they need.”
Twitter: @1Leontina
Contact the author: lpostelnicu@himss.org
ONC’s Senior Innovation Strategist Stephen Konya discusses the Health and Human Services road show visiting American cities to give digital health upstarts and entrepreneurs better access to federal agencies. The next HHS Startup Day is slated for Nov. 8, 2018 in Cleveland.
While the two federal agencies have worked together on vulnerability disclosures in the past, a new memorandum of agreement will improve coordination.
The cooperative aims to bring stakeholders together to find new and pragmatic approaches to data sharing, and come up with ways to combat information blocking.
The Food and Drug Administration issued a cybersecurity alert on two Medtronic devices that could allow a hacker to hijack the software update process to change the device’s function. Medtronic disabled the online software update to eliminate the flaw.
IMPACT
Following a review of potential security vulnerabilities around the internet connection, the FDA found 34,000 CareLink cardiac implantable electronic devices are at risk. If exploited, a hacker could change the programmer’s functionality or the device itself during the implantation or follow-up visits.
The flaw is found in the internet connection between the CareLink 2090 and Encore 29901 Programmers, used for downloading software from Medtronic’s Software Distribution Network. The programmers are used by providers to adjust the cardiac device settings and collect locally stored data.
While software updates typically include new software for the programmer functionality and updates to the implanted device firmware through a virtual private network, the programmers don’t verify they’re still connect to the VPN before downloading the updates.
As a result, attempting to update the program through the internet connection will result in an error message.
Medtronic updated its network, which was approved by the FDA on Oct. 5. The fix will intentionally block the currently existing programmer from accessing the Medtronic SDN. The vendor is continuing to implement security updates to further address the flaw.
The FDA recommends providers continue to use the programmers, as network connectivity isn’t required for normal CIEF programming. Further, providers should not attempt to update the programmer through the SDN, which is no longer available. Future updates are currently only available through Medtronic with a USB update.
THE TREND
Medical device vulnerabilities are well-known, and vulnerability reporting by vendors have increased 400 percent per quarter since the FDA released its cybersecurity guidance in 2016. However, the increase in FDA alerts is meant to further improve cybersecurity, rather than to shame the vendor.
Medtronic has reported several vulnerabilities in recent years, as has Philips, Abbott and a host of others.
.jumbotron{ background-image: url("http://www.healthcareitnews.com/sites/default/files/u2231/cybersecurity-jumbotron-712.jpg"); background-size: cover; color: white; } .jumbotron h2{ color: white; }
Focus on Cybersecurity
In October, we take a deep dive into security strategy and pressing threats.
Twitter: @JF_Davis_
Email the writer: jessica.davis@himssmedia.com
Technology was critical but so, too, were the personal and patient-centric stories shared on Twitter this week.
The two nonprofit health IT groups hope to strengthen public-private partnerships and advance policy, starting by collaborating on the next Health Datapalooza.
The U.S. Department of Health and Human Services is working with Healthbox, a HIMSS innovation company, to reach out to investors and better understand the barriers to innovation.
WHY IT MATTERS
"This is going to be the first time we formally engage the investment community," HHS Deputy Secretary Eric Hargan told Healthcare IT News. "We work with providers, payers, pharma, medical device companies all the time – but we never talk to the people who are funding those to understand their challenges."
HHS aims to change that with a series of events, dubbed Deputy Secretary's Innovation and Investment Summit, which was first announced in mid-September to bring together federal officials with investors and innovators.
"What we're trying to do is open the doors at HHS regarding investment in innovation," Hargan said. "We see the investment community as important to innovation within the sector and that is going to be a major way we solve the bedrock mission of the department to promote the health and wellbeing of American people."
Healthbox President Neil Patel said the summits will convene the perspectives across all of healthcare and Healthbox's role will be to bring its innovation expertise.
"One of the challenges will be figuring out what we can feasibly tackle," Patel said.
THE BIGGER TREND
Considerable innovation is happening in healthcare, with an explosion of apps and data on the horizon. But even more is needed in areas such as HIE, interoperability, patient experience and telehealth, for instance – and by many accounts the industry must move faster, because things are something of a mess today.
WHAT TO EXPECT FROM HHS
DSIIS will consist of quarterly meetings designed to foster innovation in digital health, life sciences, medical devices, IT and payment systems.
At those events, federal officials intend to listen to investors and innovators to ideally gain an understanding of which policies and regulations are getting in the way of funding for emerging technologies.
The idea is to find places where HHS has put up barriers that are troublesome and unnecessary, as well as "to make our policies more rational, get rid of duplicative and contradictory policies and to help HHS develop policies and regulations that facilitate investment in the healthcare sector."
HHS anticipates a yearlong process to get this from beginning to end, starting in December 2018, Hargan said.
The department might be able to move on some ideas quickly, while for others, particularly those requiring legislative changes, it's harder to determine how long that could take.
"Right now we're approaching this in an open way because the interaction has not happened so we have to look at it from a 30,000-foot level," Hargan said. "We've never engaged in a process like this, but I think there's probably fertile ground."
HOW TO APPLY
Investors interested in participating can apply until midnight Friday, October 12, 2018. They should send an email to DeputySecretary@HHS.gov with the subject line "DSIIS Recommendation."
The department is also looking for subject matter experts, so send suggestions to the same email address with the subject line "Topic and Subject Matter Expert Recommendation."
Twitter: SullyHIT
Email the writer: tom.sullivan@himssmedia.com