ASP
A feature of the new environment is a requirement for the
selected electronic medical record (EMR) systems to be hosted in
and provided from an approved central data centre. This service is
often referred to as an application service provider (ASP)
environment - where data and the EMR application software is hosted
off-site and not within the physician's clinic.
For physicians this means that all new EMR solutions will be
hosted in the data centre selected by the EMR qualified service
provider.* The ASP environment offers several enhanced security
features for patient information over those provided in stand alone
local installations, including:
Data Security - Alberta Health and Wellness has
mandated that industry standards must be met by each qualified
service provider (EMR vendor) within their ASP environments. The
Med Access, Practice Solutions and Wolf Medical Systems ASP
environments have been tested and all have met these rigorous
standards.
Data Privacy - Each physician's patient data
will be maintained separately in a partitioned database. There will
be no consolidation or amalgamation of patient data between
physicians-unless there is a need and agreement between physicians
to such sharing.
Data Encryption - All patient data being
transferred between the hosted data centre and the physician's
office through an open Internet connection will be encrypted to
ensure privacy and security.
Access Management - Access to patient data will
be controlled giving only the physician and his/her staff or
designate role-based access to the data. All access to data will be
recorded and can be audited.
Reliability/Availability - Failure in the
server hardware, power and communications network should not result
in a loss of service to the physician's office - there will be no
"single point of failure." Vendors must also provide network and
application management as part of the hosted service, as well as
disaster recovery to restore service quickly following a
catastrophic event or failure.
Performance Monitoring - The performance and
the responsiveness of the hosted services will be monitored to
ensure the highest level of service is delivered to Alberta
physicians.
Data Centre Security - The data centre itself
will be required to meet rigourous security requirements, including
monitored and secure access to the facility; power back up, cooling
and fire suppression systems, and staffing on a 24/7 basis.
* In cases where a physician resides in an area without
access to high speed Internet service, a local install of the EMR
system may be permitted and supported.
Download the ASP
Fact Sheet