ASP

A feature of the new environment is a requirement for the selected electronic medical record (EMR) systems to be hosted in and provided from an approved central data centre. This service is often referred to as an application service provider (ASP) environment - where data and the EMR application software is hosted off-site and not within the physician's clinic.

For physicians this means that all new EMR solutions will be hosted in the data centre selected by the EMR qualified service provider.* The ASP environment offers several enhanced security features for patient information over those provided in stand alone local installations, including:

Data Security - Alberta Health and Wellness has mandated that industry standards must be met by each qualified service provider (EMR vendor) within their ASP environments. The Med Access, Practice Solutions and Wolf Medical Systems ASP environments have been tested and all have met these rigorous standards.

Data Privacy - Each physician's patient data will be maintained separately in a partitioned database. There will be no consolidation or amalgamation of patient data between physicians-unless there is a need and agreement between physicians to such sharing.

Data Encryption - All patient data being transferred between the hosted data centre and the physician's office through an open Internet connection will be encrypted to ensure privacy and security.

Access Management - Access to patient data will be controlled giving only the physician and his/her staff or designate role-based access to the data. All access to data will be recorded and can be audited.

Reliability/Availability - Failure in the server hardware, power and communications network should not result in a loss of service to the physician's office - there will be no "single point of failure." Vendors must also provide network and application management as part of the hosted service, as well as disaster recovery to restore service quickly following a catastrophic event or failure.

Performance Monitoring - The performance and the responsiveness of the hosted services will be monitored to ensure the highest level of service is delivered to Alberta physicians.

Data Centre Security - The data centre itself will be required to meet rigourous security requirements, including monitored and secure access to the facility; power back up, cooling and fire suppression systems, and staffing on a 24/7 basis.

* In cases where a physician resides in an area without access to high speed Internet service, a local install of the EMR system may be permitted and supported.

Download the ASP Fact Sheet