A compliance journey to the cloud how to build a medical cloud platform regulatory- and ISO27000-compliant. Carl Zeiss Meditec AG Thorsten Bischoff

Similar documents
The new IOLMaster 700 Next generation biometry from ZEISS. With SWEPT Source Biometry

YOUR WAY TO PRECISE OUTCOMES

NEW. The new IOLMaster 500 from ZEISS Defining biometry. Markerless Toric IOL Alignment

December Press Conference

ZEISS Medical Technology Company Presentation. Insights 2016/2017

Essential Line from ZEISS Simplicity in basic diagnostics

Compliance and Security in a Cloud-First Era

Level Access Information Security Policy

Oracle Buys Automated Applications Controls Leader LogicalApps

AWS Webinar. Navigating GDPR Compliance on AWS. Christian Hesse Amazon Web Services

ISO Gap Analysis Excerpt from sample report

Balancing energy and environmental demands

EU General Data Protection Regulation (GDPR) Achieving compliance

WELCOME ISO/IEC 27001:2017 Information Briefing

End-to-end Safety, Security and Reliability Keys for a successful I4.0 Migration

How to implement NIST Cybersecurity Framework using ISO WHITE PAPER. Copyright 2017 Advisera Expert Solutions Ltd. All rights reserved.

Balancing energy and environmental demands

European Union Agency for Network and Information Security

Managed Network Services. Managing your network to enable your digital business

Compliant. Secure. Dependable.

10 Considerations for a Cloud Procurement. March 2017

ISO / IEC 27001:2005. A brief introduction. Dimitris Petropoulos Managing Director ENCODE Middle East September 2006

Introduction. When it comes to GDPR compliance, is OK for now enough? Minds made for protecting financial services

Learn how to explain the purpose and business benefits of an ISMS, of ISMS standards, of management system audit and of third-party certification

Digital Healthcare. Yordan Iliev Director R&D Healthcare. Regional Cybersecurity Forum, November 2016, Grand Hotel Sofia, Bulgaria

PRESENTATION OVERVIEW

Swedish bank overcomes regulatory hurdles and embraces the cloud to foster innovation

IATF Stakeholder Conference

The Role of SANAS in Support of South African Regulatory Objectives. Mr. Mpho Phaloane South African National Accreditation System

Med-Info. Council Directive 93/42/EEC on Medical Devices. TÜV SÜD Product Service GmbH

ISO 27001:2013 certification

IMPLEMENTATION COURSE (MODULE 1) (ISO 9001:2008 AVAILABLE ON REQUEST)

NEW DATA REGULATIONS: IS YOUR BUSINESS COMPLIANT?

Integration Technologies Group, Inc. Uncompromising Performance

By 2020, a corporate no-cloud policy will be as rare as a no-internet policy is today. 1

Unisys Security Insights: Australia A Consumer Viewpoint 2015

Intelligent 3DHD Visualization for Microsurgery

CIAM: Need for Identity Governance & Assurance. Yash Prakash VP of Products

SUCCESS STORY INFORMATION SECURITY

How icims Supports. Your Readiness for the European Union General Data Protection Regulation

Controlled Document Page 1 of 6. Effective Date: 6/19/13. Approved by: CAB/F. Approved on: 6/19/13. Version Supersedes:

Med-Info. Council Directive 93/42/EEC on medical devices. TÜV SÜD Product Service GmbH

Operator cooperation in South Korea has created a successful identity solution. SK Telecom South Korea

_isms_27001_fnd_en_sample_set01_v2, Group A

The IECEE CB Scheme facilitates Global trade of Information Technology products.

Essential Line from ZEISS Simplicity in basic diagnostics NEW

Building YOUR Privacy Program: One Size Does Not Fit All. IBM Security Services

ioct Discover a new dimension with intraoperative OCT

With the successful completion of this course the participant will be able to:

ISO in the world today

Med-Info. Council Directive 93/42/EEC on medical devices. TÜV SÜD Product Service GmbH

Innovative Fastening Technologies

Avanade s Approach to Client Data Protection

GDPR: Get Prepared! A Checklist for Implementing a Security and Event Management Tool. Contact. Ashley House, Ashley Road London N17 9LZ

Global Mobile Patient Lifts Market Research Report 2018

SAMPLE. Cataract Surgery Devices Market Outlook in BRICS (Brazil, Russia, India, China, South Africa) to Reference Code: GDME0175BDB

CyberSecurity. Penetration Testing. Penetration Testing. Contact one of our specialists for more information CYBERSECURITY SERVICE DATASHEET

HS ALLEGRA 90. For efficient working

United4Health session Regulatory Framework Trends & Updates. Nicole Denjoy COCIR Secretary General Wed. 7 May 2014, Berlin (Germany)

ISO9001:2015 LEAD IMPLEMENTER & LEAD AUDITOR

Cyber Security and Data Protection: Huge Penalties, Nowhere to Hide

DQS Group. DQS Medizinprodukte GmbH August-Schanz-Straße Frankfurt am Main, Germany 04/

Twilio cloud communications SECURITY

What is ISO ISMS? Business Beam

AWS Security. Stephen E. Schmidt, Directeur de la Sécurité

Village Software. Security Assessment Report

Accelerate GDPR compliance with the Microsoft Cloud Ole Tom Seierstad National Security Officer Microsoft Norway

Checklist for Applying ISO 27000, PCI DSS v2 & NIST to Address HIPAA & HITECH Mandates. Ali Pabrai, MSEE, CISSP (ISSAP, ISSMP)

Access international opportunities

DQS Group. DQS Medizinprodukte GmbH August-Schanz-Straße Frankfurt am Main, Germany 04/

FACTS FIGURES TÜV SÜD AG

When Recognition Matters WHITEPAPER ISO SUPPLY CHAIN SECURITY MANAGEMENT SYSTEMS.

Keeler Accutome Connect. Your single source for ultrasound patient management

Keeler Accutome Connect. Your single source for ultrasound patient management

CA Security Management

ISO/IEC Information technology Security techniques Code of practice for information security management

This presentation is intended to provide an overview of GDPR and is not a definitive statement of the law.

ASD CERTIFICATION REPORT

Ensure safe and efficient mobility

ITG. Information Security Management System Manual

Crises Control Cloud Security Principles. Transputec provides ICT Services and Solutions to leading organisations around the globe.

John Snare Chair Standards Australia Committee IT/12/4

A company built on security

OPMI LUMERA 300 from ZEISS Best-in-class visualization. With new BrightFlex LED illumination

EXCiPACT: taking an idea to global reality

Introduction to AWS GoldBase

Fiscal year 2017: TÜV Rheinland continues growth strategy with investments in future-oriented topics

A HOLISTIC APPROACH TO IDENTITY AND AUTHENTICATION. Establish Create Use Manage

WLA Certification : Preparation and Management

TIVATO 700 from ZEISS Seize The Digital Future

Creating a Global Network

Security Aspekts on Services for Serverless Architectures. Bertram Dorn EMEA Specialized Solutions Architect Security and Compliance

EU Cloud Computing Policy. Luis C. Busquets Pérez 26 September 2017

Retail website certification

A Global Look at IT Audit Best Practices

Global Intraocular Lens (IOL) Market: Trends, Opportunities and Forecasts ( )

HS Hi-R NEO 900 For first class surgery

GDPR: The Day After. Pierre-Luc REFALO

Half Year Results February 2017

Achilles System Certification (ASC) from GE Digital

Transcription:

A compliance journey to the cloud how to build a medical cloud platform regulatory- and ISO27000-compliant Carl Zeiss Meditec AG Thorsten Bischoff

Carl Zeiss Meditec Company Snapshot Headquarters in Jena, Germany Revenue in million 861.9 906.4 909.3 1040.1 1088.4 1189.9 EBIT in million 122.9 133.8 120.7 130.6 154.3 180.8 Around 3,000 employees worldwide Listed on the TecDAX 59% of shares held by Carl Zeiss AG 11/12 12/13 13/14 14/15 15/16 16/17 11/12 12/13 13/14 14/15 15/16 16/17 Significant sales growth over the last five years Strong level of profitability (mid-term outlook: 14 16 % EBIT margin)

ZEISS Medical Technology Driving Progress in Medicine through Innovation As a world-leading medical technology company, we drive progress in medicine, enabling doctors to achieve the best possible outcomes for their patients Ophthalmic Devices Comprehensive solutions to diagnose and treat eye diseases Systems and consumables for cataract, retinal and refractive surgery Focus on networking of systems and the integrated management of data, to make workflows in hospitals and medical practices efficient Microsurgery Complete product range of visualization solutions for minimally invasive surgical treatments (e.g. Neuro, ENT, spinal, dental) Intraoperative diagnostics to enhance effectiveness and safety of surgical procedures complete with cuttingedge video technology and three-dimensional imaging Ophthalmic Diagnostics Refractive Laser Surgery Surgical Ophthalmology Visualization Surgical Oncology

You should always have the full perspective

and do not look through the fog

Cataract surgery in the past

Cataract surgery today Optical Biometry Markerless toric IOL alignment The Reference Image is the starting point of a markerless toric IOL workflow: an image of the eye is taken along with the keratometry measurement. Both, reference images and keratometry data are transferred to the ZEISS CALLISTO eye computer-assisted surgery system.

Cataract surgery today data management, diagnostic and surgery planning ZEISS FORUM Streamline your workflow Decide with confidence Simplify your environment

Cataract surgery with CALLISTO eye and LUMERA 700 Z ALIGN Toric Assistant Use the reference axis from the ZEISS IOLMaster 500 and target axis in your microscope eyepiece to ensure precise toric IOL alignment without corneal markers.

Business Motivation attending surgeons and referring ophthalmologists How does the patient data come into the operating room today? Around 70 % to 80 % using an USB stick or manual data entry at the microscope This is not safety neither secure! The surgeon needs a solution which helps him to fulfill his liability.

System Architecture EQ Mobile Site A Practice/Hospital Site B Practice/Hospital IOL Master FORUM/ EQ Mobile Plugin Personal mobile device of surgeon CALLISTO eye/ LUMERA 700 wireless via LAN wireless

AWS Cloud Native Services Secure EQ Mobile Architecture Load/Store EQ Mobile Write Index AWS Lambda Get Data Key Decrypt Data Key AWS Key Management Service Amazon API Gateway AWS Lambda Read Index Amazon DynamoDB Amazon S3 bucket Update Trigger Load Mobile User Authenticate Amazon Cognito

highly regulated medical and personal data Following highly regulated personal data and medical data are collected and processed. The data is needed and processed for administration, billing and as well as maintenance of said service. Personal data: People Master Data (e.g. first name, last name) Registration data (e.g. user name, password) Contact data (e.g. E-Mail, IP-address) Specific usage data (e.g. registration status/login, logging of uploads and downloads, reports) Patient data: Surgery planning and surgery report Diagnose data, keratometry data Patient demographic data (e.g. first name, last name, date of birth, ) Reference images

Medical regulations EU Medical Device Regulation (MDR) BfArM Medizinproduktegesetz (MDR) IEC 62304 13485:2016 Medical Device Regulation

Regulations for personal data and cybersecurity GDPR Privacy Act 1988 Australian Privacy Principles (APPs) Cybersecurity Federal Data Protection Act 2018 (BDSG 2018) catalogues Data Protection Act & Public Health Code

Real start of the journey We have a secure software, but now we have to establish Operations, because of data saving and data processing in AWS We have only a tiny feeling about the compliance More and more practice and hospitals ask after GDPR and ISO 27001 conform products Hospitals become critical infrastructure and request from the suppliers an Information Security Management System (ISMS) and ISO 27001 certified suppliers Operations We need an ISMS and a 27001 certificate

ISMS: Make or buy We need the 27001 certificate in 12 months! Is this possible within a bigger company with existing processes, quality management system and with all internal stakeholders? Do we have the competence to build an ISMS? Project partners: direkt gruppe is commissioned to build together with us an ISMS and to consult us to be conformable to the compliance Technology partner to consult and review our secure AWS infrastructure that complies with the requirements and to introduce the ISO 27001 certification The Austrian TÜV TRUST IT (TTIT) is involved as a certification specialist via direkt gruppe

How to get an ISO 27001 certificate? Requirements / expectations for information security Established Information Security Strategy Certificate ISO 27001 Management Initialization Processes Analysis Assets Planning - Realization Organization Measures Operation / continuous improvement certification Re- certification Audits Definition of context Initiate Management Commitment Create Security Policy set Build security Organization Planning Resources Staff training Definition of Risk Management Methodology Analysis of current state Identify Security and Compliance requirements Threat and Risk Assessments Identify Measures Create the security framework Build and realize the security strategy Definition of organizational and technical measures Configure and implement measures Regularly Awareness Campaign Measurement and evaluation of results Carrying out regularly Audits Build continuous improvement communication Execute certification audit Implement corrective actions from certification audit prepare Re-certification Source: TÜV Trusted IT

Hands-on Information Security Management System ISMS QMS for medical products IS Strategy Carl Zeiss Meditec New Policies and SOPs based on ISO 27001 AWS 27001 certification

Hands-on Compliance Regulatory highly regulated medical and personal data can be processed in the cloud, but the practice/hospital needs the help of the manufacturer to comply with the regulations and the compliance Practice/Hospital AWS CloudTrail Process patient data in cloud applications AWS KMS Amazon S3 AWS Shared Responsibility Carl Zeiss Meditec

Summary Regulatory and Compliance requirements are solved for EQ Mobile and another solution Best prepared for further products an their requirements ISO 27001 Certificate was given by third party TÜV Trust IT as approval for best design of solution using AWS services on sensitive personal data EQ Mobile Rollout After successful rollout to the pilot markets Germany, France, Australia, US Global rollout to United States, Europe, United Kingdom, Canada, Japan, New Zealand, South East Asia, India, Korea, Brazil, Mexico

Take away Business enabler ISO 27001 certificate: Marketing: Unique selling proposition to the competitors Increase your competitiveness - e.g. demand in tenders Minimize IT risks, possible damages and follow-up costs Lowering costs Speak the language of customers IT departments Compliance proof Reduce your liability risks

Thank You and Questions for best cooperation!