ABELMed Platfrm Setup Cnventins 1 Intrductin 1.1 Purpse f this dcument The purpse f this dcument is t prvide prspective ABELMed licensees and their hardware vendrs with the infrmatin that they will require t prepare fr the installatin and peratin f ABELMed. It will start with a brief verview f typical platfrms, and then prvide specific infrmatin that will be required t cnfigure an ABELMed ready platfrm. The sectins n cnfiguratin are mderately technical and intended primarily fr the use f the hardware vendr r IT prfessinal that will be cnfiguring the system. They are nt detailed instructins, it is expected that a cmpetent IT prfessinal will be familiar with these ubiquitus platfrms, and understand the cnventins. If yur hardware vendr needs clarificatin n any f the pints, please have them call r email ABEL. We are happy t cperate and wrk with yur hardware vendr t ensure that they get all the infrmatin required t get yur system setup fr ABELMed. 1.2 General Platfrm Overview ABELMed runs n the Micrsft Windws perating systems, and uses the Micrsft SQL Server database. ABEL can bundle RUNTIME licenses fr MS SQL Server with yur ABELMed licenses. ABELMed is designed t scale frm small peer t peer netwrks with just a cuple wrkstatins, t larger netwrks in busy clinics with dedicated servers serving administrative and clinical wrkstatins in examinatin rms. The smaller netwrks, say with less than 5 wrkstatins, can be served by a wrkgrup cnsisting entirely f cmputers running the Micrsft Windws XP Prfessinal perating system. The Wrkgrup Editin f SQL server wuld suffice in such an envirnment. On netwrks with 5 r mre wrkstatins, a file server with the Micrsft Windws Sever 2003 perating system (r Windws Small Business Server 2003) is recmmended. The Windws Server 2003 perating system supprts larger netwrks and advanced features such as Active Directry security dmains, disk mirrring, terminal services, and many ther features and tls. Sme practices with less than 5 wrkstatins pt fr a dedicated server with the server versin f the perating system in rder use active directry, r disk mirrring, r ther such features. Nte: SQL Server 200x Standard Editin will nt wrk n a small server running Windws XP. Wrkgrup Editin is apprpriate in such envirnments. 1.3 Hw t prceed ABEL recmmends that when lking int purchasing yur hardware, perating system, and ther sftware fr ABELMed that yu get at least three qutes. Please make sure that yu prvide the ABELMed hardware Platfrm Requirements tables, and these setup cnventins, s that the hardware vendr can include setup t these cnventins in the price that yu are quted. Current platfrm requirements and setup cnventins are always available n the ABEL website http://www.abelmed.cm. Sme custmers pt t purchase their wn hardware frm vendrs that d nt prvide setup and installatin services. In such cases yu are likely t require the services f an experienced technical persn wh can understand these setup cnventins and cnfigure the system(s) in cnfrmance with the cnventins. If yu are dealing with a hardware vendr that yu have nt wrked with in the past, ABEL recmmends checking references. In many areas ABEL can prvide the names f hardware vendrs wh have prepared ABELMed systems in the past. The IT persn setting up the systems shuld read this full dcument befre setting up the systems. The cnventins are nt necessarily in the rder that they will be perfrmed; rather they are gruped by subject. Servers, Database, Clients, etc.. ABELMed Setup Cnventins Page 1 f 8 Last updated June 26, 2009
ABELMed Platfrm Setup Cnventins 2 Server Setup Cnventins 2.1 Operating system 2.1.1 Windws Server 2003 2.1.1.1 Setup Please cnfrm t the fllwing cnventins when setting up a Micrsft Windws 2003 Server. We recmmend that an Active directry dmain be set up. We recmmend an NTFS file system. Setup TCP/IP as the netwrk prtcl. Cnfigure a DHCP server t assign the IP addresses. ABEL recmmends a ruter with a firewall n all high speed Internet cnnectins. Name the cmputer with the custmer s ABEL client ID number. Fr example if the ABEL custmer ID number is CØ9999 OMG, name the server CØ9999. Yu can get the custmer ID number by calling ABEL s sales department and asking fr it. An Active directry dmain is nrmally set up if using Windws Server 2003. With AD, user accunts nly have t be set up n the server, nt n each wrkstatin. Create an accunt fr each user. Create an ABELMed Users security grup Ensure that each accunt has a passwrd. The users shuld change their passwrd the first time they lg in. Disable the guest accunt. Put a passwrd n the administratr accunt. Make sure that the apprpriate persn at the ffice r clinic has this passwrd. Nrmally the dentist, ffice manager, r IT persn. Navigate t C:\ABELMed and right click and select Prperties>Security tab>select Users>uncheck Full Cntrl If the custmer will nt have Internet access, then install and cnfigure Ruting and Remte Access Server (RRAS) s that ABEL will have a means f accessing the machine, shuld the custmer need supprt. Install pcanywhere if the custmer has purchased it t facilitate supprt. If a custmer des nt have pcanywhere, enable Remte Desktp access t facilitate remte supprt by ABEL. If the custmer will nt have an Internet Cnnectin and is using RRAS t allw supprt cnnectivity, then create an accunt fr ABEL t use when they have t lg in t prvide supprt fr the prduct. Please cntact ABEL directly t prvide the username and passwrd, d nt email this type f infrmatin. Make sure that the ABEL user has dial in permissins and is part f the ABELMed users grup. ABEL s nrmal Internet based supprt methds d nt require that ABEL have an accunt. If ABELMed will ever be run n the server set the display reslutin t at least 1024x768. Install the mst recent perating system service pack, and all critical patches and htfixes frm Micrsft. Turn ff any CPU pwer savers. Display pwer savers shuld be fine, but refrain frm using third party screensavers. Turn ff Hibernatin. Install the latest drivers fr all printer(s). ABELMed Setup Cnventins Page 2 f 8 Last updated June 26, 2009
ABELMed Platfrm Setup Cnventins Install and cnfigure any required tape backup drivers and prgrams. ABEL recmmends the backup prgram that cmes with Windws 2003. Shrtcuts shuld be setup n the desktp fr all users, r apprpriate users, t: The backup prgram, t facilitate ASR (Autmatic System Recvery) backups, Perfrm a Full System backup with System State, Data nly backups. This will have t be setup after ABELMed is installed. ABEL recmmends that the ABELMed flder and its sub flders be backed up. Nte: A regular user will nt have apprpriate privileges t perfrm full system backups; any users that perfrm backups will have t be added t the Backup Operatr s grup. A backup schedule can als be set. Mst custmers will have enugh space available n tape t perfrm a full backup with system state n a daily basis. This is recmmended fr small ffices withut an n site IT persn t ensure that all data frm all applicatins is backed up. Mre sphisticated backup rtatins can be set up if and when space becmes an issue. If the custmer has a high speed always n Internet cnnectin it is recmmended that Autmatic Updates be turned n. Setup the default grup plicy fr the dmain t: Nte: Setting these plicies is mandatry in rder t meet CCHIT and OntariMD certificatin standards hwever the exact numbers can be decided by each practice. Our recmmended values are belw. The audit plicies are mandatry. Maximum passwrd age enabled fr 90 days Passwrd must meet cmplexity requirements Accunt lckut duratin set t 15 minutes Accunt lckut threshld enabled fr 3 attempts Reset accunt lckut cunter set t 15 minutes Audit accunt lgn events enabled fr success/failure Audit accunt management enabled fr success/failure Audit lgn events enabled fr success/failure Audit bject plicy enabled fr success/failure Audit plicy change enabled fr success/failure Screen saver passwrd prtected enabled fr 3 minutes Netwrk security: D nt stre LAN Manager hash value n next passwrd change t enabled Turn ff unnecessary Services such as Messenger, IIS (If it will nt be needed) and FTP. If using these services d nt allw annymus access. Install and cnfigure a reputable Antivirus Prduct. Set it up t autmatically get updates regularly. It shuld be cnfigured fr Real time scanning and fr at least 1 full disk scan per week. Mst prducts d nt require that require that the ABELMed flder be added t exceptins. 2.1.1.2 Testing If there is n Internet cnnectin, test RRAS by calling in via the mdem using Dialup Netwrking. Test Remte Desktp Sharing r pcanywhere. ABELMed Setup Cnventins Page 3 f 8 Last updated June 26, 2009
ABELMed Platfrm Setup Cnventins Test Windws printing frm all wrkstatins, t all printers t which they will need t print. 2.1.2 Windws XP Prfessinal File Server 2.1.2.1 Setup Please cnfrm t the fllwing cnventins when setting up a Windws XP Prfessinal File server We recmmend an NTFS file system. Setup TCP/IP as the netwrk prtcl. We nrmally cnfigure TCP/IP t btain an IP autmatically. ABEL recmmends a ruter with a firewall n all high speed Internet cnnectins. The ruter if available usually des DHCP. If there is nt a ruter, XP will use Autmatic Private IP Addressing (APIPA). Name the cmputer with the custmer s ABEL client ID number. Fr example if the ABEL custmer ID number is CØ9999 OMG, name the server CØ9999. Yu can get the custmer ID number by calling ABEL s sales department and asking fr it. TURN OFF simple file sharing. Open My cmputer > Tls >Flder Optins >G t the view Tab>Uncheck simple file sharing. While yu are here als uncheck Hide extensins fr knwn file types. Create an accunt fr ABELMed users. An accunt can be set up fr each user, but yu shuld be aware that this accunt wuld have t be set up n all client machines frm which the user will be running ABELMed. This will require a little mre nging maintenance t administer the accunts when yu have staff changes. It is up t individual custmers t decide what is best fr their practice. Certified Slutins require accunts fr each user. Create an ABELMed Users security grup The ABELMed users shuld nt be part f the administratr grup. Ensure that each accunt has a passwrd. The users shuld change their passwrd the first time they lg in. Disable the guest accunt. Put a passwrd n the administratr accunt. Make sure that the apprpriate persn at the ffice r clinic has this passwrd. Nrmally the dentist, ffice manager, r IT persn. Navigate t C:\ABELMed and right click and select Prperties>Security tab>select Users>uncheck Full Cntrl If the custmer will nt have Internet access, then install and cnfigure Ruting and Remte Access Server (RRAS) s that ABEL will have a means f accessing the machine, shuld the custmer need supprt. Install pcanywhere if the custmer has purchased it t facilitate supprt. If a custmer des nt have pcanywhere, enable Remte Desktp access t facilitate remte supprt by ABEL. Steps t cnfigure RRAS Setup mdem Netwrk cnnectins>create a new cnnectin>wizard starts>next>setup an Advanced cnnectin>next>accept Incming cnnectins>next>select mdem>next> Select d nt allw virtual private cnnectins>next>select the ABEL supprt user > Next >Check TCP/IP>Next>Finish If the custmer will nt have an Internet Cnnectin and is using RRAS t allw supprt cnnectivity, then create an accunt fr ABEL t use when they have t lg in t prvide supprt fr the prduct. Please cntact ABEL directly t prvide the username and passwrd, d nt email this type f infrmatin. Make sure that the ABEL user has dial in permissins and is part f the ABELMed users grup. ABEL s nrmal Internet based supprt methds d nt require that ABEL have an accunt. ABELMed Setup Cnventins Page 4 f 8 Last updated June 26, 2009
ABELMed Platfrm Setup Cnventins Set the display reslutin t at least 1024x768. Install the mst recent perating system service pack, and all critical patches and htfixes frm Micrsft. Turn ff any CPU pwer savers. Display pwer savers shuld be fine, but refrain frm using third party screensavers. Turn ff Hibernatin. Install the latest drivers fr all printer(s). Install and cnfigure any required tape backup drivers and prgrams. ABEL recmmends the backup prgram that cmes with Windws XP Prfessinal. Shrtcuts shuld be setup n the desktp fr apprpriate users, t: The backup prgram, t facilitate ASR (Autmatic System Recvery) backups, Perfrm a Full System backup with System State, Data nly backups. This will have t be setup after ABELMed is installed. ABEL recmmends that the ABELMed flder and its sub flders be backed up. Nte: A regular user will nt have apprpriate privileges t perfrm full system backups; any users that perfrm backups will have t be added t the Backup Operatr s grup. A backup schedule can als be set. Mst custmers will have enugh space available n tape t perfrm a full backup with system state n a daily basis. This is recmmended fr small ffices withut an n site IT persn t ensure that all data frm all applicatins is backed up. Mre sphisticated backup rtatins can be set up if and when space becmes an issue. If the custmer has a high speed always n Internet cnnectin it is strngly recmmended that Autmatic Updates be turned n. Turn ff unnecessary Services such as Messenger, IIS (If it will nt be needed) and FTP. If using these services d nt allw annymus access. Install and cnfigure a reputable Antivirus Prduct. Set it up t autmatically get updates regularly. It shuld be cnfigured fr Real time scanning and fr at least 1 full disk scan per week. Sme prducts require that ABELMed be added t exceptins. Setup the grup plicy t: Nte: Setting these plicies is mandatry in rder t meet CCHIT and OntariMD certificatin standards hwever the exact numbers can be decided by each practice. Our recmmended values are belw. The audit plicies are mandatry. In an XP based peer peer / wrkgrup envirnment this plicy must be established n each machine. Maximum passwrd age enabled fr 90 days Passwrd must meet cmplexity requirements Accunt lckut duratin set t 15 minutes Accunt lckut threshld enabled fr 3 attempts Reset accunt lckut cunter set t 15 minutes Audit accunt lgn events enabled fr success/failure Audit accunt management enabled fr success/failure Audit lgn events enabled fr success/failure Audit bject plicy enabled fr success/failure Audit plicy change enabled fr success/failure ABELMed Setup Cnventins Page 5 f 8 Last updated June 26, 2009
ABELMed Platfrm Setup Cnventins Screen saver passwrd prtected enabled fr 3 minutes Netwrk security: D nt stre LAN Manager hash value n next passwrd change t enabled 2.1.2.2 Testing If there is n Internet cnnectin, test RRAS by calling in via the mdem using Dialup Netwrking. Test Remte Assistance, Remte Desktp Sharing, r pcanywhere. Test Windws printing. 2.2 Database 2.2.1 Micrsft SQL Server 2005 Install MS SQL Server 2005 and prerequisites befre installing ABELMed. Remember t install all Service packs and htfixes fr Micrsft SQL Server 2005. ABELMed uses Windws authenticatin. The ABELMed installatin will create the required databases. It als creates a shrtcut, under Start>Prgrams>ABELMed Administratin. This shrtcut will run a script t autmate the creatin f typical maintenance schedules and backup jbs. After the SQL and ABELMed installatins apprpriate permissins have t be set n the databases using SQL Management Studi (SQL 2005) r Enterprise Manager (SQL 2000). Rather than adjusting permissins per individual user it is recmmended that permissins t the database be granted by User grups. This usually nly has t be dne nce per grup, nt fr each user. The steps are as fllws: 1. On the server, Start Enterprise Manager 2. Expand Micrsft SQL Servers>SQL Server Grup>(lcal) (Windws NT)>Security>Lgins 3. Right Click n Lgins and select New Lgin ABELMed Setup Cnventins Page 6 f 8 Last updated June 26, 2009
ABELMed Platfrm Setup Cnventins 4. Fr the Name Brwse and select the ABELMed Users Grup > Add> OK 5. On the Database Access Tab Select each f the ABELMed Databases and give ABELMed Users read/write access t all by selecting each database in turn and checking public db_datareader and db_datawriter. ABEL FirstData Lab ClinicalFrms Clinical AbelSecurity MedicalReprting 3 Client Machine Setup 3.1 Windws XP Prfessinal client machine 3.1.1 Setup Please cnfrm t the fllwing cnventins when setting up Windws XP Prfessinal client machines: ABELMed Setup Cnventins Page 7 f 8 Last updated June 26, 2009
ABELMed Platfrm Setup Cnventins We recmmend an NTFS file system. Setup TCP/IP as the netwrk prtcl. We nrmally cnfigure TCP/IP t btain an IP autmatically. ABEL recmmends a ruter with a firewall n all high speed internet cnnectins. The ruter usually des DHCP if there is a high speed Internet cnnectin. If there is nt a ruter, XP will use Autmatic Private IP Addressing (APIPA). Name the cmputer with the custmer s ABEL client ID number fllwed by a hyphen and a numeric extensin. Fr example if the ABEL custmer ID number is CØ9999 OMG, name the first client machine CØ9999 1, the secnd client machine CØ9999-2, and s n TURN OFF simple file sharing. Open My cmputer > Tls >Flder Optins >G t the view Tab>Uncheck simple file sharing. While yu are here als uncheck Hide extensins fr knwn file types. Create accunt(s) fr ABELMed users. The Accunt names and passwrds must exactly match the accunt(s) created n the server. The users shuld nt be part f the administratr grup, they shuld be part f the Users grup. Yu can create a grup fr ABELMed users but n mst systems, all regular users will be ABELMed users s the regular users grup can be used instead. Ensure that each accunt has a passwrd. The users shuld change their passwrd the first time they lg in. (this will have t be dne fr each user n all machines). Disable the guest accunt. Put a passwrd n the administratr accunt. Make sure that the apprpriate persn at the ffice r clinic has this passwrd. Nrmally the dentist, ffice manager, r IT persn. Set the display reslutin t at least 1024x768. Install the mst recent perating system service pack, and all critical patches and htfixes frm Micrsft. Turn ff any CPU pwer savers. Display pwer savers shuld be fine, but refrain frm using third party screensavers. Install the latest drivers fr all printer(s). If the custmer has a high speed always n Internet cnnectin, it is recmmended that Autmatic Updates be turned n. Turn ff unnecessary Services such as Messenger, IIS (If it will nt be needed) and FTP. If using these services d nt allw annymus access. Nte that sme practices use ABEL s case presentatin sftware & will need IIS. Install and cnfigure a reputable AntiVirus Prduct. Set it up t autmatically get updates regularly. It shuld be cnfigured fr Real time scanning and fr at least 1 full disk scan per week.. Sme prducts require that ABELMed be added t exceptins. 3.1.2 Testing Test Windws printing frm all wrkstatins. Make sure that the client machine can cnnect t the server and access shares created n the server. If yu create test shares, please remember t remve them when yu are thrugh. ABELMed Setup Cnventins Page 8 f 8 Last updated June 26, 2009