The challenge
A government health and care service was replacing its patient records with a new Electronic Patient Record (EPR) system, used by clinicians every day, connected to dozens of other clinical systems and supplied by several vendors. The programme needed a technical lead who could sit between the clinical programme, the vendors and the government’s IT department and keep a live clinical system secure, connected and performing.
What we did
As the programme’s technical subject-matter expert:
- Technical interface between the EPR programme and government IT, turning programme requirements into infrastructure and security delivery.
- Security testing and remediation: oversaw penetration testing of the EPR estate (infrastructure and web applications) and drove remediation with the vendors through to closure.
- Secure remote access: VPN access for vendors and end users, codes of connection and acceptable-use controls, and improved connectivity for visiting clinicians.
- Integrations: the network design for connecting the EPR to the other health systems through the integration engine, including radiology (RIS and PACS) systems.
- Performance assurance: non-functional load and performance testing, with an executive report giving clinical and executive leaders a clear governance position before go-live.
- Change control for live systems, from session timeouts to firewall and connectivity changes, and upgrade test planning.
The result
A clinical system that went forward with its security findings addressed, its connections documented and its performance assured, and with clinicians, vendors and government IT aligned around a single plan. The same discipline goes into every connected system we build. See about us.