SlideShare a Scribd company logo
1 of 19
Preparing for Possibly, Maybe,
Handling PHI at the Broad Institute
IQPC 13th Laboratory Informatics Summit
Boston, MA
2016/12/06, v3
About the Speaker
Bruce Kozuma is a projectprogram manager in
the Broad Information Technology Services (BITS)
department with experience in software
development, operations, and IT in industries
such as manufacturing, telecommunications,
biotechnology, and biomedical research
Overview
• Title of this presentation was originally “Preparing
Laboratory Data at the Broad Institute for HIPAA
Compliance”
• It’s morphed, much like things at the Broad
• If you were expecting to hear about a settled plan, I’m sorry
to disappoint you
• The presentation may still be interesting however (you can
tell me at the break if you like)
About the Broad Institute of MIT & Harvard
• Propelling the
understanding and
treatment of disease
• Collaborating deeply
• Reaching globally
• Empowering scientists
• Building partnerships
• Sharing data and
knowledge
• Promoting inclusion
HIPAA and Laboratory Data at the Broad
• Broad is NOT Covered Entity nor a Business Associate
under HIPAA
• However, we collaborate with places that handle PHI, like
HMS, MGH, DFCI, BCH, just to name a few
• There is a big push for translational medicine, including at
the Broad, i.e., a push for both bringing clinical data into
research and delivering therapies more quickly
• Have a variety of laboratory data management solutions
due to:
• Legacy
• Funding sources
• Culture
Towards a Common Solution
Laboratory Data Management
• Project to provide centrally-managed solutions for
management of laboratory data, divided into functions:
• Data capturearchive (instruments and other sources)
• Container inventoryregistration (chemical,
biological, hybrid)sample management
• Core Electronic Laboratory Notebook (ELN, experiment
documentationIP protectionlinking to data)
• Dataworkflow management
• Data analysisvisualization
Context for LDM
• Make using LDM easy for scientists
• Have much of IT processes outside user’s daily work
• Introduce light system controls
• Slowly bring in compliance to enable science
• Had early success identifying those with needs, with
adoption, started down the compliance path
The Plan
• Make using LDM easy for scientists
• Have much of IT processes outside user’s daily work
• Introduce light system controls
• Slowly bring in compliance to enable science
• Had early success identifying those with needs, with
adoption, started down the compliance path
The Plan
LDM Compliance Assessment
• Started as a subset of the overall LDM project
• Goals
• Determine the regulations that most likely apply that relate to LDM,
e.g., HIPAA, CLIA, GxP, FISMA
• Establish baseline understanding of the Broad’s system
management practices with respect to LDM with those regulations
• Have a roadmap for improvement, with aim of being substantially
audit-ready at some point (likely a few years) in the future
• Do as much of the compliance work with as little impact on the
LDM user community as possible
Best Laid Plans of Mice and Men…
So What Now?
• Results is that the need to handle PHI at the Broad, not in
a few years in the future, but now
• Why?
• Researchers are often working at multiple institutions, e.g., HMS,
MGH, and the Broad
• PHI being handled at the partner institutions, resulting in barriers
to research
• Want to enable researchers to have more focus on their research,
and less on information technology and mechanics of meeting IRB
requirements
• Want researchers to do more of their research at the Broad
• Broad is challenged by having early stage offerings for
technical infrastructure and procedural controls for PHI
Practical Immediate Steps
• Ensure PIs are aware of the PHI-related risks they face
and explicitly accept those risks
• Encourage PIs to use resources of collaborators to handle
PHI (e.g., if DFCI has a preferred secure email vendor, use
theirs)
• Document what PIs can do with PHI at the Broad
Practical Immediate Steps
• Ensure PIs are aware of the PHI-related risks they face
and explicitly accept those risks
• Encourage PIs to use resources of collaborators to handle
PHI (e.g., if DFCI has a preferred secure email vendor, use
theirs)
• Document what PIs can do with PHI at the Broad
Longer Terms Steps
• Build on the work of the LDM Compliance Assessment
project/recast it as the PHI Compliance Readiness project
• Implement quality management framework for handling PHI
• Refine risk assessment methodology for outsourced partners
• Execute on plan to address prioritized HIPAA compliance gaps
Longer Terms Steps
• Propose projectsbudgets for technology and process
solutions to offer more services to PIs to streamline their
research by bringing PHI to the Broad
• Implement plan to proactively manage risks, e.g.:
• Implement necessary policies
• Raise awareness of responsibilities
and risks via training
• Establish clear response matrices to
guide people to answers
Things Learned Along the Way
• <>
• Embrace agility and get something out there
Things Learned Along the Way
• Hire outside expertise to parse Federal regulations
Things Learned Along the Way
• Partner with technology vendors who take time to listen
and understand your needs
• Responsive, proactive management makes a lot of things
possible
• Remember that the Broad pushes the edge of possible
• Compliance approach will remain unfinished because the Broad is
not done reinventing itself
• Engaging with the world of regulatory compliance, when the Broad
chooses what boundaries to push, makes things challenging
• Our solution (for now): enter into a continual compliance
conversation, where we can choose what parts of research are
done, by which party, where what capabilities the Broad offers or
should offer is considered

More Related Content

What's hot

PFL data collection – hands on session
PFL data collection – hands on sessionPFL data collection – hands on session
PFL data collection – hands on sessionISSDA
 
Data Governance in two different data archives: When is a federal data reposi...
Data Governance in two different data archives: When is a federal data reposi...Data Governance in two different data archives: When is a federal data reposi...
Data Governance in two different data archives: When is a federal data reposi...Carolyn Ten Holter
 
Almaden presentation 15-dec-2015
Almaden presentation 15-dec-2015Almaden presentation 15-dec-2015
Almaden presentation 15-dec-2015Paul Courtney
 
OU Library Research Support webinar: Working with research data
OU Library Research Support webinar: Working with research dataOU Library Research Support webinar: Working with research data
OU Library Research Support webinar: Working with research dataIzzyChad
 
Virginia Data Management Bootcamp: Building the Research Data Community of Pr...
Virginia Data Management Bootcamp: Building the Research Data Community of Pr...Virginia Data Management Bootcamp: Building the Research Data Community of Pr...
Virginia Data Management Bootcamp: Building the Research Data Community of Pr...Sherry Lake
 
Institutional Data Management Blueprint
Institutional Data Management BlueprintInstitutional Data Management Blueprint
Institutional Data Management BlueprintJisc
 
Empowering Data in Scholarly Publishing
Empowering Data in Scholarly PublishingEmpowering Data in Scholarly Publishing
Empowering Data in Scholarly PublishingCharleston Conference
 
How to Improve Research Visibility and Impact: Session 5, Online Repository
How to Improve Research Visibility and Impact: Session 5, Online RepositoryHow to Improve Research Visibility and Impact: Session 5, Online Repository
How to Improve Research Visibility and Impact: Session 5, Online RepositoryNader Ale Ebrahim
 
Increasing transparency in Medical Education through Open Data
Increasing transparency in Medical Education through Open Data Increasing transparency in Medical Education through Open Data
Increasing transparency in Medical Education through Open Data Rebecca Grant
 
Data visualisations: drawing actionable insights from science and technology ...
Data visualisations: drawing actionable insights from science and technology ...Data visualisations: drawing actionable insights from science and technology ...
Data visualisations: drawing actionable insights from science and technology ...EFSA EU
 
Common Ground: a policy framework for open access to research data
Common Ground: a  policy framework for open access to research dataCommon Ground: a  policy framework for open access to research data
Common Ground: a policy framework for open access to research dataLIBER Europe
 
Big Data in Biomedicine: Where is the NIH Headed
Big Data in Biomedicine: Where is the NIH HeadedBig Data in Biomedicine: Where is the NIH Headed
Big Data in Biomedicine: Where is the NIH HeadedPhilip Bourne
 
The value of emerging technologies for investigating academic practice
The value of emerging technologies for investigating academic practice The value of emerging technologies for investigating academic practice
The value of emerging technologies for investigating academic practice University of Otago
 
ELSS use cases and strategy
ELSS use cases and strategyELSS use cases and strategy
ELSS use cases and strategyAnton Yuryev
 
2018 Bio-IT World Agile in Wet Labs Speeds Big Data
2018 Bio-IT World Agile in Wet Labs Speeds Big Data2018 Bio-IT World Agile in Wet Labs Speeds Big Data
2018 Bio-IT World Agile in Wet Labs Speeds Big DataBruce Kozuma
 
The Vision for Data @ the NIH
The Vision for Data @ the NIHThe Vision for Data @ the NIH
The Vision for Data @ the NIHPhilip Bourne
 
Foundations for Discovery Informatics
Foundations for Discovery InformaticsFoundations for Discovery Informatics
Foundations for Discovery InformaticsPhilip Bourne
 
[3.4] Practical Benefits and Annoyences of Sharing Data - Daniël Lakens [3TU....
[3.4] Practical Benefits and Annoyences of Sharing Data - Daniël Lakens [3TU....[3.4] Practical Benefits and Annoyences of Sharing Data - Daniël Lakens [3TU....
[3.4] Practical Benefits and Annoyences of Sharing Data - Daniël Lakens [3TU....3TU.Datacentrum
 

What's hot (20)

PFL data collection – hands on session
PFL data collection – hands on sessionPFL data collection – hands on session
PFL data collection – hands on session
 
Data Governance in two different data archives: When is a federal data reposi...
Data Governance in two different data archives: When is a federal data reposi...Data Governance in two different data archives: When is a federal data reposi...
Data Governance in two different data archives: When is a federal data reposi...
 
Almaden presentation 15-dec-2015
Almaden presentation 15-dec-2015Almaden presentation 15-dec-2015
Almaden presentation 15-dec-2015
 
OU Library Research Support webinar: Working with research data
OU Library Research Support webinar: Working with research dataOU Library Research Support webinar: Working with research data
OU Library Research Support webinar: Working with research data
 
Virginia Data Management Bootcamp: Building the Research Data Community of Pr...
Virginia Data Management Bootcamp: Building the Research Data Community of Pr...Virginia Data Management Bootcamp: Building the Research Data Community of Pr...
Virginia Data Management Bootcamp: Building the Research Data Community of Pr...
 
Institutional Data Management Blueprint
Institutional Data Management BlueprintInstitutional Data Management Blueprint
Institutional Data Management Blueprint
 
Empowering Data in Scholarly Publishing
Empowering Data in Scholarly PublishingEmpowering Data in Scholarly Publishing
Empowering Data in Scholarly Publishing
 
How to Improve Research Visibility and Impact: Session 5, Online Repository
How to Improve Research Visibility and Impact: Session 5, Online RepositoryHow to Improve Research Visibility and Impact: Session 5, Online Repository
How to Improve Research Visibility and Impact: Session 5, Online Repository
 
Increasing transparency in Medical Education through Open Data
Increasing transparency in Medical Education through Open Data Increasing transparency in Medical Education through Open Data
Increasing transparency in Medical Education through Open Data
 
Data visualisations: drawing actionable insights from science and technology ...
Data visualisations: drawing actionable insights from science and technology ...Data visualisations: drawing actionable insights from science and technology ...
Data visualisations: drawing actionable insights from science and technology ...
 
Common Ground: a policy framework for open access to research data
Common Ground: a  policy framework for open access to research dataCommon Ground: a  policy framework for open access to research data
Common Ground: a policy framework for open access to research data
 
Why managedata
Why managedataWhy managedata
Why managedata
 
Big Data in Biomedicine: Where is the NIH Headed
Big Data in Biomedicine: Where is the NIH HeadedBig Data in Biomedicine: Where is the NIH Headed
Big Data in Biomedicine: Where is the NIH Headed
 
The value of emerging technologies for investigating academic practice
The value of emerging technologies for investigating academic practice The value of emerging technologies for investigating academic practice
The value of emerging technologies for investigating academic practice
 
ELSS use cases and strategy
ELSS use cases and strategyELSS use cases and strategy
ELSS use cases and strategy
 
Concept on e-Research
Concept on e-ResearchConcept on e-Research
Concept on e-Research
 
2018 Bio-IT World Agile in Wet Labs Speeds Big Data
2018 Bio-IT World Agile in Wet Labs Speeds Big Data2018 Bio-IT World Agile in Wet Labs Speeds Big Data
2018 Bio-IT World Agile in Wet Labs Speeds Big Data
 
The Vision for Data @ the NIH
The Vision for Data @ the NIHThe Vision for Data @ the NIH
The Vision for Data @ the NIH
 
Foundations for Discovery Informatics
Foundations for Discovery InformaticsFoundations for Discovery Informatics
Foundations for Discovery Informatics
 
[3.4] Practical Benefits and Annoyences of Sharing Data - Daniël Lakens [3TU....
[3.4] Practical Benefits and Annoyences of Sharing Data - Daniël Lakens [3TU....[3.4] Practical Benefits and Annoyences of Sharing Data - Daniël Lakens [3TU....
[3.4] Practical Benefits and Annoyences of Sharing Data - Daniël Lakens [3TU....
 

Similar to 2016 IQPC 13th Laboratory Informatics Summit Preparing for Possibly, Maybe, Handling PHI at the Broad Institute

Creating a Data Management Plan for your Research
Creating a Data Management Plan for your ResearchCreating a Data Management Plan for your Research
Creating a Data Management Plan for your ResearchRobin Rice
 
NIH Grants and Data: New Rules Coming in 2023
NIH Grants and Data: New Rules Coming in 2023NIH Grants and Data: New Rules Coming in 2023
NIH Grants and Data: New Rules Coming in 2023Erin Owens
 
14.05.08 connecting the it dots
14.05.08 connecting the it dots14.05.08 connecting the it dots
14.05.08 connecting the it dotskevin_donovan
 
Data Management for librarians
Data Management for librariansData Management for librarians
Data Management for librariansC. Tobin Magle
 
DMP health sciences
DMP health sciencesDMP health sciences
DMP health sciencesSarah Jones
 
Ask Not What the NIH Can Do For You; Ask What You Can Do For the NIH
Ask Not What the NIH Can Do For You; Ask What You Can Do For the NIH     Ask Not What the NIH Can Do For You; Ask What You Can Do For the NIH
Ask Not What the NIH Can Do For You; Ask What You Can Do For the NIH Philip Bourne
 
Common Protocol Template Executive Summary
Common Protocol Template Executive SummaryCommon Protocol Template Executive Summary
Common Protocol Template Executive SummaryTransCelerateBioPharma
 
Business Continuity Planning During and After the Coronavirus (COVID-19) Pand...
Business Continuity Planning During and After the Coronavirus (COVID-19) Pand...Business Continuity Planning During and After the Coronavirus (COVID-19) Pand...
Business Continuity Planning During and After the Coronavirus (COVID-19) Pand...PECB
 
Research data management at TU Eindhoven
Research data management at TU EindhovenResearch data management at TU Eindhoven
Research data management at TU EindhovenLeon Osinski
 
Botor_project_research_methodology_2016
Botor_project_research_methodology_2016Botor_project_research_methodology_2016
Botor_project_research_methodology_2016Shayne Botor
 
Elmallah june27 11am_room230_a
Elmallah june27 11am_room230_aElmallah june27 11am_room230_a
Elmallah june27 11am_room230_aDataWorks Summit
 
Technology training for PG students
Technology training for PG studentsTechnology training for PG students
Technology training for PG studentsJez Cope
 
2012 Fall Data Management Planning Workshop
2012 Fall Data Management Planning Workshop2012 Fall Data Management Planning Workshop
2012 Fall Data Management Planning WorkshopLizzy_Rolando
 
Curlew Research Brussels 2014 Electronic Data & Knowledge Management
Curlew Research Brussels 2014 Electronic Data & Knowledge ManagementCurlew Research Brussels 2014 Electronic Data & Knowledge Management
Curlew Research Brussels 2014 Electronic Data & Knowledge ManagementNick Lynch
 
LTC Lunch & Learn: Information sharing for care coordination, 29 April 2015
LTC Lunch & Learn: Information sharing for care coordination, 29 April 2015LTC Lunch & Learn: Information sharing for care coordination, 29 April 2015
LTC Lunch & Learn: Information sharing for care coordination, 29 April 2015NHS Improving Quality
 
Creating a Data Management Plan for your Grant Application
Creating a Data Management Plan for your Grant ApplicationCreating a Data Management Plan for your Grant Application
Creating a Data Management Plan for your Grant ApplicationHistoric Environment Scotland
 
Creating a Data Management Plan for your Grant Application
Creating a Data Management Plan for your Grant ApplicationCreating a Data Management Plan for your Grant Application
Creating a Data Management Plan for your Grant ApplicationEDINA, University of Edinburgh
 
Willmers&King open con2016-ct-14.11.16
Willmers&King open con2016-ct-14.11.16Willmers&King open con2016-ct-14.11.16
Willmers&King open con2016-ct-14.11.16Michelle Willmers
 
Open Access Week 2017: Research data management and data management plans (Fl...
Open Access Week 2017: Research data management and data management plans (Fl...Open Access Week 2017: Research data management and data management plans (Fl...
Open Access Week 2017: Research data management and data management plans (Fl...OpenAIRE
 

Similar to 2016 IQPC 13th Laboratory Informatics Summit Preparing for Possibly, Maybe, Handling PHI at the Broad Institute (20)

Creating a Data Management Plan for your Research
Creating a Data Management Plan for your ResearchCreating a Data Management Plan for your Research
Creating a Data Management Plan for your Research
 
NIH Grants and Data: New Rules Coming in 2023
NIH Grants and Data: New Rules Coming in 2023NIH Grants and Data: New Rules Coming in 2023
NIH Grants and Data: New Rules Coming in 2023
 
14.05.08 connecting the it dots
14.05.08 connecting the it dots14.05.08 connecting the it dots
14.05.08 connecting the it dots
 
Data Management for librarians
Data Management for librariansData Management for librarians
Data Management for librarians
 
DMP health sciences
DMP health sciencesDMP health sciences
DMP health sciences
 
Ask Not What the NIH Can Do For You; Ask What You Can Do For the NIH
Ask Not What the NIH Can Do For You; Ask What You Can Do For the NIH     Ask Not What the NIH Can Do For You; Ask What You Can Do For the NIH
Ask Not What the NIH Can Do For You; Ask What You Can Do For the NIH
 
Common Protocol Template Executive Summary
Common Protocol Template Executive SummaryCommon Protocol Template Executive Summary
Common Protocol Template Executive Summary
 
Business Continuity Planning During and After the Coronavirus (COVID-19) Pand...
Business Continuity Planning During and After the Coronavirus (COVID-19) Pand...Business Continuity Planning During and After the Coronavirus (COVID-19) Pand...
Business Continuity Planning During and After the Coronavirus (COVID-19) Pand...
 
Research data management at TU Eindhoven
Research data management at TU EindhovenResearch data management at TU Eindhoven
Research data management at TU Eindhoven
 
Botor_project_research_methodology_2016
Botor_project_research_methodology_2016Botor_project_research_methodology_2016
Botor_project_research_methodology_2016
 
Elmallah june27 11am_room230_a
Elmallah june27 11am_room230_aElmallah june27 11am_room230_a
Elmallah june27 11am_room230_a
 
Technology training for PG students
Technology training for PG studentsTechnology training for PG students
Technology training for PG students
 
2012 Fall Data Management Planning Workshop
2012 Fall Data Management Planning Workshop2012 Fall Data Management Planning Workshop
2012 Fall Data Management Planning Workshop
 
Curlew Research Brussels 2014 Electronic Data & Knowledge Management
Curlew Research Brussels 2014 Electronic Data & Knowledge ManagementCurlew Research Brussels 2014 Electronic Data & Knowledge Management
Curlew Research Brussels 2014 Electronic Data & Knowledge Management
 
LTC Lunch & Learn: Information sharing for care coordination, 29 April 2015
LTC Lunch & Learn: Information sharing for care coordination, 29 April 2015LTC Lunch & Learn: Information sharing for care coordination, 29 April 2015
LTC Lunch & Learn: Information sharing for care coordination, 29 April 2015
 
Creating a Data Management Plan for your Grant Application
Creating a Data Management Plan for your Grant ApplicationCreating a Data Management Plan for your Grant Application
Creating a Data Management Plan for your Grant Application
 
Creating a Data Management Plan for your Grant Application
Creating a Data Management Plan for your Grant ApplicationCreating a Data Management Plan for your Grant Application
Creating a Data Management Plan for your Grant Application
 
Willmers&King open con2016-ct-14.11.16
Willmers&King open con2016-ct-14.11.16Willmers&King open con2016-ct-14.11.16
Willmers&King open con2016-ct-14.11.16
 
Implementation science and learning health systems: Connecting the dots
Implementation science and learning health systems:  Connecting the dotsImplementation science and learning health systems:  Connecting the dots
Implementation science and learning health systems: Connecting the dots
 
Open Access Week 2017: Research data management and data management plans (Fl...
Open Access Week 2017: Research data management and data management plans (Fl...Open Access Week 2017: Research data management and data management plans (Fl...
Open Access Week 2017: Research data management and data management plans (Fl...
 

Recently uploaded

Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDGMarianaLemus7
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 

Recently uploaded (20)

Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDG
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort ServiceHot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 

2016 IQPC 13th Laboratory Informatics Summit Preparing for Possibly, Maybe, Handling PHI at the Broad Institute

  • 1. Preparing for Possibly, Maybe, Handling PHI at the Broad Institute IQPC 13th Laboratory Informatics Summit Boston, MA 2016/12/06, v3
  • 2. About the Speaker Bruce Kozuma is a projectprogram manager in the Broad Information Technology Services (BITS) department with experience in software development, operations, and IT in industries such as manufacturing, telecommunications, biotechnology, and biomedical research
  • 3. Overview • Title of this presentation was originally “Preparing Laboratory Data at the Broad Institute for HIPAA Compliance” • It’s morphed, much like things at the Broad • If you were expecting to hear about a settled plan, I’m sorry to disappoint you • The presentation may still be interesting however (you can tell me at the break if you like)
  • 4. About the Broad Institute of MIT & Harvard • Propelling the understanding and treatment of disease • Collaborating deeply • Reaching globally • Empowering scientists • Building partnerships • Sharing data and knowledge • Promoting inclusion
  • 5. HIPAA and Laboratory Data at the Broad • Broad is NOT Covered Entity nor a Business Associate under HIPAA • However, we collaborate with places that handle PHI, like HMS, MGH, DFCI, BCH, just to name a few • There is a big push for translational medicine, including at the Broad, i.e., a push for both bringing clinical data into research and delivering therapies more quickly • Have a variety of laboratory data management solutions due to: • Legacy • Funding sources • Culture
  • 6. Towards a Common Solution Laboratory Data Management • Project to provide centrally-managed solutions for management of laboratory data, divided into functions: • Data capturearchive (instruments and other sources) • Container inventoryregistration (chemical, biological, hybrid)sample management • Core Electronic Laboratory Notebook (ELN, experiment documentationIP protectionlinking to data) • Dataworkflow management • Data analysisvisualization
  • 8. • Make using LDM easy for scientists • Have much of IT processes outside user’s daily work • Introduce light system controls • Slowly bring in compliance to enable science • Had early success identifying those with needs, with adoption, started down the compliance path The Plan
  • 9. • Make using LDM easy for scientists • Have much of IT processes outside user’s daily work • Introduce light system controls • Slowly bring in compliance to enable science • Had early success identifying those with needs, with adoption, started down the compliance path The Plan
  • 10. LDM Compliance Assessment • Started as a subset of the overall LDM project • Goals • Determine the regulations that most likely apply that relate to LDM, e.g., HIPAA, CLIA, GxP, FISMA • Establish baseline understanding of the Broad’s system management practices with respect to LDM with those regulations • Have a roadmap for improvement, with aim of being substantially audit-ready at some point (likely a few years) in the future • Do as much of the compliance work with as little impact on the LDM user community as possible
  • 11. Best Laid Plans of Mice and Men…
  • 12. So What Now? • Results is that the need to handle PHI at the Broad, not in a few years in the future, but now • Why? • Researchers are often working at multiple institutions, e.g., HMS, MGH, and the Broad • PHI being handled at the partner institutions, resulting in barriers to research • Want to enable researchers to have more focus on their research, and less on information technology and mechanics of meeting IRB requirements • Want researchers to do more of their research at the Broad • Broad is challenged by having early stage offerings for technical infrastructure and procedural controls for PHI
  • 13. Practical Immediate Steps • Ensure PIs are aware of the PHI-related risks they face and explicitly accept those risks • Encourage PIs to use resources of collaborators to handle PHI (e.g., if DFCI has a preferred secure email vendor, use theirs) • Document what PIs can do with PHI at the Broad
  • 14. Practical Immediate Steps • Ensure PIs are aware of the PHI-related risks they face and explicitly accept those risks • Encourage PIs to use resources of collaborators to handle PHI (e.g., if DFCI has a preferred secure email vendor, use theirs) • Document what PIs can do with PHI at the Broad
  • 15. Longer Terms Steps • Build on the work of the LDM Compliance Assessment project/recast it as the PHI Compliance Readiness project • Implement quality management framework for handling PHI • Refine risk assessment methodology for outsourced partners • Execute on plan to address prioritized HIPAA compliance gaps
  • 16. Longer Terms Steps • Propose projectsbudgets for technology and process solutions to offer more services to PIs to streamline their research by bringing PHI to the Broad • Implement plan to proactively manage risks, e.g.: • Implement necessary policies • Raise awareness of responsibilities and risks via training • Establish clear response matrices to guide people to answers
  • 17. Things Learned Along the Way • <> • Embrace agility and get something out there
  • 18. Things Learned Along the Way • Hire outside expertise to parse Federal regulations
  • 19. Things Learned Along the Way • Partner with technology vendors who take time to listen and understand your needs • Responsive, proactive management makes a lot of things possible • Remember that the Broad pushes the edge of possible • Compliance approach will remain unfinished because the Broad is not done reinventing itself • Engaging with the world of regulatory compliance, when the Broad chooses what boundaries to push, makes things challenging • Our solution (for now): enter into a continual compliance conversation, where we can choose what parts of research are done, by which party, where what capabilities the Broad offers or should offer is considered

Editor's Notes

  1. See www.broadinstitute.org for more
  2. HIPAA: Health Insurance Portability and Accountability Act PHI: Protected Health Information HMS: Harvard Medical School MGH: Massachusetts General Hospital DFCI: Dana Farber Cancer Institute BCH: Boston Children’s Hospital
  3. ELN: Electronic Laboratory Notebook JIRA specifically
  4. HIPAA: Health Insurance Portability and Accountability Act CLIA: Clinical Laboratory Improvement Amendments SSAE: Statements on Standards for Attestation Engagements, by American Institute of Certified Public Accountants, Inc. (AICPA) ISAE: International Standard on Assurance Engagements, International Auditing and Assurance Standards Board (IAASB), part of the International Federation of Accountants (IFAC) TIA: Telecommunications Industry Association ISO: International Organization for Standardization FISMA: Federal Information Security Management Act NIST: National Institute of Standards
  5. LDM: Laboratory Data Management
  6. LDM: Laboratory Data Management
  7. LDM: Laboratory Data Management HIPAA: Health Insurance Portability and Accountability Act CLIA: Clinical Laboratory Improvement Amendments GxP: Good x Practice, where the x stands for Laboratory, Clinical, Manufacturing, etc. FISMA: Federal Information Security Management Act
  8. Taken from the Broad’s Facebook feed
  9. PHI: Protected Health Information HMS: Harvard Medical School MGH: Massachusetts General Hospital IRB: Institutional Review Board
  10. PI: Principle Investigators PHI: Protected Health Information DFCI: Dana Farber Cancer Institute
  11. PI: Principle Investigators PHI: Protected Health Information DFCI: Dana Farber Cancer Institute
  12. LDM: Laboratory Data Management PHI: Protected Health Information HIPAA: Health Insurance Portability and Accountability Act
  13. PI: Principle Investigator PHI: Protected Health Information Decision tree image source: https://www.edrawsoft.com/images/examples/decisiontree.png
  14. Department of Health and Human Services Office of Civil Rights Department of Justice (for penalties) Federal Trade Commission (Breach Notification Rule)