PageSierra Wireless Proprietary and Confidential 1
The Vigisanté project &
Matters of importance for M2M E-Health
ETSI M2M Workshop, 24th-25th October 2012, Mandelieu, France
Nicolas Damour – Senior Manager, Business & Innovation Development – ndamour@sierrawireless.com
Page
The Vigisanté Project
• Arterial hypertension - a public health issue
• Stakeholders and perimeter
• Solution description and highlights
Matters of importance for M2M E-Health
• Regulation and Standardization
• M2M Platforms Interoperability
• Medical Data Security and Privacy
2
Agenda
© Sierra Wireless 2012
Page 3
Vigisanté Project - Arterial hypertension
© Sierra Wireless 2012
Source: World Health Organization and Global Health Observatory, 2011. http://www.who.int
Percentages of population aged 25 years and over with raised blood pressure (systolic ≥140 or diastolic ≥90).
Number one cause of deaths in the world
23.6% of all deaths – 13.4 million deaths per year
15 million
hypertensive people
in France
29% 16%29% 25%
1.9 billion
hypertensive people
in the world
Less than 50% of people aware of their condition
Page
Vigisanté Project - Stakeholders
4© Sierra Wireless 2012
Page
• Nord – Pas-de-Calais region
• 22000 employees of more than 50 companies
• 4000 screened candidates
• 1000 actual patients
Vigisanté Project - Perimeter
5© Sierra Wireless 2012
April 2010
Call for
e-health projects
November 2010
Vigisanté project
awarded funding
June 2012
End of
screening
April 2013
Planned end of first
phase and extension
2011 20122010 2013
December 2011
Candidates
screening
Page
Vigisanté Project - Solution Overview
Scales
Electrocardiograph
Pill dispenser on
communications base
GSM Network
AirVantage M2M Cloud
Business
Web-application
MMC Server
(ECG data)
Inovelan
Appliance
Participants
Doctors
Medicalized support
(Patient’s home)
(Medical center)
6© Sierra Wireless 2012
Tensiometer
Page
Platforms Interoperability
Regulatory aspects
Business model
Vigisanté Project – Important Aspects
7© Sierra Wireless 2012
Page
95/46/CE Directive on Protection of Personal data
Data must be kept on European territory
Exceptions: Canada, Switzerland, Argentina
Privacy – Transaction – Security (admin, physical, technical)
Unique Identifier – Enforcement
Data must be kept on US territory
Seven principles
Notice – Choice – Onward Transfer – Security
Data Integrity – Access – Enforcement
Legal - Regulation
8© Sierra Wireless 2012
Page
Medical devices
IEC 60601 US FDA 510K process
Information technologies
Health and Data Semantics
ISO 27005
ISO 13485
Technological - Standardization
9© Sierra Wireless 2012
Page
• Service Oriented Architecture
• Service Abstraction Layer
• RESTful Architecture and APIs
M2M Platforms Interoperability
10© Sierra Wireless 2012
Page
Confidentiality
Prevention of disclosure of information to unauthorized individuals or systems.
Confidentiality is necessary (but not sufficient) for privacy
Integrity
Prevention of undetectable modification of the data
Accessibility
The information must be available when it is needed
Medical Data Security and Privacy
11© Sierra Wireless 2012
Page
Security Chain
12
GSM Network
Data Center
and Application
Service User
on Web Client Internet
© Sierra Wireless 2012
Page 13
M2M Communications Security
Security based on credentials :
• Server unique identity
• Device unique identity
• Nonce: one-time password, different for each session
• Public keys and Hardware Security Modules
Implementation:
• HMAC-MD5 or HMAC-SHA1 authentication
• AES Cypher Block Chaining and Counter Mode encryption
• 128 and 256 bits encryption
• Hardware security modules to store keys
© Sierra Wireless 2012
Page
M2M Cloud Security
• Physical Security
• Locks, Card reader access
• Security guards, Motion sensors and cameras
• Controlled environment
• Backup power, Fire containment
• Redundant network connections
• Low probability of natural disasters
• Application Security
• Monitoring of access logs
• Backups of data and OS
• Periodic Security Testing
• Firewall
• Redundancy and Data Recovery plans
• Tier 3+ Datacenters, SAS70 Type II audits, ISO certification
14© Sierra Wireless 2012
Page
Web Security
• Web Authentication over HTTPS, 256 bits data encryption
• Option to use RSA SecurID tokens for user authentication
• Virtual Private Networks
15© Sierra Wireless 2012
Page
Conclusion – Questions?
Nicolas DAMOUR
Senior Manager, Business & Innovation Development
ndamour@sierrawireless.com
Phone: +33 670 706 003
Page
Backup Slides
17
Page 18
Vigisanté Project - Arterial hypertension
© Sierra Wireless 2012
Arterial hypertension in countries per income Men Women
High income (eg. USA, Japan, Germany, France, United Kingdom) 24,8% 17,4%
Upper middle income (eg. China, Brazil, Russia, Mexico, Iran) 35,3% 28,3%
Lower middle income (eg. India, Indonesia, Pakistan, Nigeria) 28,7% 26,0%
Low income (eg. Bangladesh, Dem. Rep. of Congo, Ethiopia) 32,9% 29,9%
Source: World Health Organization and Global Health Observatory, 2011. http://www.who.int
Percentages of population aged 25 years and over with raised blood pressure (systolic ≥140 or diastolic ≥90).
Income-group aggregates are based on the 2008 World Bank list of economies: http://siteresources.worldbank.org/DATASTATISTICS/Resources/CLASS.XLS
29,1% 16,2%
29,2% 24,8%
Number one cause of deaths in the world
23,6% of all deaths – 13,4 million deaths per year
15 millions total
in France

Vigisanté Project

  • 1.
    PageSierra Wireless Proprietaryand Confidential 1 The Vigisanté project & Matters of importance for M2M E-Health ETSI M2M Workshop, 24th-25th October 2012, Mandelieu, France Nicolas Damour – Senior Manager, Business & Innovation Development – ndamour@sierrawireless.com
  • 2.
    Page The Vigisanté Project •Arterial hypertension - a public health issue • Stakeholders and perimeter • Solution description and highlights Matters of importance for M2M E-Health • Regulation and Standardization • M2M Platforms Interoperability • Medical Data Security and Privacy 2 Agenda © Sierra Wireless 2012
  • 3.
    Page 3 Vigisanté Project- Arterial hypertension © Sierra Wireless 2012 Source: World Health Organization and Global Health Observatory, 2011. http://www.who.int Percentages of population aged 25 years and over with raised blood pressure (systolic ≥140 or diastolic ≥90). Number one cause of deaths in the world 23.6% of all deaths – 13.4 million deaths per year 15 million hypertensive people in France 29% 16%29% 25% 1.9 billion hypertensive people in the world Less than 50% of people aware of their condition
  • 4.
    Page Vigisanté Project -Stakeholders 4© Sierra Wireless 2012
  • 5.
    Page • Nord –Pas-de-Calais region • 22000 employees of more than 50 companies • 4000 screened candidates • 1000 actual patients Vigisanté Project - Perimeter 5© Sierra Wireless 2012 April 2010 Call for e-health projects November 2010 Vigisanté project awarded funding June 2012 End of screening April 2013 Planned end of first phase and extension 2011 20122010 2013 December 2011 Candidates screening
  • 6.
    Page Vigisanté Project -Solution Overview Scales Electrocardiograph Pill dispenser on communications base GSM Network AirVantage M2M Cloud Business Web-application MMC Server (ECG data) Inovelan Appliance Participants Doctors Medicalized support (Patient’s home) (Medical center) 6© Sierra Wireless 2012 Tensiometer
  • 7.
    Page Platforms Interoperability Regulatory aspects Businessmodel Vigisanté Project – Important Aspects 7© Sierra Wireless 2012
  • 8.
    Page 95/46/CE Directive onProtection of Personal data Data must be kept on European territory Exceptions: Canada, Switzerland, Argentina Privacy – Transaction – Security (admin, physical, technical) Unique Identifier – Enforcement Data must be kept on US territory Seven principles Notice – Choice – Onward Transfer – Security Data Integrity – Access – Enforcement Legal - Regulation 8© Sierra Wireless 2012
  • 9.
    Page Medical devices IEC 60601US FDA 510K process Information technologies Health and Data Semantics ISO 27005 ISO 13485 Technological - Standardization 9© Sierra Wireless 2012
  • 10.
    Page • Service OrientedArchitecture • Service Abstraction Layer • RESTful Architecture and APIs M2M Platforms Interoperability 10© Sierra Wireless 2012
  • 11.
    Page Confidentiality Prevention of disclosureof information to unauthorized individuals or systems. Confidentiality is necessary (but not sufficient) for privacy Integrity Prevention of undetectable modification of the data Accessibility The information must be available when it is needed Medical Data Security and Privacy 11© Sierra Wireless 2012
  • 12.
    Page Security Chain 12 GSM Network DataCenter and Application Service User on Web Client Internet © Sierra Wireless 2012
  • 13.
    Page 13 M2M CommunicationsSecurity Security based on credentials : • Server unique identity • Device unique identity • Nonce: one-time password, different for each session • Public keys and Hardware Security Modules Implementation: • HMAC-MD5 or HMAC-SHA1 authentication • AES Cypher Block Chaining and Counter Mode encryption • 128 and 256 bits encryption • Hardware security modules to store keys © Sierra Wireless 2012
  • 14.
    Page M2M Cloud Security •Physical Security • Locks, Card reader access • Security guards, Motion sensors and cameras • Controlled environment • Backup power, Fire containment • Redundant network connections • Low probability of natural disasters • Application Security • Monitoring of access logs • Backups of data and OS • Periodic Security Testing • Firewall • Redundancy and Data Recovery plans • Tier 3+ Datacenters, SAS70 Type II audits, ISO certification 14© Sierra Wireless 2012
  • 15.
    Page Web Security • WebAuthentication over HTTPS, 256 bits data encryption • Option to use RSA SecurID tokens for user authentication • Virtual Private Networks 15© Sierra Wireless 2012
  • 16.
    Page Conclusion – Questions? NicolasDAMOUR Senior Manager, Business & Innovation Development ndamour@sierrawireless.com Phone: +33 670 706 003
  • 17.
  • 18.
    Page 18 Vigisanté Project- Arterial hypertension © Sierra Wireless 2012 Arterial hypertension in countries per income Men Women High income (eg. USA, Japan, Germany, France, United Kingdom) 24,8% 17,4% Upper middle income (eg. China, Brazil, Russia, Mexico, Iran) 35,3% 28,3% Lower middle income (eg. India, Indonesia, Pakistan, Nigeria) 28,7% 26,0% Low income (eg. Bangladesh, Dem. Rep. of Congo, Ethiopia) 32,9% 29,9% Source: World Health Organization and Global Health Observatory, 2011. http://www.who.int Percentages of population aged 25 years and over with raised blood pressure (systolic ≥140 or diastolic ≥90). Income-group aggregates are based on the 2008 World Bank list of economies: http://siteresources.worldbank.org/DATASTATISTICS/Resources/CLASS.XLS 29,1% 16,2% 29,2% 24,8% Number one cause of deaths in the world 23,6% of all deaths – 13,4 million deaths per year 15 millions total in France