FNHSO PANORAMA DATA GOVERNANCE FORUM Regular Forum Meeting April 12, 2016.

Slides:



Advertisements
Similar presentations
Managing Risk: A Framework and Reporting Cycle 2014.
Advertisements

Internal Control–Integrated Framework
Security Controls – What Works
CEET Conference 2008 Is Quality Assurance Improving? Rob Fearnside, Deputy Director VRQA.
Quality evaluation and improvement for Internal Audit
Office of Inspector General (OIG) Internal Audit
Measuring the effectiveness of government IT systems Current ANAO initiatives to enhance IT Audit integration and support in delivering Audit outcomes.
Community Sector Governance Capability Framework
Auditing Standards IFTA\IRP Audit Guidance Government Auditing Standards (GAO) Generally Accepted Auditing Standards (GAAS) International Standards on.
Minnesota Adoption of the Green Book April 16, 2015 Jo Kane Internal Control & Accountability Specialist.
Internal Auditing and Outsourcing
The Clarified International Standards on Auditing Brian Smith June 8, 2011.
Organize to improve Data Quality Data Quality?. © 2012 GS1 To fully exploit and utilize the data available, a strategic approach to data governance at.
The Policy Company Limited © Control of Infection.
IAEA International Atomic Energy Agency Reviewing Management System and the Interface with Nuclear Security (IRRS Modules 4 and 12) BASIC IRRS TRAINING.
1 Office of the Privacy Commissioner for Personal Data Hong Kong SAR Tony LAM Deputy Privacy Commissioner for Personal Data Asian Personal Data Privacy.
United States Department of Agriculture Food Safety and Inspection Service February William C. Smith Assistant Administrator Office of Program.
Name Position Organisation Date. What is data integration? Dataset A Dataset B Integrated dataset Education data + EMPLOYMENT data = understanding education.
Appraisal update NHS England (Severn) Maurice Conlon FRCGP National Appraisal Lead 23 April 2013.
Copyright © 2007 Pearson Education Canada 7-1 Chapter 7: Audit Planning and Documentation.
Performance Management A briefing for new managers.
1 The Future Role of the Food and Veterinary Office M.C. Gaynor, Director, FVO EUROPEAN COMMISSION HEALTH & CONSUMER PROTECTION DIRECTORATE-GENERAL Directorate.
Code of Conduct and Ethics Scope of Practice Eileen Quinn
Mindset 2000 LtdSlide 1 Train to Gain Provider Support Programme October 2007 Self assessment - introduction.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
Tax Administration Diagnostic Assessment Tool MODULE 11 “POA 9: ACCOUNTABILITY AND TRANSPARENCY”
SUPPORTING PEOPLE PROVIDER FORUMS An overview of Supporting People’s new approach to Performance Monitoring and Quality Assurance.
Internal Audit Section. Authorized in Section , Florida Statutes Section , Florida Statutes (F.S.), authorizes the Inspector General to review.
FNHSO Privacy and Security Framework Forum Mar 15, 2016 BC First Nations Panorama Support.
Training for organisations participating in Peer Review of Paediatric Diabetes.
FNHSO PANORAMA DATA GOVERNANCE FORUM Kick-off Meeting July 8, 2014.
FNHSO PANORAMA DATA GOVERNANCE FORUM Regular Forum Meeting April 14, 2015.
FNHSO Privacy and Security Framework Forum Feb 16, 2016 BC First Nations Panorama Support.
Service Organization Control Reports What Have We Learned? Chris Bruhn DIRECTOR, IT RISK SERVICES, BKD, LLP SAS 70 ENDS EXIT TO SSAE 16.
Internal Audit Quality Assessment Guide
FNHSO Privacy and Security Framework Forum Nov 19, 2014 BC First Nations Panorama Support.
FNHSO Privacy and Security Framework Forum Jan 19, 2016 BC First Nations Panorama Support.
FNHSO Privacy and Security Framework Forum June 16, 2015 BC First Nations Panorama Support.
FNHSO PANORAMA DATA GOVERNANCE FORUM Regular Forum Meeting December 8, 2015.
FNHSO Privacy and Security Framework Forum October 15, 2014 BC First Nations Panorama Support.
Incorporating Privacy Into Systems Development Methodology Phil Moleski Director Corporate Information Technology Branch Saskatchewan Health
FNHSO PANORAMA DATA GOVERNANCE FORUM Regular Forum Meeting March 8, 2016.
A LOOK AT AMENDMENTS TO ISO/IEC (1999) Presented at NCSLI Conference Washington DC August 11, 2005 by Roxanne Robinson.
JMFIP Financial Management Conference
FNHSO Panorama Data Governance Forum
FNHSO Privacy and Security Framework Forum Jan 19, 2016
FNHSO Panorama Data Governance Forum
FNHSO Panorama Data Governance Forum
FNHSO Panorama Data Governance Forum
FNHSO Panorama Data Governance Forum
FNHSO Panorama Data Governance Forum
FNHSO Privacy and Security Framework Forum Sept 20, 2016
FNHSO Panorama Data Governance Forum
FNHSO Privacy and Security Framework Forum April 16, 2014
FNHSO Panorama Data Governance FOrum
FNHSO Panorama Data Governance Forum
IS4680 Security Auditing for Compliance
Service Organization Control (SOC)
GDPR Overview Gydeline – October 2017
GDPR Overview Gydeline – October 2017
NRC Cyber Security Regulatory Overview
Data Security and Protection Toolkit
Environmental Management Systems The ISO Approach Initial Environmental Review & Gap Analysis Presented by: NC Division of Pollution Prevention.
Statistics Governance and Quality Assurance: the Experience of FAO
Public Internal Control (PIC) in Belgium
The Elements of appropriate Internal Controls
IBM GTS Storage Security and Compliance overview.
Mr Mirco Barbero European Commission, IAS.C1
Auditing Compliance with the Privacy Rule
SWIFT Security Update ReBIT Saqib Sheikh, saqib.
Presentation transcript:

FNHSO PANORAMA DATA GOVERNANCE FORUM Regular Forum Meeting April 12, 2016

Agenda Roll-call Review of items from last PDGC meeting (Feb 23) Public Health Reporting Data Warehouse (PHRDW) update IHA Panorama ISA Compliance Assessment Results FNHSO Panorama ISA Compliance Process Cowichan Tribes ISA Compliance Assessment Results Roundtable review (i.e. future agenda items; other items; etc.)

Role Call KDC TCHSS WFN Tla’amin OKIB NTC Seabird Saulteau Cowichan Scw’exmx Nazko Pauquachin ITHA Na’kazdli Simpcw Ktunaxa Splatsin Sto:lo FNHA Health Protection Carrier Sekani Family Services Heiltsuk

PHRDW Update Security model has been applied to the CD Data Mart to support authorized RHA users to access a subset of Panorama CD data The same security model will also be applied across other PHRDW Data Marts thereby enabling RHA views/access to other PHRDW datasets A new Public Health Indicators Data Mart will make aggregate-level Indicators of Health data available New Data Marts are being developed that will integrate Panorama data with other data sets (lab data, for instance) and will increase the utility and value of the PHRDW (other examples: Vaccine Preventable Disease data integrated with Vaccine History data, lab data, etc.) Vital Stats data may also be integrated into PHRDW Data Marts Currently, there is no authorized access to First Nation or FNHSO identified data through any of the PHRDW Data Marts

5 PHRDW Architecture 2016

IHA ISA Compliance Assessment Refer to slides from March PDGC meeting

Panorama Information Sharing Agreement Compliance Assessment March 22, 2016 Givonna DeBruin, Corporate Director, Internal Audit

Background Purpose to measure Interior Health’s (IH) compliance with the Information Sharing Agreement and Data Governance Framework as part of the implementation of the Panorama system. Top Risks: 1.Privacy or security breaches occur and are not identified or addressed on a timely basis. 2.Information in the Panorama database is inaccurate, incomplete or out of date. 3.Staff have access to patient information that is not required for their job. 8

Background Audit requested by the Office of the Information Privacy Commissioner “Audit” – What does that Mean? – Systematic examination and assessment – Independent mindset and validation 9

Background IH piloted the audit tool to be used by other health authorities to measure compliance of this system containing significant patient data. Tool Development – Key components from Agreement – Developed and Piloted tool to guide assessment Tool findings provide valuable information and guidance to assist with strengthening maturity. 10

Findings at IH of the 18 data governance requirements fully met Most other requirements partially met Demonstrates a good level of maturity Requirements that are fully met include: Principle Data Steward responsibility Whistleblower policy and program Foreign access restrictions Foreign information demands Breach management policy Security Threat Risk and Privacy Impact Assessments User Privacy obligations acceptance Clients’ information use notification Data use for internal research Data use for program evaluation or surveillance (3 aspects: self, multiple party, foreign) Client’s access to own information

Findings at IH 5 requirements not fully met, comprise 3 main themes. – Risk Assessment and Audit — Privacy and Security Audits are not conducted on a regular basis as required, rather only completed when a breach is suspected or reported. – Evidence Retention — Evidence to support compliance with the Agreement has not been consistently retained for all items in all areas. – Periodic Awareness and Acknowledgement — Panorama specific user awareness training and Acceptable Use Acknowledgements currently are only completed at onset of use of the application and does not include an annual re- acknowledgement/training process. 12

Lessons Learned Self-assessment by management – Increases engagement – Tool familiarity Independent assurance added – Objective validation Overall increase in knowledge and understanding of ISA requirements 13

Ts’ewulhtun Health Centre ISA Compliance Assessment Refer to Ts’ewulhtun Health Centre Panorama Information Sharing Agreement Compliance Assessment PowerPoint presentation

Roundtable Questions? Request for agenda items to be included in next meeting?