CSTE National ELR Workgroup

Welcome to the CSTE National ELR Workgroup Basecamp! We hope you will utilize the space to share resources with colleagues, start discussion threads, and identify topics for the workgroup to tackle on future calls. All workgroup members will have the opportunity to join. Please note that you may edit your notification preferences to suit your needs (and your email inbox). If you are not already on the ELR distribution list and would like to receive call communications, please enroll using this subscription form (copy and paste in browser): https://app.smartsheet.com/b/form/5a91a4579952496682084796b82112e6

🛠 Secure file transport mechanisms

Hi all, as a follow up to today's ELR Workgroup call, we'd like to know the following:

1) What secure file transport mechanisms are you using for ELR in your jurisdiction, e.g., PHINMS, AIMS AWS S3, other AWS S3, SFTP, etc. (please list all of them)

2) Briefly explain why your jurisdiction is using the mechanism(s) you listed

3) Have you encountered any major issues (that were not resolved) or have any major concerns with any of those transport mechanisms?

Comments & Events

Sita Smith
Responses for MA (edited)

1) AIMS AWS S3/ AWS S3/ Mass HIWay (HIE)/sFTP for flat files
2) Strongly encouraged by ELC team to do so; it made sense to consolidate our transport mechanisms so we only need to maintain one set of pipes. PHINMS was always slightly unstable.
3) No major concerns
Mark Dittman
For PA:


1. A: PA-ELR secure web service. Users can use our spec to build their own service to consume/connect to ours

B: PAWS, our proprietary secure web service app which is hosted by the reporting entity. This is a PhinMS-like app which is based on folder polling, connects securely to our web service and passes credentials. This can be fully configured to run on any schedule, poll multiple locations and send to multiple endpoints. Originally developed in 2006, it was overhauled in 2016 and serves us well although we prefer the use of PhinMS, when possible, to reduce the overhead of user management.

C: PhinMS is used more than 20 providers and we generally have no issues with it. Our biggest problem is that our IT overlords took control of it from our IT team and now we have no access to the console or any other role other than submitting tickets to have things ‘done’ when necessary, which adds days/weeks to any need.

D: AIMS S3.

E: Public Health Gateway/HIE network within PA which has eliminated direct connections to five HIEs and/or approximately 25 facilities. Reduces our direct user maintenance but with nearly 600 reporting entities, this is not that big of a relief.

1. Necessity. Not all reporting entities have competent IT units, if any, to implement our secure web service option. Many entities manually upload their HL7 files directly into PA-NEDSS (uses the same secure web service). PhinMS has provided some flexibility and was very valuable during the mass onboarding for COVID in 2020/21. Multiple options need to exist to fit the varying degree of user ability.
2. AIMS S3 was a huge issue for about two years in that we could not send files back to AIMS. There were other unique issues that I believe two or three other states also had. Eventually issues were mitigated. PhinMS is an issue in only that my team can no longer administrate it as we did from 2007 until 2018. Our own web service and PAWS app are more than adequate but require direct user management and have a 60-day expiring password rule, which is more overhead user management for our team. The Public Health Gateway is mired in politics and I would prefer to not use it at all if given the power to withdraw our participation.


Mark Dittman | Project Manager, PA-ELR
PA Office of Administration | Health and Human Services Delivery Center
2525 North 7th Street, 3rd Floor| Harrisburg, PA 17110
Phone: 717.836.3512 | Fax: 717.783.3695
www.oa.pa.gov<http://www.oa.pa.gov/>
David DiCesare
For NYS


1. UPHN Lite (NYS software similar to PHINMS), S3
2. UPHN Lite was developed as an alternative to PHINMS to provide more flexibility in modifications based on transport needs within NYS. S3 is primarily used for files coming from AIMS
3. No issues or concerns at this time



Thanks.

David DiCesare
NYS ELR Coordinator
ECLRS Help Desk
Bureau of Surveillance and Data Systems
Local – 518-402-5943
Long Distance - 866-325-7743
David.dicesare@health.ny.gov
Swathi Ramasahayam
For IA:

1. AIMS AWS S3 for Centalized ELR, PHINMS for connecting to National Labs, VPN connection to our HIE (covers most of the Iowa Hospital connections), SFTP and Secure Email Templates for low tech senders (Rhapsody automatically reads the attachment and converts it to HL7 message)
2. These are the mechanisms that the ELR senders were comfortable with and we supported them.
3. No major concerns
Julie Vanderkolk
1) What secure file transport mechanisms are you using for ELR in your jurisdiction & 2) Why
  • MFT (replaced SFT early 2023) - some facilities will only use this because they don’t have other tools
  • PHINMS (for national/regional labs and CDC) - set up some of these long ago and they are still running fine
  • AIMS Platform (AWS S3) - moved to this because of volume
  • HIE (web service) - transitioned from AS2 end of 2022, DOH policy to use HIE for data exchange
3) Have you encountered any major issues (that were not resolved) or have any major concerns with any of those transport mechanisms?
The only serious issue we have run into was the volume of messages we were receiving via AS2 and PHINMS exceeded the ability of the connections to process.
We moved from PHINMS to S2 with AIMS and from HIE (AS2) to HIE (web service) to address these.  PHINMS for all other senders has stayed below the level that causes a problem.

Julie Vanderkolk, MSPH
Pronouns: she/her
Electronic Laboratory Reporting (ELR) supervisor / Sr. Informatics Epidemiologist
Center for Data Modernization and Informatics
Office of Innovation and Technology
Washington State Department of Health
doh.wa.gov   |  360-890-6639
Robb Byres
For Idaho


1. SFTP, PHINMS (RNR Only), AIMS S3
2. SFTP is supported by almost everyone and has a web front-end for non-Technical users.

PHINMS is being retired for ELR purposes and will not be used after the final RNR sender switches to SFTP

1. No

Thank You

Robb
Todd Davis
Illinois:
1.  SFTP using MoveIT for most ELR data with scripts that copy the data for HL7 versions at different times due to COVID volumes.  The MoveIT tool has a web front end for manual uploads for smaller pharmacies and facilities without technical teams. 

PHINMS for just a couple of the national labs remaining and only with RNR, would like to totally phase out PHINMS due to file size issues with COVID and move everything to SFTP / MoveIT.

AIMS - SFTP

2.  SFTP / MoveIT has worked well for us and agree with others that almost everyone has SFTP interfaces or tools that can connect.  We use scripting within MoveIT to move data at different times for example all HL7 2.3.1 data gets moved at the top of every hour and all HL7 2.5.1 gets moved at the bottom of the hour and we move our CSV data at 15 after and 45 after the hour to help our database processing. 

3.  The main issue we had was with PHINMS in the middle of COVID and it was all due to file sizes.  
Nicole Kikuchi
Secure file transport mechanisms used in Florida 
  • SFTP (78.7% of reporting facilities) 
    • ELR Team controls SFTP account setup/management
    • Most facilities can support SFTP
    • No major issues/concerns
  • AWS S3 (14.0%)
    • Primarily used for facilities reporting through AIMS 
    • Supports InterPartner ELR
    • No major issues/concerns
  • VPN (7.0%)
    • Supports high volume facilities
    • Set-up takes a long time due to additional involvement/management by FDOH IT
    • No major issues/concerns
  • Direct data pull (0.3%)
    • Only used for systems behind the FDOH firewall (i.e., state/county PHLs, public facing web portal for point-of-care lab result reporting)
    • No major issues/concerns  
Nicole Kikuchi, MPH, CPM
Surveillance/Informatics Epidemiologist
Florida Department of Health Nicole.Kikuchi@flhealth.gov<mailto:Nicole.Kikuchi@flhealth.gov>
Jonathan Johnson, Informatics and Data Science Lead (HI - DOH)
For Hawaii,

1.) We recently transistioned away from PhinMS and use AIMS AWS S3 for eCR and AIMS sends and SFTP for local laboratories and providers inclusive of a lab reporting portal. HIE for all major local lab sends.

2.) SFTP for local laboratories who needed quick onboarding for COVID-19 sending and were unable to meaningful automate or engage with our local HHIE. This also includes a lab reporting portal that generates into our SFTP bucket. AIMS AWS S3 as it provides automated transit directly into our Rhapsody Engine without work arounds to move data into pick-up buckets.

3.) We're looking into transitioning our Lab Reporting Portal into Simple Report/Report Stream.
Michael Nuss, Informatician at Nebraska Department of Health and Human Services
Updated feedback for Nebraska:

Immunization:

1) What secure file transport mechanisms are you using for ELR in your jurisdiction, e.g., PHINMS, AIMS AWS S3, other AWS S3, SFTP, etc. (please list all of them)

SOAP
PHINMS

2) Briefly explain why your jurisdiction is using the mechanism(s) you listed

SOAP is an XML-based messaging protocol which is used to send or receive messages between client and server. NESIIS supports the SOAP standard interface 1.2 specifications, Web Services Definition Language (WSDL), as endorsed by the CDC.
PHINMS is software available from the CDC that securely sends and receives encrypted data over the Internet to public health information systems using Electronic Business Extensible Markup Language (ebXML) technology. Requires provider IT staff to install and configure the PHINMS server at the provider site, with remote assistance from the OCIO IT staff.

3) Have you encountered any major issues (that were not resolved) or have any major concerns with any of those transport mechanisms?

PHINMS is outdated and hasn't been used by many for years for this very reason.

Reportable Disease ELR:

1) What secure file transport mechanisms are you using for ELR in your jurisdiction, e.g., PHINMS, AIMS AWS S3, other AWS S3, SFTP, etc. (please list all of them)

SFTP

2) Briefly explain why your jurisdiction is using the mechanism(s) you listed

We transitioned from PHINMS to SFTP when we contracted with Inductive Health.  The primary benefit is SFTP is it’s supported by almost everyone and is quite simple to implement while encrypting everything being transferred.

3) Have you encountered any major issues (that were not resolved) or have any major concerns with any of those transport mechanisms?

No.

Syndromic Surveillance:

1) What secure file transport mechanisms are you using for ELR in your jurisdiction, e.g., PHINMS, AIMS AWS S3, other AWS S3, SFTP, etc. (please list all of them)

PHINMS

2) Briefly explain why your jurisdiction is using the mechanism(s) you listed

It is the cheapest, mostly reliable, and easiest to implement option for both internal and external parties.

3) Have you encountered any major issues (that were not resolved) or have any major concerns with any of those transport mechanisms?

It is beginning to show it’s age compared to emerging options, and support/fix turnaround is taking longer and longer. 
We are looking to replace PHINMS with a bespoke RESTful web service.  It's similar to PHINMS, but does not rely on the PHINMS software. Connections are secured using TLS 1.3.
Nancy Barrett, Epi 4/PH Informatics Specialist
Hi - from CT:
1) What secure file transport mechanisms are you using for ELR in your jurisdiction. We use PHINMS, AIMS AWS S3, SFTP, AWS S3 (not AIMS)
 
2) Briefly explain why your jurisdiction is using the mechanism(s) you listed
  1. PHINMS used as was the original secure transport we could offer to our hospital and lab partners for ELR reporting that was free for their use. 
  2. AIMS AWS S3 started to support interpartner. We are working with AIMS to transition all of our reporting to CDC to use the AIMS AWS S3 and away from PHINMS. We have worked with AIMS to get set the metadata for better file identification.
  3. State supported SFTP was stood up to accommodate the huge increase in testing locations/labs that were required to report SARS-CoV-2 test results. We are slowly migrating our PHINMS partners to use SFTP as possible.
  4. We use AWS S3 with SSG, Inc. who support the Casetivity application. We pull files from their S3. Providers who still need to report in-office performed tests for SARS-CoV-2, influenza or blood lead results are being transition to using Casetivity. Note: our state does not offer us a state supported S3 option.
3) Have you encountered any major issues (that were not resolved) or have any major concerns with any of those transport mechanisms?
  1. PHINMS does not work with SQL 2019. Our new state server environment will not allow continued use of SQL 2016 due to security issues. Issues during the pandemic were: Hospitals sending too large a file size for PHINMS - we had to move one large system to SFTP to fix that even after they tried to reduce file size and increase frequency of batch sending to DPH: we were running some hospitals in the PHINMS staging platform as we only wanted COVID and FLU results and did not have the capacity to fully onboard them for all of our reportable diseases - there was a big issue when CDC updated staging PHINMS without telling us and disrupted reporting for over a week - that was also a motivator for moving that one large hospital system to SFTP. I have to note that the CDC PHINMS staff worked with us even on a weekend call with tech folks on both sides to get this issue identified and resolved.
  2. SFTP does not allow for the same monitoring processes as PHINMS so we manage those a bit more manually.
Final note: We had not heard of MFT before, but would be interested in finding out more.
Sarah Boneske
Minnesota:
1)  What secure file transport mechanisms are you using for ELR in your jurisdiction, e.g., PHINMS, AIMS AWS S3, other AWS S3, SFTP, etc. (please list all of them)

PHINMS, AIMS AWS S3, SFTP, MLLP, HTTP (Variant, Reportal, etc.)

2) Briefly explain why your jurisdiction is using the mechanism(s) you listed. 

PHINMS, CDC required for reporting.  Working to sunset.

AIMS AWS S3, Moved to this for CDC Reporting when PHINMS couldn’t handle the volumes.

SFTP, easy to integrate with

MLLP, Best process for managing request/response like lab orders for MN Public Health Lab. 

HTTP (internal only), Outside SFTP, easy to integrate with.  Flows with FHIR and REST type conventions.

3) Have you encountered any major issues (that were not resolved) or have any major concerns with any of those transport mechanisms?

PHINMS, Reliant on CDC to upgrade software.

AIMS AWS S3, no NACK feature, so MDH is required to fix Provider issues.

SFTP, no NACK feature, so MDH is required to fix Provider issues.

MLLP, expensive and time consuming to get established.  Requires multiple layer of access to troubleshoot.

HTTP (internal only), MDH is working on better Authentication approach (oauth) to move more in this direction.