🛠 Secure file transport mechanisms
Hi all, as a follow up to today's ELR Workgroup call, we'd like to know the following:
1) What secure file transport mechanisms are you using for ELR in your jurisdiction, e.g., PHINMS, AIMS AWS S3, other AWS S3, SFTP, etc. (please list all of them)
1) What secure file transport mechanisms are you using for ELR in your jurisdiction, e.g., PHINMS, AIMS AWS S3, other AWS S3, SFTP, etc. (please list all of them)
2) Briefly explain why your jurisdiction is using the mechanism(s) you listed
3) Have you encountered any major issues (that were not resolved) or have any major concerns with any of those transport mechanisms?
1) AIMS AWS S3/ AWS S3/ Mass HIWay (HIE)/sFTP for flat files
2) Strongly encouraged by ELC team to do so; it made sense to consolidate our transport mechanisms so we only need to maintain one set of pipes. PHINMS was always slightly unstable.
3) No major concerns
1. A: PA-ELR secure web service. Users can use our spec to build their own service to consume/connect to ours
B: PAWS, our proprietary secure web service app which is hosted by the reporting entity. This is a PhinMS-like app which is based on folder polling, connects securely to our web service and passes credentials. This can be fully configured to run on any schedule, poll multiple locations and send to multiple endpoints. Originally developed in 2006, it was overhauled in 2016 and serves us well although we prefer the use of PhinMS, when possible, to reduce the overhead of user management.
C: PhinMS is used more than 20 providers and we generally have no issues with it. Our biggest problem is that our IT overlords took control of it from our IT team and now we have no access to the console or any other role other than submitting tickets to have things ‘done’ when necessary, which adds days/weeks to any need.
D: AIMS S3.
E: Public Health Gateway/HIE network within PA which has eliminated direct connections to five HIEs and/or approximately 25 facilities. Reduces our direct user maintenance but with nearly 600 reporting entities, this is not that big of a relief.
1. Necessity. Not all reporting entities have competent IT units, if any, to implement our secure web service option. Many entities manually upload their HL7 files directly into PA-NEDSS (uses the same secure web service). PhinMS has provided some flexibility and was very valuable during the mass onboarding for COVID in 2020/21. Multiple options need to exist to fit the varying degree of user ability.
2. AIMS S3 was a huge issue for about two years in that we could not send files back to AIMS. There were other unique issues that I believe two or three other states also had. Eventually issues were mitigated. PhinMS is an issue in only that my team can no longer administrate it as we did from 2007 until 2018. Our own web service and PAWS app are more than adequate but require direct user management and have a 60-day expiring password rule, which is more overhead user management for our team. The Public Health Gateway is mired in politics and I would prefer to not use it at all if given the power to withdraw our participation.
Mark Dittman | Project Manager, PA-ELR
PA Office of Administration | Health and Human Services Delivery Center
2525 North 7th Street, 3rd Floor| Harrisburg, PA 17110
Phone: 717.836.3512 | Fax: 717.783.3695
www.oa.pa.gov<http://www.oa.pa.gov/>
1. UPHN Lite (NYS software similar to PHINMS), S3
2. UPHN Lite was developed as an alternative to PHINMS to provide more flexibility in modifications based on transport needs within NYS. S3 is primarily used for files coming from AIMS
3. No issues or concerns at this time
Thanks.
David DiCesare
NYS ELR Coordinator
ECLRS Help Desk
Bureau of Surveillance and Data Systems
Local – 518-402-5943
Long Distance - 866-325-7743
David.dicesare@health.ny.gov
1. AIMS AWS S3 for Centalized ELR, PHINMS for connecting to National Labs, VPN connection to our HIE (covers most of the Iowa Hospital connections), SFTP and Secure Email Templates for low tech senders (Rhapsody automatically reads the attachment and converts it to HL7 message)
2. These are the mechanisms that the ELR senders were comfortable with and we supported them.
3. No major concerns
Julie Vanderkolk, MSPH
Pronouns: she/her
1. SFTP, PHINMS (RNR Only), AIMS S3
2. SFTP is supported by almost everyone and has a web front-end for non-Technical users.
PHINMS is being retired for ELR purposes and will not be used after the final RNR sender switches to SFTP
1. No
Thank You
Robb
1. SFTP using MoveIT for most ELR data with scripts that copy the data for HL7 versions at different times due to COVID volumes. The MoveIT tool has a web front end for manual uploads for smaller pharmacies and facilities without technical teams.
PHINMS for just a couple of the national labs remaining and only with RNR, would like to totally phase out PHINMS due to file size issues with COVID and move everything to SFTP / MoveIT.
AIMS - SFTP
2. SFTP / MoveIT has worked well for us and agree with others that almost everyone has SFTP interfaces or tools that can connect. We use scripting within MoveIT to move data at different times for example all HL7 2.3.1 data gets moved at the top of every hour and all HL7 2.5.1 gets moved at the bottom of the hour and we move our CSV data at 15 after and 45 after the hour to help our database processing.
3. The main issue we had was with PHINMS in the middle of COVID and it was all due to file sizes.
Surveillance/Informatics Epidemiologist
Florida Department of Health Nicole.Kikuchi@flhealth.gov<mailto:Nicole.Kikuchi@flhealth.gov>
1.) We recently transistioned away from PhinMS and use AIMS AWS S3 for eCR and AIMS sends and SFTP for local laboratories and providers inclusive of a lab reporting portal. HIE for all major local lab sends.
2.) SFTP for local laboratories who needed quick onboarding for COVID-19 sending and were unable to meaningful automate or engage with our local HHIE. This also includes a lab reporting portal that generates into our SFTP bucket. AIMS AWS S3 as it provides automated transit directly into our Rhapsody Engine without work arounds to move data into pick-up buckets.
3.) We're looking into transitioning our Lab Reporting Portal into Simple Report/Report Stream.
Immunization:
1) What secure file transport mechanisms are you using for ELR in your jurisdiction, e.g., PHINMS, AIMS AWS S3, other AWS S3, SFTP, etc. (please list all of them)
SOAP
PHINMS
2) Briefly explain why your jurisdiction is using the mechanism(s) you listed
SOAP is an XML-based messaging protocol which is used to send or receive messages between client and server. NESIIS supports the SOAP standard interface 1.2 specifications, Web Services Definition Language (WSDL), as endorsed by the CDC.
PHINMS is software available from the CDC that securely sends and receives encrypted data over the Internet to public health information systems using Electronic Business Extensible Markup Language (ebXML) technology. Requires provider IT staff to install and configure the PHINMS server at the provider site, with remote assistance from the OCIO IT staff.
3) Have you encountered any major issues (that were not resolved) or have any major concerns with any of those transport mechanisms?
PHINMS is outdated and hasn't been used by many for years for this very reason.
Reportable Disease ELR:
1) What secure file transport mechanisms are you using for ELR in your jurisdiction, e.g., PHINMS, AIMS AWS S3, other AWS S3, SFTP, etc. (please list all of them)
SFTP
2) Briefly explain why your jurisdiction is using the mechanism(s) you listed
We transitioned from PHINMS to SFTP when we contracted with Inductive Health. The primary benefit is SFTP is it’s supported by almost everyone and is quite simple to implement while encrypting everything being transferred.
3) Have you encountered any major issues (that were not resolved) or have any major concerns with any of those transport mechanisms?
No.
Syndromic Surveillance:
1) What secure file transport mechanisms are you using for ELR in your jurisdiction, e.g., PHINMS, AIMS AWS S3, other AWS S3, SFTP, etc. (please list all of them)
PHINMS
2) Briefly explain why your jurisdiction is using the mechanism(s) you listed
It is the cheapest, mostly reliable, and easiest to implement option for both internal and external parties.
3) Have you encountered any major issues (that were not resolved) or have any major concerns with any of those transport mechanisms?
It is beginning to show it’s age compared to emerging options, and support/fix turnaround is taking longer and longer.
We are looking to replace PHINMS with a bespoke RESTful web service. It's similar to PHINMS, but does not rely on the PHINMS software. Connections are secured using TLS 1.3.
1) What secure file transport mechanisms are you using for ELR in your jurisdiction. We use PHINMS, AIMS AWS S3, SFTP, AWS S3 (not AIMS)
1) What secure file transport mechanisms are you using for ELR in your jurisdiction, e.g., PHINMS, AIMS AWS S3, other AWS S3, SFTP, etc. (please list all of them)
2) Briefly explain why your jurisdiction is using the mechanism(s) you listed.
3) Have you encountered any major issues (that were not resolved) or have any major concerns with any of those transport mechanisms?