46
VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Embed Size (px)

Citation preview

Page 1: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

VA/DEA PKI e-Prescribing Pilot for Controlled Substances

Rob Silverman, PharmDJanuary 13, 2005

Page 2: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Topics

e-Prescribing in Department of Veterans Affairs

VA/DEA PKI Pilot Participants Other roles Goals

Security Examples Findings

Page 3: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

e-Prescribing is the norm at a VA Medical Center

Transmit prescriptions directly to the VA pharmacy Legend drugs Over-the-counter items provided by VA Document items obtained elsewhere

Result: a complete medication and patient allergy/adverse reaction history available at any VA workstation in the hospital, remote clinic, or via VPN access, with real-time order checks

Page 4: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005
Page 5: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005
Page 6: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005
Page 7: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005
Page 8: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005
Page 9: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Schedule II controlled substances

Under 21 CFR 1306, a C-II controlled substance may only be dispensed from a WRITTEN prescription signed by the practitioner

This creates one exception to an otherwise all-electronic prescribing environment

Page 10: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005
Page 11: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005
Page 12: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

The VA/DEA PKI Pilot

An “ongoing” pilot ... although the formal review period has ended, the system is still in daily use and items are fixed as new issues come up

Scope of the project … demonstrate the application of a digital signature in place of a written signature for electronic transmission of prescriptions

Page 13: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

http://www.deadiversion.usdoj.gov/ecomm/index.html

Page 14: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Participants

Original pilot: 50 Hines physicians were selected based on volume of Schedule II prescriptions written in the preceding 3 month period

Current usage: approximately 2 dozen active providers, some from original study and some added since

Page 15: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Other participant roles

“Can’t tell the players without a scorecard”

DEA PEC (DEA’s selected contractor) VA Office of Information

Emerging Technologies Infrastructure CPRS & Pharmacy

VISN Information Security Officer

Local Information Security Officer

CPRS Coordinator IRM

Workstation setup Central server

Page 16: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Specific goals

Create the infrastructure necessary to transmit a digitally signed prescription within the VistA CPRS system Kernel (the EMR’s “operating system”) CPRS (provider access to the electronic health

record) Pharmacy VA PKI certificates

Compare the existing ELECTRONIC signature to the PKI-enabled DIGITAL signature

Page 17: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

A continuum of signature methods

Written signature Ink and paper

Captured signature Credit card machine at the store VA’s use of iMedConsent application

Electronic signature Provider knows an electronic code

Digital signature (PKI) Provider knows an electronic code and

possesses a smart card with matching information

Page 18: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Security

Digital Signature Prescription Integrity - The content of a

prescription has not been altered in transit.

Non-Repudiation - The sender of a prescription cannot deny sending it.

Authentication - The sender of a prescription is the person claimed and not an imposter.

http://www.deadiversion.usdoj.gov/ecomm/e_ordrs/index.html

Page 19: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Security – the current process

Provider contacts Clinical Informatics Service [CIS], requests to be a participant in the DEA PKI program

CIS contacts PEC PEC locates provider’s record in a

database extract from DEA, transfers it to a registrant database

Page 20: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Security – the current process

PEC confirms registration back to CIS and transmits that registration to a VA database

CIS gives provider an application/registration form

Acting as an “identity proofing agent”, CIS witnesses the application form signature Could be the local ISO or their delegate Photo ID required Resident physicians without individual DEA

numbers also require pharmacy authorization

Page 21: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Security – the current process

Application form faxed to VISN ISO, acting as LRA (local registration authority)

VISN ISO has a registration database that matches the PEC database

An 8-digit enrollment number is generated

Page 22: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Security – the current process

Enrollment number is returned securely to the local ISO

That number is then delivered in person to the applicant

Provider registers for the electronic certificate at http://vaww.va.gov/vapkidea (takes user to https://vaww1.va.gov/vapkidea/client/userEnrollMS.htm)

Other Tasks for the Card Select PIN Number Photo printed on card

Page 23: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

“ActiveCard Upgrade Instructions” – given to the Hines physicians with their card and enrollment number

Page 24: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Security – the current process

Upon completion of the preceding steps, CIS activates the provider in the computer system as eligible to participate

Page 25: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

What makes that so secure?

The certificate from the web site matches their DEA number

Their VistA CPRS account matches their DEA number

Prescription signature indicates Knowledge of VistA CPRS access/verify code Knowledge of the VistA CPRS electronic

signature code Possession of the photo ID smart card Knowledge of the card’s PIN number Certificate has not been revoked

Page 26: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Scaling the process nationally

The next few slides repeat the previous steps with a suggestion of how some areas are likely to change when this system is deployed nationally

Page 27: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Security – possible scenario for national deployment

Providers are eligible to participate by virtue of having a current and valid DEA registration … no need for manual addition to an enrollment database

Page 28: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Security – possible scenario for national deployment

Provider obtains a registration form from the DEA website and signs it in the presence of the station’s authorized “identity proofing agents” Could be the local ISO or their delegate Photo ID required

Page 29: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Security – possible scenario for national deployment

Application form transmitted to the LRA, possibly still the VISN ISO

An 8-digit enrollment number is generated

Enrollment number is returned securely to the local ISO

That number is then delivered in person to the applicant

Page 30: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Security – possible scenario for national deployment

Provider registers for the electronic certificate at a VA hosted web site https://vaww1.va.gov/vapkidea/client/userEnrollMS.htm

PIN number and card photo are probably already done because this card is used for

Access to the grounds Access to parking Access to building Other PKI activities, such as secure

email

Page 31: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Security – possible scenario for national deployment

Provider notifies CIS that they have obtained a digital certificate so that CIS can enable VistA CPRS to accept digital signature

Page 32: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

What makes that so secure?

The certificate from the web site matches their DEA number

Their VistA CPRS account matches their DEA number

Prescription signature indicates Knowledge of VistA CPRS access/verify code Knowledge of the VistA CPRS electronic

signature code Possession of the photo ID smart card Knowledge of the card’s PIN number Certificate has not been revoked

Page 33: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Ordering is relatively unchanged --- place the order as usual

Page 34: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Sign the order using regular CPRS functionality, with the Electronic Signature Code

Page 35: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

CPRS will prompt for the Smart Card PIN when it recognizes a C-II medication being signed

Page 36: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Activity:09/10/2004 14:15 New Order entered by SILVERMAN,CALL Order Text: MORPHINE TAB,SA 30MG TAKE ONE TABLET BY MOUTH TWICE A DAY Quantity: 60 Refills: 0 Nature of Order: ELECTRONICALLY ENTERED Dig Signature: SILVERMAN,CALL on 09/10/2004 14:16

CPRS will identify the order as DIGITALLY signed when both the electronic signature and smart card PIN have authenticated the order.

Page 37: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

The VistA pharmacy application will also identify the order as DIGITALLY signed, indicating to the pharmacist that a paper copy is not necessary. Orders that fail to validate against the digital signature are displayed to the pharmacist once, and then automatically cancelled by the system.

Page 38: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005
Page 39: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005
Page 40: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Findings of the pilot

First and foremostIT WORKS!

Time savings to practitioners No need to deliver the prescription to the

pharmacy Prescriptions are complete One-stop-shopping, all prescriptions can

be handled in the same manner Permanent “storage” of the prescription is

now an electronic file vs. boxes of prescription sheets

Page 41: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Issues solved in the pilot

The system has been maintained through Change in smart card type (x1) Change in certificate issuance authority

(x1) Change in smart card software (x2) Change in COM object (x10 !)

Page 42: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

More items solved

Workstation installation functions for “all users”

PIN caching for multiple Rx’s in the same patient profile at the same time

Forced VA to re-evaluate the drug file settings to clearly define a “schedule II drug”

Page 43: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Some “gotchas”

Biometrics testing experience Precise MC 100 used during pilot Example of alternative: Identix

Biotouch PowerUser access to computer

systems Tied to a specific smart card vendor

Page 44: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Items for discussion

Security needs for a DEA certificate are different than a VA email certificate (sign & encrypt) How many copies of the certificate may

exist? Default setup is different in a clinic than

an office environment

Does card-based logon save time? Remembering password vs. PIN

Page 45: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Future model

One ideal outcome of the pilot would be a DEA registration website that allowed online payment of a physician’s renewal, provided immediate response, and delivered a new PKI certificate at that time.

Page 46: VA/DEA PKI e-Prescribing Pilot for Controlled Substances Rob Silverman, PharmD January 13, 2005

Contact information

Rob SilvermanHines VA [email protected]