47
DISCLAIMER: The views and opinions expressed in this presentation are those of the author and do not necessarily represent official policy or position of HIMSS. The Cloud as a Platform for Better Health Presented by: Jinesh Varia 02/23/2012

Aws jvaria e_collaborationforum

Embed Size (px)

Citation preview

Page 1: Aws jvaria e_collaborationforum

DISCLAIMER: The views and opinions expressed in this presentation are those of the author and do not necessarily represent official policy or position of HIMSS.

The Cloud as a Platform for Better Health

Presented by: Jinesh Varia

02/23/2012

Page 2: Aws jvaria e_collaborationforum

The Cloud

Page 3: Aws jvaria e_collaborationforum

Each day, AWS adds the

equivalent server capacity to power Amazon when it was a global, $2.76B enterprise

(circa 2000)

Page 4: Aws jvaria e_collaborationforum

Growth of our storage service

Q4 2006 Q4 2007 Q4 2008 Q4 2009 Q4 2010 Q4 2011

Peak Requests:500,000+

per second

Total Number of Objects Stored in Amazon S3

2.9 Billion 14 Billion 40 Billion102 Billion

762 Billion

262 Billion

Page 6: Aws jvaria e_collaborationforum

Why are people so excited about the cloud?

Page 7: Aws jvaria e_collaborationforum

Helps you focus on your application

Page 8: Aws jvaria e_collaborationforum

“IT spends 80% of its time and resources keeping the lights on”

Contract negotiation

Large Capital Expenditures

Patching SoftwareOut of Datacenter Space

Prices too high for IT products

Slow IT DeploymentsScaling down as needed

Underutilized IT Assets

Scaling up quickly

Managing physical growth

On-Premise Infrastructure is Costly & Complex

Page 9: Aws jvaria e_collaborationforum

No Up-Front Capital Expense

Pay Only for What You Use

Self-Service Infrastructure

Easily Scale Up and Down

Improve Agility & Time-to-Market

Low Cost

Cloud Computing Benefits Are Real

Deploy

Page 10: Aws jvaria e_collaborationforum

The AWS Cloud

ComputeAmazon EC2Auto Scaling

NetworkAmazon VPC

ELB, DirectConnectAmazon Route 53

AWS Global Physical Infrastructure (Geographical Regions, Availability Zones, Edge Locations)

StorageAmazon S3

Amazon EBS

Your Application

DatabaseAmazon RDS

Amazon DynamoDBAmazon ElastiCache

Libraries and SDKs.NET/Java etc.

Web InterfaceManagement Console

ToolsAWS Toolkit Eclipse, VS

Command Line Interface

Auth, Authorization, Federation

AWS IAM, MFA

MonitoringAmazon CloudWatch

Deployment and AutomationAWS Elastic BeanstalkAWS CloudFormation

Low-level building blocks

High-level building blocks

Tools to access services

Cross Service features

Content DeliveryAmazon

CloudFront

EmailAmazon SES

TransferImport/Export

Storage Gateway

Parallel Processing

Amazon Elastic MapReduce

MessagingAmazon SNSAmazon SQS

Page 11: Aws jvaria e_collaborationforum

Global Infrastructure

US West(Northern California)

US East(Northern Virginia)

EU(Ireland)

Asia Pacific

(Singapore)

Asia Pacific(Tokyo)

AWS RegionsAWS Edge Locations

GovCloud(US ITAR Region)

US West(Oregon)

South America(Sao Paulo)

Page 12: Aws jvaria e_collaborationforum

Cloud Benefits

Zero upfront investment

On-demand provisioning

Instant scalability

Auto scaling and elasticity

Pay as you go

Removes undifferentiated heavy lifting

Developer productivity

Automation

CloudStrategy

New applications

Build a Cloud-Ready

Design

Existing Applications

Planned Phased migration

Enterprise Cloud Strategy

Health 2.0 Startup or

SMB Firmor

Large Enterprise

Page 13: Aws jvaria e_collaborationforum

Flexibility

Choice of location (Region) Choice of development and system management tools

Choice of programming language – Java, Ruby, Python, Perl, .NET..

Programmable Infrastructure

Choice of Operating SystemsLinux, Windows, Suse, RedHat….

Choice of Databases (Commercial)Oracle, SQL Server, MySQL, PostGres…

Purchasing Options On-Demand, Reserved, Spot, Invoice, Credit Card

Choice of as much or as littleAnd only pay only what you use

Page 14: Aws jvaria e_collaborationforum

The Cloud as a Platform

Page 15: Aws jvaria e_collaborationforum

The Cloud as a PlatformFor Collaboration – Data

Page 16: Aws jvaria e_collaborationforum

Data Collaboration

• Storage Services• Amazon S3• Amazon EBS• Amazon DynamoDB

• Transfer Services• AWS Import/Export• AWS Storage Gateway

• Identity and Access Management

• Federation• Encryption features

• Amazon S3 Server Side Encryption

• Client side encryption• Key Management (Partners)

Page 17: Aws jvaria e_collaborationforum

BioSense 2.0 protects the health of the American people by providing timely insight into the health of communities, regions, and the nation by offering a variety of features to improve data collection, standardization, storage, analysis, and collaboration.

Facts:1. Authorization to Operate (ATO) from CDC2. FISMA- Moderate3. CDC use NIST Standards for Certification &

Accreditation Process (NIST SP 800-18, NIST SP 800-37, NIST SP 800-53)

4. Launched on 15 Nov 20115. In AWS GovCloud Region (US-Persons only)

Page 18: Aws jvaria e_collaborationforum

State Health Department

Hospital

HIE

Health System

State Health Dept. Cloud

HospitalHIE

Health System

State Lockers

DataWarehouse

BioSenseEssense

State/Local User/ Admin

Authorized Collaborator

CDC User

Page 19: Aws jvaria e_collaborationforum
Page 20: Aws jvaria e_collaborationforum

Data Exchange and Integration

Page 21: Aws jvaria e_collaborationforum

The Cloud as a PlatformFor Collaboration – Data

Page 22: Aws jvaria e_collaborationforum

The Cloud as a PlatformFor Collaboration – DataFor Clinical Research

Page 23: Aws jvaria e_collaborationforum
Page 24: Aws jvaria e_collaborationforum

Clinically Actionable / Evidenced Based

Information at the Point of Care

MomentPatientSpecific

InformationMolecular

Clinical

Disease Treatments

Disease

Molecular

GlobalClinically

ActionableInformation

They create a patient specific storydesigned to support treatment decision

Patient Specific PhysicianEducation

Patient Specific Education at Point Of Care Moment

25

Page 25: Aws jvaria e_collaborationforum

• 8 Algorithms• 54K molecular data

points• Asynchronous

analysis

• Four content stores• 30M+ records• Textual search

engine

Personalized Medicine Service

Page 26: Aws jvaria e_collaborationforum

OncInsights Report

• Interactive

• Explore Evidence

• Easy to Navigate

Clinical Knowledge SystemAlignment of molecularly identified therapeutic candidates …With clinically relevant knowledge in the disease context

• Scientific Literature

• Clinical Trials

• Compendium Support

Page 27: Aws jvaria e_collaborationforum

The Cloud as a PlatformFor Collaboration – DataFor Clinical Research

Page 28: Aws jvaria e_collaborationforum

The Cloud as a PlatformFor Collaboration – DataFor Clinical ResearchFor Data Protection

Page 29: Aws jvaria e_collaborationforum

Data Protection and Disaster Recovery

Continuous Online Data Backup

Page 30: Aws jvaria e_collaborationforum

Regions and Availability Zones

Customer Decides Where Applications and Data Reside

Page 31: Aws jvaria e_collaborationforum

Dedicated Instances

On-demandInstances

• Pay as you go

• Starts from 0.02/Hour

ReservedInstances

• Onetime upfront + Pay as you go

• $56 for 1 year term and then $0.01/Hour

SpotInstances

• Requested Bid Price and Pay as you go

• $0.005 /Hour as of today at 9 AM

Dedicated Instances

• Standard and Reserved

• Single Tenant Instances

• $10/Region + 0.105/Hour

For Spiky Workloads

For Steady State

Workloads

For Time-insensitive workloads

For Regulatory and Compliant

Workloads

Page 32: Aws jvaria e_collaborationforum

The Cloud as a PlatformFor Collaboration – DataFor Clinical ResearchFor Data Protection

Page 33: Aws jvaria e_collaborationforum

The Cloud as a PlatformFor Collaboration – DataFor Clinical ResearchFor Data ProtectionFor Corporate Apps

Page 34: Aws jvaria e_collaborationforum

DirectConnectLocationCorporate

Data Center

Amazon Virtual Private

Cloud

10G

Extend your existing datacenter

Page 35: Aws jvaria e_collaborationforum

Amazon VPC

AWS Region

Public Subnet

Private Subnet

Corporate data center

Corporate Headquarters

Availability Zone 1

Availability Zone 2

Branch Offices

VPN GatewayCustomer Gateway

Internet Gateway

Router

DirectConnectLocation

Amazon S3 Amazon SimpleDB Amazon SES Amazon SQSNew Enterprise IT Network architecture

10G

Page 36: Aws jvaria e_collaborationforum

Cloud-based NLP Service

A Strategy for Deploying Secure Cloud-Based Natural Language ProcessingSystems for Applied Research Involving Clinical TextDavid Carrell

Page 37: Aws jvaria e_collaborationforum

Built on Security Standards

Certifications

SOC1 Type 2(SAS-70)

ISO 27001

PCI DSS 2.0 for EC2, S3, EBS, VPC, RDS, ELB, IAM

FISMA Moderate Compliant Controls

Enables HIPAA & ITAR Compliant Architecture

Physical Security

Datacenters in nondescript facilities

Physical access strictly controlled

Must pass two-factor authentication at least twice for floor access

Physical access logged and audited

HW, SW, Network

Systematic change management

Phased updates deployment

Safe storage decommission

Automated monitoring and self-audit

Advanced network protection

AWS Security and Compliance Center: http://aws.amazon.com/security

Page 38: Aws jvaria e_collaborationforum

SOC1 Type 2 AuditISO 27001/2 CertificationPCI DSS 2.0 Level 1-5HIPAA/SOX ComplianceFISMA A&A ModerateFEDRamp/GSA ATO

Enforce IAM policiesUse MFA, VPC, Leverage S3

bucket policies, EC2 Security groups, EFS in EC2 Etc..

Encrypt data in transitEncrypt data at rest

Protect your AWS CredentialsRotate your keys

Secure your application

Security is a Shared Responsibility

Application Security

Services Security

Infrastructure Security

How we secure our infrastructure

What security options and features are available to you?

How can you secure your application and what is your responsibility?

Page 39: Aws jvaria e_collaborationforum

Security and Compliance Assessment

You own the data, not AWS. You choose which geographic location to

store the data. It doesn’t move from AWS region unless you decide to move it.

You have the flexibility to decide when and how you will encrypt your data while it is in transit and while it is at rest based on sensitivity of your data

You can download or delete your data whenever you like.

You can set highly granular permissions to manage access of a user within your organization to specific service operations, data, and resources in the cloud for greater security control.

Involve your Security and Compliance Teams early in the process

Page 40: Aws jvaria e_collaborationforum

The Cloud as a PlatformFor Collaboration – DataFor Clinical ResearchFor Data ProtectionFor Corporate Apps

Page 41: Aws jvaria e_collaborationforum

The Cloud as a PlatformFor Collaboration – DataFor Clinical ResearchFor Data ProtectionFor Corporate Apps For Platforms

Page 42: Aws jvaria e_collaborationforum
Page 43: Aws jvaria e_collaborationforum
Page 44: Aws jvaria e_collaborationforum
Page 45: Aws jvaria e_collaborationforum

The Cloud as a PlatformFor Collaboration – DataFor Clinical ResearchFor Data ProtectionFor Corporate Apps For Platforms

Page 46: Aws jvaria e_collaborationforum

The Cloud as a PlatformFor Better Health

Page 47: Aws jvaria e_collaborationforum

Thank you!

Jinesh [email protected] Twitt er:@jinman

htt p://linkedin.com/in/jinman