Healthcare

Meeting HIPAA Requirements for Secure Data Exchange

Cleo’s VersaLex products allow Healthcare organizations to comply with HIPAA regulations for the security of data in transit. VersaLex provides an efficient, expedient method to exchange confidential healthcare information that helps to control costs and improve patient care, while protecting patient privacy.

The traditional methods of faxing, proprietary point-to-point communications, and VANs (Value Added Networks) are expensive. VersaLex leverages secure Internet communication protocols to transfer information quickly and affordably. A move to secure Internet communications can result in substantial cost-savings.

Certified Secure Communications Solution
The Drummond Group certifies communications products for security and interoperability. AS2 and ebMS (ebXML Messaging) are two protocols that may be used to meet HIPAA requirement for secure data exchange. VersaLex is Drummond certified for AS2, AS3, and ebXML Messaging Service (ebMS, HL7, CDC-PHIN, STAR ), and Cleo also supports FTP, FTP/S, OFTP, SSH FTP, FTP/PGP , MQ Series ®, SMTP, HTTP, and HTTP/S connections.

Secure File Transfer for Any Data
There is no restriction on what file types or data can be exchanged with VersaLex. Common files include XML, EDI, Binary files, Spreadsheets, and Graphical files. Use VersaLex to transfer:

  • Healthcare EDI with suppliers
  • Insurance Forms between hospitals and payors
  • Patient Records between physicians’ offices, hospitals, etc.
  • Disease outbreak data to Public Health agencies
  • HL7 data for PHIN (Public Health Information Network) compliance
  • And more


How do AS2 and ebMS differ from FTP/S?

AS2 and ebMS offer the advanced level of security and reliability required for organizations dealing with sensitive information. They address the four universally recognized requirements for securing an Internet document exchange referred to by the acronym “PAIN.”

  • Privacy is achieved through the encryption of the message. AS2 and ebMS utilize HTTP/S as the underlying protocol.
  • Authentication is achieved through the exchange of digital certificates to verify the identity of the sender and receiver.
  • Integrity: Public and private keys are exchanged to ensure the sender and receiver are who they claim to be.
  • Non-repudiation: Acknowledgements or receipts provide a legal way to verify that the sender did receive the message. The sender can request a digital signature along with the acknowledgement, ensuring the identity of the recipient. In AS2 these receipts are called Message Disposition Notifications (MDNs). The combination of an acknowledgement and digital signature provides a high level of security and verification known as “Non-repudiation.” Non-repudiation is a key differentiator that separates AS2 and ebMS from FTP/S.

Additionally, AS2 and ebMS are certified interoperable protocols. Interoperability makes AS2 and ebMS attractive to organizations that desire to do business with a wide variety of partners and do not want to be constrained to the limits and expense of a proprietary solution. Since there is no one well accepted standard for FTP/S, both parties exchanging data must use the exact same secure FTP product or communicate via an expensive proprietary secure network. Interoperability provides the flexibility for each party to use any certified solution that is best suited for their needs, while knowing that the solutions will communicate with one another successfully.

More on AS2             More on ebMS

Many Requirements, One Solution
VersaLex is a multi-protocol solution allowing Healthcare Organizations to communicate using different methods, per each requirement. For example, you may be required to exchange Insurance information over ebMS, while your medical suppliers require AS2, and your headquarters location uses FTP/S. VersaLex allows you to use one solution to meet all your requirements. VersaLex is Drummond certified for AS2, AS3, and ebXML Messaging Service (ebMS, HL7, CDC-PHIN, STAR ), and also supports FTP, FTP/S, OFTP, SSH FTP, FTP/PGP , MQ Series ®, HTTP, and HTTP/S connections for full flexibility and scalability.

Scalable, Easy, and Automated
VersaLex allows Healthcare Organizations to start with a few connections, and easily add more as their network and requirements grow. The software is intuitive and easy to use. Many choose to fully automate data exchanges using the integrated scheduler. For those with EDI requirements, VersaLex integrates with all the major EDI translators to create a streamlined solution.

Sized Right
For a larger network or high-volume secure file transfers, choose our server solution, VersaLex Trader. For a few to a dozen connections and a moderate volume, LexiCom is an economical client software.

Leverage Cleo's Experience
The VersaLex products are proven in thousands of installations worldwide. Cleo understands the complexities of constantly evolving protocol standards, encryption, and digital certificates. To learn more, please contact Cleo Sales. Cleo can recommend and implement a solution and strategy that will ensure your success with secure communications. Want hands-on information? Download a free 30-day trial of LexiCom.