What is the ICW Healthcare Connector?

The ICW Healthcare Connector is a connector linking primary systems to the telematics infrastructure. It acts as a gateway joining a medical practice to the telematics infrastructure. Physically, the connector is a separate device that sits between a medical practice PC and the network connection. From an architectural point of view it is the first layer of the telematics infrastructure rather than part of the medical practice?s local area network (LAN). The ICW Healthcare Connector encapsulates a primary systems? business logic and security functionality leaving the central infrastructure in control. This interoperability is transparent to the users of Practice Management Systems who can continue to use their systems as before. Additionally the connector provides a connection between Primary systems and card terminals, giving platform- and driver independent access to electronic Health Cards and Health Professional Cards.

What does the ICW Healthcare Connector do?

The ICW Healthcare Connector is a gematik approved connector or access point currently in use in Germany in the electronic Health Card (eHC) test regions and in a pilot project for a national eHC in Bulgaria. It enables services such as electronic prescriptions based on the eHC. Gematik is the company that oversees the telematics infrastructure and applications for the eHC in Germany.

The ICW Healthcare Connector provides a platform for qualified digital signatures by identifying and authenticating eHCs and Health Professional Cards (HPC). It allows physicians and pharmacists to access to the central telematics infrastructure of the German healthcare system.

Architecture

The ICW Healthcare Connector is made up of two components, the Cisco Healthcare Router and an application connector - ICW?s Healthcare Connector Application (HCA), housed in one box. The Healthcare Router establishes a safe connection between a local physician?s office or a pharmacy?s network and the healthcare network of the eHC. In the physician or pharmacy?s network, the HCA controls the flow of information between the connected card readers, the available physician practice or pharmacy software and the healthcare network. This allows the safe and comfortable use of applications based on the eHC, e.g. electronic prescriptions or personal health records using the existing physician or pharmacy practice software.

Image showing internal architecture of the ICW Box showing Cisco and ICW's software on the AIM board.
Figure 1. Architecture of the ICW Healthcare Connector
ICW Healthcare Connector Application

The ICW Healthcare Connector Application (HCA) is software that provides a link between different components of a modern telematics infrastructure. It is a practical solution that:

  • Implements the gematik specified functions
  • Provides and/or dispense electronic prescriptions
  • Administers the emergency data set
  • Checks contraindication and interactions for medications
  • Exchanges medical documents with the LifeSensor personal health record.

The HCA can be easily configured using a web browser. ICW offers additional applications like a remote management system for connectors (RMS) and kiosks (K-RMS), and a Software Development Kit (SDK) for primary system vendors. Primary system vendors can create an interface to the ICW HCA as well as to the LifeSensor personal health record using ICW?s SDK.  New added-value applications or updates of existing applications can be installed automatically and remotely on the connector at any time.

Cisco Router

The ICW Healthcare Connector is based on the Cisco Integrated Services Router (ISR) series with an AIM board. IBM WebSphere Everyplace Micro Environment (J9) is used to run the connector on top of the Aim board?s operating system. In addition to Hardware-based encryption acceleration on the motherboard, the integrated Firewall, the support for net-based Intrusion Protection Systems (IPS) the router also allows the efficient execution of remote updates. The Healthcare router can be supplied with an integrated DSL modem, ISDN modem or alternatively with an Ethernet interface. Connections to the user?s LAN (Local Area Network) can be made using the integrated 4-Port switch or an optional WLAN interface (Wireless Local Area Network).

System Landscape

To create a viable system the following elements are required: at least one computer running a primary system including a TrustedViewer, a connector, here the ICW Healthcare Connector, and an approved SICCT card reader with 2 slots.  

Figure 2 shows the ICW Healthcare Connector in the context of the proposed German telematics infrastructure as an example.

Image showing the ICW Box in the context of the system landscape.
Figure 2. ICW Healthcare Connector System Landscape

Primary systems
These are defined as IT systems used by health care professionals, they include Practice Management Systems, Pharmacy Management Systems and Hospital Information Systems.


TrustedViewer
The TrustedViewer is an application needed by the ICW Healthcare Connector to display a list of documents prior to generating the actual signature and to display a document with the verification results after signature validation. When producing a signature the user first wants to see what they digitally. If signatures need to be validated, the ICW Healthcare Connector uses the TrustedViewer to show the user the document and the results of the validation test.

Card Readers
Card readers read the insured persons' data; they show the emergency data set on the eHC and communicate with the HPC. In the medium term  they will be based on the SICCT standard.

Electronic Health Card
Electronic health cards with microprocessor chips enable the quick and secure exchange of information between doctors, patients, hospitals and other medical or care facilities involved and thus enable more efficient medical care. Unnecessary duplicate examinations can be avoided and dangerous interactions between different medications can be better recognized.

Health Professional Card
If prescriptions are to be written on the card or emergency data read then a Health Professional card is necessary. The HPC is an individually programmed access card for health care professionals. This card is used to assign read and/or write access rights to specific data fields on the patient card.

What about Security?

Secure transmission of data is one of the key features of the ICW Healthcare Connector. The software for the ICW Healthcare Connector is built according to OSGi standards. The OSGi platform extends the basic Java security model. The ICW HCA runs in a separate, protected processor and memory environment on the router. Cisco runs a hardened version of Linux and security features like the firewall, the encryption of the network connection as well as the routing are unimpaired.

Use in other Markets

The ICW Healthcare Connector can be adapted as needed for other markets where a similar telematics infrastructure is used. The first projects using the ICW Healthcare Connector are regional networks for integrated healthcare and the official test regions for the eHC in Germany. An adapted version is used in the Pilot project for the national eHC in Bulgaria. There is also a server-based version of the ICW Healthcare Connector approved by gematik for use in German hospitals.