Back to Top Skip to main content

Oak Harbor achieves first with crucial new information technology milestone

Naval Health Clinic Oak Harbor seal Naval Health Clinic Oak Harbor seal

Recommended Content:

Military Hospitals and Clinics | Research and Innovation

Due to a rigorous and lengthy process to ensure patient information and privacy standards are now more secure than ever, Naval Health Clinic Oak Harbor (NHCOH) has been awarded the first ever three-year Risk Management Framework (RMF) Authorization To Operate (ATO) for a Navy Medicine command.

The ATO falls under the Defense Health Agency’s (DHA) new RMF process and is contingent on a command such as NHCOH effectively minimizing risk in protecting patient information, including Health Insurance Portability and Accountability Act (HIPAA) and Personally Identifiable Information (PII).

“It is commonly understood that the threat to healthcare systems from cyber security attacks is among the greatest risks in the world of information management. Patient records are highly sought after by cyber criminals and many healthcare networks in America have recently been targeted by a wide variety of cyber threats to illegally obtain medical records or simply hold healthcare institutions hostage,” said NHCOH’s Director for Administration, Navy Cmdr. Tim Coker.

“Reducing risks so that our patients' information is as safe as we can make it is a top priority for the DoD and for the DHA,” stated NHCOH Executive Officer, Navy Capt. Denise Gechas. “This ATO represents a very long process of setting in place the security and controls needed to keep those records safe”.

According to Coker, implementation of the RMF process began several years ago. It involved mitigating cyber security risks, building a new secure network, and developing and documenting hundreds of pages of evidence related to the security of the command’s network.

“For our Information Management staff, this represents several years of dedicated effort to achieve something that has not been done before in Navy Medicine,” explained NHCOH Commanding Officer, Navy Capt. Christine Sears. “The health, wellness, and peace of mind of all our patients has always come first in everything we do, and this commitment to ensuring all personal information is safe and secure is another example of that.”

Mr. Greg Carruth, NHCOH Chief Information Officer, attests the hard work required for this accreditation will have long-lasting ramifications for other Navy Medicine commands. By providing a blueprint that others may follow, NHCOH’s lessons learned can be utilized to ensure patient information is secure and privacy standards are fully met, while minimizing risk to the network.

“It was an intense effort for an extended period of time. The process itself made it a learning exercise at all levels,” said Carruth.

Mr. Rex Collins, Information Systems Security Manager for NHCOH, added that there was significant dedication required. “This was the longest IT project in my 20 years as an IT professional. It took 37 months from the first e-mail to DHA requesting resources and guidance to the final ATO itself,” noted Collins.

Disclaimer: Re-published content may have been edited for length and clarity. Read original post.

You also may be interested in...

DHA PI 6025.10: Change 1: Standard Processes, Guidelines, and Responsibilities of the DoD Patient Bill of Rights and Responsibilities in the Military Health System (MHS) Military Medical Treatment Facilities (MTFs)


This Defense Health Agency-Procedural Instruction (DHA-PI), based on the authority of References (a) through (d), and in accordance with the guidance of References (e) through (t), establishes the Defense Health Agency’s (DHA) procedures to begin standard processes and guidelines for the Patient’s Bill of Rights and Responsibilities, Reference (e)), in MTFs.

Continuing Implementation of the Reform of the Military Health System


This memorandum directs the continued implementation of the Military Health System (MHS) organizational reform required by 10 U.S.C. § 1073c, and sections 71 land 712 of the John S. McCain National Defense Authorization Act (NDAA) for Fiscal Year (FY) 2019. The DoD policy for this reform is guided by the goals of improved readiness, better health, better care, and lower cost. The Department will advance these objectives through specific organizational reforms directed by Congress and the continued direction of the Secretary of Defense·anct the National Defense Strategy.

DHA-PI 3200.01: Research and Development (R&D) Enterprise Activity (EA)


This Defense Health Agency-Procedural Instruction (DHA-PI), based on the authority of References (a) and (b), and in accordance with the guidance of References (c) through (p): a. Establishes the Defense Health Agency’s (DHA) procedures for the Deputy Assistant Director (DAD), R&D to manage and execute, on behalf of the Assistant Secretary of Defense for Health Affairs (ASD(HA)), the portion of the Defense Health Program (DHP) Research, Development, Test, and Evaluation (RDT&E) appropriation assigned to it (referred to as the “DHP Science and Technology (S&T) Program)”. The DHP S&T Program includes Budget Activities (BAs) 6.1-6.3 and 6.6. The ASD(HA) provides policy, direction, and guidance to inform planning, programming, budgeting, and execution of the DHP RDT&E appropriation in accordance with statute, regulation, and policy in Reference (a). The DAD-R&D, and Component Acquisition Executive (CAE) manage and execute DHP RDT&E Program funds aligned to them on behalf of the ASD(HA). The CAE is responsible for managing BAs 6.4, 6.5, and 6.7 funding, as well as Procurement and Operations and Maintenance funding required to support DHP-funded Acquisition Programs, regardless of acquisition activity. b. Supports the Director, DHA, in developing appropriate DHA management models to maximize efficiencies in the management and execution of DHP RDT&E-funded activities carried out by the Combatant Commands (CCMDs), Services, Uniformed Services University of the Health Sciences (USU), Defense Agencies, and other DoD Components, as applicable. c. Codifies processes to confirm DHP RDT&E funds are applied towards medical priorities and aligned to ASD(HA) policy, direction, and guidance to develop and deliver innovative medical products and solutions that increase the readiness of the DoD medical mission in accordance with Reference (a). d. Supports the following objectives of the R&D EA: (1) Increasing the quantity, quality, and pace of medical research through improved programmatic organization, processes, and oversight. (2) Ensuring DHP RDT&E funded efforts align to ASD(HA) published program guidance that provides resourcing guidance and translates national, departmental, and Service priorities into specific program objectives. (3) Verifying alignment of DHP RDT&E funds to medical priorities and to ASD(HA) policy, direction, and guidance to ensure the development and delivery of medical materiel and knowledge solutions. (4) Facilitating coordination with the CCMDs, Services, USU, Defense Agencies, and other DoD Components, as applicable, to ensure DHP RDT&E funded activities address joint medical capability gaps, and avoid unnecessary duplication.

Implementing Congressional Direction for Reform of the Military Health System


Policy Memorandum, signed by Deputy Secretary of Defense Patrick M. Shanahan, to direct implementation of the Military Health System (MHS) organizational reform required by the National Defense Authorization Act.

DHA-PI 6025.03: Standard Processes and Criteria for Establishing Urgent Care (UC) Services and Expanded Hours and Appointment Availability in Primary Care in Medical Treatment Facilities (MTFs) to Support an Integrated Health Care System (IHCS)


This Defense Health Agency-Procedural Instruction (DHA-PI), based on the authority of References (a) through (c), and in accordance with the guidance of References (d) through (l), describes standard processes and criteria for the establishment of UC services and expanded hours and appointment availability in primary care in MTFs.

Military Health System Prescription Transfer Procedures


Effective immediately, all Department of Defense (DoD) military treatment facility (MTF) outpatient pharmacies will accept patient requests for prescription transfers from another MTF and from retail pharmacies. When another pharmacy requests prescription transfer information on behalf of a patient, DoD MTF outpatient pharmacies will respond to the inquirer in a timely manner.

Guidance on the Establishment of a Human Cell, Tissue, and Cellular and Tissue Based Products Program


This memorandum requests the Services resource a Human Cell, Tissue, and Cellular and Tissue Based Products (HCT/Ps) Program that complies with regulatory standards for management and oversight of HCT/Ps, according to the best fit for their Service.

Showing results 1 - 7 Page 1 of 1

DHA Address: 7700 Arlington Boulevard | Suite 5101 | Falls Church, VA | 22042-5101

Some documents are presented in Portable Document Format (PDF). A PDF reader is required for viewing. Download a PDF Reader or learn more about PDFs.