dom & tom nyc healthcare cloud meetup case study (5/4)
TRANSCRIPT
![Page 1: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/1.jpg)
DOM & TOM INC DOMANDTOM.COM NEW YORK: 646 741 5049 / CHICAGO: 773 377 5585
DOMANDTOM.COM NYC 646.741.5049 / CHI 773.377.5585
![Page 2: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/2.jpg)
Do Good. Be Good. That’s what we do.
![Page 3: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/3.jpg)
WHO AM I?
Dom Tancredi » Full-Stack Developer of 18+ years. » CTO School Member (since 2014). » Fun Fact: Theatre + Computer Science degrees. » Certified ScrumMaster + Product Owner.
3
Dom & Tom » Launched 90+ mobile // 300+ web products. » 60 team members. » New York, Chicago & Los Angeles. » Digital product development agency. » Enterprise + startup-friendly.
![Page 4: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/4.jpg)
D&T BREAKDOWN
![Page 5: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/5.jpg)
CASE STUDY: Dignity Health Hospital Group
![Page 6: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/6.jpg)
OPPORTUNITY
6
Goals » Bring brand to the 21st Century on mobile and tablet. » Grow relationships with patients. » Stay within InfoSec and legal policies of hospital.
![Page 7: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/7.jpg)
SOLUTION
7
The Product » St. Rose's NICU app reaches out to new parents on mobile and tablet. » Cross-platform marketing approach to communicate with parents. » Portfolio of products:
» iPhone, iPad, Android phone and tablet. » 2 hospital NICU centers.
![Page 8: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/8.jpg)
SOLUTION
8
Mobile » iOS and Android phone and tablet applications for Dignity Health
Group’s neonatal intensive-care unit (NICU). » The hospital group was not granted access to retrieving cloud patient
data. » The applications track and graph measurements and feeding data.
Information is provided to doctors for tracking child progress after parents bring their infants home. All data is stored locally.
![Page 9: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/9.jpg)
SOLUTION
9
Mobile » Strong collaboration with Dignity Health’s legal team to approve all
content. » Architecture for white labeling and sharing resources among
applications made building and deploying much more efficient. » 6 applications were built. » iOS: utilized multi-target codebase and had a core library for specific
packages and extended to custom visuals. » Android: utilized core library (package-first) philosophy to integrate into
custom product versions.
![Page 10: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/10.jpg)
SOLUTION
10
Mobile » Encryption of data locally in key-value pairs. » Decrypted data when visualized and viewed by users. » iOS data stored in key-value pairs which, since iOS6, has encryption built
in. » Recommend RNCryptor (iOS) and AESCrypt (Android) for higher-order
encryption (AES-256) if customizing encryption with datastores methodologies.
» Datastore (iOS): CoreData, SQlite, Plist (iOS), Keychain as potential vectors for lifting datasets out of system.
» Datastore (Android): Database, Internal // External Storage, SQLite Shared Pref (similar to Keychain).
![Page 11: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/11.jpg)
Personally identifiable information (PII) is any data that could potentially identify a specific individual. Any information that can be used to distinguish one person from another and can be used for de-anonymizing anonymous data can be considered PII.
SOLUTION
11
Server-Side » AWS utilization was planned for in the product roadmap.
» AWS technologies roadmapped.
![Page 12: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/12.jpg)
SOLUTION // PROCESS
» Planning: Project planning added milestones and estimations for user experience, design and sprint feature-set per platform for legal review.
» Legal: Created early relationship in process with legal teams on feature-set, design and implementation changes.
» “MLR:” Medical Legal Review where legal can make adjustments and changes to any part of an application.
» Planning: Planned per release platform for MLR.
12
![Page 13: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/13.jpg)
DEVSECOPS @ D&T
FIP-range restricted access to servers
Key-restricted servers to DevOps + Tech leads
Tech AWS + Digital Oceans; Ansible; Docker + Rancher for dev, staging, production instances.
13
Client-side encryption of data
Encryption via SSL communication to servers
MDM or testing Mobile device management or testing with Hockey or TestFlight.
Ask yourself: How might someone access the data, the business logic or spoof the experience?
![Page 14: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/14.jpg)
DEVSECOPS @ D&T
» InfoSec Policy defined at D&T.
» InfoSec Training with technical leads.
» Working to shape and share DevSecOps policies with startup clients (being aware of OWASP Top 10, social engineerings, etc.).
14
![Page 15: Dom & Tom NYC Healthcare Cloud Meetup Case Study (5/4)](https://reader034.vdocument.in/reader034/viewer/2022042618/58abae3f1a28abdf3c8b670f/html5/thumbnails/15.jpg)
Questions?