It's a New Day in Public Health.
The Florida Department of Health works to protect, promote & improve the health of all people in Florida through integrated state, county & community efforts.
The Health Management System (HMS)
Vendor Name: The Florida Department of Health
Product Name and Version: The Florida Department of Health, Health Management System (HMS) version 2015
Date Certified: June 26, 2019
Certification ID: 15.05.05.1498.FDOH.01.00.1.190626
Multi Factor Authentication (MFA)
The Florida Department of Health is a user of Microsoft’s Office365 line of products and Azure Active Directory (AD) Premium 2. Multi-factor Authentication is built into Microsoft Office365 and Azure AD.
- Azure AD Premium P1 provides features such as identity management, access management, administration of dynamic groups, and Microsoft Identity Manager.
- Azure AD Premium P2 includes all of the features of Azure AD Premium P1 – plus a few more useful capabilities, such as Identity Protection and Privileged Identity Management (PIM).
Accessing the EHR application from outside of the FDOH network will initiate MFA authentication. If the multi-factor authentication request is not approved, access to the network is denied. FDOH does not allow variation among user roles for authentication purposes.
“This Florida Department of Health, Health Management System is 2015 Edition compliant and has been certified by SLI, an ONC-ACB, in accordance with the applicable certification criteria adopted by the Secretary of Health and Human Services. This certification does not represent an endorsement by the U.S. Department of Health and Human Services.”
The HMS EHR has been tested and certified against the following certification criteria:
- 170.315(a)(5) Demographics
- 170.315(a)(12) Family Health History
- 170.315(a)(14) Implantable Device List
- 170.315(a)(9) Clinical Decision Support
- 170.315(b)(2) Clinical Information Reconciliation and Incorporation
- 170.315(d)(1) Authentication, Access Control, and Authorization
- 170.315(d)(2) Auditable Events and Tamper-Resistance
- 170.315(d)(3) Audit Report(s)
- 170.315(d)(4) Amendments
- 170.315(d)(5) Automatic Access Time-Out
- 170.315(d)(6) Emergency Access
- 170.315(d)(7) End-user Device Encryption
- 170.315(d)(8) Integrity
- 170 315(d)(10) Auditing Actions on Health Information
- 170.315(d)(12) Encrypt Authentication Credentials
- 170.315(d)(13) Multi-factor Authentication
- 170.315(b)(1) Transitions of Care
- 170.315(b)(6) Data Export
- 170.315(f)(1) Transmission to Immunization Registries
- 170 315(g)(6) Consolidated CDA Creation Performance
- 170.315(g)(3) Safety Enhanced Design
- 170.315(g)(4) Quality management system
- 170 315(g)(5) Accessibility-centered Design
Additional Products Needed:
- The HMS requires the following additional software to demonstrate compliance with certification criteria adopted by the Secretary:
3rd Party Product Name and Version
Functionality Provided by Additional Software
DataMotion Direct (DataMotion) Release 6.3
170.315(b)(1) Transitions of Care
Transportation mechanism (Direct)
- The HMS has not been tested and certified for any clinical quality measures.
- There are no types of costs that users are required to pay to implement or use the HMS’ capabilities, whether to meet meaningful use objectives and measures or to achieve any other use within the scope of the HMS' certification.