Accessing your practice network from home
Originally published in GP magazine .
Written for GP magazine around 2002. This is the version I submitted - the published article may have been edited.
Want to work from home? Not everyone does, but there are times when it can be useful to access your practice network; either to check your email or lab-links, enter a home visit or check a patient’s record, especially if you still do on-call from home. It may also be useful to access the NHSnet from home, which increasingly has interesting and useful sites, such as reference works, that are only viewable from inside the NHSnet. An out-of-hours co-operative may also find it useful to access records, at least until the total electronic patient record is in place, though there are concerns re too many people having access to your system and current systems not having enough different levels of access available.
To access the NHSnet from home for the principal purpose of accessing library resources there is a system called “Athens” which provides users with a username and password. More information can be found at www.athens.nhs.uk, though this doesn’t provide any access to your clinical system.
You can also gain direct access to the NHSnet via BT or Cable and Wireless, who run the NHSnet. They will provide a phone number, user ID, PIN number and password that will allow you into the NHSnet; however, to access your practice network your firewall will have to be altered to let you in. While this can be done it isn’t common and your clinical systems supplier may not approve. Costs involved are roughly £50-135 + VAT for setup and £50-75 + VAT per quarter, plus phone bills. (Prices from 2001 - info on this service is difficult to find.)
Traditionally some GP clinical suppliers have provided a method of accessing the clinical system by modem from home using a terminal emulator program that makes the home user appear as a dumb terminal on the network. This dates back to systems that started when dumb terminals were used by the majority of users and the interface was text based. For solely text-based interfaces this still works well, though most suppliers have moved on and where this is the case this type of access can only provide limited access, usually to the basic record. Most current GP networks are based on a Windows NT/2000 server and use Microsoft Exchange to manage email, and even systems that aren’t fully Windows based have add-ons such as scanned attached documents or links to Microsoft Office that, as stated, won’t work down a dumb terminal connection.
Luckily Windows NT/2000 server has a service called Remote Access Server, or RAS, that allows a dial-up connection to behave as a full client on the network, albeit slower. This means you can access your email, clinical system, any other programs or files on your network and even the internet and NHSnet. To meet the NHSnet code of connectivity, however, this service is not secure enough to guarantee patient confidentiality etc and additional hardware is required. There are various means of doing this, including cards that contain unique long passwords which require special readers, usually an extra box or adapted keyboard, and there even exists a mouse with a built-in fingerprint reader. (Using the user’s personal characteristics rather than passwords is known as biometrics.)
The approved and commonly available method for accessing GP systems uses a piece of hardware known as a token that is usually the size of a credit card. It contains an algorithm that is matched on the server and produces a long password when queried that confirms the user’s identity. There are two types of token in use. One relies on time synchronisation with the server and generates a number, based on the time and the hidden algorithm, that varies constantly and is recognised by the server to allow access. The other uses a challenge-response technique; this is where a number is produced by the server when logging on to it, and when this number is entered into the token it uses the algorithm to produce a number that is then used as the password. In both cases the token is usually protected by a user-remembered PIN.
There are two main suppliers of these tokens, ISL (www.informer.co.uk) and Intercede (www.intercede.co.uk). Costs vary and are based on an initial purchase price, annual support costs and the price of tokens. Expect to pay £1,250-1,500 for the product licence and variable amounts for the others; for latest prices check the websites, though your clinical supplier may have a preferred option and a special price.
It is worth mentioning that dial-back is usually still available; this is the facility where the server rings you back, not only to save your phone bills but also as a triple security measure in that it has to previously know your phone number. For a really high-flying system, if you have a lot of users and enough phone lines you can get a multi-port modem to replace your single-port modem for your server that can deal with multiple users logging on remotely using token-based security. Four-port modems are common, though more ports are available.
It may well be worth approaching your PCT to see if a co-ordinated approach is possible, especially if bulk discounts are available, and this may be especially sensible in areas where all practices have been encouraged to go to one supplier.
Further technical details can be obtained from the NHSIA NHSnet website.