Difference between revisions of "User:Shawndouglas/sandbox/sublevel22"

From LIMSWiki
Jump to navigationJump to search
(More updates to the OpenELIS Global article.)
 
(2 intermediate revisions by the same user not shown)
Line 1: Line 1:
===4.2 Regulatory considerations===
<div class="nonumtoc">__TOC__</div>
[[File:Workshop GDPR compliance at the 2019 Global Entrepreneurship Summit.jpg|right|500px]]In Chapter 2, we examined standards and regulations influencing cloud computing. We also noted that there's an "elephant in the room" in the guise of data privacy and protection considerations in the cloud. Many of the regulations and data security considerations mentioned there apply not only to financial firms, manufacturers, and software developers, but also laboratories of all shapes and sizes. At the heart of it all is keeping client, customer, and organizational data out of the hands of people who shouldn't have access to it, a significant regulatory hurdle.
{{ombox
| type      = notice
| style    = width: 960px;
| text      = This is sublevel22 of my sandbox, where I play with features and test MediaWiki code. If you wish to leave a comment for me, please see [[User_talk:Shawndouglas|my discussion page]] instead.<p></p>
}}


Most regulation of data and information in an enterprise, including laboratories, is based on several aspects of the data and information: its sensitivity, its location or geography, and its ownership.<ref name="SimorjayData14">{{cite web |url=https://download.microsoft.com/download/0/A/3/0A3BE969-85C5-4DD2-83B6-366AA71D1FE3/Data-Classification-for-Cloud-Readiness.pdf |format=PDF |title=Data classification for cloud readiness |author=Simorjay, F.; Chainier, K.A.; Dillard, K. et al. |publisher=Microsoft Corporation |date=2014 |accessdate=28 July 2023}}</ref><ref name="TolsmaGDPR18">{{cite web |url=https://www2.deloitte.com/nl/nl/pages/risk/articles/cyber-security-privacy-gdpr-update-the-impact-on-cloud-computing.html |title=GDPR and the impact on cloud computing: The effect on agreements between enterprises and cloud service providers |author=Tolsma, A. |publisher=Deloitte |date=2018 |accessdate=28 July 2023}}</ref><ref name="EusticeUnder18">{{cite web |url=https://legal.thomsonreuters.com/en/insights/articles/understanding-data-privacy-and-cloud-computing |title=Understand the intersection between data privacy laws and cloud computing |author=Eustice, J.C. |work=Legal Technology, Products, and Services |publisher=Thomson Reuters |date=2018 |accessdate=28 July 2023}}</ref> Not coincidentally, these same aspects are often applied to data classification efforts of an organization, which attempt to determine and assign relative values to the data and information managed and communicated by the organization. This classification in turn allows the organization to better discover the risks associated with those classifications, and allow data owners to realize that all data shouldn't be treated the same way.<ref name="SimorjayData14" /> And well-researched regulatory efforts recognize this as well.
==Sandbox begins below==
{{About|the international successor to the original OpenELIS software, OpenELIS Global|the original software, which is still actively developed|OpenELIS}}<br />
{{Infobox software
| name                  = OpenELIS Global
| title                  = OpenELIS Global
| logo                  = [[File:OpenELIS_logo.jpg|230px]]
| screenshot            = <!-- [[File: ]] -->
| caption                =  
| collapsible            =  
| author                 = Casey Iiams-Hauser
| developer              = Digital Initiatives Group (DIGI) – University of Washington
| released              = {{Start date|2012|02|29}}<ref name="2.4Notes">{{cite web |url=https://sites.google.com/site/openelisglobal/openelis-global-2-4-release-notes |archiveurl=https://web.archive.org/web/20210130143717/https://sites.google.com/site/openelisglobal/openelis-global-2-4-release-notes |title=OpenELIS Global 2.4 Release Notes |publisher=University of Washington I-TECH |date=29 February 2012 |archivedate=30 January 2021 |accessdate=30 July 2026}}</ref>
| discontinued          =  
| frequently updated    = yes<!-- Release version update? Don't edit this page, just click on the version number! -->
| programming language  = Java (Spring), JavaScript (React, Carbon Design System)
| operating system      = Cross-platform
| platform              =
| size                  =  
| language              =  
| status                =  
| genre                  = [[Laboratory informatics]] software
| license                = Mozilla Public License 2.0
| website                = [https://openelis-global.org/ openelis-global.org]
}}


Take for example the European Union's [[General Data Protection Regulation]] (GDPR). The GDPR stipulates how personal data is collected, used, and stored by organizations in the E.U., as well as by organizations providing services to individuals and organizations in the E.U.<ref name="GoogleGDPR">{{cite web |url=https://cloud.google.com/privacy/gdpr |title=Google Cloud & the General Data Protection Regulation (GDPR) |publisher=Google Cloud |accessdate=28 July 2023}}</ref> The GDPR appears to classify "personal data" as sensitive "in relation to fundamental rights and freedoms," formally defined as "any information relating to an identified or identifiable natural person."<ref name="EUR-LexGDPR16">{{cite web |url=https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679 |title=Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance) |work=EUR-Lex |publisher=European Union |date=27 April 2016 |accessdate=28 July 2023}}</ref> This is the sensitivity aspect of the regulation. GDPR also addresses location at many points, from data transfers outside the E.U. to the location of the "main establishment" of a data owner or "controller."<ref name="EUR-LexGDPR16" /> As for ownership, GDPR refers to this aspect of data as the "controller," defined as "the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data."<ref name="EUR-LexGDPR16" /> The word "controller" appears more than 500 times in the regulation, emphasizing the importance of ownership or control of data.<ref name="EUR-LexGDPR16" /> However, cloud providers using hybrid or multicloud approaches pose a challenge to labs, as verifying GDPR compliance in these deployments gets even more complicated. The lab would likely have to turn to key documents such as the CSP's SOC 2 audit report (discussed later) to get a fuller picture of GDPR compliance.<ref name="TellingHowCloud19">{{cite web |url=https://cloudcomputing-news.net/news/2019/jun/03/how-cloud-computing-changing-laboratory-ecosystem/ |title=How cloud computing is changing the laboratory ecosystem |author=Telling, C. |work=CloudTech |date=03 June 2019 |accessdate=28 July 2023}}</ref>
'''OpenELIS Global''' is a free open-source [[laboratory information system]] (LIS) designed "to run national laboratory networks that serve millions of people,"<ref name="OpenELISGlobalAbout">{{cite web |url=https://openelis-global.org/about/ |title=Laboratory information, built for the public good |publisher=DIGI at the University of Washington |accessdate=30 July 2026}}</ref>, particularly in low- and middle-income countries. The software is as an offshoot of the [[OpenELIS]] open-source software project, which received development contributions from the likes of the Minnesota State Public Health Laboratory and the University of Iowa. The larger international influence on OpenELIS of collaborators such as the Association of Public Health Laboratories (APHL), the U.S. [[Centers for Disease Control and Prevention]] (CDC), and the University of Washington's International Training and Education Center on HIV (I-TECH) later spread the OpenELIS technology (in the form of separate branches of the software) to other parts of the world, including Vietnam, Haiti, and Côte d'Ivoire.<ref name"OpenELISOldAboutArch">{{cite web |url=https://sites.google.com/site/openelisglobal/about |archiveurl=https://web.archive.org/web/20190719065729/https://sites.google.com/site/openelisglobal/about |title=About/Team  |publisher=ITECH at Washington University |archivedate=19 July 2019 |accessdate=30 July 2026}}</ref> While OpenELIS continues on as a separate project run by the OpenELIS Foundation, it states that it "has limited involvement in development of global OpenELIS."<ref name="OpenELISOrgAbout">{{cite web |url=https://openelis.org/about-openelis/ |title=About OpenELIS |publisher=OpenELIS Foundation |date=2026 |accessdate=30 July 2026}}</ref>


While data privacy and protection regulations like GDPR, the Personal Data Protection Law (KVKK), and California Consumer Privacy Act (CCPA) take a broad approach, affecting most any organization doing cloud- or non-cloud business while handling sensitive and protected data, some regulations are more focused. The U.S.' [[Health Insurance Portability and Accountability Act]] (HIPAA) is huge for any laboratory handling electronic protected health information (ePHI), including in the cloud. The regulation is so significant that the U.S. Department of Health & Human Services (HHS) has released its own guidance on HIPAA and cloud computing.<ref name="HHSGuidance20">{{cite web |url=https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html |title=Guidance on HIPAA & Cloud Computing |author=Office for Civil Rights |work=Health Information Privacy |publisher=U.S. Department of Health & Human Services |date=23 December 2022 |accessdate=28 July 2023}}</ref> That guidance highlights the sensitivity (ePHI), location (whether inside or outside the U.S.), and ownership (HIPAA covered entities and business associates) of data. That ownership part is important, as it addresses the role a CSP takes in this regard<ref name="HHSGuidance20" />:
OpenELIS Global is recognized as a Digital Square Global Good and a verified Digital Public Good<ref name="DSGlobalGoods23">{{cite web |url=https://datafi.thepalladiumgroup.com/wp-content/uploads/2024/11/2.-Global_Goods_Guidebook_Version_4.0_FINAL_forpublishing.pdf |format=PDF |title=The Global Goods Guidebook - An Overview of the Software Global Goods Ecosystem |publisher=Digital Square |page=48 |date=May 2023 |accessdate=30 July 2026}}</ref><ref name="DPGAOpenELISArch">{{cite web |url=https://www.digitalpublicgoods.net/registry/openelis-global.html |archiveurl=https://web.archive.org/web/20230526130236/https://www.digitalpublicgoods.net/registry/openelis-global.html |title=OpenELIS Global |publisher=Digital Public Goods Alliance |date=2022 |archivedate=26 May 2023 |accessdate=30 July 2026}}</ref>, and its Cote d'Ivoire implementation was evaluated in a 2024 peer-reviewed study in ''JMIR Public Health and Surveillance''.<ref name="HeLab24">{{cite journal |title=Laboratory Data Timeliness and Completeness Improves Following Implementation of an Electronic Laboratory Information System in Côte d’Ivoire: Quasi-Experimental Study on 21 Clinical Laboratories From 2014 to 2020 |author=He, Y.; Kouabenan, Y.-R.; Assoa, P.H; et al. |journal=JMIR Public Health and Surveillance |year=2024 |volume=10 |issue=e50407 |doi=10.2196/50407 |pmid=38506899}}</ref>


<blockquote>When a covered entity engages the services of a CSP to create, receive, maintain, or transmit ePHI (such as to process and/or store ePHI), on its behalf, the CSP is a business associate under HIPAA. Further, when a business associate subcontracts with a CSP to create, receive, maintain, or transmit ePHI on its behalf, the CSP subcontractor itself is a business associate. This is true even if the CSP processes or stores only encrypted ePHI and lacks an encryption key for the data. Lacking an encryption key does not exempt a CSP from business associate status and obligations under the HIPAA Rules. As a result, the covered entity (or business associate) and the CSP must enter into a HIPAA-compliant business associate agreement (BAA), and the CSP is both contractually liable for meeting the terms of the BAA and directly liable for compliance with the applicable requirements of the HIPAA Rules.</blockquote>
==Product history==
In 2012, the University of Washington I-TECH began hosting OpenELIS Global, an international version of the OpenELIS software. The intent of the developers—the International Training and Education Center for Health (I-TECH) at Washington University—was to expand the functionality of OpenELIS to be more flexible while still "maintaining a common code base" among the the variation of feature requirements across different countries.<ref name"OpenELISOldAGlobalArch">{{cite web |url=https://sites.google.com/site/openelisglobal/global-implementation |archiveurl=https://web.archive.org/web/20210130143701/https://sites.google.com/site/openelisglobal/global-implementation |title=A Global LIS |publisher=ITECH at Washington University |archivedate=30 January 2021 |accessdate=30 July 2026}}</ref> The first public open-source release of the software was with version 2.4 on February 29, 2012<ref name="2.4Notes" />, followed by a 2.5 release on March 30.<ref name="2.5Notes">{{cite web |url=https://sites.google.com/site/openelisglobal/openelis-global-2-5-release-notes |archiveurl=https://web.archive.org/web/20210130143717/https://sites.google.com/site/openelisglobal/openelis-global-2-5-release-notes |title=OpenELIS Global 2.5 Release Notes |publisher=University of Washington I-TECH |date=30 March 2012 |archivedate=30 January 2021 |accessdate=30 July 2026}}</ref> The incrementation was chosen not as a numerical order of release, but rather as an identifying string as "Version.Pl​annedRelea​se.Unplann​edRelease (build number)," with versions incrementing yearly.<ref name="2.5Notes" />


Clinical and public health laboratories are already affected by HIPAA, but understanding how moving to the cloud affects those HIPAA requirements is vital and not always clear.<ref name="HHSGuidance20" /> In particular, the idea of a CSP as a business associate must be taken seriously, in conjunction with its shared responsibility policy and compliance products. Laboratories that need to be HIPAA-compliant should be prepared to do their research on HIPAA and the cloud by reading [https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html the HHS guide] and other reference material, as well consulting with experts on the topic when in-house expertise isn't available.
Since then, the software has received regular updates. Following the May 2019 release of version 9.1, work slowed slightly, apparently in favor of a planned rewrite of the code using Java Spring. In August 2019, I-TECH's Casey Iiams-Hauser (the OpenELIS Global project owner) put out a call for a software development team to tackle the transition to Java Spring and [[PostgreSQL]], with a target date of September 15, 2019.<ref name="Liams-HauserComeWork19">{{cite web |url=https://talk.openmrs.org/t/come-work-on-openelis-global-with-i-tech-we-are-looking-for-tech-writers-ui-ux-designers-and-devs-an/24221 |title=Come work on OpenELIS Global with I-TECH! |work=OpenMRS Talk |author=Liams-Hauser, C. |date=05 August 2019 |accessdate=30 July 2026}}</ref> The first release of the new version occurred in January 2020; the release notes stated: "This is a re-write of OpenELIS on modern frameworks and a significant security upgrade. At the end of this process, all tech will be currently supported and up to hardening standards. This software will be certified for use on US Government, and other high-security networks."<ref name="Liams-HauserOpenELISSoft22">{{cite web |url=https://docs.google.com/document/d/1p0zMfoUXRBbr9JyjjMeWRt1dgi7EbOd3IZdP6NCulow/edit?pli=1#heading=h.71anhixmrzil |archiveurl=https://web.archive.org/web/20220328192537/https://docs.google.com/document/d/1p0zMfoUXRBbr9JyjjMeWRt1dgi7EbOd3IZdP6NCulow/edit?pli=1#heading=h.71anhixmrzil |title=OpenELIS Software Release Roadmap |author=Liams-Hauser, C. |date=March 2022 |archivedate=28 March 2022 |accessdate=30 July 2026}}</ref> Updates over the years have added support for [[COVID-19]] testing, the [[Health Level 7#Fast Healthcare Interoperability Resources (FHIR)|FHIR API]], ASTM analyzer interfaces, data warehousing, and more.<ref name="Liams-HauserOpenELISSoft22" />


Another area of concern for laboratories is GxP or "good practice" quality guidelines and regulations. Take for example the pharmaceutical manufacturer and their laboratories, which must take sufficient precautions to ensure that any manufacturing documentation (data, information, etc.) related to [[good manufacturing practice]] (GMP) requirements (e.g., via E.U. GMP Annex 11, U.S. 21 CFR Part 211, or Germany's AMWHV) is securely stored yet available for a specific retention period "in the event of closure of the manufacturing or testing site where the documentation is stored."<ref name="ECACloud20">{{cite web |url=https://www.gmp-compliance.org/gmp-news/cloud-computing-regulations-for-the-return-transmission-of-data-in-the-event-of-business-discontinuation |title=Cloud Computing: Regulations for the Return Transmission of Data in the Event of Business Discontinuation |work-ECA Academy |date=16 December 2020 |accessdate=28 July 2023}}</ref> As the ECA Academy notes, in the cloud computing realm, it would be up to the laboratory to get provisions added into the CSP's service-level agreement (SLA) to address the GMP's necessity for data availability, and to decide whether maintaining a local backup of the data would be appropriate (as in, perhaps, a hybrid cloud scenario).
==Features==


That part about the SLA is important. Although a formal contract will address agreed-upon services, it's usually in vague terms; the SLA, on the other hand, defines all the responsibility the cloud provider holds, as well as your laboratory, for the supply and use of the CSP's services.<ref name="CaldwellContracts19">{{cite web |url=https://www.asgnational.com/miscellaneous/contracts-vs-service-level-agreements/ |archiveurl=https://web.archive.org/web/20200930063443/https://www.asgnational.com/miscellaneous/contracts-vs-service-level-agreements/ |title=Contracts vs. Service Level Agreements |author=Caldwell, D. |work=ASG Blog |date=16 February 2019 |archivedate=30 September 2020 |accessdate=28 July 2023}}</ref> These are your primary protections, along with vetting the CSP you use. This may be difficult, however, particularly in a public cloud, where auditing the security controls and protections of the CSP will be limited at best. To ensure GxP compliance in the cloud, your lab will have to examine the various certifications and compliance offerings of the CSP and hope that the CSP staff handling your GxP data are trained on the requirements of GxP in the cloud.<ref name="McDowallClouds20">{{cite web |url=https://www.csolsinc.com/blog/clouds-or-clods-software-as-a-service-in-gxp-regulated-laboratories/ |title=Clouds or Clods? Software as a Service in GxP Regulated Laboratories |author=McDowall, B. |work=CSols Blog |publisher=CSols, Inc |date=27 August 2020 |accessdate=28 July 2023}}</ref> However, public cloud providers like Microsoft<ref name="MazzoliGood20">{{cite web |url=https://learn.microsoft.com/en-us/compliance/regulatory/offering-gxp |title=Good Clinical, Laboratory, and Manufacturing Practices (GxP) |author=Mazzoli, R. |work=Microsoft Documentation |publisher=Microsoft, Inc |date=26 January 2023 |accessdate=28 July 2023}}</ref> and Google<ref name="GoogleUsing20">{{cite web |url=https://cloud.google.com/security/compliance/cloud-gxp-whitepaper |title=Using Google Cloud in GxP Systems |publisher=Google Cloud |date=May 2020 |accessdate=28 July 2023}}</ref> provide their own documentation and guidance on using their services in GxP environments. As Microsoft notes, however, "there is no GxP certification for cloud service providers."<ref name="MazzoliGood20" /> Instead, the CSPs focus on meeting [[Quality management system|quality management]] and information security standards and employing their own best practices that match up with GxP requirements. Finally, they may also have an independent third party conduct GxP qualification reviews, with the resulting qualification guidelines detailing GxP responsibility between the CSP and the laboratory.<ref name="MazzoliGood20" /><ref name="GoogleUsing20" />
Known features of OpenELIS Global include<ref name="2.4Notes" /><ref name="2.5Notes" /><ref name="Liams-HauserOpenELISSoft22" />:


Ultimately, navigating the challenge of ensuring your laboratory's move to the cloud complies with necessary regulations is a tricky matter. Ensuring the CSP you choose actually meets HIPAA, GxP, and other requirements isn't always a guaranteed proposition by simply auditing the CSPs whitepapers and other associated compliance documents. However, experts such as Linford & Co.'s Nicole Hemmer and IDBS' Damien Tiller emphasize that the most comprehensive CSP documentation to examine towards gaining a more complete picture of the CSP's security is the SOC 2 (SOC for Service Organizations: Trust Services
* sample entry
Criteria) report.<ref name="HemmerTrust19">{{cite web |url=https://linfordco.com/blog/trust-services-critieria-principles-soc-2/ |title=2023 Trust Services Criteria (TSCs) for SOC 2 Reports |author=Colby, L. |work=Linford & Company IT Audit & Compliance Blog |publisher=Linford and Co. LLP |date=01 February 2023 |accessdate=28 July 2023}}</ref><ref name="TillerIsThe19">{{cite web |url=https://storage.pardot.com/468401/1614781936jHqdU6H6/Whitepaper_Is_the_cloud_a_safe_place_for_your_data.pdf |archiveurl=https://web.archive.org/web/20210308231558/https://storage.pardot.com/468401/1614781936jHqdU6H6/Whitepaper_Is_the_cloud_a_safe_place_for_your_data.pdf |format=PDF |title=Is the Cloud a Safe Place for Your Data?: How Life Science Organizations Can Ensure Integrity and Security in a SaaS Environment |author=Tiller, D. |publisher=IDBS |date=2019 |archivedate=08 March 2023 |accessdate=28 July 2023}}</ref> A CSP's SOC 2 audit results outline nearly 200 information security, data integrity, data availability, and data retention controls and any non-conformities with those controls (the CSP must show those controls have been effectively in place over a six- to 12-month period). The SOC 2 report has other useful aspects, including a full service description and audit observations, making it the best tool for a laboratory to judge a CSP's ability to assist with regulatory compliance.<ref name="TillerIsThe19" />
* results entry
* user management and administration
* role-based security
* reporting
* data validation
* workplans
* patient reports
* study reports
* test catalogs
* workflow management
* barcoded labels
* raw data export
* audit trail logging
* electronic signatures
* instrument integration
* email and SMS support
* LOINC code compatibility
* FHIR support
* English or French language configuration
* iSante interoperability
 
==Hardware/software requirements==
 
OpenELIS Global can be run in a virtual machine like VirtualBox or it can be built and installed from source code.  
 
===Virtual machine===
 
System requirements for an OpenELIS Global [https://openelis-global.org/getting-started/ virtual machine] installation will be based on the requirements to run the virtual machine.
 
===Source code===
 
To build and install from source, you'll need:
 
* Ubuntu 20.04 LTS
* Net Tools
* Python
 
More information can be found [http://docs.openelis-global.org/en/latest/ here].
 
==Videos, screenshots, and other media==
 
===Videos===
 
The following YouTube videos exist for OpenELIS Global:
 
* [https://www.youtube.com/watch?v=jJMJzEmiyVg OpenELIS Global Airport Arrival Webapp for Covid testing]
* [https://www.youtube.com/watch?v=ZBx0p2xRXOw After the airport passenger locator form, we have the OpenELIS system itself through to result]
* [https://www.youtube.com/watch?v=MReLJoiDcwc OpenELIS and OpenMRS Lab Orders and Results Exchange Demo]
* [https://www.youtube.com/watch?v=vceADLpaDNc OpenELIS Global QuanStudio 3 and 5 Analyzer Integration]
* [https://www.youtube.com/watch?v=BbDuvrUBpIs Setting up the analyzer script]
 
===Demos===
 
An online demo of OpenELIS Global can be found on the [https://openelis-global.org/getting-started/demo/ OpenELIS website].
 
===Documentation===
 
Documentation for OpenELIS Global can be [http://docs.openelisci.org/en/latest/ found here].
 
==Entities using OpenELIS==
 
The following entities are known to be utilizing or have used some form of OpenELIS:
 
CDC Retrovirus Côte d'Ivoire, Clinical Informatics Research Group, Institut Pasteur Côte d'Ivoire, Laboratoire National de Santé Publique - Côte d'Ivoire, Laboratoire National de Santé Publique - Haiti, Minnesota State Public Health Laboratory, State Hygienic Laboratory at the University of Iowa
 
==Further reading==
 
* {{cite journal |title=Laboratory Data Timeliness and Completeness Improves Following Implementation of an Electronic Laboratory Information System in Côte d’Ivoire: Quasi-Experimental Study on 21 Clinical Laboratories From 2014 to 2020 |author=He, Y.; Kouabenan, Y.-R.; Assoa, P.H; et al. |journal=JMIR Public Health and Surveillance |year=2024 |volume=10 |issue=e50407 |doi=10.2196/50407 |pmid=38506899}}
 
==External links==
 
* [https://github.com/DIGI-UW/OpenELIS-Global-2 OpenELIS Global (current) on GitHub]
* [https://github.com/openelisglobal/openelisglobal-core/ OpenELIS (pre-2.0) at GitHub]
* [https://code.google.com/archive/p/openelisglobal/ OpenELIS Global at Google Code] (Archived)
 
* NOTE: The country specific blogs for Haiti and Cote d'Ivoire have been combined at: [http://openelis.blogspot.com/ OpenELIS Global blog]
 
==References==
<references />
 
<!---Place all category tags here-->
[[Category:Health informatics software (open source)]]
[[Category:Laboratory informatics software (open source)]]
[[Category:Laboratory information systems (open source)]]
[[Category:Public health software (open source)]]

Latest revision as of 23:29, 30 July 2026

Sandbox begins below


OpenELIS Global
OpenELIS logo.jpg
Original author(s) Casey Iiams-Hauser
Developer(s) Digital Initiatives Group (DIGI) – University of Washington
Initial release February 29, 2012 (2012-02-29)[1]
Stable release

3.2.1.11  (July 13, 2026; 20 days ago (2026-07-13))

[±]
Written in Java (Spring), JavaScript (React, Carbon Design System)
Operating system Cross-platform
Type Laboratory informatics software
License(s) Mozilla Public License 2.0
Website openelis-global.org

OpenELIS Global is a free open-source laboratory information system (LIS) designed "to run national laboratory networks that serve millions of people,"[2], particularly in low- and middle-income countries. The software is as an offshoot of the OpenELIS open-source software project, which received development contributions from the likes of the Minnesota State Public Health Laboratory and the University of Iowa. The larger international influence on OpenELIS of collaborators such as the Association of Public Health Laboratories (APHL), the U.S. Centers for Disease Control and Prevention (CDC), and the University of Washington's International Training and Education Center on HIV (I-TECH) later spread the OpenELIS technology (in the form of separate branches of the software) to other parts of the world, including Vietnam, Haiti, and Côte d'Ivoire.[3] While OpenELIS continues on as a separate project run by the OpenELIS Foundation, it states that it "has limited involvement in development of global OpenELIS."[4]

OpenELIS Global is recognized as a Digital Square Global Good and a verified Digital Public Good[5][6], and its Cote d'Ivoire implementation was evaluated in a 2024 peer-reviewed study in JMIR Public Health and Surveillance.[7]

Product history

In 2012, the University of Washington I-TECH began hosting OpenELIS Global, an international version of the OpenELIS software. The intent of the developers—the International Training and Education Center for Health (I-TECH) at Washington University—was to expand the functionality of OpenELIS to be more flexible while still "maintaining a common code base" among the the variation of feature requirements across different countries.[8] The first public open-source release of the software was with version 2.4 on February 29, 2012[1], followed by a 2.5 release on March 30.[9] The incrementation was chosen not as a numerical order of release, but rather as an identifying string as "Version.Pl​annedRelea​se.Unplann​edRelease (build number)," with versions incrementing yearly.[9]

Since then, the software has received regular updates. Following the May 2019 release of version 9.1, work slowed slightly, apparently in favor of a planned rewrite of the code using Java Spring. In August 2019, I-TECH's Casey Iiams-Hauser (the OpenELIS Global project owner) put out a call for a software development team to tackle the transition to Java Spring and PostgreSQL, with a target date of September 15, 2019.[10] The first release of the new version occurred in January 2020; the release notes stated: "This is a re-write of OpenELIS on modern frameworks and a significant security upgrade. At the end of this process, all tech will be currently supported and up to hardening standards. This software will be certified for use on US Government, and other high-security networks."[11] Updates over the years have added support for COVID-19 testing, the FHIR API, ASTM analyzer interfaces, data warehousing, and more.[11]

Features

Known features of OpenELIS Global include[1][9][11]:

  • sample entry
  • results entry
  • user management and administration
  • role-based security
  • reporting
  • data validation
  • workplans
  • patient reports
  • study reports
  • test catalogs
  • workflow management
  • barcoded labels
  • raw data export
  • audit trail logging
  • electronic signatures
  • instrument integration
  • email and SMS support
  • LOINC code compatibility
  • FHIR support
  • English or French language configuration
  • iSante interoperability

Hardware/software requirements

OpenELIS Global can be run in a virtual machine like VirtualBox or it can be built and installed from source code.

Virtual machine

System requirements for an OpenELIS Global virtual machine installation will be based on the requirements to run the virtual machine.

Source code

To build and install from source, you'll need:

  • Ubuntu 20.04 LTS
  • Net Tools
  • Python

More information can be found here.

Videos, screenshots, and other media

Videos

The following YouTube videos exist for OpenELIS Global:

Demos

An online demo of OpenELIS Global can be found on the OpenELIS website.

Documentation

Documentation for OpenELIS Global can be found here.

Entities using OpenELIS

The following entities are known to be utilizing or have used some form of OpenELIS:

CDC Retrovirus Côte d'Ivoire, Clinical Informatics Research Group, Institut Pasteur Côte d'Ivoire, Laboratoire National de Santé Publique - Côte d'Ivoire, Laboratoire National de Santé Publique - Haiti, Minnesota State Public Health Laboratory, State Hygienic Laboratory at the University of Iowa

Further reading

  • He, Y.; Kouabenan, Y.-R.; Assoa, P.H; et al. (2024). "Laboratory Data Timeliness and Completeness Improves Following Implementation of an Electronic Laboratory Information System in Côte d’Ivoire: Quasi-Experimental Study on 21 Clinical Laboratories From 2014 to 2020". JMIR Public Health and Surveillance 10 (e50407). doi:10.2196/50407. PMID 38506899. 


External links

  • NOTE: The country specific blogs for Haiti and Cote d'Ivoire have been combined at: OpenELIS Global blog

References

  1. 1.0 1.1 1.2 "OpenELIS Global 2.4 Release Notes". University of Washington I-TECH. 29 February 2012. Archived from the original on 30 January 2021. https://web.archive.org/web/20210130143717/https://sites.google.com/site/openelisglobal/openelis-global-2-4-release-notes. Retrieved 30 July 2026. 
  2. "Laboratory information, built for the public good". DIGI at the University of Washington. https://openelis-global.org/about/. Retrieved 30 July 2026. 
  3. "About/Team". ITECH at Washington University. Archived from the original on 19 July 2019. https://web.archive.org/web/20190719065729/https://sites.google.com/site/openelisglobal/about. Retrieved 30 July 2026. 
  4. "About OpenELIS". OpenELIS Foundation. 2026. https://openelis.org/about-openelis/. Retrieved 30 July 2026. 
  5. "The Global Goods Guidebook - An Overview of the Software Global Goods Ecosystem" (PDF). Digital Square. May 2023. p. 48. https://datafi.thepalladiumgroup.com/wp-content/uploads/2024/11/2.-Global_Goods_Guidebook_Version_4.0_FINAL_forpublishing.pdf. Retrieved 30 July 2026. 
  6. "OpenELIS Global". Digital Public Goods Alliance. 2022. Archived from the original on 26 May 2023. https://web.archive.org/web/20230526130236/https://www.digitalpublicgoods.net/registry/openelis-global.html. Retrieved 30 July 2026. 
  7. He, Y.; Kouabenan, Y.-R.; Assoa, P.H; et al. (2024). "Laboratory Data Timeliness and Completeness Improves Following Implementation of an Electronic Laboratory Information System in Côte d’Ivoire: Quasi-Experimental Study on 21 Clinical Laboratories From 2014 to 2020". JMIR Public Health and Surveillance 10 (e50407). doi:10.2196/50407. PMID 38506899. 
  8. "A Global LIS". ITECH at Washington University. Archived from the original on 30 January 2021. https://web.archive.org/web/20210130143701/https://sites.google.com/site/openelisglobal/global-implementation. Retrieved 30 July 2026. 
  9. 9.0 9.1 9.2 "OpenELIS Global 2.5 Release Notes". University of Washington I-TECH. 30 March 2012. Archived from the original on 30 January 2021. https://web.archive.org/web/20210130143717/https://sites.google.com/site/openelisglobal/openelis-global-2-5-release-notes. Retrieved 30 July 2026. 
  10. Liams-Hauser, C. (5 August 2019). "Come work on OpenELIS Global with I-TECH!". OpenMRS Talk. https://talk.openmrs.org/t/come-work-on-openelis-global-with-i-tech-we-are-looking-for-tech-writers-ui-ux-designers-and-devs-an/24221. Retrieved 30 July 2026. 
  11. 11.0 11.1 11.2 Liams-Hauser, C. (March 2022). "OpenELIS Software Release Roadmap". Archived from the original on 28 March 2022. https://web.archive.org/web/20220328192537/https://docs.google.com/document/d/1p0zMfoUXRBbr9JyjjMeWRt1dgi7EbOd3IZdP6NCulow/edit?pli=1#heading=h.71anhixmrzil. Retrieved 30 July 2026.