Efficient and secure transborder exchange of patient data

Slides:



Advertisements
Similar presentations
ICT research priorities and recommendations for strategy development in the WBC Ulrike Kunze / PT-DLR, Germany Consultation session on recommendations.
Advertisements

The World Internet Security Company ID Management in e-Health February 2007.
The eHealth platform as a secure and efficient data transfer tool in the health sector Frank Robben General manager eHealth platform Sint-Pieterssteenweg.
EHealth: some challenges Frank Robben General manager eHealth-platform Sint-Pieterssteenweg 375 B-1040 Brussels
The eHealth platform as a support of high quality healthcare and administrative simplification Frank Robben General Manager eHealth platform Sint-Pieterssteenweg.
Grid Computing, B. Wilkinson, 20045a.1 Security Continued.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
eHealth Platform: Progress and Prospects
EHealth for quality & continuity of care and patient
Massachusetts: Transforming the Healthcare Economy John D. Halamka MD CIO, Harvard Medical School and Beth Israel Deaconess Medical Center.
Page 1 Issues in and perspectives on electronic authentication of health professionals Pascal POITEVIN Marketing and Communication manager GIP-CPS e-Health.
Public Key Infrastructure (PKI) Providing secure communications and authentication over an open network.
Crossroads Bank for Social Security & eHealth platform How federal institutions support Belgian social and health care sector.
E-government in the Belgian social sector coordinated by the Crossroads Bank for Social Security Frank Robben General manager Crossroads Bank for Social.
eHealth Platform: Progress and Prospects
The Crossroads Bank for Social Security, a model for the health care sector ? Frank Robben General manager Crossroads Bank for Social Security Sint-Pieterssteenweg.
Elias M. Awad Third Edition ELECTRONIC COMMERCE From Vision to Fulfillment 13-1© 2007 Prentice-Hall, Inc ELC 200 Day 23.
E-Government Security and necessary Infrastructures Dimitrios Lekkas Dept. of Systems and Products Design Engineering University of the Aegean
The new Belgian legal framework for eHealth Frank Robben General manager eHealth-platform Sint-Pieterssteenweg 375 B-1040 Brussels
EHealth-platform: state of affairs and
1st MODINIS workshop Identity management in eGovernment Frank Robben General manager Crossroads Bank for Social Security Strategic advisor Federal Public.
The eHealth platform: current situation and future perspectives 23/04/2014 Frank Robben General manager of the eHealth platform Quai de Willebroeck 38.
How can I trust the rest of Europe ? Requirements and a possible organisation with regard to epSOS and eHealth Frank Robben General manager eHealth platform.
E-Commerce Security Technologies : Theft of credit card numbers Denial of service attacks (System not availability ) Consumer privacy (Confidentiality.
Identity Conference: modernization of health processes in Belgium 14/05/2014 Frank Robben General manager of the eHealth platform Quai de Willebroeck 38.
Be-Health as a driving force of electronic cooperation in the Belgian health care sector, based on the experience in the social sector Frank Robben General.
The possible support of the Crossroads Bank for Social Security (CBSS) and the eHealth platform to a Belgian Longitudinal Health Information System Frank.
Chapter 9: Using and Managing Keys Security+ Guide to Network Security Fundamentals Second Edition.
Protecting Internet Communications: Encryption  Encryption: Process of transforming plain text or data into cipher text that cannot be read by anyone.
Electronic identity management for eGovernment Conceptual framework and objectives Frank Robben General manager Crossroads Bank for Social Security Strategic.
EHealth: Belgian approach with specific attention to research support 27/05/2014 Frank Robben General manager of the eHealth platform Quai de Willebroeck.
DICOM and ISO/TC215 Hidenori Shinoda Charles Parisot.
The eHealth platform: current situation and future perspectives Leuven.Inc Frank Robben General manager of the eHealth platform Quai de Willebroeck 38.
The eHealth platform as a support of high quality healthcare and administrative simplification Frank Robben General Manager eHealth platform Sint-Pieterssteenweg.
1 ELECTRONIC PRESCRIBING AND APPLICATION OF NEW TECHNOLOGIES IN THE SPANISH PHARMACY Carmen Peña López Secretary General. General Spanish Council of Pharmacists.
Encryption / Security Victor Norman IS333 / CS332 Spring 2014.
EHealth-platform: state of affairs and
The eHealth platform: objectives, operating principles and status questions Frank Robben General manager eHealth platform Sint-Pieterssteenweg 375 B-1040.
How the eHealth platform can be of use for eLifeSciences Frank Robben General Manager eHealth platform Sint-Pieterssteenweg 375 B-1040 Brussels
The pillars of E-government Frank Robben General manager Crossroads Bank for Social Security Strategic advisor Federal Public Service for ICT Sint-Pieterssteenweg.
Security fundamentals Topic 5 Using a Public Key Infrastructure.
EHealth: state of affairs and
Security By Meenal Mandalia. What is ? stands for Electronic Mail. much the same as a letter, only that it is exchanged in a different.
Lithuania eHealth Overview Normantas Ducinskas Head of eHealth Coordination and Implementation Division Lithuania MoH.
CRYPTOGRAPHY Cryptography is art or science of transforming intelligible message to unintelligible and again transforming that message back to the original.
ԷԿԵՆԳ ՓԲԸ | 2016 e-Health Project in Armenia. ԷԿԵՆԳ ՓԲԸ | 2016 Project Objective Project is integrated single window for health related services Management.
The continuum of care: The Role of Technology
eHealth: state of affairs and perspectives
Big data analysis in health care
01/09/17 Architecture.
Training for developers of X-Road interfaces
Luc Maes Program manager eHealth platform Sint-Pieterssteenweg 375
Development of national eHealth system
Unit 3 Section 6.4: Internet Security
eHealth: state of affairs and perspectives
Cryptography Why Cryptography Symmetric Encryption
Computer Communication & Networks
Sponsored by Healthdata.be
e-Health Platform End 2 End encryption
Public Sector Institutional Reform Project
THE STEPS TO MANAGE THE GRID
Ministry of Health Montenegro ERASMUS+ KA2 PROJECT:
Pooja programmer,cse department
Lecture 4 - Cryptography
Big data analysis in health care and the General Data Protection
Dashboard eHealth services: actual mockup
A practice testimony on the implementation of information security and data protection at the Crossroads Bank for Social Security and the eHealth platform.
eHealth: basic principles & achievements
Electronic Payment Security Technologies
Presentation transcript:

Efficient and secure transborder exchange of patient data

3/2/2017 A

Basic requirements Correct identification of the patient 3/2/2017 Basic requirements Correct identification of the patient Correct routing of information request Privacy and information security management user and access management end-to-end encryption Interoperability technical semantic

Mission of the Belgian eHealth platform 3/2/2017 Mission of the Belgian eHealth platform How? through a well-organised, mutual electronic service and information exchange between all actors in health care by providing the necessary guarantees with regard to information security, privacy protection and professional secrecy What? optimisation of health care quality and continuity optimisation of patient safety reduction of administrative burden for all actors in health care thorough support of health care policy and research

10 Tasks Development of a vision and of a strategy for eHealth 3/2/2017 10 Tasks Development of a vision and of a strategy for eHealth Organization of the cooperation between all governmental institutions which are charged with the coordination of the electronic service provision The motor of the necessary changes for the implementation of the vision and the strategy with regard to eHealth Promoting and coordinating programmes and projects

3/2/2017 10 Tasks Determination of functional and technical norms, standards, specifications and basic architecture with regard to ICT Registration of software for the management of electronic patient files Managing and coordinating the ICT aspects of data exchange within the framework of the electronic patient files and of the electronic medical prescriptions

3/2/2017 10 Tasks Conceptualization, design and management of a cooperation platform for secure electronic data exchange with the relevant basic services Reaching an agreement about division of tasks and about the quality standards and checking that the quality standards are being fulfilled Acting as an independent trusted third party (TTP) for the encoding and anonymisation of personal information regarding health for certain institutions summarized in the law for the support of scientific research and policymaking

Patients, health care providers and health care institutions 3/2/2017 Basic Architecture Patients, health care providers and health care institutions Health care provider software Health portal VAS Health care institution software Site RIZIV VAS eHealth- portal MyCareNet VAS VAS VAS Users Basic Services eHealth-platform Network AS AS AS AS AS AS Suppliers 8 8

10 Basic services Coordination of electronic sub-processes Portal 3/2/2017 10 Basic services Coordination of electronic sub-processes Portal Integrated user and access management Logging management System for end-to-end encryption eHealthBox Timestamping Encoding and anonymization Consultation of the National Identification Registers Reference directory (metahub)

Identification of the patient 3/2/2017 Identification of the patient Obligatory use of social security identification number (SSIN) in health sector Procedures are available in order to guarantee unicity of SSIN SSIN is available on electronic identity card or ISI+-card Link register is available in order to link the Belgian SSIN with identification numbers in other countries

Routing: hubs & metahub system 3/2/2017 Routing: hubs & metahub system 5 hubs 3 technical implementations All Belgian hospitals connected

Hubs & metahub system before 3/2/2017 Hubs & metahub system before

Hubs & metahub system today 3/2/2017 Hubs & metahub system today 3. Retrieve data from hub A A 1: Where can we find data? 2: In hub A and C 4: All data available 3: Retrieve data from hub C C B

3/2/2017 Extramural data A InterMed BruSafe C B

User and access management 3/2/2017 User and access management

User and access management 3/2/2017 User and access management

End-to-end encryption 3/2/2017 End-to-end encryption 2 methods: In the case of a known recipient: use of an asymmetric encryption system (2 keys) In the case of an unknown recipient: use of symmetric encryption (the information is encrypted and stored outside the eHealth platform; the decryption key can only be obtained through the eHealth platform)

Asymmetric end-to-end encryption 3/2/2017 Asymmetric end-to-end encryption Healthcare actor Person or entity eHealth platform Internet 1 3 Connector or other software to generate key pair Authenticates sender 4 2 Identification certificate Stores public key Identificatieoncertificate Sends public key Web service Register key 2 Public keys repository Stores private key in a secure way

Asymmetric end-to-end encryption 3/2/2017 Asymmetric end-to-end encryption eHealth platform Message originator Internet Identification certificate 1 Web service Ask public key Identification certificate 2 Asks for public key Authenticates sender Send message Any protocol 3 4 Sends public key Encrypts message Identification certificate Public keys repository Message recipient Stored private key 5 Decrypts message

Symmetric end-to-end encryption 3/2/2017 Symmetric end-to-end encryption Key Management / Depot Symmetric key Encrypted with public key of user 1 Encrypted with public key of user 2 Symmetric key 2 sends key 5 receives key User 1 Originator 1 asks for key User 2 Recipient 4 justifies right to obtain key 4 justifies right to obtain message 3 sends encrypted message Encrypted with public key of Message depot 5 receives message Encrypted with public key of User 2 Message encrypted with symmetric key Messages Depot Message encrypted with symmetric key Message encrypted with symmetric key

3/2/2017

Thank you ! Any questions ?