European Interoperability of Identification Management in eHealth Dr. Ramin Tavakolian with Dr. Gerhard Brenner (ZI, Berlin, DE); Dr. Stephan Schug, Marc.

Slides:



Advertisements
Similar presentations
Confidential RISK ADVISORY SERVICES Latvijas Republikas Veselības ministrija Healthcare Information System Policy in Latvia Rinalds Muciņš, Ministry of.
Advertisements

ICT research priorities and recommendations for strategy development in the WBC Ulrike Kunze / PT-DLR, Germany Consultation session on recommendations.
S.O.S. eHealth Project Open eHealth initiative for a European large scale pilot of patient summary and electronic prescription Daniel Forslund, Head of.
Conclusions from e-Health
Supporting National e-Health Roadmaps WHO-ITU-WB joint effort WSIS C7 e-Health Facilitation Meeting 13 th May 2010 Hani Eskandar ICT Applications, ITU.
E-health Initiatives in Poland
Policy interoperability in electronic signatures Andreas Mitrakas EESSI International event, Rome, 7 April 2003.
ETen E-Poll ID – Strasbourg COE meeting November, 2006 Slide 1 E-TEN E-POLL Project Electronic Polling System for Remote Operation Strasbourg.
EU Cross-Border Care Directive from the Primary Care perspective Results of a simulation Rita Baeten Gothenburg, 3 September 2012.
Data-Sharing and Governance Consultation ANALYSIS OF RESPONSES.
Page 1 Issues in and perspectives on electronic authentication of health professionals Pascal POITEVIN Marketing and Communication manager GIP-CPS e-Health.
Workshop on registered electronic mail policies and implementation Ankara, March 2015 Davide Mula REM country practice in legal infrastructure,
Cross-border Empowerment of Next Generation Access National Networks MINISTRY OF TRANSPORT, INFORMATION TECHNOLOGY AND COMMUNICATIONS REPUBLIC OF BULGARIA.
1 of 1 E- Health in the European Union Dr. Andrzej Rys Director for Health and Risk Assessment DG SANCO European Commission OPEN DAYS 2009 Mobility in.
PHC Meeting the global challenge of unique identification of medicinal products Overview of objectives, outcomes and process Contact:
LOGO MIRJANA SEKULOVSKA, PhD, DEPUTY MINISTER OF INFORMATION SOCIETY Republic of Macedonia Ministry of Information Society.
EHealth and Accession - Sofia7 June 2005 eHealth Focal Point for Europe by Marc lange Manager.
1st MODINIS workshop Identity management in eGovernment Frank Robben General manager Crossroads Bank for Social Security Strategic advisor Federal Public.
Creating an eHealth Infostructure for Mobile Citizens – the Interoperability Initiative for a European eHealth Area Dr. Karl A. Stroetmann, Dr. Veli N.
The Digital Agenda for Europe Interoperability and Standards
Identity management – developments within the European Social Security Sector Pantelis Angelidis.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
How can I trust the rest of Europe ? Requirements and a possible organisation with regard to epSOS and eHealth Frank Robben General manager eHealth platform.
0 Presentation to: Health IT HIPPA Workshop Presented by: Stacey Harris, Director of Health IT Innovation September 26, 2014 Division of Health Information.
ESIP annual conference 2008 European citizenship: tied up in red tape ECAS – European Citizen Action Service Claire Damilano – Legal Officer.
EGovernment Services in Poland Today & in The Future Dariusz Bogucki Ph.D, IDA II, National Co-ordinator National Registers Department, Ministry of Internal.
EPHA Presentation EPHA, the EU and Health. EPHA Presentation European Public Health Alliance A network of more that 100 non governmental and not-for-profit.
State Alliance for e-Health Conference Meeting January 26, 2007.
Ensuring Food Safety in Europe through Scientific Cooperation and Networking The Role of EFSA Carola Sondermann EFSA Polish Focal Point – Annual Experts.
Telematikplattform für Medizinische Forschungsnetze (TMF) e.V. TMF – A Common Platform for Medical Research Networks in Germany Improving the Organisation.
RIDE ConsortiumRIDE Workshop, December 8, 2006, Brussels 1 The RIDE Roadmap Methodology and the Current Progress Prof. Dr. Asuman Dogac, Turkey Dr. Jos.
The Porvoo Group Tapio Aaltonen Director, CA-services, co- chair Porvoo Group Population Register Centre Finland.
METU-SRDCEUROREC Meeting, Geneva, October 10, 2006 RIDE Overview Asuman Dogac Middle East Technical University Ankara, Turkey.
Secure Messaging Workshop The Open Group Messaging Forum February 6, 2003.
Europe's work in progress: quality of mHealth Pēteris Zilgalvis, J.D., Head of Unit, Health and Well-Being, DG CONNECT Voka Health Community 29 September.
Geneva, Switzerland, April 2012 Introduction to session 7 - “Advancing e-health standards: Roles and responsibilities of stakeholders” ​ Marco Carugi.
EUNetPaS is a project supported by a grant from the EAHC. The sole responsibility for the content of this presentation lies with the author(s). The EAHC.
European Standards on Confidentiality and Privacy in Healthcare Dr Colin M Harper Division of Psychiatry & Neuroscience Queen’s University.
EHealth Interoperability – EU Commission activities Dr Octavian Purcarea Unit H1 – ICT for Health Directorate ICT for citizens and businesses DG INFSO.
International E-Health Conference “E-Health:around the clock care for everyone, everywhere” Quality in Health Care and Medical care E-Health in Friuli.
| 1 European Maritime Day 2010 Gijon Workshop 2.9 Shipping in the Common European Maritime Space Gijón, 21 May 2010 European maritime transport space without.
E-Health concept in Romania Sofia, 7 th of June 2005.
Promoting excellence in social security Building on sector wide commonalities to enhance the benefits of Information.
Data protection as an integral part of OOP implementations: The Austrian approach Peter Kustor.
The German eID and eIDAS
European Union Agency For Network And Information Security Security and resilience for eHealth Infrastructures and Service – ENISA study Dimitra Liveri.
EHGI and Convergence 21st March DIRECTIVE 2011/24/EU OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 9 March 2011 on the application of patients’
EPHA Briefing Paper (Part 2): High Level Reflection Process on Patient Mobility in the EU - summary of final recommendations - December 2003 (See also.
EUNetPaS is a project supported by a grant from the EAHC. The sole responsibility for the content of this presentation lies with the author(s). The EAHC.
19-20 October 2010 IT Directors’ Group meeting 1 Item 6 of the agenda ISA programme Pascal JACQUES Unit B2 - Methodology/Research Local Informatics Security.
Bulding blocks of e- government Ingmar Pappel. Bulding blocks of e-government  Personal Code  Digital Identity  Digital signature  X-Road  Organizations.
Week 12. Lecture 2. Health Law & the EU Cross-border healthcare: patients’ rights.
A look into current and future trends in national policies for eHealth and Innovation in the WHO European Region Clayton Hamilton, eHealth and Innovation.
Lithuania eHealth Overview Normantas Ducinskas Head of eHealth Coordination and Implementation Division Lithuania MoH.
The legal aspects of eHealth: the specific case of telemedicine Céline Deswarte ICT for Health Unit, European Commission TAIEX Multi-country seminar on.
Organization and Implementation of a National Regulatory Program for the Control of Radiation Sources Co-ordination and Co-operation.
Smart Data infrastructure
Anne-Marie Yazbeck, PhD National Infoday, Sweden 2017
eHealth Standards and Profiles in Action for Europe and Beyond
The Citizen in the centre in EU, Bratislava November,2005
Efficient and secure transborder exchange of patient data
Development of national eHealth system
The European Union (EU) policy challenge
Enhancing maritime domain awareness and responsiveness in Europe
European Citizens’ Initiative, Commission regulation proposal Focus on IT aspects Jérôme Stefanini DIGIT.B.2 05/06/2018.
Dan Tofan | Expert in NIS 21st Art. 13a WG| LISBON |
Legal Framework for Civil Registration, Vital Statistics
CEF eID SMO The use of eID in eHealth
Dashboard eHealth services: actual mockup
SCOOP4C: Societal Vision for Once Only Principle for Citizens
Presentation transcript:

European Interoperability of Identification Management in eHealth Dr. Ramin Tavakolian with Dr. Gerhard Brenner (ZI, Berlin, DE); Dr. Stephan Schug, Marc Lange (EHTEL); Dr. Karl A. Stroetmann, Daniel Spichtinger, (empirica, Bonn / DE) Central Research Institute of Ambulatory Health Care in Germany, Herbert-Lewin-Platz Berlin; Tel.:

Bern, Tavakolian 2 i2Health project background Growing awareness that emerging eHealth applications might stop at European borders Multiple policy drivers for eHealth interoperability Citizen mobility Free healthcare market (limited EU-responsibility) Decision of the European Court of Justice Border regions Pressure from stakeholder groups

Bern, Tavakolian 3 The European Parliament "notes the importance of providing an efficient and secure method of exchanging patient records between Member States„ Draft report on patient mobility and healthcare developments in the European Union, "Interoperability is the corner stone supporting citizens mobility and patient centred care„ Report of the High Level Group on Health Services and Medical Care (to the Council of the EU), Dec "Establish a platform with a mandate and the necessary resources to facilitate co- operation between European Member States with support of the European Commission to promote e-health interoperability for the mobile citizen." Report of the eHealth Standardisation Focus Group, Feb "The high level e-Health forum... will be able to set up working groups on specific topics, one of which should obviously be interoperability.„ Opinion of the Committee of the Regions on the Action Plan for a European eHealth Area, Specific policy drivers

Bern, Tavakolian 4 Objectives focus on fundamental interoperability issues analyse priority applications relating to e.g. e-prescription, electronic patient record and messaging develop a roadmap and concrete projects involving all relevant actors EU Support Action: i2-Health - the Interoperability Initiative for a European eHealth Area Workplan Elements Generic elements Conceptual framework (WP1) Analysis of infrastructure concepts and building blocks (WP2) Specific subjects for in-depth analysis Identification management of actors, organisations and fundamental interoperability issues (WP3) Workflow interoperability – e-prescribing and messaging (WP4)

Bern, Tavakolian 5 ID management in eHealth – Difference to the conventional setting Identification and authentication of actors in healthcare is a mixture of administrative measures, common sense, and personal human interaction. This needs to be trustworthy! (thoroughly designed for its whole life- cycle) To fake a physician in conventional setting you need an office, yellow pages listing, big desk, nice manners, framed diplomas, trusting employees, etc... To fake a physician in the electronic world you just need a digital certificate file

Bern, Tavakolian 6 ID management in eHealth Just emerging on national level Natural persons (citizens, patients, health care professionals) Institutions (care providers, insurance organisations) Less advanced for other entities (e.g. systems components, messages, etc.) Requirements for use cases not comprehensively defined (e.g. administrative vs. medical patient identification) European use cases?

Bern, Tavakolian 7 Generating an eHealth ID Identity Provider CA RA Actor Attribute Source Generation of Identifier Production of token Delivery of electronic ID/token    Registration Requests eHealth Identity  Specific to eHealth ID of individuals is the attribute (MR Jones + physician)

Bern, Tavakolian 8 Utilizing an eHealth ID Identity Provider RA, CA Requester e.g physician Attribute Source   Asks for service Supplies ID (+ Auth.) data Asks for verification Confirms Indentity Trusted Third Party Decider e.g. hospital with EPR  Grants access 

Bern, Tavakolian 9 i2Health Interoperability Model

Bern, Tavakolian 10 Layer Model of ID Management What is the legal base for issuing/using the identifier How is the registering process organised? Which identifier is to be used? On which support is the identifier available? Organisational Semantic Technical Registration procedures, verification procedures Data models, identifiers, numbering systems Certificates, ID-tokens (e.g. cards), directory databases, networking infrastructure Political / Legal Legislation, nomination of responsible authorities, definition of covered entities

Bern, Tavakolian 11 Technical Layer of ID On which support is the identifier available? There are European initiatives working on the interoperability of this layer eEHIC HPC standardisation Technical Certificates, ID tokens (e.g. cards), directory databases, networking infrastructure

Bern, Tavakolian 12 Semantic Layer of ID What quality does the identifier have? Domain Definition of sector or entity group Application of global object ID schemes Semantic

Bern, Tavakolian 13 Persistency of identifiers Biometric identification is utmost permanent No alterations or revocations are possible If copied and maliciously used no defence option exist “Almost” permanent identifiers are e.g. Social security numbers Alteration or revocation organisationally difficult Usability & Implementation ease Misuse & Privacy defence Permanent Temporary Tailored Persistency

Bern, Tavakolian 14 Semantic Layer of ID Internal or public? Semantic Example 1: UPIN (USA) Unique lifelong physician identification number Mandatory for Medicare/Medicaid scheme Established 1993 Publicly available in directories ( 6-digit alpha-numeric Crucial transactions bound to an internal billing-ID Example 2: BAN (Germany) Unique lifelong physician identification number Mandatory for all physicians Established 2003 Internal within chambers 8-digit alpha-numeric

Bern, Tavakolian 15 Semantic load Additional information carried by identifiers Sex (e.g. odd or even digit in Danish social security number) Date of birth (frequently visible in social security/health insurance numbers) Region of occupational residence (e.g. German physicians number) Potential collision with privacy aspects Difficulties arise when carried information becomes invalid (e.g. sex change)

Bern, Tavakolian 16 Organisational Layer of ID How is the registration process organised? What elements are to be identified? 1.Individual or juridical persons Health Care Professionals Patients Insurance Providers Health care institutions Others (Government, Research) Organisational Registration policy

Bern, Tavakolian 17 The sum of details causes the problem MS XMS Y Organisational Semantic Patient transport services are not recognized as healthcare services in country D The professions “speech therapist”, “dietary consultant” and “podologist” are neither registered or protected in country C Being spouse of a general practitioner is the only attribute of several thousands of individuals who participate in healthcare in country B For opening an electronic prescription the identification of both the institution and the employee is required in nation E A patient may not have an EHIC because he/she is not covered by a social security scheme in country A

Bern, Tavakolian 18 The Interoperability Issue Are all entities comparables? Are the registration authorities recognised across borders? Are the registration procedures recognised across borders? Are the identifiers usable across borders? Are their formats acceptable across borders? MS XMS Y Organisational Semantic

Bern, Tavakolian 19 Solution - Approach Define priority use cases Mobile patient Mobile health care professional Cross border health message Analyse existing base matched with interoperability layer model Perform a gap analysis Facilitate solutions

Bern, Tavakolian 20 Use case 1a: mobile insured (administrative) EHIC Organisational Semantic Technical Registration procedures exercised by MS EHIC identifiers (Insured and insurance providers) Eye-readable EHIC, Code list database of insurance providers Political / Legal European regulations 1408/71, 574/72, Decisions no , …

Bern, Tavakolian 21 Use case 1b: Medical ID Is the Insured ID from the EHIC usable By all information systems within an hospital? By other eHealth services such as On-line booking? Access to on-line electronic health records? ePrescribing services? Some categories of (potential) patients are out of the “EHIC scheme” (7% of the population in Germany, Civil servants from EU …) Consent required Harborer of medical information frequently independent from insurance provider

Bern, Tavakolian 22 A physician from nation A shall utilize his/her electronic proof of professional attribute in nation B Electronic document e.g. on a health professional card shall be accessed by authorities Identity and professional attribute must be confirmed Use case 2: Mobile health care professional

Bern, Tavakolian 23 Use case 3: Cross border health message Patient medical data shall be transmitted by a physician in nation A to a colleague in nation B address of recipient must be located Identity and professional attribute of recipient must be confirmed Message linked to a patient ID must be securely transmitted Receiving physician must receive confirmation of ID and professional attribute of the sender

Bern, Tavakolian 24 ID management in eHealth - one touchstone for interoperability Workshop on March 20&21, 2006 in Amsterdam, NL Jointly organised by the Dutch ministry of Health, NICTIZ (NL), EHTEL, and i2Health 3 parallel sessions including 81 experts from 21 nations Results: Raised problem awareness Best practice exchange among MS Recommendations of cross border ID utilisation WS-Proceedings incl. summary and conclusions are available at:

Bern, Tavakolian 25 eHealth-ID Workshop on March 20&21, 2006 in Amsterdam, NL – extract of results 1. The electronic communication of medical data calls for the highest level of security. 2. As a healthcare professional, you have to prove who you are and what you are e.g. mrs.J.A. Claassen, general practitioner. 3. There is a need to identify who is responsible for ID management in each country. 4. The patient should be in the lead in reading and having access to his record. 5. There should always be logging. 6. There should be an adequate system of supervising the logging process.

Bern, Tavakolian 26 Contact: Dr. Ramin Tavakolian Zentralinstitut für die kassenärztliche Versorgung Herbert-Lewin-Platz 2 D Berlin Germany Tel.: (+49)