The 4BF The Four Bridges Forum The SAFE-BioPharma Digital Identity and Signature Standard.

Slides:



Advertisements
Similar presentations
Overview of US Federal Identity Management Initiatives Peter Alterman, Ph.D. Chair, Federal PKI Policy Authority and Asst. CIO E-Authentication, NIH.
Advertisements

Public Key Infrastructure A Quick Look Inside PKI Technology Investigation Center 3/27/2002.
EDUCAUSE 2001, Indianapolis IN Securing e-Government: Implementing the Federal PKI David Temoshok Federal PKI Policy Manager GSA Office of Governmentwide.
15June’061 NASA PKI and the Federal Environment 13th Fed-Ed PKI Meeting 15 June ‘06 Presenter: Tice DeYoung.
SLIDE 1 Westbrook Technologies from Fortis: A Healthcare Solution for Medical Records, Billing and HIPAA.
Public Key Infrastructure (PKI) Hosting Services.
SAFE-BioPharma: Industry’s Digital Identity and Signature Standard Practical Use Cases Cindy Cullen CTO Oct. 1, 2008.
Electronic Submission of Medical Documentation (esMD) for Medicare FFS Presentation to HITSC Provenance Workgroup January 16, 2015.
SAFE BioPharma Association CONFIDENTIAL1 SAFE Public Key Infrastructure (PKI) 2005 EDUCAUSE/Dartmouth PKI Deployment Summit.
ESign-Online Digital Signature Service February 2015 Controller of Certifying Authorities Department of Electronics and Information Technology Ministry.
August 2004 Providing Industry-wide Security and Identity Management Solutions.
The SAFE-BioPharma Identity Proofing Process Author of Record SWG (Digital Credentials) October 3, 2012 Peter Alterman, Ph.D. Chief Operating Officer,
21 mai 2015 Bridges between Certification Authorities.
PKI in US Higher Education TAGPMA Meeting, March 2006 Rio De Janeiro, Brazil.
The 4BF The Four Bridges Forum Higher Education Bridge Certificate Authority.
E-Government Security and necessary Infrastructures Dimitrios Lekkas Dept. of Systems and Products Design Engineering University of the Aegean
Identity Management and PKI Credentialing at UTHSC-H Bill Weems Academic Technology University of Texas Health Science Center at Houston.
SAFE is a member-governed, not-for-profit enterprise that: Manages and promotes the SAFE standard Provides a legal and contractual framework Provides technical.
SAFE-BioPharma Digital Identity and Signature Standard and Services Fed/Ed XVIII Friday, December 12 th, 2008.
Deploying a Certification Authority for Networks Security Prof. Dr. VICTOR-VALERIU PATRICIU Cdor.Prof. Dr. AUREL SERB Computer Engineering Department Military.
Vilnius, October 21st, 2002 © eEurope SmartCards Securing a Telework Infrastructure: Smart.IS - Objectives and Deliverables Dr. Lutz Martiny Co-Chairman,
Chapter © 2012 Pearson Education, Inc. Publishing as Prentice Hall.
E-Authentication: The Need for Open-Standards in Implementing E-Government October 6, 2004 The E-Authentication Initiative.
The InCommon Federation The U.S. Access and Identity Management Federation
“ Technology Working For People” Intro to HIPAA and Small Practice Implementation.
1 International Forum on Trade Facilitation May 2003 Trade Facilitation, Security Concerns and the Postal Industry Thomas E. Leavey Director General, UPU.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
Johnson & Johnson’s Public Key Infrastructure Bob Stahl
Trusted Federated Identity and Access Management to provide the Cornerstone for Cyber Defense.
© Copyright 2011, Alembic Foundation. All Rights Reserved. Aurion: Health Information Exchange Technology Today Alembic Foundation OSCON 2011 July 27,
1 EAP and EAI Alignment: FiXs Pilot Project December 14, 2005 David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
U.S. General Services Administration Federal Technology Service November 9, 1999 Judith Spencer Director, Center for Governmentwide Security Office of.
1 June Richard Guida Stephanie Evans Johnson & Johnson Director, WWIS WWIS SAFE Infrastructure Overview.
State HIE Program Chris Muir Program Manager for Western/Mid-western States.
CRIX: toward a secure, standards-based, clinical research information exchange.
PKI Forum Business Panel March 6, 2000 Dr. Ray Wagner Sr. Director, Technology Research.
Security Overview  System protection requirements areas  Types of information protection  Information Architecture dimensions  Public Key Infrastructure.
The IT Quality Assurance FDA Validation Specialists Phone: 877-MGD-TEST ( ) n n n n Web Site:
1 National Audioconference Sponsored by the HIPAA Summit June 6, 2002 Chris Apgar, CISSP Data Security & HIPAA Compliance Officer Providence Health Plan.
1 UNECE Capacity Building Workshop on Trade Facilitation Implementation: October 2004 Electronic PostMark (EPM) Security & Authentication for eTrade Documents.
Meganet Corporation VME Sign Meganet Corporation Meganet Corporation is a leading worldwide provider of data security to Governments, Military,
The Federal Bridge A Brief Overview 1. 4BF Industry Forum April Fed PKI: View from 20,000 km FBCA C4 Common Policy CA (HSPD-12) CertiPath SSPs.
Security Management Press Conference, April 14 th 2003 Russ Artzt, Executive Vice President, Computer Associates International, Inc. Joe Grillo, President.
Electronic PostMark (EPM) Project Overview May, 2003 Copyright Postal Technology Centre.
Federated Authentication at NIH: Trusting External Credentials at Known Levels of Assurance Debbie Bucci and Peter Alterman November, 2009.
COAG AUSTRALIA The Prime Minister, Premiers and Chief Ministers signed the IGA at the COAG meeting on 13 April The key objectives of the Strategy,
Identity Proofing, Signatures, & Encryption in Direct esMD Author of Record Workgroup John Hall Coordinator, Direct Project June 13, 2012.
“Trust me …” Policy and Practices in PKI David L. Wasley Fall 2006 PKI Workshop.
1 Federal Identity Management Initiatives Federal Identity Management Initatives David Temoshok Director, Identity Policy and Management GSA Office of.
Part 11 Public Meeting PEERS Questions & Responses The opinions expressed here belong to PEERS members and not the corporate entities with which they are.
Hajar Sabuur Johnson & Johnson Worldwide Information Security June 16, 2005
Transforming Government Federal e-Authentication Initiative David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
Chapter © 2012 Pearson Education, Inc. Publishing as Prentice Hall.
Pfizer’s SAFE Use Case Michael Lavoie, CISSP, PMP Member, SAFE Board of Directors 24-FEB-2016.
SAFE-BioPharma Association Blocking the Big Breach SCOPE Summit 2016 Mollie Shields Uehling SAFE-BioPharma Association.
Jim Bland Executive Director, CRIX International
Managing Complexity Through Innovation
Data and Applications Security Developments and Directions
U.S. Federal e-Authentication Initiative
SAFE-BioPharma Digital Identity and Signature Standard and Services
Regional Health Information Exchange: Getting There
NAAS 2.0 Features and Enhancements
EDUCAUSE Fed/Higher ED PKI Coordination Meeting
Technical Approach Chris Louden Enspier
HIMSS National Conference New Orleans Convention Center
E-Lock ProSigner ProSigner means “Professional Signer” signifying the software that can apply legally enforceable Advanced electronic signatures to electronic.
FDA Sentinel Initiative
Remote Coding: Best Practices and Strategies AHIMA 2016
Every 80 Secs – someone dies from this curable disease
Health Information Exchange for Eligible Clinicians 2019
Presentation transcript:

The 4BF The Four Bridges Forum The SAFE-BioPharma Digital Identity and Signature Standard

2SAFE-BioPharma Association Why an Industry Digital Identity and Signature Standard?  Revolution in life sciences and medical technology: –Costly, complex, many partners, global  Need to improve safety, quality, development times: –Need to achieve process efficiencies & improvements.  Government imperative – soon to be mandated for regulatory submissions and healthcare.  Fundamental to sensitive electronic exchanges of information are trusted identities and legal signatures.  Special issues/barriers for biopharmaceutical industry – legal, global, clinical researchers, regulatory, risk mitigation.

3 SAFE-BioPharma Digital Identity and Signature Standard and Services  2005: Strategic initiative to transform industry business and regulatory processes to fully electronic –Member-governed non-profit collaboration –Standard for trusted identity and non-repudiable digital signature based on same standards as used by Federal Govt. –Contract-based system -- Risk mitigation scheme, regulatory requirements, global applicability –Technology and vendor neutral – , pilots and early adopters – , expansion of standard; increased implementations and use cases –2008 cross-certified with FBCA –2008 Member establishment of tiered services  Shared infrastructure to provision employees, external partners (researchers), at low cost  Identity-proofing and digital signing technologies for healthcare professionals  Fee structure revisions – small entity, non-profit, government, special use –Growing implementations and use cases -- clinical research, alliance management, purchasing, legal, research notebooks, investigator portals –Maturing technology and supportive policy environment

SAFE-BioPharma Bridge Infrastructure 4

Options for Flexible Use  Two levels of trust: –Basic Assurance for authentication –Medium Assurance for trusted identity uniquely linked to digital signature and EU-qualified  Three digital signing technologies: –Software –Hardware (zero footprint now undergoing FIPS certification) –Roaming  Three identity-proofing options –Antecedent – enterprise and on-line –Trusted agent –Notary – including office/home notary services 5

On-Line Antecedent Process  ID Vetting Successful: –Applicant Passes 3 rd Party Antecedent identity proofing –Moved to RA queue for processing and Certificate Issuance steps. –It’s a matter of minutes end-to-end. ID Vetting Not Successful: ― Unable to verify identity via 3rd Party Antecedent ― Process reverts to Notary Process with two service options: User locates notary RAS/NNA will have a local notary contact the Applicant directly 6

7 SAFE-BioPharma and Regulators SAFE-BioPharma and Regulators  EMEA and FDA are on paths to require fully electronic submissions within the next few years  FDA helped write SAFE-BioPharma standard; engaged since inception –FDA has received 10,000s of SAFE-BioPharma submissions since 9/06  EMEA engagement since inception – helped write standard –EMEA to use SAFE-BioPharma for access to Safety Reports Database –eSubmissions now underway  SAFE-BioPharma and the MHLW/PMDA –Expect to launch SAFE-BioPharma services in late 2009

Centers for Disease Control (CDC): Public Health Surveillance Accelerate and simplify the Disease Investigation process Build a scalable framework aligned with the National Health Information Network (NHIN) architecture and structures Establish a cross-jurisdictional, credential compatible with the Federal Architecture and Federal PKI Policy Authority (FPKIPA) Disease investigator can access state systems and query for meta data and request a CDA or CCD document back electronically. Reduction of phone calls, faxes and s needed for routine investigation workflow. Overall time to track and close investigations should decrease.  Will be validated by ROI analysis in Pilot Phase. Reduced cost due to increased efficiency of investigation workflow Reduced maintenance cost of security sub systems.  Certificates not maintained by state investigator or CDC.  Federal Identity provider issues the certificates. Efficiency Cost Purpose

CDC Disease Investigation Federation Overview

 Company profile –Largest Group Purchasing Organization (GPO) in U.S. –Owned by non-profit hospitals –Serves 2,000 U.S. hospitals and 53,000-plus other healthcare sites –Buys from ~700 suppliers –  Scope: –Eliminate overnight shipping, fax and related workflows for contract origination and amendments –Provide SAFE-BioPharma credentials to Premier Sourcing/Procurement employees and their supplier colleagues for signing new and amended supplier contracts –eContracting process ~700 companies and thousands of contracts and/or amendments  Future: –Digitally sign and submit required reports to CMS Premier Purchasing

11 Strategic Value of SAFE-BioPharma SAFE-BioPharma makes end-to-end eBusiness and eRegulatory processes possible Legal enforceability Regulatory compliant (US, EU, Japan) Global standard In EU, SAFE-BioPharma digital signature is the legal equivalent of handwritten Mitigates risk Vendor, technology neutral Secure Record integrity Only one digital identity per investigator or other user Links Federal agencies to pharma and healthcare providers Provides interoperability Improves productivity Improved auditability and compliance Reduces cycle time Facilitates collaboration Enabling technology to transform business and regulatory processes