HIT Standards Committee Privacy and Security Workgroup Dixie Baker, Chair Walter Suarez, Co-Chair June 22, 2011.

Slides:



Advertisements
Similar presentations
1 HIT Standards Committee Privacy and Security Workgroup: Reformatted Standards Recommendations & Implementation Guidance Dixie Baker, SAIC Steven Findlay,
Advertisements

HIT Standards Committee Privacy and Security Workgroup Recommendations for Electronic Health Record (EHR) Query of Provider Directories Dixie Baker, Chair.
Electronic Submission of Medical Documentation (esMD) Face to Face Informational Session esMD Requirements, Priorities and Potential Workgroups – 2:00pm.
Provider Directories Deliberations NwHIN Power Team May 29, 2014.
1 HIT Standards Committee Privacy and Security Workgroup: Recommendations Dixie Baker, SAIC Steven Findlay, Consumers Union August 20, 2009.
S&I Framework Provider Directories Initiative esMD Work Group October 19, 2011.
HIT Policy Committee Privacy and Security Tiger Team Deven McGraw, Chair Paul Egerman, Co-Chair Certificate Authority- Provider Authentication Recommendations.
NHIN Direct Project Communications Work Group Message for State HIE/RECs August 30, 2010.
Certification NPRM Comments Package Transport and Security Standards Workgroup Dixie Baker, Chair Lisa Gallagher, Co-Chair May 20, 2015.
Privacy and Security in the Direct Context Session 6 April 12, 2010.
User Authentication Recommendations Transport & Security Standards Workgroup December 10, 2014.
NextGen Interoperability – Leading the Charge Presenter – David Venier DISCLAIMER: The views and opinions expressed in this presentation are those of the.
S&I Framework Doug Fridsma, MD, PhD Director, Office of Standards and Interoperability, ONC Fall 2011 Face-to-Face.
HIT Standards Committee Privacy and Security Workgroup: Standards for Consumer Engagement Dixie Baker, SAIC Steve Findlay, Consumers Union May 26, 2010.
HISP-to-HISP Discussion May 13, HISP Definition What is a HISP? An organization that provides security and transport services for directed exchange.
Understanding and Leveraging MU2 Optional Transports Paul M. Tuten, PhD Senior Consultant, ONC Leader, Implementation Geographies Workgroup, Direct Project.
HIT Policy Committee Privacy and Security Tiger Team Deven McGraw, Chair Paul Egerman, Co-Chair Provider Authentication Recommendations November 19, 2010.
HIT Standards Committee Implementation Workgroup Judy Murphy, Aurora Health Care, Co-Chair Liz Johnson, Tenet Healthcare, Co-Chair September 21, 2010.
What IHE Delivers Healthcare Provider Directories IHE IT Infrastructure Planning Committee Eric Heflin – Medicity/THSA.
Collaborative Direct-- Status Update December 6, 2013 Don Jorgenson Inpriva, Inc.
HIT Policy Committee Privacy and Security Tiger Team Deven McGraw, Chair Paul Egerman, Co-Chair August 3,
Data Gathering HITPC Workplan HITPC Request for Comments HITSC Committee Recommendations gathered by ONC HITSC Workgroup Chairs ONC Meaningful Use Stage.
HIT Standards Committee Hearing on Trusted Identity of Patients in Cyberspace November 29, 2012 Jointly sponsored by HITPC Privacy and Security Tiger Team.
HIT Standards Committee Privacy and Security Workgroup: Update Dixie Baker Dixie Baker, SAIC Steve Findlay Steve Findlay, Consumers Union December 18,
HITSC Workplan: April Update April 17, 2013 Doug Fridsma, MD, PhD, FACP, FACMI Chief Science Officer & Director, Office of Science & Technology.
Privacy and Security Tiger Team Recommendations Adopted by The Health IT Policy Committee Relevant to Consumer Empowerment May 24, 2013.
HIT Policy Committee Nationwide Health Information Network Governance Workgroup Recommendations Accepted by the HITPC on 12/13/10 Nationwide Health Information.
HIT Standards Committee Privacy and Security Workgroup: Standards for Consumer Engagement Dixie Baker, SAIC Steve Findlay, Consumers Union April 28, 2009.
HIT Standards Committee HIT Standards Committee Privacy and Security Workgroup Discussion of NwHIN Power Team Recommendations August 6,
Privacy & Security Workgroup NPRM Comments Dixie Baker, Chair Lisa Gallagher, Co-Chair April 24, 2014.
HIT Standards Committee Privacy and Security Workgroup Recommendations on Certification of EHR Modules Dixie Baker, Chair Walter Suarez, Co-Chair December.
HIT Standards Committee Privacy and Security Workgroup: Initial Reactions Dixie Baker, SAIC Steven Findlay, Consumers Union June 23, 2009.
Data Gathering HITPC Workplan HITPC Request for Comments HITSC Committee Recommendations gathered by ONC HITSC Workgroup Chairs ONC Meaningful Use Stage.
HIT Standards Committee Privacy and Security Workgroup Dixie Baker, Chair, Privacy and Security Workgroup Walter Suarez, Co-Chair, Privacy and Security.
Interoperability Framework Overview Health Information Technology (HIT) Standards Committee June 24, 2010 Presented by: Douglas Fridsma, MD, PhD Acting.
HIT Policy Committee NHIN Workgroup Recommendations Phase 2 David Lansky, Chair Pacific Business Group on Health Danny Weitzner, Co-Chair Department of.
HIT Policy Committee Privacy & Security Tiger Team Update Deven McGraw, Co-Chair Center for Democracy & Technology Paul Egerman, Co-Chair June 25, 2010.
HIT Standards Committee Clinical Operations Workgroup Report Jamie Ferguson, Chair Kaiser Permanente John Halamka, Co-chair Harvard Medical School 20 August,
HIT Standards Committee Privacy and Security Workgroup: Privacy and Security Workgroup: Update Dixie Baker, SAIC Steve Findlay, Consumers Union March 24,
HIT Policy Committee Privacy and Security Tiger Team Deven McGraw, Chair Paul Egerman, Co-Chair Patient Matching Recommendations February 2,
PD Provider Directories Initiative Overview PD January 20, 2012.
HIT Policy Committee Information Exchange Workgroup NwHIN Conditions for Trusted Exchange Request For Information (RFI) May 18,
HIT Policy Committee Report from HIT Standards Committee Privacy and Security Workgroup Dixie Baker, SAIC December 15, 2009.
S&I Provider Directories Initiative Revisions to Initiative Charter July 1, 2011.
Health eDecisions Use Case 2: CDS Guidance Service Strawman of Core Concepts Use Case 2 1.
HIT Standards Committee Privacy and Security Workgroup Final Recommendations for NwHIN Governance RFI Assigned Questions Dixie Baker, Chair Walter Suarez,
HIT Standards Committee Technical Review of The Direct Project Dixie Baker December 17, 2010.
Identity Proofing, Signatures, & Encryption in Direct esMD Author of Record Workgroup John Hall Coordinator, Direct Project June 13, 2012.
HIT Standards Committee Clinical Operations Workgroup Jamie Ferguson, Kaiser Permanente John Halamka, Harvard Medical School June 23, 2009.
HIT Standards Committee NwHIN Power Team Preliminary Results Dixie Baker, Chair August 17,
HIT Standards Committee Overview and Progress Report March 17, 2010.
HIT Standards Committee Privacy and Security Workgroup Dixie Baker, Chair, Privacy and Security Workgroup Walter Suarez, Co-Chair, Privacy and Security.
HIT Policy Committee Privacy and Security Tiger Team Deven McGraw, Chair Paul Egerman, Co-Chair October 20,
Mariann Yeager, NHIN Policy and Governance Lead (Contractor) Office of the National Coordinator for Health IT David Riley, CONNECT Lead (Contractor) Federal.
Draft Provider Directory Recommendations Begin Deliberations re Query for Patient Record NwHIN Power Team July 10, 2014.
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
HIT Standards Committee Implementation Workgroup Aneesh Chopra Chief Technology Officer Office of Science & Technology Policy (OSTP) October 29, 2009.
Information Exchange Workgroup June 14, IE WG Presentation to HITPC (draft) IE WG Workplan Query exchange recommendations Provider directory.
Discussion - HITSC / HITPC Joint Meeting Transport & Security Standards Workgroup October 22, 2014.
Privacy and Security Tiger Team Potential Questions for Request for Comment Meaningful Use Stage 3 October 3, 2012.
1 HIT Standards Committee Hearing on Health Information Technology Security Issues, Challenges, Threats, and Solutions - Introduction Dixie Baker, SAIC.
Framing Identity Management Recommendations Transport & Security Standards Workgroup November 19, 2014.
HIT Standards Committee Privacy and Security Workgroup Progress Report on Review of Governance RFI Dixie Baker, Chair Walter Suarez, Co-Chair May 24, 2012.
HIT Standards Committee Privacy and Security Workgroup Task Update: Standards and Certification Criteria for Certifying EHR Modules Dixie Baker, Chair.
Provider Directories Tasking, Review and Mod Spec Presentation NwHIN Power Team April 17, 2014.
Data Gathering HITPC Workplan HITPC Request for Comments HITSC Committee Recommendations gathered by ONC HITSC Workgroup Chairs ONC Meaningful Use Stage.
Health IT Standards Committee Update December 19, 2012 Doug Fridsma, MD, PhD, FACP, FACMI Chief Science Officer & Director, Office of Science & Technology.
What IHE Delivers Healthcare Provider Directories IHE IT Infrastructure Planning Committee Eric Heflin - Medicity.
HIT Standards Committee NwHIN Power Team Dixie Baker, Chair July 20,
Presentation transcript:

HIT Standards Committee Privacy and Security Workgroup Dixie Baker, Chair Walter Suarez, Co-Chair June 22, 2011

Dixie Baker, SAIC Anne Castro, BlueCross BlueShield of South Carolina Aneesh Chopra, Federal Chief Technology Officer Mike Davis, Veterans Health Administration Lisa Gallagher, HIMSS Chad Hirsch, Mayo Ed Larsen David McCallie, Cerner Corporation John Moehrke, General Electric Steve Findlay, Consumers Union Jeff Jonas, IBM Wes Rishel, Gartner Walter Suarez, Kaiser Permanente Sharon Terry, Genetic Alliance Privacy and Security Workgroup NEW MEMBER

Agenda Provider Directory Standards –Review through May HITSC meeting –Activity since the May meeting Next topic: Stage 2 meaningful-use standards Recommendations

Enterprise-Level Provider Directory (ELPD) Review: Need Identified by HIT Policy Committee HIT Policy Committee identified need for national ELPD system that would provide the capability to search for and find “discoverable” information essential for enabling exchange of health information between enterprises – limited content to: 1.Basic entity information (e.g., name, address, human point- of-contact) 2.Externally accessible information describing exchange services (e.g., domains, message protocols, transport protocols, “inbox” locations) 3.Security credentials

Enterprise-Level Provider Directory (ELPD) Review: Initial Focus and Recommendation to HITSC ONC requested that HITSC address immediate need for standards and certification criteria to support EHR query of ELPD per HITPC policy recommendations At May HITSC meeting, Privacy and Security Workgroup recommended tailored subset of IHE Healthcare Provider Directory (HPD) profile as standard to provide required functionality and content HITSC Response –Recommendation was good representation of current state of applicable directory standards, but national ELPD capability may not be necessary for exchange –Direct Project approach of using domain name service (DNS) query to retrieve digital certificates may be good enough for the short term, with EHR query of ELPDs as a longer term vision –Recommended working with HIT Policy Committee and ONC to refine business requirements

Provider Directory Activity Since May HITSC Meeting ONC Standards and Interoperability (S&I) Framework launched work on provider directories, focusing primarily on community- based directories –Certificate discovery –Search & retrieval of provider information when provider address is known/not known Alternatives for providing national-level functionality were suggested by members of both HITPC and HITSC 1.Broadly adopt Direct Project’s strategy of using Domain Name Service (DNS) to retrieve digital certificates 2.Create health top-level-domain (TLD) – something like.MED to facilitate end-user search for information about trusted health exchange points 3.Use embedded microformats to standardize tagged data fields and vocabulary for providing directory information from a protected web page Privacy and Security Workgroup considered these alternatives

Results from Consideration of Alternatives Lack a strong business case for creating health TLD – potential benefit would not justify significant effort required Direct Project’s use of DNS to retrieve digital certificates is working well and has been generally accepted by participants in Direct pilot –Some browsers and clients do not currently support query of DNS for digital certificates needed for secure and secure web connections – though DNS specification does include the capability –DNS cannot be used to retrieve more general directory information, such as the transport standards supported, or rich content, such as specialties of provider organizations Use of DNS for certificate retrieval, along with with publishing of web pages providing additional directory information as structured, encoded content warrants further consideration

DNS + Structured & Encoded Web Content: Concept Organizations create public web pages containing directory information they wish to expose for search Provider directory information is structured and encoded into the web page, using standard schema and vocabulary –Improves search engine indexing –Enables extraction of information into local systems (EHR, Exchange gateway, Direct HISP, etc.) Organizations can obtain Extended Validation certificates to provide assurance of the authenticity of its web pages Standard search engines provide a flexible and free Query Service DNS is used to retrieve digital certificates for the published service address names which have been embedded in the web pages

DNS + Structured & Encoded Web Content Benefits –Simple, widely available, and highly scalable web technology Three leading search engines (Google, Bing, Yahoo!) have launched Schema.org metadata project to provide tools for building common vocabulary for structuring web page data –Organization maintains control over what information is exposed Can start simple and build over time –Allows discovery of services and certificates using familiar names, without requiring advance knowledge of formal identifier (e.g., OID used in NwHIN Exchange, Direct Address) Recommend that S&I Framework team consider this approach for meeting need for nationwide access to directory information without requiring “national provider directory”

Next Topic: Privacy and Security for Stage 2 Stage 2 measures are unlikely to significantly change required EHR privacy and security functionality or content However, HITPC Privacy and Security Tiger Team has recommended policies that do imply new EHR privacy and security standards and functionality Privacy and Security Workgroup has undertaken an examination of these recommended policies to identify new needs for EHR standards, implementation specifications, and certification criteria

Example Privacy and Security Functionality Derived from Tiger Team Recommendations Secure and web transactions Retrieval, validation, and use of intended recipient’s digital certificate to authenticate recipient Strong protection of sender’s digital certificate Use of sender’s digital certificate to authenticate sender and to digitally sign content Support two-factor authentication for high-risk transactions, including e-prescribing of controlled substances Detect and block programmatic attacks, and attacks from unauthorized entities Enable consumers to securely download their own health information, including provenance, and to securely send their health information to a third party Audit events on consumer portals Require consumer to log into consumer portal before accessing health information Standard metadata and vocabulary for data fields commonly used in patient matching (may be a Clinical Operations assignment)

Summary Recommendation: Recommend that S&I Framework team consider approach of structuring and encoding web content, using standard schema and vocabulary, for meeting need for nationwide access to directory information without requiring “national provider directory” Will present initial recommendations for Stage 2 privacy and security standards, implementation specifications, and certification criteria at July meeting