Www.DirectTrust.org 1101 Connecticut Ave NW, Washington, DC 20036 DirectTrust Collaborating to Build the Security and Trust Framework for Direct Exchange.

Slides:



Advertisements
Similar presentations
Georgia Department of Community Health
Advertisements

#CONNECT2013 Connecting for Good Loews Coronado Bay Resort, San Diego, California David C. Kibbe, MD MBA President and CEO, DirectTrust David C. Kibbe,
EDUCAUSE 2001, Indianapolis IN Securing e-Government: Implementing the Federal PKI David Temoshok Federal PKI Policy Manager GSA Office of Governmentwide.
ONC Policy and Program Update Health IT Standards Committee Meeting February 20, 2013 Jodi Daniel, Office of Policy and Planning, ONC.
Certificate Interoperability S&I Framework Initiative Final Report August 17, 2011.
Connecticut Ave NW, Washington, DC Understanding Patient Engagement in Stage 2 MU: Direct, HIPAA, VDT, and Patient Engagement.
1101 Connecticut Ave NW, Washington, DC :00 pm EST, January 9, (626)
1101 Connecticut Ave NW, Washington, DC :00 pm ET, April 4, (773)
Identity Standards (Federal Bridge Certification Authority – Certificate Lifecycle) Oct,
Connecticut Ave NW, Washington, DC Direct Exchange from Provider to Patient/Consumer ….and Back! David C. Kibbe, MD MBA.
Direct Implementation Perspective 0 Mark Bamberg, Vice President Research & Development MEDfx.
1101 Connecticut Ave NW, Washington, DC :00 pm EDT, July 11, (773)
HIT Standards Committee: Digital Certificate Trust – Policy Question for HIT Policy Committee March 29, 2011.
Connecticut Ave NW, Washington, DC September 30, 2014 David C. Kibbe, MD MBA President and CEO, DirectTrust Luis Maas, MD.
NHIN Direct Project Communications Work Group Message for State HIE/RECs August 30, 2010.
Direct Project Scalable Trust and Trust Bundles. 12/06/10 Overview What is Scalable Trust State of Trust Trust Issues Trust Solutions Trust Bundle Demo.
Texas Approach to Supporting Statewide Health Information Exchange January 2013.
Supporting Meaningful Use Stage 2 Transition of Care Requirements
Public Key Infrastructure (PKI) Providing secure communications and authentication over an open network.
David L. Wasley Information Resources & Communications Office of the President University of California Directories and PKI Basic Components of Middleware.
Introduction to PKI Seminar What is PKI? Robert Brentrup July 13, 2004.
Centers for Disease Control and Prevention Office of the Associate Director for Communication Electronic Health Records/Meaningful Use and Public Health.
Building Trusted Transactions Identity Authentication & Attribute Exchange In Public and Private Federations OASIS Conference September 2010 Joni Brennan,
Presented by Xiaoping Yu Cryptography and PKI Cosc 513 Operating System Presentation Presented to Dr. Mort Anvari.
1101 Connecticut Ave NW, Washington, DC :00 pm EDT, October 3, (626)
HISP-to-HISP Discussion May 13, HISP Definition What is a HISP? An organization that provides security and transport services for directed exchange.
Understanding and Leveraging MU2 Optional Transports Paul M. Tuten, PhD Senior Consultant, ONC Leader, Implementation Geographies Workgroup, Direct Project.
1101 Connecticut Ave NW, Washington, DC :00 pm EDT, May 2, (773)
Connecticut Ave NW, Washington, DC Direct Exchange An Introduction for Providers Engaged in Stage 2 Meaningful Use David.
Connecticut Ave NW, Washington, DC HISP Policy “HP” 1.0 Overview Policy Document available at DirectTrust.Org Presented.
NHIN Direct Project Communications Work Group Messages for Physicians August 24, 2010.
Masud Hasan Secue VS Hushmail Project 2.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
Georgia Health Information Exchange Georgia Rural Health IT Forum January 26, 2012.
NENA Development Conference | October 2014 | Orlando, Florida Security Certificates Between i3 ESInet’s and FE’s Nate Wilcox Emergicom, LLC Brian Rosen.
Exchange: The Central Feature of Meaningful Use Stage Meaningful Use and Health Care Innovation Conference Craig Brammer Office of the National.
An XMPP (Extensible Message and Presence Protocol) based implementation for NHIN Direct 1.
Wicked Problems, Righteous Solutions: Learnings from Two Years of DirectTrust PKI and Interoperability Testing Experiences DirectTrust Technical Break-out.
0 Presentation to: Health IT HIPPA Workshop Presented by: Stacey Harris, Director of Health IT Innovation September 26, 2014 Division of Health Information.
S&I Framework Architecture Refinement & Management (ARM) 01/07/2013.
Nationwide Health Information Network: Conditions for Trusted Exchange Request For Information (RFI) Steven Posnack, MHS, MS, CISSP Director, Federal Policy.
© Copyright 2011, Alembic Foundation. All Rights Reserved. Aurion: Health Information Exchange Technology Today Alembic Foundation OSCON 2011 July 27,
Chapter 9: Using and Managing Keys Security+ Guide to Network Security Fundamentals Second Edition.
Connecticut Ave NW, Washington, DC David C. Kibbe, MD MBA President and CEO, DirectTrust Senior Advisor, AAFP AMDIS, Boston,
XMPP Concrete Implementation Updates: 1. Why XMPP 2 »XMPP protocol provides capabilities that allows realization of the NHIN Direct. Simple – Built on.
HIT Policy Committee NHIN Workgroup Recommendations Phase 2 David Lansky, Chair Pacific Business Group on Health Danny Weitzner, Co-Chair Department of.
HEPKI-PAG Policy Activities Group David L. Wasley University of California.
Secure Messaging Workshop The Open Group Messaging Forum February 6, 2003.
1. 2 Overview In Exchange security is managed by assigning permissions in Active Directory Exchange objects are secured with DACL and ACEs Permissions.
1101 Connecticut Ave NW, Washington, DC :00 pm ET, July 10, (626)
1 David C. Kibbe, MD MBA DirectTrust A Discussion About Scalable Trust May 9,
1101 Connecticut Ave NW, Washington, DC :00 pm ET, June 15, (626)
Identity Proofing, Signatures, & Encryption in Direct esMD Author of Record Workgroup John Hall Coordinator, Direct Project June 13, 2012.
“Trust me …” Policy and Practices in PKI David L. Wasley Fall 2006 PKI Workshop.
Scalable Trust Community Framework STCF (01/07/2013)
Security fundamentals Topic 5 Using a Public Key Infrastructure.
Mariann Yeager, NHIN Policy and Governance Lead (Contractor) Office of the National Coordinator for Health IT David Riley, CONNECT Lead (Contractor) Federal.
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
Transforming Government Federal e-Authentication Initiative David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
Don Thibeau, Executive Director, OpenID Foundation (OIDF) Drummond Reed, Executive Director, Information Card Foundation (ICF)
Stanford University & National Student Clearinghouse Shibboleth Pilot CAMP Phoenix, AZ February 5, 2009.
Doc.: IEEE /0098r0 Submission July 2010 Alex Reznik, et. al. (InterDigital)Slide Security Procedures Notice: This document has been.
1 US Higher Education Root CA (USHER) Update Fed/Ed Meeting December 14, 2005 Jim Jokl University of Virginia.
1 David C. Kibbe, MD MBA DirectTrust Collaborating to Build the Security and Trust Framework for Direct Exchange June 20, 2013.
The Federal E-Authentication Initiative David Temoshok Director, Identity Policy GSA Office of Governmentwide Policy February 12, 2004 The E-Authentication.
HIE Landscape in California
Technical Approach Chris Louden Enspier
HIMSS National Conference New Orleans Convention Center
PKI (Public Key Infrastructure)
Health Information Exchange for Eligible Clinicians 2019
Presentation transcript:

Connecticut Ave NW, Washington, DC DirectTrust Collaborating to Build the Security and Trust Framework for Direct Exchange David C. Kibbe, MD MBA RedWood MedNet Conference July 24, 2013

Connecticut Ave NW, Washington, DC Mission and Goals DirectTrust.org, Inc. (DirectTrust) is a voluntary, self-governing, non-profit alliance dedicated to the support of Direct exchange of health information at national scale, through the establishment of policies, interoperability requirements, and business practice requirements. Taken together, these create a Security and Trust Framework for the purpose of uniting multiple Direct implementations and their communities, enhancing public confidence in privacy, security, and trust in identity when using Direct. DirectTrust is the recipient of an ONC Cooperative Agreement award in the amount of $280,205 as part of the Exemplar HIE Governance Program. Within this Program, DirectTrust is charged by ONC with further development of the Direct Trusted Agent Accreditation Program, and the establishment of a national trust anchor bundle distribution service for Direct exchange implementers. 2

Connecticut Ave NW, Washington, DC Today’s talk Brief introduction to DirectTrust The problem we’re trying to solve Level setting: how Direct exchange works Why security and trust are important, and options for achieving HISP-HISP trust The DirectTrust approach: accreditation and trust anchor bundle distribution for “scalable” trust.

Connecticut Ave NW, Washington, DC The problem Direct exchange is designed to help solve - fragmentation near Phoenix, Az.

Connecticut Ave NW, Washington, DC Direct exchange is well suited to replace fax, e- fax, mail, and proprietary connections: Between providers during transitions of care; Between providers and patients; Between federal and state agencies and providers for document exchange, requests for information; Between payers and provider organizations; Between patients and patient applications for organization, display, reconciliation, analysis. Direct exchange: it’s not just about Stage 2 MU requirements

Connecticut Ave NW, Washington, DC DirectTrust is an outgrowth of the Direct Project “Rules of the Road” WG DirectTrust’s membership includes over 80 entities, including state HIEs and state agencies, coalitions, HISPs, EHR vendors, provider groups, certificate authorities, consultants, and private individuals. DirectTrust members are serving Direct users/subscribers in all 50 states as HISPs, CAs, and RAs within the context of Stage 2 Meaningful Use, and beyond. DirectTrust is the only national Security and Trust Framework provider for Direct, and in partnership with EHNAC, the sole accrediting body for Direct trusted agents – HISPs, CAs, and RAs. X.509 Certificate Policy Established X.509 Certificate Policy Established December 2011 X.509 Certificate Policy Established X.509 Certificate Policy Established December 2011 Accreditation Program Kick-off February 2013 Accreditation Program Kick-off February 2013 ONC Cooperative Agreement Award March 2013 ONC Cooperative Agreement Award March 2013 Trust Anchor Bundle Distribution Service Starts May 2013 Trust Anchor Bundle Distribution Service Starts May 2013

Connecticut Ave NW, Washington, DC HISP A SMTP Server Sending System Receiving System Receiving System Sending System Endpoint Communication ( XDR, SMTP, others) SSL/TLS How it works: Single HISP exchange is via an encrypted session HISP A subscribers Central hub for all HISP’s subscribers. Direct STA not invoked. No use of Direct certificates. At this point, exchange is limited to subscribers of this HISP. MacMail Web portal EHR Outlook

Connecticut Ave NW, Washington, DC HISP-HISP Direct exchange adds in a layer of security & trust in order to enable point-to-point exchange between subscribers of different HISPs, over the Internet, without a central hub. encryption identity validation 8 MacMail Web portal

Connecticut Ave NW, Washington, DC HISP definition In order for there to be Direct services, there must be a Health Information Service Provider, HISP. A HISP is an entity that conducts the secure transmission of Direct messages to and from Direct Addresses, each of which is bound to a Direct X.509 digital certificate (i.e. provides “Direct Services”). A HISP must act in the capacity of a Business Associate or Contractor for the Customer, in which case the HISP may hold and manage PKI private keys associated with Direct digital certificates on behalf of the Customer’s users/addressees. A HISP may be a part of a larger organization that offers and performs services that are beyond the boundary of the HISP’s roles and responsibilities. A HISP does NOT use, manage, analyze, or otherwise perform actions upon the information transmitted and made secure.

Connecticut Ave NW, Washington, DC encryption identity validation HISP-HISP between EHRs 10 EHR

Connecticut Ave NW, Washington, DC HISP-HISP exchange between EHR and PHR encryption identity validation 11 Web portal PHR

Connecticut Ave NW, Washington, DC Questions How does HISP A know that HISP B...X,Y,Z are trustworthy enough to exchange HISP’s subscribers’ Personal Health Information with them? What are the risks? How does HISP A establish a baseline of assurance regarding security and trust-in-identity with HISP B…X,Y,Z ? A baseline that will scale? What mechanisms are available for HISP A to signal its trustworthiness to others, efficiently and at scale? 12

Connecticut Ave NW, Washington, DC If HISPs choose to negotiate the “rules of the road” with each other one at a time, forging one-off contracts, the cost of Directed exchange goes up with each new HISP contract. Complex. Rate limiting. Will not scale. 13 Building a Network via Bi-directional Contracts is Unworkable

Connecticut Ave NW, Washington, DC Scalable Trust and the N-squared problem Scalable Trust is a strategy for enabling Directed exchange between a large number of endpoints, in this case HISPs and their users/subscribers. If “ scalable, ” – Trust should happen “ quickly ” and uniformly. – A “ complete ” network will be formed voluntarily. – Complexity and cost of establishing a network will decrease, while the value of the network itself will increase, as more nodes are added. – This “ network effect ” will be a by-product of making trust scalable. – Eliminates the need for one-off manual business agreements and technical connection.s If not “scalable,” – Parties will be forced to create one-off manual business agreements and technical connections increasing cost and complexity. – Manual exchange and maintenance of trust anchors doesn’t scale beyond the smallest of numbers – N-squared problem.

Connecticut Ave NW, Washington, DC DirectTrust Approach The goal is to make it easy and inexpensive for trusted agents, e.g. HISPs, to voluntarily know of and follow the “ rules of the Road, ” while also easily and inexpensively knowing who else is following them. Security & Trust Framework EHNAC- DirectTrust Accreditation Program Trusted Anchor Bundle Distribution

Connecticut Ave NW, Washington, DC Trusted agents: key roles and responsibilities for HISPs, CAs, RAs HISP Certificate Authority Registration Authority Healthcare Organizations/Providers/ Patients/Consumers Provides identity proofing and verification relying on trusted documents at known levels of assurance, LoA. Securely passes that information to Certificate Authority. Updates identity Information as required. Adheres to policies for identity verification in DirectTrust Certificate Policy, based upon NIST , FICAM, FBCA CP. Issues Direct X.509 digital certificate to unique Direct address, relying on RA’s policies and practices, and at the corresponding LoA(s). Manages certificates, e.g. revocation services, certificate validation services. Adheres to DirectTrust Certificate Policy. Provides accounts and addresses to Direct users, performs STA functions of encryption, signing of messages, DNS discovery, etc. Relies on CA, RA policies and practices. Adheres to DirectTrust HISP Policy. Trusted Agents Relying Parties

Connecticut Ave NW, Washington, DC Example of the DirectTrust Community’s “Scalable” Trust KEY Trust relationship based on accreditation HISP BHISP A Provider/EHR A Community A Provider/HIE B Community B Centralized Trust Anchor Bundle Site HISP C Provider/PHR C Community C

Connecticut Ave NW, Washington, DC DirectTrust Approach Avoid this: With this:

Connecticut Ave NW, Washington, DC Resources and additional information DirectTrust website Information on Membership Information on Workgroups and Active Projects DirectTrust Membership List Accreditation Status List Code of Ethics DirectTrust Community X.509 Digital Certificate Policy Federation Agreement Direct Trusted Agent Accreditation Program (DTAAP) Trust Anchor Bundle Website