HITSP Security and Privacy Work Group

Slides:



Advertisements
Similar presentations
National HIT Agenda and HIE John W. Loonsk, M.D. Director of Interoperability and Standards Office of the National Coordinator Department of Health.
Advertisements

August 2006 Health Information Technology Standards Panel HITSP Technical Committee and Approval of its Interoperability Specifications Charles Parisot,
HISPC-Illinois II The Public-Private Partnership Moves Forward on Privacy and Security.
Joyce Sensmeier MS, RN, BC, CPHIMS, FHIMSS HIMSS Vice President Informatics August 25, 2006 Healthcare Information Technology Standards Panel (HITSP) Overview.
ELTSS Alignment to Nationwide Interoperability Roadmap DRAFT: For Stakeholder Consideration in response to public comment.
0 Chicago, IL March 6 th, 2007 Use Case Requirements, Design and Standards Selection HITSP Use Case Requirements, Design and Standards Selection Date:
HITSP – enabling healthcare interoperability 1 enabling healthcare interoperability 1 Standards Harmonization HITSP’s efforts to address HIT-related provisions.
Health Information Technology Standards Panel Ed Mikoski 19MAR09 TIA Healthcare ICT Section Teleconference.
Healthcare Information Technology Standards Panel 2006, 2007 and Beyond John D. Halamka MD Chair, HITSP.
HITSP – enabling healthcare interoperability 1 enabling healthcare interoperability 1 Standards Harmonization HITSP’s efforts to address HIT-related provisions.
American Health Information Community HITSP Accomplishments John D. Halamka MD Chair, HITSP November 12, 2008.
1 Joyce Sensmeier MS, RN, FHIMSS, HIMSS Glen Marshall, Siemens Healthcare Charles Parisot, GE Healthcare IHE's contribution to standards harmonization.
TM Overview of National HIT Standards a presentation to the Seminar Series on Integrated Surveillance Presented by Steven J Steindel, Ph.D. National Center.
Arlington, VA January 5, 2006 Evaluation of Standards Harmonization Process for HIT Project Overview HITSP 05 N 42 December 29, 2005.
Achieving Breakthroughs Towards Health Information Exchange 17 th Annual Summer Institute in Nursing Informatics July 20, 2007 Joyce Sensmeier MS, RN-BC,
Overview of the National Agenda for Health Information Technology Kelly Cronin Director, Office of Programs and Coordination Visit our website at:
© 2009 The MITRE Corporation. All rights Reserved. Healthcare Interoperability: Simplified Health Data Standard Andrew Gregorowicz Beth Halley Joy Keeler.
0 enabling healthcare interoperability Webinar Series Sponsored by the HITSP Education, Communications and Outreach Committee Standardizing How We Share.
0 Harmonization Process, Work Plan, and Schedule Chicago IL. March 5, 2007 HITSP Project 2007 Work Plan and Schedule Contract HHSP EC.
HITSP’s Scope  The Panel’s mission is to assist in the development of a Nationwide Health Information Network (NHIN) by addressing the standards-related.
0 HIMSS Interoperability Showcase Orlando, Florida | February 2008.
1 Charles Parisot, GE Healthcare IHE IT Infrastructure Planning Committee Co-chair IHE and US National Health IT Initiatives.
HITSP Technical Committee Orientation Joyce Sensmeier MS, RN-BC, CPHIMS, FHIMSS Vice President, Informatics, HIMSS.
Public Health Data Standards Consortium
A Quick Look at Health Information Technology Howard E. Clark DICOM Secretariat April 5, 2006.
Beyond the EMR – Exchanging Health Information Outside of Your Organization John W. Loonsk, MD, FACMI Office of the National Coordinator for Health Information.
September, 2005What IHE Delivers 1 Didi Davis, Director of IHE, HIMSS National Committee on Vital and Health Statistics (NCVHS) July 27, 2006 IHE Testimony.
T.I.G.E.R. National HIT Collaborative Certification Commission for Healthcare Information Technology (CCHIT) Tutorial June 2008.
0 Connectathon 2009 Registration Bob Yencha Webinar | August 28, 2008 enabling healthcare interoperability.
Public Health Data Standards Consortium
Healthcare Information Technology Standards Panel 2006, 2007 and Beyond John D. Halamka MD Chair, HITSP.
January 26, 2007 State Alliance for e-Health January 26, 2007 Robert M. Kolodner, MD Interim National Coordinator Office of the National Coordinator for.
0 An introduction to HITSP Last update: April 2008.
HIT Standards Committee Overview and Progress Report March 17, 2010.
Moving the National Health Information Technology Agenda Forward The Fourth Health Information Technology Summit March 28, 2007 Robert M. Kolodner, MD.
Healthcare Information Standards Panel 2007,2008, and Beyond John D. Halamka MD Chair, HITSP.
July 27, 2007 HITSP Project Medications Management Use Case Presentation to CCHIT Steve Wagner and Scott Robertson.
Office of the National Coordinator for Health Information Technology ONC Update for HITSP Board U.S. Department of Health and Human Services John W. Loonsk,
©2004 CSC Proprietary www.csc.com The Health IT Agenda This presentation discusses a NHIN Architecture Prototype project made.
Healthcare Information Technology Standards Panel General Introduction June 15, 2007.
HITSP Project Orientation Joyce Sensmeier MS, RN-BC, CPHIMS, FHIMSS Vice President, Informatics, HIMSS.
Illinois Health Network The 14th Global Grid Forum Chicago, Illinois June 27, 2005.
August 11, 2006 Washington DC HITSP Project Interoperability Specification Inspection Test Contract HHSP EC.
Arlington, VA March 2006 HITSP Standards Harmonization Technical Committees Update Report to the Healthcare Information Technology Standards Panel Document.
September, 2005What IHE Delivers 1 Joyce Sensmeier, MS, RN, BC, CPHIMS, FHIMSS Vice President, Informatics, HIMSS Charles Parisot, GE Healthcare IT infrastructure.
0 Evaluation of Standards Harmonization Process for HIT Arlington, VA September 6, 2006 Standards Harmonization Technical Committees Update Report to the.
United States Health Information Knowledgebase: An Online Metadata Registry J. Michael Fitzmaurice Agency for Healthcare Research and Quality ANSI HITSP.
Arlington, VA December 12, 2005 Standards Harmonization Use Case Committee Update Report to the Healthcare Information Technology Standards Panel – Use.
AHRQ’s US Health Information Knowledgebase Health Information Technology Standards Panel J. Michael Fitzmaurice, Ph.D. Agency for Healthcare Research and.
Randall (Randy) Snyder, PT, MBA Division Director January 27, 2016
HITSP Project Orientation
HITSP Technical Committee Orientation
Healthcare Information Technology Standards Panel
HITSP Project Medications Management Use Case Presentation to CCHIT
Current Framework and Fundamental Concepts
Public Health Laboratory Data (PH-Lab) Exchange Project: Overview
HITSP Project Orientation
Standards and the National HIT Agenda John W. Loonsk, MD
Arizona Health-e Connection Leadership from Governor Napolitano
HITSP Project 2007 Work Plan and Schedule Contract HHSP EC
John D. Halamka MD CIO, Harvard Medical School CIO, CareGroup
Lynn Egan, JD HIT Summit – HHS/ONC Initiatives
HITSP Standards Harmonization Technical Committees Update
American Health Information Management Association
Presented at: HIT Symposium at MIT Cambridge, MA July 18, 2006
Voluntary Private Sector Preparedness Certification Program
Privacy in Nationwide Health IT
Biosurveillance and the National Health IT Agenda
T.I.G.E.R. National Healthcare IT Agenda
ONC Update for HITSP Board
Presentation transcript:

HITSP Security and Privacy Work Group Requirements, Design and Standards Selection (RDSS) Town Hall Meeting Joyce Sensmeier MS, RN-BC, CPHIMS, FHIMSS Vice President, Informatics, HIMSS Johnathan Coleman, CISM, CISSP Principal, Security Risk Solutions, Inc. HITSP Security and Privacy Technical Committee Facilitator April 19, 2007

Agenda Relationship between HITSP, HISPC and CCHIT HITSP Charter and Goals Harmonization Process Current Status of HITSP Security and Privacy Activities HITSP Security and Privacy Constructs under Consideration Security and Privacy RDSS Document Review Contact Information

A public-private “Community” was then established to serve as the focal point for America’s health information concerns and drive opportunities for increasing interoperability Healthcare Information Technology Standards Panel (HITSP) Nationwide Health Information Network Architecture Projects (NHIN) The Health Information Security and Privacy Collaboration (HISPC) The Certification Commission for Healthcare Information Technology (CCHIT) American Health Information Community HITSP includes 348 different member organizations and is administered by a Board of Directors 24 SDOs (7%) 247 Non-SDOs (71%) 30 Govt. bodies (9%) 12 Consumer groups (3%) 36 Project Team and Undeclared (10%) The Community is a federally-chartered commission and will provide input and recommendations to HHS on how to make health records digital and interoperable, and assure that the privacy and security of those records are protected, in a smooth, market-led way.

The HITSP team is charged with completing eleven different tasks, with current efforts focused on the harmonization process Eleven Tasks are included in this contract: Comprehensive Work Plan Conduct a Project Start Up Meeting Deliver Recommended Use-Cases Participate in related meetings and activities, including the AHIC Meetings Develop a Gap Analysis Standards Selection, Evaluations and Testing Define a Harmonization Approach Develop Interoperability Specifications Develop and Evaluate a Business Plan for the self-sustaining processes Submit Monthly Reports – ongoing efforts Assist with communications – ongoing efforts The Community HHS Secretary Mike Leavitt, Chair HHS ONCHIT1 PO, Dr. John Loonsk HITSP Dr. John Halamka, Chair Member populated Technical Committees Project Management Team Executive in Charge, F. Schrotter, ANSI Program Manager, L. Jones GSI Deputy PM, J Corley, ATI Project Manager, Julie Pooley, Booz Allen Harmonization Process Definition Technical Manager Michelle Deane, ANSI Harmonization Process Delivery Technical Manager Joyce Sensmeier, HIMSS

HITSP formed Technical Committees to focus on AHIC breakthrough areas - Initial focus is on 3 use cases Biosurveillance -- Transmit essential ambulatory care and emergency department visit, utilization, and lab result data from electronically enabled health care delivery and public health systems in standardized and anonymized format to authorized public health agencies with less than one day lag time. Consumer Empowerment -- Deploy to targeted populations a pre-populated, consumer-directed and secure electronic registration summary. Deploy a widely available pre-populated medication history linked to the registration summary. Electronic Health Records -- Deploy standardized, widely available, secure solutions for accessing laboratory results and interpretations in a patient-centric manner for clinical care by authorized parties. Security and Privacy – Initially a formed as a Work Group to address Security and Privacy (S & P) requirements of the first three Use Cases. Now a Technical Committee charged with addressing S & P requirements for all Use Cases provided to HITSP.

HITSP Coordinating Committees and Leadership HITSP Technical Committees and Leadership HITSP Technical Committee - Care Delivery James Ferguson, Kaiser Permanente Steve Hufnagel, DoD Steve Wagner, Department of Veterans Affairs HITSP Technical Committee - Consumer Empowerment Elaine Blechman, PhD, University of Colorado, Boulder Charles Parisot, GE Healthcare Scott Robertson, Kaiser Permanente HITSP Technical Committee- Population Health Floyd Eisenberg, MD, MPH, Siemens Medical Solutions Peter Elkin, MD, Mayo Clinic College of Medicine Shaun Grannis, Department of Family Medicine, Indiana University School of Medicine HITSP Technical Committee- Security and Privacy Cochair nominations in progress Foundations Committee Steve Wagner Bob Dolin HITSP Process Review Committee Lynne Gilbertson Erik Pupo HITSP-CCHIT Joint Work Group Jamie Ferguson, Kaiser Permanente Harmonization Readiness Committee Business Plan Committee Steve Lieber International Landscape Committee Bill Braithwaite Governance Committee Michael Aisenberg

Harmonization Process Steps The actual harmonization process is a series of steps taken by industry stakeholders within the context of HITSP Harmonization Process Steps Receive Request I Harmonization Request II Requirements Analysis III Identification of Candidate Standards IV Gaps, Duplications and Overlaps Resolution V Standards Selection VI Construction of Interoperability Specification VII Inspection Test VIII Interoperability Specification Release and Dissemination IX Program Management Begin Support

Current Status of HITSP Security and Privacy Activities Review Use Cases and identify Security and Privacy Requirements. This will serve to populate the Requirements sections of the Requirements, Design and Standards Selection (RDSS) document. Completed Identify candidate standards (from our Inventory of Standards and other sources), and sort them into buckets which correspond to the security and privacy requirements (potential HITSP constructs). Completed Develop Requirements, Design, Standards Selection (RDSS) document Completed Technical Actors, Business Actors & mappings from use cases UML diagrams (initially a high level relationship roadmap) Identify Security and Privacy Requirements and map to use cases Public Comment Period: 05/16 – 06/14 Apply Tier 2 criteria to select from the existing standards for each of our potential constructs. Current Activity Develop HITSP Security and Privacy Constructs which will frame implementation of the selected standards to achieve the requirements as identified in the Use Cases.  Current Activity Inspection Test and Public Comment: 07/20 – 08/16 Comment Resolution and Panel Approval: 08/17 – 10/15

HITSP Security and Privacy Constructs under Consideration (Requirements and Key Capabilities from the Three Initial Use Cases) Secured Communication Channel (includes mutual node authentication, integrity and confidentiality of transmission contents) Collect and Communicate Security Audit Trail Privacy Consents Verify Privacy Consents Manage Entity Identity Credentials Document Integrity Authenticate User Manage and Control Data Access Non Repudiation Fail-Safe/Emergency access (now rolled into #4 and #8) Consistent Time

HITSP Security and Privacy Constructs under Consideration

Security and Privacy RDSS Document Review

Security and Privacy RDSS Document The RDSS document is located on the www.hitsp.org web site via the following link: http://publicaa.ansi.org/sites/apdl/Documents/Forms/AllItems.aspx?RootFolder=%2fsites%2fapdl%2fDocuments%2fStandards%20Activities%2fHealthcare%20Informatics%20Technology%20Standards%20Panel%2fRequirements%2c%20Design%20and%20Standards%20Selection%2fRDSS%2d51%20Security%20and%20Privacy HITSP members and public stakeholders are also encouraged to work with the Security and Privacy Work Group as they continue the process of standards selection and construct development. If your organization is a HITSP member and you are not currently signed up as a Security and Privacy Work Group member, but would like to participate in this process, please contact jkant@himss.org

For General Technical Committee related questions please contact: Joyce Sensmeier MS, RN-BC, CPHIMS, FHIMSS Vice President, Informatics HIMSS 230 East Ohio, Suite 500 Chicago, IL 60611-3269 Phone: 312-915-9281 email: jsensmeier@himss.org Or Jessica Kant Coordinator, Standards Harmonization Healthcare Information & Management Systems Society 230 E. Ohio St., Suite 500 Chicago, IL 60611 Phone: 312-915-9283 Fax: 312-915-9511 email: jkant@himss.org For HITSP Security and Privacy related questions please contact: Johnathan Coleman Principal, Security Risk Solutions, Inc. 690 Libbys Pt. Mt. Pleasant, SC 29464 Tel: 843-442-9104 email: jc@securityrisksolutions.com