Mobile Health January 2018 HL7 New Orleans WGM

Slides:



Advertisements
Similar presentations
What is GARP®? GARP® is an Acronym for Generally Accepted Recordkeeping Principles ARMA understands that records must be.
Advertisements

ELTSS Alignment to Nationwide Interoperability Roadmap DRAFT: For Stakeholder Consideration in response to public comment.
Security Controls – What Works
1 © Health Level Seven International ®, Inc. All Rights Reserved. HL7 International and Health Level Seven International are registered trademarks.
Note: This is a preliminary discussion
Connecting Health and Care for the Nation: A Shared Nationwide Interoperability Roadmap – DRAFT Version 1.0 Joint FACA Meeting Chartese February 10, 2015.
August 12, Meaningful Use *** UDOH Informatics Brown Bag Robert T Rolfs, MD, MPH.
Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved. McGraw-Hill Chapter 5 Personal Health Records Electronic Health Records for Allied.
A Robust Health Data Infrastructure P. Jon White, MD Director, Health IT Agency for Healthcare Research and Quality
HIT Policy Committee Accountable Care Workgroup – Kickoff Meeting May 17, :00 – 2:00 PM Eastern.
FDASIA REGULATIONS SUBCOMMITTEE May 22, Agenda 4:00 p.m.Call to Order – MacKenzie Robertson Office of the National Coordinator for Health Information.
1 © Health Level Seven International ®, Inc. All Rights Reserved. HL7 International and Health Level Seven International are registered trademarks.
Authentication, Access Control, and Authorization (1 of 2) 0 NPRM Request (for 2017) ONC is requesting comment on two-factor authentication in reference.
Nationwide Health Information Network: Conditions for Trusted Exchange Request For Information (RFI) Steven Posnack, MHS, MS, CISSP Director, Federal Policy.
EHealth/mHealth Gisele Roesems Deputy Head of Unit Health and Well-Being DG CONNECT EUROPEAN COMMISSION 2 nd International Conference on Health Informatics.
Inter-agency workshop on cash and protection March Nairobi, Kenya E-learning: E-Transfers and operationalizing beneficiary data protection.
S&I Public Health * We will start the meeting 3 min after the hour October 7 th, 2014.
Chapter 2 Standards for Electronic Health Records McGraw-Hill/Irwin Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved.
Chapter 6 – Data Handling and EPR. Electronic Health Record Systems: Government Initiatives and Public/Private Partnerships EHR is systematic collection.
UN CEFACT Single Window Recommendation Simplifying International Trade Gordon Cragge Chair – International Trade Procedures Working Group (TBG 15 of UN.
Enabling Inclusion and Creating a New Future Proof Industry Prof. Jutta Treviranus Inclusive Design Research Centre (IDRC), OCAD University.
The Framework for Privacy Policies in the UK: Is telling people what information is gathered about them part of the framework? Does it need to be? Emma.
Robert Guerra Director, CryptoRights Foundation Implementing Privacy Implementing Privacy: Rules of the Game for Developers Mac-Crypto Conference on Macintosh.
Policies for Information Sharing April 10, 2006 Mark Frisse, MD, MBA, MSc Marcy Wilder, JD Janlori Goldman, JD Joseph Heyman, MD.
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
IoT Trust Framework leading to self regulation code of conduct and certification models Craig Spiezle Executive Director & President Online.
Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved. McGraw-Hill Chapter 5 Personal Health Records Electronic Health Records for Allied.
Discussion - HITSC / HITPC Joint Meeting Transport & Security Standards Workgroup October 22, 2014.
Creating an Interoperable Learning Health System for a Healthy Nation Jon White, M.D. Acting Deputy National Coordinator Office of the National Coordinator.
ELECTRONIC SERVICES & TOOLS Strategic Plan
API Task Force Josh Mandel, Co-Chair Meg Marshall, Co-Chair December 4, 2015.
Mobile Technology and Insurance Employee Benefit Programs By Scott Warner.
IT Audit for non-IT auditors Cornell Dover Assistant Auditor General 31 March 2013.
Health Tech Council: Health IT Supporting Engaged Patients Damon L. Davis Special Assistant to the National Coordinator, Consumer e-Health.
© 2016 Chapter 6 Data Management Health Information Management Technology: An Applied Approach.
Security and resilience for Smart Hospitals Key findings
Audit Trail LIS 4776 Advanced Health Informatics Week 14
Remarks by Dr Mawaki Chango Kara University DigiLexis Consulting
Update from the Faster Payments Task Force
Open Platforms for Innovation
Opening slide.
IHE Quality, Research and Public Health QRPH domain
Microsoft 365 Get help with regulatory compliance
Service Organization Control (SOC)
Mobile Health Overview
EHR System Function and Information Model (EHR-S FIM is based on EHR-S FM R2.0) CPS.3.9 Clinical Decision Support System Guidelines Updates aka S
Health Informatics
Saturday, January 27 & Sunday, January 28
Health Informatics
Electronic Health Information Systems
NextGen Access Control Platform
2017 Modified Stage 2 Meaningful Use Objectives Overview Massachusetts Medicaid EHR Incentive Program September 19 & 20, 2017 September 19,
Mobile Health October 2018 HL7 Baltimore, MD WGM
The HIPAA Privacy Rule and Research
Omnibus Care Plan (OCP) Care Coordination System
HL7 FHIR Connectathon Care Planning & Management Track
Informed Consent (SBER)
Data and Interoperability:
What Is VQIP? FDA required to establish a program to provide for the expedited review of food imported by voluntary participants. Eligibility is limited.
HIPAA Compliance Services CTG HealthCare Solutions, Inc.
Managing Privacy Risk in Your Commercial Practices
Privacy in Nationwide Health IT
Upcoming PIPEDA Changes
Modern benefits administration and HR software, supported by us.
Mobile Health (MH) Working Group – Projects Update
About the national data opt-out
National data opt-out - Preparing for implementation
Basic Data Provenance April 22, 2019
US Core Data for Interoperability (USCDI): Data Provenance IG
eHealth/mHealth Gisele Roesems
Presentation transcript:

Mobile Health January 2018 HL7 New Orleans WGM Consumer Mobile Health Application Functional Framework (cMHAFF) Overview and Update Mobile Health January 2018 HL7 New Orleans WGM

cMHAFF Scope and Goals Provide a framework for assessment of the common foundations of mobile health apps Product Information (disclosures/transparency) Security Privacy/consent/ authorization Risk assessment/analysis Data access privileges Data exchange/sharing Usability & Accessibility Assessment could include attestation, endorsement, testing, voluntary or regulatory-driven certification Out of scope: specific clinical content or functionality cMHAFF is scoped towards general-purpose standards and guidelines that span most mobile apps, such as privacy, security, data export, and transparency. Because of the huge range of potential functionality, cMHAFF does not attempt to provide specific guidance for functionality, such as data and capabilities for disease management, fitness, etc. Assessment methods are to be determined, but most likely private sector testing, endorsement, and certification, rather than regulation. 9/16/2018

Why cMHAFF? What’s the Need? Target Audience: mobile health app developers needing guidance on building apps Beneficiaries: consumers, providers, caregivers Consumers need protection, transparency and assurance regarding mobile apps. Some examples: What does the app do? What evidence supports it? What security protections exist behind that “cloud?” Can I comprehend, or even find, privacy policy and terms of use? Who can the app share data with? What does the app know about me (location, microphone, camera, contacts, etc.), and what can it do on my device? Can I access my app data like I can under HIPAA? What happens to my data if I delete an app? To refresh your memory on why this project exists, we believe there are unmet needs that exist in the marketplace, as health IT is increasingly moving to mobile delivery platforms, for consumers as well as clinicians. There is much attention at the Federal level as well, including ONC and FTC, on the need for better guidance for MH apps. While some of the results of cMHAFF may benefit clinicians as well, its scope of guidance is targeted towards developers who build mobile apps for consumers, while the benefiiciaries of apps following that guidance should be the consumers who use those apps. And, of course, if assessment programs arise such as voluntary certification or endorsements, cMHAFF can be a baseline for those. 9/16/2018

cMHAFF January Ballot Results Passed already! 48 Affirmative (30 needed to pass) 2 Negative (both already agreed to withdraw) 57 Abstain 79 specific comments 3 NEG 76 A-S, A-Q, or A-C All comments will be reviewed (11 dispositioned already)

cMHAFF Exemplar Use Cases 9/16/2018

EHR-Integrated Use Case “C” A diabetes management app allows a consumer to collect blood sugar readings through a Bluetooth-enabled glucometer. A healthcare provider offers the app to enable the patient’s blood sugar to be captured through devices, rather than relying on manual entry by the patient, and to electronically transmit the readings to the patient’s physician, rather than using paper or FAX. Activity data are collected through an activity tracker, and a consumer can open the app to record meals and snacks to enable estimates of caloric consumption. Collected data is automatically “pushed” to a third-party cloud-based platform. The patient is aware of the cloud, though not familiar in detail with how data are protected in transit or storage. When a consumer views information in the app, which shows daily glucometer readings and related information, this information is “pulled” in but does not persist on the smartphone when the app is closed. It is also possible for the consumer to directly enter blood sugar readings (e.g., if Bluetooth connection is not working). From the cloud platform, consumer information is “pushed” to a provider’s Electronic Health Record (EHR), where it is accepted as Patient Generated Health Data (PGHD), according to the preferences of the patient and the policies of the provider. From the EHR, a physician can define logic to assess blood sugar readings such that the consumer is alerted through the app when a measurement is out of range, or when a set number of high or low readings are noted within a prescribed period of time. 9/16/2018

cMHAFF Sections and App Life Cycle App Development and Support  Regulatory Considerations  Risk Assessment and Mitigation  Usability Assessment  Customer Support Consumer Use of App Product Information Launch app, establish account Authentication Authorization/ consent for data collection/ use Data exchange/ interop Data provenance/ authenticity Security for data at rest & in transit Pairing or syncing with user devices Notifications and Alerts Product Upgrades Audit App and Data Removal 9/16/2018

Disclosures Evidence Limitations Contents Informing Consumers Disclosures Evidence Limitations Contents 9/16/2018

Criteria Example: General Product Info No. Strength Requirement   GENERAL INFORMATION G1 SHALL The description of an app includes the main functionality, the intended use, the intended (target) audience, and potential use of the user’s personal data by the app. G2 Screen shots of the app accurately depict the screens of the current version of the product. G3 Product information is provided before the app is used by the consumer, to help consumers decide whether the app is suitable. G4 SHOULD The app description clearly states the human languages the app supports. G5 Provide information about accessibility characteristics in the app description and in contextual assistance sections of the app. G6 Provide information about the app publisher (persons/organizations) and provide mechanisms to communicate with the publishers G7 Provide disclosure about sources of funding and possible conflicts of interest for the app (e.g., app use could incent user to buy products or services from app publisher.

European Guidelines Assessed French mHealth Good Practice Guidelines German Mobile Health Assessment Criteria Andalusian App Recommendations U.K. PAS277 Quality Criteria Finland PHR Cert Criteria Other EU initiatives 9/16/2018

Related U.S. & Global Industry Efforts OWASP Mobile Top 10 Security Risks ONC ISA Task Force and PGHD Whitepaper Some of the many industry efforts being tracked, and publications being referenced, are referenced here. cMHAFF does not intend to reinvent the wheel, but rather to reference authoritative sources of requirements, use cases, standards, guidance, and best practices where they exist, such as: NIST threat catalog and many other publications HITRUST Alliance risk assessments and security frameworks OWASP Mobile Top 10 Security Risks and mitigations FTC’s interactive tool for mobile app developers (co-sponsored by FDA and Office of Civil Rights) SMART on FHIR ISA Task Force Consumer Use Cases ONC/Accenture White Paper on a Policy Framework for Patient-Generated Health Data (PGHD) FTC/FDA/OCR Mobile App Developer Guidance Tool on 9/16/2018

cMHAFF Invitation: Join us! It’s a major opportunity in an exploding space: get in on the ground floor! Action is under way around the world – people are ready! Passed January 2018 STU ballot: just needs to be finalized! Help HL7 collaborate well with the public and private sectors Stay connected via HL7 Mobile Health listserv We will reconciled all comments and then publish 9/16/2018

Project and Contact Info cMHAFF meetings are Thursdays at 3pm Eastern Web Meeting Info to be updated Phone 770-657-9270, passcode 465623 Project Lead: Nathan Botts Join us to publish and start using cMHAFF! 9/16/2018

Mobile Health Topics & Projects January WGM - MH Special Session Wednesday - Q3 Panel Discussion Interactive Perspective on Accreditation and Certification for MH Applications Consumer Mobile Health Application Functional Framework cMHAFF Weekly Meetings Thursdays 3 pm EST Mobile Framework for Healthcare Adoption of Short-Message Technologies mFHAST Weekly Meetings Thursdays 2 pm EST MH Interoperability Environmental Scan (Frameworks and API Comparisons) Pictorial Representation in Mobile Health (ISO/TC 215 Healthcare Informatics) Mobile Health Fridays Every Fridays 11 am EST