NYS Office of Health Information Technology Transformation 1 HEAL 5 Kickoff Meeting Privacy and Security Workgroup Co-chairs: Tom Check – VNS of NY Lisa.

Slides:



Advertisements
Similar presentations
The Role of the IRB An Institutional Review Board (IRB) is a review committee established to help protect the rights and welfare of human research subjects.
Advertisements

Manatt manatt | phelps | phillips New York State Health Information Technology Summit Initiative Overview and Update Rachel Block, Project Director United.
Legal Work Group Developing a Uniform EHR/HIE Patient Consent Form.
HISPC-Illinois II The Public-Private Partnership Moves Forward on Privacy and Security.
ELTSS Alignment to Nationwide Interoperability Roadmap DRAFT: For Stakeholder Consideration in response to public comment.
HIPAA Basics Brian Fleetham Dickinson Wright PLLC.
Changes to HIPAA (as they pertain to records management) Health Information Technology for Economic Clinical Health Act (HITECH) – federal regulation included.
NCVHS: Privacy and Confidentiality Leslie P. Francis, Ph.D., J.D. Distinguished Professor of Law and Philosophy Alfred C. Emery Professor of Law University.
Health IT Privacy and Security Policy Jodi Daniel, J.D., M.P.H. Director, Office of Policy and Research, Office of the National Coordinator for Health.
1 HIT Standards Committee Privacy and Security Workgroup: Recommendations Dixie Baker, SAIC Steven Findlay, Consumers Union August 20, 2009.
Legal Agreements and Policy Work Group Co-facilitators: Linda Attarian and Jill Moore Dial: Enter room#: * * (don’t forget the asterisks.
IS 700.a NIMS An Introduction. The NIMS Mandate HSPD-5 requires all Federal departments and agencies to: Adopt and use NIMS in incident management programs.
Consumer Engagement in Heath IT in NY Katie O’Neill Legal Action Center Lygeia Ricciardi Clear Voice Consulting, LLC.
FSMA: Where We’ve Been and Where We’re Going Supplemental Notices of Proposed Rulemaking Public Meeting November 13, 2014 Roberta F. Wagner, B.S., M.S.
Minnesota Law and Health Information Exchange Oversight Activities James I. Golden, PhD State Government Health IT Coordinator Director, Health Policy.
Building Public Health / Clinical Health Information Exchanges: The Minnesota Experience Marty LaVenture, MPH, PhD Director, Center for Health Informatics.
Taking Steps to Protect Privacy A presentation to Hamilton-area Physiotherapy Managers by Bob Spence Communications Co-ordinator Office of the Ontario.
Internal Auditing and Outsourcing
HIT Policy Committee Accountable Care Workgroup – Kickoff Meeting May 17, :00 – 2:00 PM Eastern.
Tackling the Policy Challenges of Health Information Exchange Carol Diamond, MD, MPH Managing Director, Markle Foundation.
HIE Implementation in Michigan for Improved Health As approved by the Michigan Health Information Technology Commission on March 4, 2009.
New York Health Information Security and Privacy Collaboration (NY HISPC) AHRQ Annual Meeting September 27, 2007 Ellen Flink Project Director NYS DOH.
Staff Structure Support HCCA Special Interest Group New Regulations: A Strategy for Implementation Sharon Schmid Vice President, Compliance and.
HIPAA PRIVACY AND SECURITY AWARENESS.
BITS Proprietary and Confidential © BITS Security and Technology Risks: Risk Mitigation Activities of US Financial Institutions John Carlson Senior.
HIT Policy Committee Nationwide Health Information Network Governance Workgroup Recommendations Accepted by the HITPC on 12/13/10 Nationwide Health Information.
IAEA International Atomic Energy Agency Reviewing Management System and the Interface with Nuclear Security (IRRS Modules 4 and 12) BASIC IRRS TRAINING.
Update on Federal HIT Legislation Kirsten Beronio Mental Health America.
2008 New York - Member Forum Council for Responsible Jewellery Practices, Ltd. Overview of CRJP.
Risk Management, Assessment and Planning Committee III-4.
Local Public Health System Assessment using the NPHPSP Local Instrument Essential Service 6 Enforce Laws and Regulations that Protect Health and Ensure.
Nationwide Health Information Network: Conditions for Trusted Exchange Request For Information (RFI) Steven Posnack, MHS, MS, CISSP Director, Federal Policy.
1 Manatt Health Solutions NYS Office of Health Information Technology Transformation Academy Health State Health Research and Policy Interest Group 2008.
State Alliance for e-Health Conference Meeting January 26, 2007.
HIT Standards Committee Privacy and Security Workgroup: Initial Reactions Dixie Baker, SAIC Steven Findlay, Consumers Union June 23, 2009.
General Principles for the Procurement of Goods and Services Asst. Prof. Muhammad Abu Sadah.
April 14, A Watershed Date in HIPAA Privacy Compliance: Where Should You Be in HIPAA Security Compliance and How to Get There… John Parmigiani National.
State HIE Program Chris Muir Program Manager for Western/Mid-western States.
HIT Policy Committee NHIN Workgroup Recommendations Phase 2 David Lansky, Chair Pacific Business Group on Health Danny Weitzner, Co-Chair Department of.
HIT Policy Committee Privacy & Security Workgroup Update Deven McGraw Center for Democracy & Technology Rachel Block Office of Health Information Technology.
HIT Policy Committee Information Exchange Workgroup NwHIN Conditions for Trusted Exchange Request For Information (RFI) May 18,
North Carolina Health Information Exchange Governance Workgroup Date: May 12, 2011 Time: 9:00 am – 11:00 am Location: NC Institute of Medicine 630 Davis.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
Policies for Information Sharing April 10, 2006 Mark Frisse, MD, MBA, MSc Marcy Wilder, JD Janlori Goldman, JD Joseph Heyman, MD.
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
Data Governance 101. Agenda  Purpose  Presentation (Elijah J. Bell) Data Governance Data Policy Security Privacy Contracts  FERPA—The Law  Q & A.
Kevin W. Ryan JD, MA Associate Director – ACHI Assistant Professor – UAMS COPH Rural TeleCon ’06 10th Annual Conference of the Rural Telecommunications.
Health Delivery Services May 29, Eastern Massachusetts Healthcare Initiative Policy Work Group Session 2 May 29, 2009.
PRESENTED AT THE STAKEHOLDERS FORUM ON QUALITY OF SERVICE AND CONSUMER EXPERIENCE LAICO REGENCY HOTEL Creating Space for Consumer Rights in.
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
National Public Health Performance Standards Local Assessment Instrument Essential Service:6 Enforce Laws and Regulations that Protect Health and Ensure.
The Patient Choice Project Project Kickoff December 14 th, 2015.
Nevada State Innovation Model (SIM) Delivery System and Payment Alignment May 6,
Moving the National Health Information Technology Agenda Forward The Fourth Health Information Technology Summit March 28, 2007 Robert M. Kolodner, MD.
Overview of ONC Report to Congress on Health Information Blocking Presented to the Health IT Policy Committee, Task Force on Clinical, Technical, Organizational,
HIT Policy Committee Meeting Nationwide Health Information Network Governance June 25, 2010 Mary Jo Deering, PhD ONC, Office of Policy and Planning NHIN.
Connecting for Health Common Framework: the Model Contract for Health Information Exchange Gerry Hinkley com July 18, 2006 Davis Wright.
HIMSS – Chicago – April, 2009 New Jersey - Health Information Technology – NJ HIT Act – Office for Health Information Technology Development - Recovery.
Wait Time Project Implementation Strategy. Implementation Plan: Goals 1.To educate and provide clarification around the wait time project, wait time definitions,
© 2014 By Katherine Downing, MA, RHIA, CHPS, PMP.
Organization and Implementation of a National Regulatory Program for the Control of Radiation Sources Program Performance Criteria.
1 CDC Health Information Exchange (HIE) Accelerating State-wide Public Health Situational Awareness in New York Through Health Information Exchanges August.
COBIT. The Control Objectives for Information and related Technology (COBIT) A set of best practices (framework) for information technology (IT) management.
State Steering Committee
Update from the Faster Payments Task Force
Health Information Security and Privacy Collaborative (HISPC) Overview
Paul T. Smith, Esq. Partner, Davis Wright Tremaine LLP
Enforcement and Policy Challenges in Health Information Privacy
THE 13TH NATIONAL HIPAA SUMMIT HEALTH INFORMATION PRIVACY & SECURITY IN SHARED HEALTH RECORD SYSTEMS SEPTEMBER 26, 2006 Paul T. Smith, Esq. Partner,
Privacy in Nationwide Health IT
Presentation transcript:

NYS Office of Health Information Technology Transformation 1 HEAL 5 Kickoff Meeting Privacy and Security Workgroup Co-chairs: Tom Check – VNS of NY Lisa Santelli – Excellus Ellen Flink – DOH Staff: Bill Bernstein – Manatt, Phelps & Phillips Katie O’Neill – Legal Action Center

NYS Office of Health Information Technology Transformation 2 Privacy and Security Workgroup Agenda for Today’s Breakout Session Introductions Objectives and process for this session Q & A from morning session Overview of Privacy and Security Workgroup and Subgroups Discuss scope of work, consensus on priorities, charter, timelines, and organization and decision process

NYS Office of Health Information Technology Transformation 3 Privacy and Security Workgroup Overview

NYS Office of Health Information Technology Transformation 4 Workgroup Overview This workgroup will be initially comprised of 3 subgroups to develop the suite of privacy and security policies, including: –Consumer consent and operational and environmental processes to support these policies –Authorization, Authentication, Access controls, and Audits (the 4As) –Contractual and regulatory framework to enforce these policies

NYS Office of Health Information Technology Transformation 5 Workgroup Overview (cont.) RHIOs have responsibility for ensuring privacy and security of information collected and exchanged via the Statewide Health Information Network for New York (SHIN-NY) –Authorization for access –Authentication of identity –Access controls –Audit trails for clinicians and consumers –Consumer and provider identification –Transmission security –Data integrity –Administrative and physical security –Enforcement and protections

NYS Office of Health Information Technology Transformation 6 Workgroup Purpose and Scope Overview Purpose and Scope Protecting privacy, strengthening security, ensuring affirmative and informed consent and supporting the right of New Yorkers to have greater control over and access to their personal health information are foundational requirements for interoperable HIE Statewide collaboration process requires: Develop -- develop policies to enable HIE Operate -- determine operational and environmental processes to support the policies efficiently and accurately Specify -- specify business requirements and solutions to support policies Enforce -- develop contractual and regulatory framework to enforce policies Contractual framework to enforce policies, including: state- level participation agreements and vendor subcontractor requirements Regulatory framework to enforce policies while allowing market innovation, e.g, RHIO accreditation as governance entities

NYS Office of Health Information Technology Transformation 7 Key Principles of Consent Policies and Procedures Policies and procedures for consent will: Promote patient-centered care by facilitating consumer choice and addressing consumer concerns about privacy Promote exchange of comprehensive information ensuring clinical effectiveness to improve the quality and efficiency of care Minimize burdens on healthcare providers Be practical and “implementable” for RHIO participants providing operational flexibility Be simple and clear with a concrete rationale Foster innovation while ensuring public trust Be neutral on technology model

NYS Office of Health Information Technology Transformation 8 Principles for Affirmative and Informed Consent Any New Yorker has the right not to participate in interoperable HIE enabled by the RHIO If a patient grants consent to participate, they have a right to allow or prohibit access to their PHI by provider organizations of their choice The patient consent allows provider organization to access PHI for permitted uses: treatment, quality improvement and disease management The patient consent allows health plans, employers and other third parties to access PHI for permitted uses: quality improvement and disease management Provider organization can then access all PHI, including sensitive information from all providers participating in interoperable HIE Patient is informed about all participating providers in the RHIO and how updates to the participant list can be obtained Patient gives consent at the provider organization level and allows access to patient’s PHI by all authorized individuals in the organization to the extent needed Permitted uses are limited to treatment, quality improvement and disease management

NYS Office of Health Information Technology Transformation 9 Analytic Framework RHIO – Core Components Nature of participants Purpose of exchange/Mission Type of information exchanged How information is exchanged Multi-stakeholder & All Consumers Improve quality, safety, efficiency of care Clinical data Protocols, standards and services via SHIN-NY Scope of services Privacy, security, authentication, authorization, access, and auditing policies Governance Transparent policy framework, inclusive decision making process Consumer Access Provisions for ensuring consumer access to and control of data

NYS Office of Health Information Technology Transformation 10 Consumer Consent Implementation and Harmonization Subgroup

NYS Office of Health Information Technology Transformation 11 Consumer Consent Implementation and Harmonization Subgroup Advance health information exchange via the SHIN-NY through the development and implementation of a standardized, clear and consistent consent process for RHIOs in NYS Address outstanding issues including previous recommendations –One to one exchange –Break the glass –Provider Organizations –Minors –Workflow issues –Independent physician practices –Care management –Federally qualified alcohol and substance abuse facilities –Use of de-identified data exchanged through RHIOs

NYS Office of Health Information Technology Transformation 12 Consumer Consent Implementation and Harmonization Subgroup (cont.) Standardized consent form and educational materials –Ensure that consumer consent is informed and knowing Operations Guidance to RHIOs Implementing White Paper Provisions Give RHIOs standing to address patient consent on behalf of physicians, providers and New Yorkers

NYS Office of Health Information Technology Transformation 13 Deliverables and Timeline Updated White Paper Recommendations on outstanding issues Recommendations on a standardized consent form Finalize as part of full suite of privacy and security policies Timetable – Oct. 2008

NYS Office of Health Information Technology Transformation 14 Authorization, Authentication, Access Controls and Auditing (4As) Subgroup

NYS Office of Health Information Technology Transformation 15 Authentication, Authorization, Access Controls and Auditing (4As) Subgroup Determine statewide 4As policy with which all RHIOs need to comply from a policy perspective and require HSPs from a technical perspective via CHxP protocol –Catalogue and assess existing practices –Establish statewide 4A policies –Determine operational and environmental processes to support 4A policies –Specify business and work with Protocol and Services work group on technical requirements and solutions to support 4A policies –Enforce 4A policies through contractual and regulatory framework Common language for participation agreements and vendor subcontracts

NYS Office of Health Information Technology Transformation 16 Deliverable and Timeline Develop common statewide policy and procedure guidelines for 4As in conjunction with consent recommendations Support Protocols and Services work group on technical requirements Timetable - Oct. 2008

NYS Office of Health Information Technology Transformation 17 Contractual and Regulatory Solutions Subgroup

NYS Office of Health Information Technology Transformation 18 Contractual and Regulatory Solutions Subgroup Proposed policies enforced through HEAL 5 contracts Development of regulatory framework as long term solutions Consider mechanisms for accountability and enforcement: –Promoting compliance –Penalizing breaches

NYS Office of Health Information Technology Transformation 19 Enforcement and Consumer Protections RHIOs need to have internal capabilities to audit disclosures and regularly monitor to protect against unauthorized access and use. These capabilities should be common statewide and finalized through the statewide collaboration process. RHIOs should designate staff who will oversee privacy and consent management functions. RHIOs should also provide ombudsman services to consumers to handle questions and facilitate referral for complaints. DOH needs to develop policies regarding RHIO and providers’ roles and responsibilities in the event of an unauthorized disclosure, disposition of complaints, consumer notification and access to information about disclosures. The consent form and education process should include information about consumer rights with regard to unauthorized disclosure or use, including how to file complaints and what remedies are available.

NYS Office of Health Information Technology Transformation 20 Enforcement and Consumer Protections (cont.) Who assumes responsibility for unauthorized disclosure of data? Current responsibilities apply: Provider currently assumes responsibility for breaches of privacy occurring on its connection to the system; RHIO assumes responsibility for breaches committed in region via SHIN-NY node. Current notification policies apply: RHIO-level breach: RHIO commits that it will notify providers (and patients) when they discover breaches committed directly in region via SHIN-NY node rather than through a provider. Provider-level breach: Provider required to mitigate the effects of such breach and notify patient as per NYS and Federal law. Provider also commits to notify RHIO of breaches. Notification for breaches of data occurring through another RHIO: Breaches involving data from an outside RHIO are required to be reported immediately to the other RHIO. Suspicious activity involving data from an outside RHIO are also required to be reported to the outside RHIO.

NYS Office of Health Information Technology Transformation 21 Enforcement and Consumer Protections (cont.) Corrective action and sanctions: In the event of a breach involving data from an outside RHIO each RHIO commits it will follow existing intra-RHIO policies for corrective action and sanctioning of users and participants. A RHIO whose data is breached through use of another RHIO’s tools is permitted access in a timely manner to the results of any investigation around that breach and the plans for corrective action. If these terms are not met, a RHIO reserves right to withdraw from data use agreement.

NYS Office of Health Information Technology Transformation 22 NYSDOH is committing hundreds of millions to develop a health information infrastructure, including the statewide health information network of New York (SHIN-NY). Success of SHIN-NY depends upon RHIOs’ ability to: –Govern statewide HIE policies ensuring consistency and compliance, including privacy & security policies and other health information policies –Requiring HSP partners to comply with CHIxP protocols and other standards For RHIOs to become trusted stewards, stakeholders need assurance that RHIOs have the necessary characteristics and capabilities to perform required services. Why a Broad Regulatory Framework is Necessary

NYS Office of Health Information Technology Transformation 23 Deliverables and Timeline Recommendations on regulatory and statutory framework and mechanism for accountability with statewide policies, including privacy and security policies –What can be enforced through accreditation –What can be enforced through regulation or legislation Timetable – Oct. 2008

NYS Office of Health Information Technology Transformation 24 Workgroup Charter

NYS Office of Health Information Technology Transformation 25 Mission Mission: –Protect privacy, strengthen security, ensure affirmative and informed consent, and support the right of New Yorkers to have greater control over and access to their personal health information as foundational requirements for interoperable HIE –Support CHITAs as necessary

NYS Office of Health Information Technology Transformation 26 Functions, Responsibilities, Deliverables: Complete Assessment Of Implementation Issues Associated With Final Consent Policy Paper -> Deliverable = Implementation Assessment Framework Review And Provide Feedback On Proposed Consent Form And Any Other Materials Developed To Support Consent Process Implementation -> Deliverable = Policy Input Develop Detailed Implementation Guides For RHIOs To Comply With NYS Consent Policies -> Deliverable = Implementation Guides Develop Technical Assistance Resources Including Dissemination Of Best Practices -> Deliverables Include A Strategy Based On Priorities Set By Group And Vetted Through POC; Identification And Collection Of Best Practices (Documents, Tools) To Be Made Available Through Collaborative Repository Coordinate With Other Workgroups Involved In Development Of Standards And Materials To Ensure Consistency And Alignment Across Implementation Spectrum (Consumer Advocacy Coalition, Education And Communications Committee, Core Services And Protocols Workgroup, Possibly Ehr Collaborative) -> Deliverable = Reflect Comments From Other Groups In All Workgroup Products

NYS Office of Health Information Technology Transformation 27 Membership Criteria and Interest Leaders or staff from RHIO/CHITA projects who can commit their organizations to workgroup decisions People with legal, policy or regulatory experience and expertise on privacy and security issues, including those who have been part of the NY HISPC project phases 1 and 2 Representatives of groups who represent consumer or public interests Directors or staff of RHIO/CHITA projects involved with the implementation of these policies Clinicians and professionals experienced in workflow/practice design who can advise the workgroup on front-line experience with privacy and security policy decisions Diversity of sectors is encouraged and recommended

NYS Office of Health Information Technology Transformation 28 Consensus on Priorities and Timelines Subgroup Chairs Frequency of meetings/conference calls Deliverables Next steps