RESTful Health Exchange (RHEx) Overview To NwHIN Power Team July 26, 2012 wiki.siframework.org/RHEx DRAFT—for discussion purposes only.

Slides:



Advertisements
Similar presentations
Meeting Etiquette Please announce your name each time prior to making comments or suggestions during the call Remember: If you are not speaking keep your.
Advertisements

wiki.siframework.org/RHEx
Advanced Health Models and Meaningful Use Workgroup: Roadmap Charge Overview Paul Tang, chair Joe Kimura, co-chair.
Electronic Submission of Medical Documentation (esMD) Face to Face Informational Session esMD Requirements, Priorities and Potential Workgroups – 2:00pm.
<<Date>><<SDLC Phase>>
Building the Digital Infrastructure for Vermont’s Learning Health System ONC HIT Policy Committee Testimony September 14, 2011 Hunt Blair, Deputy Commissioner.
Meeting Etiquette Please announce your name each time prior to making comments or suggestions during the call Remember: If you are not speaking keep your.
Meeting Etiquette Please announce your name each time prior to making comments or suggestions during the call Remember: If you are not speaking keep your.
Federal Student Aid Technical Architecture Initiatives Sandy England
1 Consolidated Health Informatics “CHI” HIPAA Summit March 9, 2004.
S&I Data Provenance Initiative Presentation to the HITSC on Data Provenance September 10, 2014.
TATRC and MITRE to NwHIN Power Team 12 June 2013 RESTful Health Exchange (RHEx)
Health IT RESTful Application Programming Interface (API) Security Considerations Transport & Security Standards Workgroup March 18, 2015.
Electronic Submission of Medical Documentation (esMD) Face to Face Informational Session Charter Discussion – 9:30am – 10:00am October 18, 2011.
A Robust Health Data Infrastructure P. Jon White, MD Director, Health IT Agency for Healthcare Research and Quality
Riki Merrick, APHL Anna Orlova, PhD, PHDSC Lise Stevens, FDA Nikolay Lipskiy, MD, DrPH, MBA – CDC CSTE Conference June 5 th, 2012 The findings and conclusions.
HIT Policy Committee Accountable Care Workgroup – Kickoff Meeting May 17, :00 – 2:00 PM Eastern.
OAuth option for mHealth Brief Profile Proposal for 2013/14 presented to the IT Infrastructure Planning Committee R Horn (Agfa Healthcare)
RESTful Health Exchange (RHEx) Overview To NwHIN Power Team July 26, 2012 wiki.siframework.org/RHEx Approved for Public Release: Distribution.
Collaborative Direct-- Status Update December 6, 2013 Don Jorgenson Inpriva, Inc.
HIT Standards Committee NwHIN Power Team Preliminary Recommendations for Standards Evaluation Criteria Dixie Baker, Chair July 19, 2012.
HIT Standards Committee HIT Standards Committee Privacy and Security Workgroup Discussion of NwHIN Power Team Recommendations August 6,
0 Presentation to: Health IT HIPPA Workshop Presented by: Stacey Harris, Director of Health IT Innovation September 26, 2014 Division of Health Information.
Interoperability Updates -National Interoperability Roadmap 8/20/2014 Erica Galvez, ONC Interoperability Portfolio Manager.
U.S. Department of Agriculture eGovernment Program August 14, 2003 eAuthentication Agency Application Pre-Design Meeting eGovernment Program.
July 26, 2012 NwHIN Power Team Specification Evaluation Criteria and Classification Process.
The Internet Identity Layer OpenID Connect Update for HIT Standards Committee’s Privacy and Security Workgroup Wednesday, March 12th from 10:00-2:45 PM.
EHR System (EHR-S) Functional Requirements Implementation Guide: Laboratory Results Interface (LRI) Kickoff March 3 rd,
OpenPASS Open Privacy, Access and Security Services “Quis custodiet ipsos custodes?”
Data Gathering HITPC Workplan HITPC Request for Comments HITSC Committee Recommendations gathered by ONC HITSC Workgroup Chairs ONC Meaningful Use Stage.
MD Digital Government Summit, June 26, Maryland Project Management Oversight & System Development Life Cycle (SDLC) Robert Krauss MD Digital Government.
Advanced Next gEneration Mobile Open NEtwork Tridentcom th International Conference on Testbeds and Research Infrastructures for the Development.
Planning the Future of CDC Secure Public Health Transactions and Public Health Information Network Messaging System (PHINMS) Jennifer McGehee, Tim Morris,
Interoperability Framework Overview Health Information Technology (HIT) Standards Committee June 24, 2010 Presented by: Douglas Fridsma, MD, PhD Acting.
HIT Policy Committee NHIN Workgroup Recommendations Phase 2 David Lansky, Chair Pacific Business Group on Health Danny Weitzner, Co-Chair Department of.
1 Geospatial and Business Intelligence Jean-Sébastien Turcotte Executive VP San Francisco - April 2007 Streamlining web mapping applications.
HIT Policy Committee Information Exchange Workgroup NwHIN Conditions for Trusted Exchange Request For Information (RFI) May 18,
9 Systems Analysis and Design in a Changing World, Fourth Edition.
NA-MIC National Alliance for Medical Image Computing UCSD: Engineering Core 2 Portal and Grid Infrastructure.
2016 Interoperability Standards Advisory Draft for comment Steve Posnack Director Office of Standards and Technology, ONC 1.
Health eDecisions Use Case 2: CDS Guidance Service Strawman of Core Concepts Use Case 2 1.
Clinical Collaboration Platform Overview ST Electronics (Training & Simulation Systems) 8 September 2009 Research Enablers  Consulting  Open Standards.
Meeting Etiquette Please announce your name each time prior to making comments or suggestions during the call Remember: If you are not speaking keep your.
Access Management 2.0: UMA for the #UMAam20 for questions 20 March 2014 tinyurl.com/umawg for slides, recording, and more 1.
Timothy Putprush Baltimore, MD September 30, 2009 Federal Emergency Management Agency (FEMA) Integrated Public Alert and Warning System Presentation to.
Health Information Exchange Roadmap: The Landscape and a Path Forward Primary and Behavioral Health Care Integration Program Grantee.
Mariann Yeager, NHIN Policy and Governance Lead (Contractor) Office of the National Coordinator for Health IT David Riley, CONNECT Lead (Contractor) Federal.
Draft Provider Directory Recommendations Begin Deliberations re Query for Patient Record NwHIN Power Team July 10, 2014.
Justin Richer The MITRE Corporation October 8, 2014 Overview of OAuth 2.0 and Blue Button + REST.
Electronic Submission of Medical Documentation (esMD)
Transforming Government Federal e-Authentication Initiative David Temoshok Director, Identity Policy and Management GSA Office of Governmentwide Policy.
Discussion - HITSC / HITPC Joint Meeting Transport & Security Standards Workgroup October 22, 2014.
U.S. Department of Agriculture eGovernment Program eDeployment Kickoff August 26, 2003.
Creating an Interoperable Learning Health System for a Healthy Nation Jon White, M.D. Acting Deputy National Coordinator Office of the National Coordinator.
NSDI Strategic Plan Update National Geospatial Advisory Committee Meeting December 11, 2013.
S&I FRAMEWORK PROPOSED INITIATIVE SUMMARIES Dr. Douglas Fridsma Office of Interoperability and Standards December 10, 2010.
Meeting Etiquette Please announce your name each time prior to making comments or suggestions during the call Remember: If you are not speaking keep your.
Integrating the Healthcare Enterprise The IHE Process: Developing Standards-based Solutions Kevin O’Donnell Co-chair, IHE Radiology Planning Committee.
Meeting Etiquette Please announce your name each time prior to making comments or suggestions during the call Remember: If you are not speaking keep your.
1 SAIC XMSF Update XMSF Workshop & MOVES Open House 4-5 August 2003 Katherine L. Morse, Ph.D., David L. Drake, Ryan.
Secure Mobile Development with NetIQ Access Manager
HIT Standards Committee NwHIN Power Team Dixie Baker, Chair July 20,
Standards and Interoperability Framework esMD Primer of S&I Phases, Procedures, and Functions S&I F2F Thursday, April 12 th, :00 AM.
Education Portal Solutions for Higher Education Education portals create a common gateway to the data and services that the people throughout your university.
L’Oreal USA RSA Access Manager and Federated Identity Manager Kick-Off Meeting March 21 st, 2011.
IHE Eye Care Process and Timeline
Hyper-V Cloud Proof of Concept Kickoff Meeting <Customer Name>
HIMSS National Conference New Orleans Convention Center
, editor October 8, 2011 DRAFT-D
Presentation transcript:

RESTful Health Exchange (RHEx) Overview To NwHIN Power Team July 26, 2012 wiki.siframework.org/RHEx DRAFT—for discussion purposes only

Outline RESTful Health Exchange (RHEx) –Overview –Security and Privacy –Fiscal Year 2012 (FY12) Pilots –Project Outcomes –Security Approach Standards Profiles HITSC Standards Readiness Test Case Next Steps 2

RHEx Overview RESTful Health Exchange (RHEx) An open source, exploratory project to apply proven web technologies to demonstrate a simple, secure, and standards-based health information exchange –Sponsored by the Federal Health Architecture (FHA) program –A Fiscal Year 2012 project being demonstrated in 2 phases Phase 1: Security approach (April – July 2012) Phase 2: Content approach (July – September 2012) A Federal Partners’ response to an identified need –Addresses NwHIN Power Team recommendation to develop a specification for RESTful exchange of health data (28 Sept 2011) –Continues the tradition of Federal Partner investment in driving innovative solutions –Intended to inform a path forward on a RESTful health exchange 3 “ We can’t wait 5 years for transport standards. We can’t afford it.” Farzad Mostashari, HIT Standards Committee, September 28, 2011 Meeting “ We can’t wait 5 years for transport standards. We can’t afford it.” Farzad Mostashari, HIT Standards Committee, September 28, 2011 Meeting

RHEx Overview RHEx Approach Apply existing standards –Refine existing standards to fit into the Nationwide Health Information Network (NwHIN) portfolio –Start with http –Layer on proven, open standards for identity management as well as user and service authentication Use pilots to test that theory works in practice –Work to reduce ambiguity or oversights in the standards being refined by the project –Extend standards where best serves the health community Implement a conformance testing framework –Provide tools and documentation to test that an independent party’s implementation conforms to RHEx standards profiles 4

RHEx Overview Piloting RHEx in Two Phases in FY12 Phase 1: Security Approach (April - July 2012) –Focus on securing web interactions –Use web/mobile friendly methods of exchanging identity information and authorizing users via HTTPS –Seek community input on satisfactory and complete RESTful security Phase 2: Content Approach (July - September 2012) –Expand pilot to show full benefit of a RESTful interaction and incorporate the content layer –Seek community input on a structured approach to granular health data exchange 5

RHEx Security and Privacy Safeguarding Access to Health Information Secure communications over TLS/SSL (https) Use proven, open standards for identity and authentication –OpenID Connect for distributed identity management and user authentication –OAuth2 for service-to-service authentication Provide information needed for authorization determination –Extend standard profile to best serve the health domain e.g., add clinical role for use in enforcing access control –Privacy is enforced at the provider location at the time the information is requested –Authorization process is out of scope for RHEx FY12 pilots 6

RHEx FY12 Pilots Testing that Theory Works in Practice 7 Initial pilot: Phase 1 & Phase 2 –Goal: Demonstrate simple, secure RESTful exchange in two phases –Use Case: Consults/Referral Selected via discussions with Federal Partners –FHA Partner: Steve Steffensen and Ollie Gray, TATRC Telemedicine & Advanced Technology Research Group (TATRC), U.S. Army Medical Research & Materiel Command (MRMC) –Status: Phase 1 scheduled for completion 31 July Second pilot: Phase 2 –Goal: Investigate use of RESTful approach to populate Maine HIE (HealthInfoNet) Clinical Data Repository –Use Case: Integrate electronic health records for medically underserved areas –FHA Partner: Todd Rogow, HealthInfoNet –Status: Development on track for 31 August demonstration Investigating possible Blue Button related third pilot

RHEx Project Outcomes Anticipated FY12 Outcomes Community dialog around RESTful approaches –How to apply the architectural style widely used on the web today –Which proven open standards for identity management and authentication best serve the Health IT Community A set of products to inform a path forward –RESTful health data exchange implementation(s) Focusing on refining existing standards Using pilots to reduce ambiguity and oversights in these standards –Testable, draft profiles for relevant, existing standards –Independent conformance testing tool to validate against profiles 8 Input to inform a path forward on a world wide web and mobile friendly way to exchange health data

RHEx Security Approach Profiles Seeking Community Feedback 9 Draft profiles for OAuth 2 and OpenID Connect will be posted to RHEx wiki in July RHEx project seeks community feedback –Attend the RHEx WebExs Thursdays, 11 am – 12 pm EDT (until Sept. 20) Security Profile Review is scheduled for Aug. 9 Previous WebExs can be accessed here here For details, see S&I calendar or RHEx WikiS&I calendarRHEx Wiki –Join the RHEx Google Group conversationRHEx Google Group Also accessible through the RHEx wiki RHEx project will document feedback and incorporate comments, as appropriate wiki.siframework.org/RHEx

HITSC Standards Readiness Test Case Preliminary Standards Assessment Exercised HIT Standards Committee (HITSC) preliminary standards evaluation criteria –Version presented to HITSC by NwHIN Power Team on 19 July 2012 Performed very preliminary assessment of two RHEx security approach standards –OAuth2 –OpenID Connect Intended to provide feedback to Power Team on preliminary recommendations for standards evaluation criteria 10 Criteria test case only – Not a vetted assessment

Context: Evaluation of Readiness of Technical Specifications to Become National Standards Emerging Standards Pilots National Standards Adoptability Maturity Low Moderate High Maturity Criteria: Maturity of Specification Maturity of Underlying Technology Components Market Adoption Adoptability Criteria: Ease of Implementation and Deployment Ease of Operations Intellectual Property Source: Dixie Baker, Preliminary Recommendations for Standards Evaluations Criteria”, Briefing to HIT Standards Committee, July 19, 2012 Preliminary placement for criteria test case; Not all criteria able to be assessed 11

Standards Evaluation Criteria Preliminary Test Notes Not a vetted assessment –Cursory pass through evaluation criteria HTTP -- Underlying technology of OAuth2 and OpenId Connect –Highly mature, adoptable and scalable OAuth2 – IETF Draft –High to Moderate maturity and adoptability OpenID Connect – Implementers Draft –Moderate maturity and adoptability Preliminary Standards Evaluation Criteria Feedback –Quite comprehensive –Additional clarification on some criteria would be beneficial Questions around context and meaning of some criteria elements –Can provide feedback on specific criteria elements 12

Next Steps Continue to engage the community –Community feedback on OpenID Connect and OAuth 2 profiles –Google Group discussions –Bi-weekly WebEx meetings Continue pilot implementations Continue work on conformance test framework 13 Powering Secure, Web-Based Health Data Exchange

BACK-UP CHARTS 14

Tentative RHEx WebEx Schedule DateTopicSpeaker June 28Overview/Kick-OffMary Pulvermacher July 12Charter DiscussionRick Cagle July 26RHEx Security ApproachJustin Richer August 9Phase I Profile Discussion Rob Dingwell and Andy Gregorowicz August 23RHEx Content ApproachAnne Kling August 30Phase II Profile Discussion Andy Gregorowicz September 6RHEx Test FrameworkJason Matthews September 20Lessons Learned from RHEx Pilots Suzette Stoutenburg September 27Wrap-up and Next StepsMary Pulvermacher 15

Core Technical Principles Internet Scale Access Management –Standards such as OAuth and OpenID have demonstrated strong, scalable security at low cost Granular and Addressable Data –Breaking healthcare information into small pieces accessible by a URL enables secure, efficient access Linking –When data is addressable, it can be linked on the web, allowing humans and software to browse the web of links to view clinical contexts Leverage HTTP –The protocol that drives the web offers a more robust, flexible and scalable solution 16

Why use OpenID Connect and OAuth 2? OpenID Connect –Strong industry participation –Flexible trust model –Alternatives Browser ID, Shibboleth, CAS Low adoption, some are more SSO oriented OAuth 2 –Wide industry adoption –Works well with browser clients –Alternatives Two way TLS/SSL –Low adoption –Key distribution and protection problems WS-Security –Does not work well with browsers 17

OpenID Connect Family Tree OpenID 1.0 OpenID 2.0 OpenID Connect XRDS OAuth 1.0/a Hybrid WRAP OAuth 2 SAML JWT/JOSE SWD AB AX PAPE Facebook Connect WS* ID-WSF XRD OpenID Connect Family Tree 18

19 OAuth An open protocol to allow secure API authorization in a simple and standard method from desktop and web applications An Internet Engineering Task Force (IETF) standard

20 OpenID is an open web standard that allows users to be authenticated in a distributed manner –For example, this could allow a VA Provider to log into a DoD system using their VA username and password Provides authentication and identity –Extensible to include profiles and claims (e.g., the user clinical role) OpenID Connect –I dentity service built on top of OAuth2

Standards Evaluation Criteria Preliminary Test Maturity Criteria 21 CriteriaOAuth2OpenID Connect Maturity of the Specification Breadth of Support HM-H Stability M-HL Degree of interoperability among independent non-coordinated implementations ?M Adoption of Specification HM Maturity of Underlying Technology Components Breadth of Support HM Stability HM-H Degree of interoperability among independent non-coordinated implementations HM Adoption of Technology HM-H Platform Support HM-H Maturity of the technology within its life cycle H? Market Adoption Installed health care user base ?L Installed user base outside of health care HL Future projections and anticipated support M-H Investments in user training?? Preliminary assessment for criteria test case; Not all criteria able to be assessed

Standards Evaluation Criteria Preliminary Test Adoptability Criteria 22 CriteriaOAuth2OpenID Connect Ease of Implementation and Deployment Availability of off-the-shelf infrastructure to support implementation HL-H Deployment Complexity ?? Conformance Criteria and Tests LL Availability of Reference Implementations H? Complexity of Specification ?? Quality and Clarity of Specifications H M-H Specification Modularity ?? Separation of Concerns HH Ease of use of specification HH Degree to which specification uses familiar terms to describe “real-world” concepts HH Runtime Coupling HH Degree of Optionality ?? Ease of Operations Comparison of targeted scale of deployment to actual scale deployed ?? Number of operational issued identified in deployment ?? Degree of peer-coordination needed HH Operational scalability (i.e., operational impact of adding a single node) HH Fit to Purpose ?? Intellectual Property Openness HH Accessibility and Fees HH Licensing Policy HH Copyrights HH PatentsHH Preliminary assessment for criteria test case; Not all criteria able to be assessed