Update on Interoperability Roadmap Comments Sections G, F and E Transport & Security Standards Workgroup Dixie Baker, chair Lisa Gallagher, co-chair March.

Slides:



Advertisements
Similar presentations
1 HIT Standards Committee Privacy and Security Workgroup: Reformatted Standards Recommendations & Implementation Guidance Dixie Baker, SAIC Steven Findlay,
Advertisements

HIPAA Security Presentation to The American Hospital Association Dianne Faup Office of HIPAA Standards November 5, 2003.
Digital Identity Group May GIXEL  GIXEL is the professional association of electronic component and system industries in France. It brings together.
ELTSS Alignment to Nationwide Interoperability Roadmap DRAFT: For Stakeholder Consideration in response to public comment.
Interoperability Roadmap Comments Sections E, F, and G Transport & Security Standards Workgroup Dixie Baker, chair Lisa Gallagher, co-chair March 11, 2015.
NCVHS: Privacy and Confidentiality Leslie P. Francis, Ph.D., J.D. Distinguished Professor of Law and Philosophy Alfred C. Emery Professor of Law University.
1 Jan 2013 © Health Level Seven International ®, Inc. All Rights Reserved. HL7 International and Health Level Seven International are registered.
1 HIT Standards Committee Privacy and Security Workgroup: Recommendations Dixie Baker, SAIC Steven Findlay, Consumers Union August 20, 2009.
Interoperability Roadmap Comments Package Transport & Security Standards Workgroup Dixie Baker, chair Lisa Gallagher, co-chair February 24, 2015.
Framework Planning Draft 1 Jack Suess Ian Glazer Peter Alterman Andrew Hughes Michael Garcia.
Interoperability Roadmap Comments Package Transport and Security Standards Workgroup Dixie Baker, Chair Lisa Gallagher, Co-Chair April 22, 2015.
Update on Interoperability Roadmap Comments Sections E, F, and G Transport & Security Standards Workgroup Dixie Baker, chair Lisa Gallagher, co-chair March.
Interoperability and Health Information Exchange Workgroup March 10, 2015 Micky Tripathi, chair Chris Lehmann, co-chair.
HITSP – enabling healthcare interoperability 1 enabling healthcare interoperability 1 Standards Harmonization HITSP’s efforts to address HIT-related provisions.
Finalize RESTful Application Programming Interface (API) Security Recommendations Transport & Security Standards Workgroup January 28, 2014.
User Authentication Recommendations Transport & Security Standards Workgroup December 10, 2014.
Connecting Health and Care for the Nation: A Shared Nationwide Interoperability Roadmap – DRAFT Version 1.0 Joint FACA Meeting Chartese February 10, 2015.
Privacy and Security Workgroup: Big Data Public Hearing December 8, 2014 Deven McGraw, chair Stan Crosley, co-chair.
Consumer Work Group Presentation Federal Health IT Strategic Plan January 9, 2015 Gretchen Wyatt Office of Planning, Evaluation, and Analysis.
Interoperability Standards Advisory Summary of Public Comments and Next Steps June 24, 2015 Chris Muir.
Standards for Shared ICT Jeju, 13 – 16 May 2013 Gale Lightfoot Senior Staff Program Manager, Office of the CTO, SPB Cisco ATIS Cybersecurity Standards.
Minnesota Law and Health Information Exchange Oversight Activities James I. Golden, PhD State Government Health IT Coordinator Director, Health Policy.
Health IT RESTful Application Programming Interface (API) Security Considerations Transport & Security Standards Workgroup March 18, 2015.
Tackling the Policy Challenges of Health Information Exchange Carol Diamond, MD, MPH Managing Director, Markle Foundation.
Privacy and Security Tiger Team Meeting Discussion Materials Today’s Topic Recommendations on Trusted Identities for Providers in Cyberspace August 20,
HIT Standards Committee Hearing on Trusted Identity of Patients in Cyberspace November 29, 2012 Jointly sponsored by HITPC Privacy and Security Tiger Team.
BITS Proprietary and Confidential © BITS Security and Technology Risks: Risk Mitigation Activities of US Financial Institutions John Carlson Senior.
Privacy and Security Tiger Team Recommendations Adopted by The Health IT Policy Committee Relevant to Consumer Empowerment May 24, 2013.
HIT Policy Committee Nationwide Health Information Network Governance Workgroup Recommendations Accepted by the HITPC on 12/13/10 Nationwide Health Information.
Privacy and Security Tiger Team Today’s Discussion: MU3 RFC Comments May 8, 2013.
1 Healthcare Privacy and Security: Concepts and Challenges Dixie B. Baker, Ph.D. Chair, HIMSS Privacy and Security Advocacy Task Force.
Lecture Materials for the John Wiley & Sons book: Cyber Security: Managing Networks, Conducting Tests, and Investigating Intrusions October 7, 2015 DRAFT1.
HIT Standards Committee Privacy and Security Workgroup: Initial Reactions Dixie Baker, SAIC Steven Findlay, Consumers Union June 23, 2009.
Workgroup Discussion on RESTful Application Programming Interface (API) Security Transport & Security Standards Workgroup January 12, 2014.
Draft – discussion only Content Standards WG (Documents and Data) Proposed HITSC Workgroup Evolution 1 Architecture, Services & APIs WG Transport and Security.
HIT Policy Committee NHIN Workgroup Recommendations Phase 2 David Lansky, Chair Pacific Business Group on Health Danny Weitzner, Co-Chair Department of.
HIT Policy Committee Privacy & Security Workgroup Update Deven McGraw Center for Democracy & Technology Rachel Block Office of Health Information Technology.
The Paradox in HIPAA Deven McGraw, JD, MPH, LLM Partner Manatt, Phelps & Phillips, LLP December 8, 2014.
HIT Policy Committee Information Exchange Workgroup NwHIN Conditions for Trusted Exchange Request For Information (RFI) May 18,
Seeking a National Standard for Security: Developing a Systematic Crosswalk of the Final HIPAA Security Rule, the NIST SP , NIST SP Security.
HIT Policy Committee Report from HIT Standards Committee Privacy and Security Workgroup Dixie Baker, SAIC December 15, 2009.
NIST / URAC / WEDi Health Care Security Workgroup Presented by: Andrew Melczer, Ph.D. Illinois State Medical Society.
Privacy and Security Solutions For Interoperable Health Information Exchange Presented by Linda Dimitropoulos, PhD RTI International Presented at AHRQ.
HIT Standards Committee Overview and Progress Report March 17, 2010.
Health Big Data Discussion Privacy and Security Workgroup Deven McGraw, Chair Stanley Crosley, Co-chair June 8, 2015.
Scalable Trust Community Framework STCF (01/07/2013)
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
Discussion - HITSC / HITPC Joint Meeting Transport & Security Standards Workgroup October 22, 2014.
HIPAA Security John Parmigiani Director HIPAA Compliance Services CTG HealthCare Solutions, Inc.
Creating an Interoperable Learning Health System for a Healthy Nation Jon White, M.D. Acting Deputy National Coordinator Office of the National Coordinator.
Overview of ONC Report to Congress on Health Information Blocking Presented to the Health IT Policy Committee, Task Force on Clinical, Technical, Organizational,
HIT Standards Committee Privacy and Security Workgroup Standards and Certification Requirements for Certified EHR Modules Dixie Baker, Chair Walter Suarez,
CCSSO Task Force Recommendations on Educator Preparation Idaho State Department of Education December 14, 2013 Webinar.
Framing Identity Management Recommendations Transport & Security Standards Workgroup November 19, 2014.
API Task Force Josh Mandel, Co-Chair Meg Marshall, Co-Chair December 4, 2015.
HIT Standards Committee Privacy and Security Workgroup Task Update: Standards and Certification Criteria for Certifying EHR Modules Dixie Baker, Chair.
Workgroup Introduction & Trust Mark Briefing Transport & Security Standards Workgroup September 22, 2014.
Progress Report on the U.S. NSTIC Efforts Jack Suess – Delegate for Research, Development, Education & Innovation
HHS Security and Improvement Recommendations Insert Name CSIA 412 Final Project Final Project.
Program Overview and 2015 Outlook Finance & Administration Committee Meeting February 10, 2015 Sheri Le, Manager of Cybersecurity RTD.
COMMUNITY-WIDE HEALTH INFORMATION EXCHANGE: HIPAA PRIVACY AND SECURITY ISSUES Ninth National HIPAA Summit September 14, 2004 Prepared by: Robert Belfort,
The Federal E-Authentication Initiative David Temoshok Director, Identity Policy GSA Office of Governmentwide Policy February 12, 2004 The E-Authentication.
Hazardous Waste Import-Export Final Rule Requirements and Implementation December 12, 2016.
Higher Education’s Role in the Identity Ecosystem
Disability Services Agencies Briefing On HIPAA
Concerns of a Privacy Advocate – and How to Respond
Enforcement and Policy Challenges in Health Information Privacy
Revolutionize USACE Civil Works
HIPAA Compliance Services CTG HealthCare Solutions, Inc.
HIPAA Compliance Services CTG HealthCare Solutions, Inc.
Presentation transcript:

Update on Interoperability Roadmap Comments Sections G, F and E Transport & Security Standards Workgroup Dixie Baker, chair Lisa Gallagher, co-chair March 25, 2015

TSS WG: Dates & Tasks 2 Today

Workgroup Discussion for Section G and F 3

ONC Specific Charges – Section G 4 WorkgroupTransport and Security Standards Section G: Consent What standards should we put forward in the 2016 standards advisory for basic choice? How much work should ONC be doing on other standards while clarifying permitted uses? If standards development needs to be done, what should we be working on (DS4CDS vs DS4P vs something else)?

Roadmap Section G: Consent 1.What standards should we put forward in the 2016 standards advisory for basic choice? DRAFT Response (for discussion): TBD 5

Roadmap Section G: Consent 2.How much work should ONC be doing on other standards while clarifying permitted uses? 3.If standards development needs to be done, what should we be working on (DS4CDS vs DS4P vs something else)? DRAFT Response (for discussion): TBD 6

ONC Specific Charges – Section F 7 WorkgroupTransport and Security Standards Section F: Identity and Authentication What ID proofing and authentication standards, policies, and protocols can we borrow from other industries? Is healthcare that different from banking, social media, or ?

Roadmap Section F: Identity and Authentication 1.What ID proofing and authentication standards, policies, and protocols can we borrow from other industries? Is healthcare that different from banking, social media, or ? DRAFT Response (for discussion): First, ONC – together with OCR, other federal partners, and industry stakeholders – should consider following the National Strategy for Trusted Identities in Cyberspace (NSTIC) program closely and pull from existing pilots, where applicable. Second, ONC should consider providing guidance on the use of third-party identity proofing services. Third, ONC should work in conjunction with NIST regarding the pending changes in NIST version 2 Fourth, ONC should endorse the use of a trusted Internet identity that may already be used by many individuals for everyday aspects of life such as shopping, banking, etc. Although good cybersecurity best practices can be applied similarly across different industries, ONC should acknowledge that because of the type of data used in the healthcare industry, healthcare is notably different from banking, social media and . Credit cards can be replaced, and new accounts can be generated, but deeply personal genetic or treatment information cannot be discarded once it is revealed. Therefore, because some harms may be irreparable, health information deserves a higher level for standard of care safeguards. 8

ONC Specific Charges – Section E 9 WorkgroupTransport and Security Standards Section E: Secure Network Infrastructure 1)Cybersecurity: a)What should the federal government (specifically) focus on first to move towards a uniform approach to enforcing cybersecurity in healthcare (keeping HIPAA and CEHRT Rules in mind and possible new cybersecurity legislation)? b)Are there frameworks, methodologies, incentive programs, etc. that the healthcare industry has not, but should, consider? 2)Encryption: Are there other gaps (aside from lack of policies and guidance for implementing encryption)in technology and standards for encryption?

Roadmap Section E: Cybersecurity 1.a) What should the federal government (specifically) focus on first to move towards a uniform approach to enforcing cybersecurity in healthcare (keeping HIPAA and CEHRT Rules in mind and possible new cybersecurity legislation)? DRAFT Response (for discussion): The Transport and Security Standards Workgroup (TSS WG) recommends that ONC partner with NIST, OCR, other federal agencies, and industry stakeholders in several ways to address a uniform approach to enforcing cybersecurity in healthcare. First, ONC should work to advance a consistent trust framework across the health IT ecosystem. Second, ONC should endorse a set of appropriate baseline security controls that are uniformly applied to all health IT technologies that enter the ecosystem. Third, ONC should work with industry to accommodate a diversity of emerging health IT technologies across infrastructures within the health IT ecosystem. Health IT infrastructures must be flexible, in that they should permit any certified health IT solution to operate within the ecosystem. Fourth, ONC should provide guidance on proper governance in cybersecurity, which is essential for building trust and security throughout the ecosystem. Finally, the ONC should bring together federal, state, and industry stakeholders to address the goal of reducing variations in cybersecurity enforcement. 10

Roadmap Section E: Cybersecurity 1.b) Are there frameworks, methodologies, incentive programs, etc. that the healthcare industry has not, but should, consider? DRAFT Response (for discussion): ONC should consider the following in further establishing trust across the health IT ecosystem: First, ONC should consider including The National Strategy for Trusted Identities in Cyberspace (NSTIC) Trustmark, PCI, and ISO as possible frameworks for establishing electronic trust among healthcare organizations across the Internet. Second, cybersecurity needs to be considered for both enterprises and for interconnections among enterprises. Third, the healthcare industry needs a minimum set of standards and metrics for measuring the strength of security protections. A number of “minimum standard sets” exist and can be drawn from. These include, but may not be limited to: OCR’s minimum standards for control areas, the CAB-forum Baseline Requirements, and the questions asked by cybersecurity insurance companies and financial auditors. Fourth, the existing security control frameworks (including NIST’s cybersecurity framework*) should be considered for alignment and guidance when gaps occur. 11 *

Roadmap Section E: Encryption 2)Are there other gaps (aside from lack of policies and guidance for implementing encryption) in technology and standards for encryption? DRAFT Response (for discussion): ONC should work with OCR, other federal partners, and industry stakeholders to address the following three issues related to technology and standards for encryption. – First, ONC should provide guidance on encryption key lifecycle management. – Second, ONC should provide guidance on a method for encryption key escrow recovery. – Third, ONC should publish guidance on key oversight and authorization, addressing the people or entities that maintain access to encryption keys. Finally, ONC should also consider providing guidance on a minimum set of encryption requirements for health IT (i.e., medical devices, systems, and software) used to store and access protected health information. 12

APPENDIX – BACKUP SLIDE SECTION Backup Slides 13

Charge to Transport and Security Workgroup WorkgroupTransport and Security Standards Section E: Secure Network Infrastructure 1)Cybersecurity: a)What should the federal government (specifically) focus on first to move towards a uniform approach to enforcing cybersecurity in healthcare (keeping HIPAA and CEHRT Rules in mind and possible new cybersecurity legislation)? b)Are there frameworks, methodologies, incentive programs, etc. that the healthcare industry has not, but should, consider? 2)Encryption: Are there other gaps (aside from lack of policies and guidance for implementing encryption)in technology and standards for encryption? Section F: Identity and Authentication What ID proofing and authentication standards, policies, and protocols can we borrow from other industries? Is healthcare that different from banking, social media, or ? Section G: Consent What standards should we put forward in the 2016 standards advisory for basic choice? How much work should ONC be doing on other standards while clarifying permitted uses? If standards development needs to be done, what should we be working on (DS4CDS vs DS4P vs something else)? 14