Electronic Submission of Medical Documentation (esMD) Identity Proofing Sub-Workgroup October 31, 2012.

Slides:



Advertisements
Similar presentations
Public Key Infrastructure A Quick Look Inside PKI Technology Investigation Center 3/27/2002.
Advertisements

Electronic Submission of Medical Documentation (esMD) Face to Face Informational Session esMD Requirements, Priorities and Potential Workgroups – 2:00pm.
© Southampton City Council Sean Dawtry – Southampton City Council The Southampton Pathfinder for Smart Cards in public services.
15June’061 NASA PKI and the Federal Environment 13th Fed-Ed PKI Meeting 15 June ‘06 Presenter: Tice DeYoung.
EsMD Author of Record L1 Use Case Meeting Friday, August 3, 2012.
Department of Health and Human Services Personal Identity Verification Training APPLICANT.
FIPS 201 Personal Identity Verification For Federal Employees and Contractors National Institute of Standards and Technology Information Technology Laboratory.
PPA Use Case Context Diagram – Information Exchange Paths – General Case 0 Payer Organization Payer Organization Provider / Provider Organization Contractors.
Electronic Submission of Medical Documentation (esMD) for Medicare FFS Presentation to HITSC Provenance Workgroup January 16, 2015.
Electronic Submission of Medical Documentation (esMD) to DirectTrust.org December 3, 2014.
Grid Security Infrastructure Tutorial Von Welch Distributed Systems Laboratory U. Of Chicago and Argonne National Laboratory.
ESign-Online Digital Signature Service February 2015 Controller of Certifying Authorities Department of Electronics and Information Technology Ministry.
Identity Standards (Federal Bridge Certification Authority – Certificate Lifecycle) Oct,
The SAFE-BioPharma Identity Proofing Process Author of Record SWG (Digital Credentials) October 3, 2012 Peter Alterman, Ph.D. Chief Operating Officer,
Lecture 23 Internet Authentication Applications
HIT Standards Committee: Digital Certificate Trust – Policy Question for HIT Policy Committee March 29, 2011.
Federal Approach to Electronic Credentials For services to citizens, businesses, other governments, and employees Mary J. Mitchell Office of Electronic.
Federal Information Processing Standard (FIPS) 201, Personal Identity Verification for Federal Employees and Contractors Tim Polk May.
Electronic submission of Medical Documentation (esMD) Author of Record Presentation to HITSC July 17, 2013 MELANIE COMBS-DYER, RN Deputy Director, Provider.
I DENTITY M ANAGEMENT Joe Braceland Mount Airey Group, Inc.
HIT Standards Committee HIT Standards Committee Privacy and Security Workgroup joint meeting with Clinical Operations Workgroup: Digital Signatures for.
EsMD Background Phase I of esMD was implemented in September of It enabled Providers to send Medical Documentation electronically Review Contractor.
Security Standards under Review for esMD. Transaction Timeline An esMD transaction begins with the creation of some type of electronic content (e.g. X12.
Federal Requirements for Credential Assessments Renee Shuey ITS – Penn State February 6, 2007.
Electronic Submission of Medical Documentation (esMD) Face to Face Informational Session Charter Discussion – 9:30am – 10:00am October 18, 2011.
(updated for esMD on ) electronic submission of Medical Documentation (esMD) HL7 Structured Documents and HL7 Attachments May 5-9, 2013 (updated.
Functions of an X.509 Certification Authority (CA)
Additional Attachment Templates Presented to the Attachments Workgroup December 10, 2013.
Electronic Submission of Medical Documentation (esMD) AoR L2 Harmonization April 17, 2013.
Electronic Submission of Medical Documentation (esMD) Digital Signature and Author of Record Pre-Discovery Wednesday May 2,
Privacy and Security Tiger Team Meeting Discussion Materials Today’s Topic Recommendations on Trusted Identities for Providers in Cyberspace August 20,
Electronic Submission of Medical Documentation (esMD) Identity Proofing Sub-Workgroup October 3, 2012.
Electronic Submission of Medical Documentation (esMD) Identity Proofing Sub-Workgroup October 17, 2012.
Secure Electronic Transaction (SET)
Electronic Submission of Medical Documentation (esMD) Digital Signature and Author of Record Pre-Discovery Wednesday May 9,
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
NENA Development Conference | October 2014 | Orlando, Florida Security Certificates Between i3 ESInet’s and FE’s Nate Wilcox Emergicom, LLC Brian Rosen.
Lecture 23 Internet Authentication Applications modified from slides of Lawrie Brown.
Electronic Submission of Medical Documentation (esMD) January 11, :00 PM – 3:00 PM Community Meeting 0.
Computer Security: Principles and Practice First Edition by William Stallings and Lawrie Brown Lecture slides by Lawrie Brown Chapter 22 – Internet Authentication.
Electronic Submission of Medical Documentation (esMD) Digital Signature and Author of Record Pre-Discovery Wednesday May 16,
1 June Richard Guida Stephanie Evans Johnson & Johnson Director, WWIS WWIS SAFE Infrastructure Overview.
Electronic submission of Medical Documentation (esMD) Author of Record Presentation to LCC August 8, 2013 ROBERT DIETERLE esMD Initiative Coordinator 1.
Electronic Submission of Medical Documentation (esMD) Digital Identity and Author of Record Sub-Workgroups September 19, 2012.
Security Standards under Review for esMD. Transaction Timeline An esMD transaction begins with the creation of some type of electronic content (e.g. X12.
Secure Messaging Workshop The Open Group Messaging Forum February 6, 2003.
Levels of Assurance in Authentication Tim Polk April 24, 2007.
Privacy and Security Tiger Team Meeting Discussion Materials Today’s Topic Recommendations on Trusted Identities for Providers in Cyberspace August 6,
DIGITAL SIGNATURE. GOOD OLD DAYS VS. NOW GOOD OLD DAYS FILE WHATEVER YOU WANT – PUT ‘NA’ OR ‘-’ OR SCRATCH OUT FILE BACK DATED, FILE BLANK FORMS, FILE.
Alternatives for Message Signature from Sender 1.Approach 1 –X12 58 to digitally sign X12 transaction set Optional: X to transmit signer’s public.
Electronic Submission of Medical Documentation (esMD) Author of Record Workgroup Friday, September 7 th,
Electronic Submission of Medical Documentation (esMD) Sub-Workgroup October 10, 2012.
EsMD Harmonization Mapping Analysis for X & X
Electronic Submission of Medical Documentation (esMD) Author of Record Workgroup Wednesday June 13,
Identity Proofing, Signatures, & Encryption in Direct esMD Author of Record Workgroup John Hall Coordinator, Direct Project June 13, 2012.
DIGITAL SIGNATURE.
“Trust me …” Policy and Practices in PKI David L. Wasley Fall 2006 PKI Workshop.
1 Federal Identity Management Initiatives Federal Identity Management Initatives David Temoshok Director, Identity Policy and Management GSA Office of.
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
Electronic Submission of Medical Documentation (esMD)
EsMD Author of Record L1 Use Case Meeting Wednesday, August 1, 2012.
EsMD Author of Record L1 Use Case Kick-Off Meeting Friday, July 20, 2012.
EsMD Author of Record L1 Use Case Meeting Wednesday, July 25, 2012.
FP6−2004−Infrastructures−6-SSA E-infrastructure shared between Europe and Latin America The Latin American Catch-all Grid Certification.
The Federal E-Authentication Initiative David Temoshok Director, Identity Policy GSA Office of Governmentwide Policy February 12, 2004 The E-Authentication.
Training for developers of X-Road interfaces
Public Key Infrastructure (PKI)
Federal Requirements for Credential Assessments
Appropriate Access InCommon Identity Assurance Profiles
WEQ-012 PKI Overview March 19, 2019
Presentation transcript:

Electronic Submission of Medical Documentation (esMD) Identity Proofing Sub-Workgroup October 31, 2012

Schedule for Identity Proofing SWG DateTopicDeliverable(s) September 26, 2012Standards (NIST/FBCA) List and review of standards October 3, 2012Industry examplesList and review industry examples October 10, 2012Requirements for identity Requirements for individuals and organizations October 17, 2012RA requirements“Certification” process for RAs October 24, 2012RA processesCombine RA with …, frequency, revocation October 31, 2012Gaps in policy and standards Identify gaps in standards, process and policy and make recommendations November 7, 2012Review SWG recommendation Review final report

Standards for Identity Proofing Document LinkTitle & Version / NotesDate NIST SP Electronic Authentication GuidelineDec 2011 FBCA X.509 Certificate Policy X.509 Certificate Policy for the Federal Bridge Certification Authority, Version 2.25 Dec FICAM Roadmap and Implementation Guidance Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance, Version 2.0 Dec

NIST Level 4 Identity Proofing Requirements In PersonRemote Basis for issuing credentials In-person appearance and verification of: a)a current primary Government Picture ID that contains Applicant’s picture, and either address of record or nationality of record (e.g., driver’s license or passport), and; b)either a second, independent Government ID document that contains current corroborating information (e.g., either address of record or nationality of record), OR verification of a financial account number (e.g., checking account, savings account, loan or credit card) confirmed via records. Not Applicable RA and CSP actions Primary Photo ID: RA inspects photo-ID and verifies via the issuing government agency or through credit bureaus or similar databases. Confirms that: name, DoB, address, and other personal information in record are consistent with the application. Compares picture to Applicant and records ID number. Secondary Government ID or financial account a)RA inspects secondary Government ID and if apparently valid, confirms that the identifying information is consistent with the primary Photo-ID, or; b)RA verifies financial account number supplied by Applicant through record checks or through credit bureaus or similar databases, and confirms that: name, DoB, address, and other personal information in records are on balance consistent with the application and sufficient to identify a unique individual. [Note: Address of record shall be confirmed through validation of either the primary or secondary ID.] Current Biometric RA records a current biometric (e.g., photograph or fingerprints) to ensure that Applicant cannot repudiate application. Credential Issuance CSP issues credentials in a manner that confirms address of record. Not Applicable

FBCA Identification Requirements by Assurance Level LevelIdentification Requirements Medium (all policies) Identity shall be established by in-person proofing before the Registration Authority, Trusted Agent or an entity certified by a State or Federal Entity as being authorized to confirm identities; information provided shall be verified to ensure legitimacy. A trust relationship between the Trusted Agent and the applicant which is based on an in-person antecedent may suffice as meeting the in-person identity proofing requirement. Credentials required are one Federal Government-issued Picture I.D., one REAL ID Act compliant picture ID1, or two Non-Federal Government I.D.s, one of which shall be a photo I.D. (e.g., Non-REAL ID Act compliant Drivers License). Any credentials presented must be unexpired. Clarification on the trust relationship between the Trusted Agent and the applicant, which is based on an in-person antecedent identity proofing event, can be found in the “FBCA Supplementary Antecedent, In-Person Definition” document. For PIV-I, credentials required are two identity source documents in original form. The identity source documents must come from the list of acceptable documents included in Form I-9, OMB No , Employment Eligibility Verification. At least one document shall be a valid State or Federal Government-issued picture identification (ID). For PIV-I, the use of an in-person antecedent is not applicable.

Gaps and Operational Issues Policy for Individual Identity Proofing – NIST Assurance Level 4 Policy for Organizational Identity Proofing (e.g. for group certificate) Solicit additional criteria for organizational IdP as part of policy creation Method for updating policy as environmental conditions change May have specific requirements based on type of organization (e.g. DME) PMD process – Ordering provider signs and send documents to DME which signs and submits to CMS Need to address “revocation of identities” (e.g. person dies, organization no longer does business) – may have implications for claim/documentation submission post “revocation” May need to consider legal issues with delegation for rights to corporations that must survive termination of the relationship. RA federation (what is required from the RA IdP by the CA for credential issuance) (RA sends information in secure manner to CA) all defined in the CPS (Policy OID) o Policy for RA Certification (including duration and termination) o Policy and process for “certification” of certification agencies o Agreement by FBCA cross-certified CA’s to recognize the policies and process – may need to explore at FBCA level – Debbie and Wendy Specifics Biometrics required – NIST Assurance Level 4 Policy for acceptance of prior in-person verification (antecedent) Frequency and conditions for reapplication (max – 3 years?)

Electronic Submission of Medical Documentation (esMD) Digital Signature and Delegation of Rights Sub-Workgroup October 31, 2012

Schedule for Identity Proofing SWG DateTopicDeliverable(s) September 26, 2012StandardsList and review of standards October 3, 2012Standards and industry examples List and review of additional standards industry examples October 10, 2012Transaction and AoR digital signature and delegation process Document digital signature and delegation of rights process October 17, 2012Transaction and AoR signature and delegation artifacts Document digital signature and delegation of rights artifacts October 24, 2012Validation process for non-repudiation review Document validation process with assurance of non-repudiation of signer and delegation(s) October 31, 2012Gaps in policy and standards Identify gaps in standards, process and policy and make recommendations November 7, 2012Review SWG recommendation Review final report

Standards for Digital Signatures Standard and LinkIssued byVersion / Date FBCA X.509 Certificate Policy X.509 Certificate Policy for the Federal Bridge Certification Authority, Version 2.25 Dec FIPS PUB 186-3Digital Signature StandardJun 2009 XML DigSig XML Signature Syntax and Processing (Second Edition), W3C Recommendation Jun

Standards for Delegation of Rights Standard and LinkIssued byVersion / Date OASIS SAML Assertions Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML), Version 2.0 All SAML v2.0 files Mar IETF RFC 3820Internet X.509 Public Key Infrastructure Proxy Certificate Profile Jun 2004

Gaps and Operational Issues Elements of the signature artifact (specific standard that includes these elements) Digest of Message Time stamp Purpose Long term validation Evidence Record e.g. RFC 4998 Long-Term access to CRL (e.g. via OCSP) Delegation of Rights Proxy Certificates Issues with creation, revocation, and industry support Assertions Issues with revocation Both cases – need definition of rights granted, duration, …

Additional Material – esMD AoR Reference from prior AoR call materials

Provider Entity Payer Entity esMD Initiative Overview Payer Provider (Individual or Organization) Provider (Individual or Organization) Contractors / Intermediaries Agent Payer Internal System Gateway esMD UC 2: Secure eMDR Transmission esMD UC 1: Provider Registration esMD AoR Level 1 Digital Identities Bundle Signatures Certificate Authority Registration Authority Provider Directories

AoR -- Phased Scope of Work 14 Level 1 – Current Focus Level 2 - TBD Level 3 - TBD Digital signature on aggregated documents (bundle) Digital signature to allow traceability of individual contributions to a document Digital signature on an individual document Focus is on signing a bundle of documents prior to transmission to satisfy an eMDR Define requirements for esMD UC 1 and UC 2 Signature Artifacts May assist with EHR Certification criteria in the future Focus is on signing an individual document prior to sending or at the point of creation by providers Will inform EHR Certification criteria for signatures on patient documentation Focus is on signing documents and individual contributions at the point of creation by providers Will inform EHR Certification criteria for one or multiple signatures on patient documentation

Topics for Digital Identities and AoR Workgroup Effort 1.Identity proofing 2.Digital identity management 3.Encryption 4.Digital signatures and artifacts 5.Delegation of Rights 6.Author of Record 15

Initiative Requirement Summary InitiativeIdentify Proofing Digital Identity Management Signing (Exchange Artifact) Encryption Delegation of Rights Author of Record DS4POrg/IndividualYes Direct ProjectAddress/ServerYes No esMDOrg/IndividualYes Healthcare Directories Org/IndividualYes No LCCOrg/IndividualYes Query HealthOrg/IndividualYes No Transitions of Care Org/IndividualYes 16 Mandatory Optional with consequences Optional Future Uses

User Story / Workflow Overall User Story Components 1)All Actors obtain and maintain a non-repudiation digital identity 2)Provider registers for esMD (see UC1)* 3)Payer requests documentation (see UC2)* 4)Provider submits digitally signed document (bundle) to address request by payer 5)Payer validates the digital credentials, signature artifacts and, where appropriate, delegation of rights *User Stories for UC 1 and 2 have already been defined. Workgroup will help define bullets 1) and 4)