Health Big Data Discussion Privacy and Security Workgroup Deven McGraw, Chair Stanley Crosley, Co-chair June 8, 2015.

Slides:



Advertisements
Similar presentations
ENTITIES FOR A UN SYSTEM EVALUATION FRAMEWORK 17th MEETING OF SENIOR FELLOWSHIP OFFICERS OF THE UNITED NATIONS SYSTEM AND HOST COUNTRY AGENCIES BY DAVIDE.
Advertisements

Legal Work Group Developing a Uniform EHR/HIE Patient Consent Form.
HIT Policy Committee Federal Health IT Strategic Plan April 13, 2011 Jodi Daniel, ONC Seth Pazinski, ONC.
Interoperability Roadmap Comments Sections E, F, and G Transport & Security Standards Workgroup Dixie Baker, chair Lisa Gallagher, co-chair March 11, 2015.
Davis Wright Tremaine LLP Non-HIPAA Governmental Regulation of Healthcare Privacy and Security Sixteenth HIPAA Summit/The Privacy Symposium August 21,
Privacy and Security Workgroup: Summary of Big Data Public Hearings January 12, 2015 Deven McGraw, chair Stan Crosley, co-chair.
NCVHS: Privacy and Confidentiality Leslie P. Francis, Ph.D., J.D. Distinguished Professor of Law and Philosophy Alfred C. Emery Professor of Law University.
Karen D. Smith, Esq. Partner Bricker & Eckler LLP 100 S. Third Street Columbus, OH (614)
Health IT Privacy and Security Policy Jodi Daniel, J.D., M.P.H. Director, Office of Policy and Research, Office of the National Coordinator for Health.
Silicon Valley Apps for Kids Meetup Laura D. Berger October 22, 2012 The views expressed herein are those of the speaker, and do not represent the views.
Privacy and Security Workgroup: Summary of Big Data Public Hearings February 9, 2015 Deven McGraw, chair Stan Crosley, co-chair.
Legal Agreements and Policy Work Group Co-facilitators: Linda Attarian and Jill Moore Dial: Enter room#: * * (don’t forget the asterisks.
Privacy and Security Workgroup October 14, 2014 Deven McGraw, chair Stan Crosley, co-chair.
Notice of Proposed Rulemaking (NPRM) Comments Privacy and Security Workgroup Deven McGraw, chair Stan Crosley, co-chair April 27, 2015.
Notice of Proposed Rulemaking (NPRM) Comments Privacy and Security Workgroup Deven McGraw, Chair Stan Crosley, Co-Chair April 20, 2015.
MU Stage 3 Notice of Proposed Rulemaking (NPRM) Comments Privacy and Security Workgroup Deven McGraw, chair Stan Crosley, co-chair May 7, 2015.
Update on Interoperability Roadmap Comments Sections E, F, and G Transport & Security Standards Workgroup Dixie Baker, chair Lisa Gallagher, co-chair March.
User Authentication Recommendations Transport & Security Standards Workgroup December 10, 2014.
Health IT Standards Committee Federal Health IT Strategic Plan December 10, 2014 Seth Pazinski Director, Office of Planning, Evaluation, and.
Data Gathering HITPC Workplan HITPC Request for Comments HITSC Committee Recommendations gathered by ONC HITSC Workgroup Chairs ONC Meaningful Use Stage.
Connecting Health and Care for the Nation: A Shared Nationwide Interoperability Roadmap – DRAFT Version 1.0 Joint FACA Meeting Chartese February 10, 2015.
Privacy and Security Workgroup: Big Data Public Hearing December 8, 2014 Deven McGraw, chair Stan Crosley, co-chair.
Consumer Work Group Presentation Federal Health IT Strategic Plan January 9, 2015 Gretchen Wyatt Office of Planning, Evaluation, and Analysis.
Privacy and Security Tiger Team Meeting Recommendations regarding a framework of security protections for EHRs December 7, 2011.
Navigating Privacy and Security Issues for HIE: A Consumer Perspective Deven McGraw Chief Operating Officer National Partnership for Women & Families
Strategy and Innovation Workgroup: Recommendations on the Federal Health IT Strategic Plan March 4, 2015 David Lansky, Chair Jennifer Covich,
HIT Standards Committee Hearing on Trusted Identity of Patients in Cyberspace November 29, 2012 Jointly sponsored by HITPC Privacy and Security Tiger Team.
Privacy and Security Workgroup: Big Data Public Hearing November 10, 2014 Deven McGraw, chair Stan Crosley, co-chair.
Public Health Tiger Team we will start the meeting 3 min after the hour DRAFT Project Charter May 6, 2014.
Notice of Proposed Rulemaking (NRPM) Comments Privacy and Security Workgroup Deven McGraw, Chair Stanley Crosley, Co-chair May 22, 2015.
Privacy and Security Tiger Team Recommendations Adopted by The Health IT Policy Committee Relevant to Consumer Empowerment May 24, 2013.
HIT Policy Committee Nationwide Health Information Network Governance Workgroup Recommendations Accepted by the HITPC on 12/13/10 Nationwide Health Information.
State of Iowa Enterprise HIPAA Compliance
Update on Interoperability Roadmap Comments Sections G, F and E Transport & Security Standards Workgroup Dixie Baker, chair Lisa Gallagher, co-chair March.
HIT Standards Committee Privacy and Security Workgroup: Initial Reactions Dixie Baker, SAIC Steven Findlay, Consumers Union June 23, 2009.
Manage by Measure: Just Do It AASHTO SCOPM Annual Meeting October 23, 2009 Steve Simmons TxDOT Deputy Executive Director.
Dr. David Mowat June 22, 2005 Federal, Provincial & Local Roles Surveillance of Risk Factors and Determinants of Chronic Diseases.
Interoperability Framework Overview Health Information Technology (HIT) Standards Committee June 24, 2010 Presented by: Douglas Fridsma, MD, PhD Acting.
HIT Policy Committee NHIN Workgroup Recommendations Phase 2 David Lansky, Chair Pacific Business Group on Health Danny Weitzner, Co-Chair Department of.
+ Regulation and Compliance Summary “ Making Great Ideas Become Reality”
Public Health Tiger Team we will start the meeting 3 min after the hour DRAFT Project Charter April 15, 2014.
HIT Policy Committee Privacy & Security Workgroup Update Deven McGraw Center for Democracy & Technology Rachel Block Office of Health Information Technology.
Draft – discussion only Advanced Health Models and Meaningful Use Workgroup June 23, 2015 Paul Tang, chair Joe Kimura, co-chair.
Notice of Proposed Rulemaking (NRPM) Comments Privacy and Security Workgroup Deven McGraw, Chair Stanley Crosley, Co-chair May 18, 2015.
The Paradox in HIPAA Deven McGraw, JD, MPH, LLM Partner Manatt, Phelps & Phillips, LLP December 8, 2014.
Public Health Performance Standards District System Assessment Karen O’Rourke, MPH Joan Orr, CHES 2009.
Health Big Data Discussion Privacy and Security Workgroup Deven McGraw, Chair Stanley Crosley, Co-chair June 22, 2015.
(Slide 1 of 22) Response to the National Vaccine Advisory Committee Recommendations on the Immunization Safety Office Scientific Agenda Frank DeStefano,
TISSUE REPOSITORIES: THE COMMON RULE and THE HIPAA PRIVACY RULE Mark A. Rothstein, J.D. Herbert F. Boehl Chair of Law and Medicine Director, Institute.
DISPARITIES COUNCIL Legislative Working Group Hank J. Porten Steve Shestakofsky Camille Watson.
HIPAA History March 3, HIPAA Ruling Health Insurance Portability Accountability Act Health Insurance Portability Accountability Act Passed by Congress.
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
1 Overview of HIT Policy Committee’s Privacy Hearing Jodi Daniel, JD, MPH Director, Office of Policy and Research Office of the National Coordinator for.
1 Changes to Privacy Regulations under ARRA May 4, 2009 Melissa Goldstein, J.D. The George Washington University School of Public Health and Health Services.
Overview of ONC Report to Congress on Health Information Blocking Presented to the Health IT Policy Committee, Task Force on Clinical, Technical, Organizational,
Interoperability Roadmap Comments Privacy and Security Workgroup March 16, 2015.
Framing Identity Management Recommendations Transport & Security Standards Workgroup November 19, 2014.
API Task Force Josh Mandel, Co-Chair Meg Marshall, Co-Chair December 4, 2015.
Data Gathering HITPC Workplan HITPC Request for Comments HITSC Committee Recommendations gathered by ONC HITSC Workgroup Chairs ONC Meaningful Use Stage.
HIPAA Privacy Rule Positive Changes Affecting Hospitals’ Implementation of the Rule.
An Unprecedented Opportunity: Using Federal Stimulus Funds to Advance Health IT in California Testimony of Sam Karp, Vice President of Programs California.
HHS Security and Improvement Recommendations Insert Name CSIA 412 Final Project Final Project.
Query Health Operations Workgroup Standards & Interoperability (S&I) Framework October 13, :00am – 12:00pm ET.
Update from the Faster Payments Task Force
VERMONT INFORMATION TECHNOLOGY LEADERS
Health IT Policy Committee Workgroup Evolution
Concerns of a Privacy Advocate – and How to Respond
Part 1: Controlled Unclassified Information (CUI)
Patients and Families Statement
Presentation transcript:

Health Big Data Discussion Privacy and Security Workgroup Deven McGraw, Chair Stanley Crosley, Co-chair June 8, 2015

Agenda Health Big Data Discussion – Review Straw Recommendations 1

PSWG Big Data Work plan 2 MeetingsTask May 18, 2015 Recap: Presentation to the HITPC Review draft big data workplan Review draft big data report  June 8, 2015 Begin review of straw recommendations June 22, 2015 Continue review of straw recommendations Finalize recommendations HITPC Meeting July 14, 2015 Goal: Present Health Big Data Recommendations

Section 6 – Draft Solutions and Recommendations 3 § Addressing Harm, Including Discriminatory Practices Call on effort that explores the following: Encourage ONC and other federal stakeholders to promote more public inquiry to fully understand the scope of the problem Call on policymakers to continue to monitor the use of health data to identify gaps in law and regulation; identify areas for further inquiry Improve trust through algorithmic transparency; Consider applying the FCRA approaches to promote trust algorithmic transparency

Section 6 – Draft Solutions and Recommendations § 6.2 – Address Uneven Policy Environment Leverage most recent recommendations by the PSWG on better educating consumers about the privacy and security laws and uses of data both within and outside of the HIPAA environment* Congressional action: FIPPs-based protections for data outside of HIPAA – For now, voluntarily adopted codes of conduct can be enforced by FTC – HHS should partner with other agencies to help develop “rules of the road” = build trust – Codes should emphasize transparency, individual access, accountability, and use limitations Re-evaluate existing rules: – Rules governing data use that contribute to a learning health system and re- use for generalizable knowledge – Rules governing research, making it more efficient (risk-based, avoid disincentives to research uses, use of data enclaves or entities that follow HIPAA and/or FIPPs)** Strengthen existing rules on patient access to data (both within HIPAA and as part of any legislation covering the non-HIPAA space) *May 22, 2015 HITPC meeting. **October 18, 2011 HITPC Transmittal Letter.

Section 6 – Draft Solutions and Recommendations 5 § 6.3 – Protect Health Information by Improving Trust in De-Identification Methodologies and Reducing the Risk of Re-Identification Call on OCR to be a better “steward” of HIPAA de-identification standards and conduct. – Conduct ongoing review of the methodologies and policies – Seek assistance from third-party experts, such as NIST Consider the following recommendations from the hearings: – Limit use of safe harbor (data = random sample of a population) – Re-evaluate de-identification status of a dataset when context changes – Develop programs to objectively evaluate statistical methodologies; consider granting safe harbor status to methodologies proven to be effective in particular context – Call on Congress to address accountability for re-identification Consider the risk-based de-identification requirements when risk is low (e.g., data enclaves or data repositories with HIPAA security rules)

Section 6 – Draft Solutions and Recommendations 6 § 6.4 – Supporting Secure Use of Data for Learning Call on policymakers to enact comprehensive legislation that includes security requirements for non-HIPAA covered entities Call on policy makers to provide incentives for entities to use privacy- enhancing technologies and architectures (e.g., secure data enclaves, secure distributed data systems) Re-endorse prior Tiger Team recommendations* – Security policy for entities collecting, storing and sharing electronic health information needs to be responsive to innovation and changes in the marketplace – Security policy needs to be flexible and scalable – Providers need education and guidance on how to comply with security policy requirements – HHS should have a consistent and dynamic process for updating security policies and rapid dissemination of new rules and guidance to all affected * 12/14/2011 HITPC Transmittal Letter.

7

Backup Slides 8

Big Data Report 9 Draft Table of Contents 1.Executive Summary 2.Background 3.Scope 4.Expert Testimony 5.Detailed Problem Statements 6.Solutions and Recommendations 7.Bibliography