Presentation is loading. Please wait.

Presentation is loading. Please wait.

10/08/20041 © 2004 Pete Palmer Federated Identity Management and Regional Health Information Organizations Pete Palmer, Principal Security Analyst, Guidant.

Similar presentations


Presentation on theme: "10/08/20041 © 2004 Pete Palmer Federated Identity Management and Regional Health Information Organizations Pete Palmer, Principal Security Analyst, Guidant."— Presentation transcript:

1 10/08/20041 © 2004 Pete Palmer Federated Identity Management and Regional Health Information Organizations Pete Palmer, Principal Security Analyst, Guidant Corporation, HIMSS NHII Task Force Member October 08, 2004, University of Minnesota Digital Technology Center

2 10/08/2004 2 © 2004 Pete Palmer Outline “Framework for Strategic Action” Goals Regional Health Information Organizations (RHIOs) Electronic Authentication Basics Federated Identity Management Schedule

3 10/08/2004 3 © 2004 Pete Palmer Goals of the Government’s 2004 “Framework for Strategic Action” Goal 1: Inform Clinical Practice Goal 2: Interconnect Clinicians Goal 3: Personalize Care Goal 4: Improve Population Health Source - HHS Health IT Strategic Framework, July 21st, 2004 http://www.hhs.gov/onchit/framework/hitframework/framework.html

4 10/08/2004 4 © 2004 Pete Palmer Goals of the Government’s 2004 “Framework for Strategic Action” Goal 1: Inform Clinical Practice Goal 2: Interconnect Clinicians: Identify interoperability as a major milestone for achieving improved healthcare delivery; encourage regional healthcare information organizations (RHIOs) and a national health information network. Goal 3: Personalize Care Goal 4: Improve Population Health

5 10/08/2004 5 © 2004 Pete Palmer Regional Health Information Organizations (RHIOs)

6 10/08/2004 6 © 2004 Pete Palmer RHIO Federation Federated System of Interoperable RHIOs Local Leadership, Local Management National Standards, National Interoperability

7 10/08/2004 7 © 2004 Pete Palmer RHIO Development Initial RHIO Federation Communities

8 10/08/2004 8 © 2004 Pete Palmer RHIO Development Challenges RHIOs require local cooperation Without RHIOs, local competition restricts interoperability Lack of Local Visionaries and Evangelists

9 10/08/2004 9 © 2004 Pete Palmer RHIO Management NE Ohio RHIO

10 10/08/2004 10 © 2004 Pete Palmer RHIO Management Challenges Local Competition Disparate Healthcare IT Systems No ‘Neutral Third Party’ Manager

11 10/08/2004 11 © 2004 Pete Palmer The RHIO Federation

12 10/08/2004 12 © 2004 Pete Palmer The RHIO Federation Interoperability Solutions Security and Trust Services Identity Management Services Standardization Assessments for Applications

13 10/08/2004 13 © 2004 Pete Palmer Electronic Authentication Basics Identity Verification Procedures Credential Issuance Credential Types

14 10/08/2004 14 © 2004 Pete Palmer Electronic Authentication Basics Authentication is not Authorization Risk Assessments Assurance Levels Credential Standards

15 10/08/2004 15 © 2004 Pete Palmer Federated Identities Identity Independent of Applications Identity Recognized by Multiple Organizations Enables Single Sign-on Enables Electronic Federations

16 10/08/2004 16 © 2004 Pete Palmer Federated Identity Management Communities of Trust Standardized Credential Types Standardized Policies and Procedures for Issuing Credentials Common Credential Validation System

17 10/08/2004 17 © 2004 Pete Palmer Components of Federated Identities Identity Credential or Token (Authentication) - Username/Password - Digital Certificate/Signed Data - Biometric Identity Attributes (Authorization) - Organization - Roles - Custom Information Federated Identity Management Standards Liberty Alliance SAML PKI w/Bridge Trust Model

18 10/08/2004 18 © 2004 Pete Palmer Internet2’s Shibboleth SAML Flow Architecture (Slide c/o Scott Cantor, The Ohio State University) Service Provider Knock, Knock Service Provider Who’s There? Assertion Consumer Service v6597w54wd7 Authn Authority Mary Attribute Requester Attribute Authority v6597w54wd7 who? Attribute Requester Attribute Authority Mary, faculty, contract:001 Resource Let me in!

19 10/08/2004 19 © 2004 Pete Palmer RHIO Development: Initial Applications Remote Electronic Health Record (EHR) Access Standardized ePrescribing Implementations

20 10/08/2004 20 © 2004 Pete Palmer The RHIO Federation Identity Management Services Standardize Criteria for Issuing Electronic Identities Standardize on a set of Electronic Credentials Standardize on a Set of Meaningful Assurance Levels for the Two Initial Applications RHIO FEDERATION RHIO FEDERATION

21 10/08/2004 21 © 2004 Pete Palmer The RHIO Federation Security and Trust Services Internet RHIO Federation Federation Approved Trust Service Providers RHIO 1 RHIO 2

22 10/08/2004 22 © 2004 Pete Palmer The RHIO Federation Security and Trust Services Partner with Trust Service Providers/Brand Trust Services Provide Training for RHIOs to Interoperate with Trust Service Providers Provide Security Training to RHIOs

23 10/08/2004 23 © 2004 Pete Palmer Internet RHIO Federation RHIO 1 RHIO 2 Initial RHIO Applications: ePrescribing and EMR Access Insurance Info, Medication History - RxHub Pharmacy Routing – SureScripts Pharmacy Delivery Home Delivery Electronic Medical Records at Providers


Download ppt "10/08/20041 © 2004 Pete Palmer Federated Identity Management and Regional Health Information Organizations Pete Palmer, Principal Security Analyst, Guidant."

Similar presentations


Ads by Google