Download presentation
Presentation is loading. Please wait.
Published byMichael Morris Modified over 9 years ago
1
“ Jericho / UT Austin Pilot” Privacy with Dynamic Patient Review April 9, 2013 Presented by: David Staggs, JD, CISSP Jericho Systems Corporation
2
204/09/2013 Agenda Administrative issues Problem statement Specific goal of the pilot Roles available in demonstration of a reference implementation Notional diagram of expected data flow Extended data flow for subsequent use Questions from the Audience POA&M Summary
3
304/09/2013 Welcome to the Pilot! This pilot is a community led pilot –Limited support provided by the ONC Apurva Dharia (ESAC) Jeanne Burton (Security Risk Solutions) Melissa Springer (HHS) In conjunction with DS4P bi-weekly return of an All Hands meeting Access to DS4P Wiki, teleconference, and calendar Meeting times: Tuesdays 11AM (ET) –Dial In: +1-650-479-3208 Access code: 662 197 169 URL: https://siframework1.webex.com/siframework1/onstage/g.php?t=a& d=662197169 https://siframework1.webex.com/siframework1/onstage/g.php?t=a& d=662197169
4
404/09/2013 Expectations for the Pilot Tasked to identify and solve anticipated problems in data segmentation and/or privacy Tasked to provide user stories that can be used in Agile development of a reference implementation that offers a solution to the problem Expected to apply current HIT standards to solve anticipated issues in the reference implementation Tasked to identify resulting issues that may be useful as an update to the DS4P Implementation Guide Ultimate goal to demonstrate practical a reference implementation and identify any gaps in or extensions to HIT standards
5
504/09/2013 Problem Statement(s) As the exchange of Personal Health Information (PHI) becomes more commonplace, how can healthcare consumers be confident that their medical information is being appropriately shared? How can the benefits of the exchange of medical information on demand be realized if healthcare consumers decide not to “opt in?” Considering the growth of medical identity theft, how can systems releasing PHI protect the physical and financial health of healthcare consumers?
6
604/09/2013 Specific Goals of the Pilot 1. Define the exchange of HL7 CDA-compliant PCD between a PCD repository and a provider evaluating that includes a report on the outcome of the request back to the healthcare consumer. 2. Additional goal: use of identifiers that can uniquely identify the healthcare consumer and PCD repository used to report the outcome of the request back to the healthcare consumer by healthcare consumer’s provider and subsequent EHR custodians. 3. Stretch goal: use of the PCD repository as a proxy allowing direct authentication by the healthcare consumer to the provider, subsequently reducing correlation errors.
7
704/09/2013 Available Roles Holder of PHI that is participating on the eHealth Exchange –Accepts eHealth Exchange compliant request –Retrieves PCD and reports result of request –Synthetic Patent Data is Available Requester of PHI that is participating on the eHealth Exchange –Makes eHealth Exchange compliant request Repository holding subject’s Patient Consent Directive (PCD) –Transmits PCD to trusted eHealth Exchange requesters –Accepts policy created by subject of shared PHI –Passes HL7-compliant PCD –Displays result of the request transmitted from holder of PHI
8
804/09/2013 Data Flow Expected Patient’s Provider Patient PCD Repository 2 nd Requestor Requestor B , = Clinical data A,B = PCD data = reporting
9
904/09/2013 Available Roles, Extended Secondary requester of PHI that is participating on the eHealth Exchange –Makes eHealth Exchange compliant request
10
1004/09/2013 Secondary Goals of the Pilot Exchange and enforce privacy metadata to ensure proper policy- based disclosure and redisclosure of PHI Accept and display reports from information owners on access control decisions for requests for the patient’s PHI Create a token passing scheme that facilitates secondary use reporting Demonstrate dynamic reporting of access to a patient’s PHI and their ability to change their PCD using their PCD central repository
11
11 Pilot Team Members 04/09/2013 NameRoleOrganization David StaggsParticipantJericho Systems Corporation Michael FieldParticipantUT Austin HIT Lab
12
1204/09/2013 Relationship to DS4P IG Parts of the IG this pilot will exercise. Section of IGSpecifics to PilotNotes 3.2Pass/enforce metadataSegmentation 12.1User Story 1 C – (Pull)Enforcement 12.1Restriction requests13405(a) update 12.2.1Accept reportingSecondary use
13
1304/09/2013 Questions? For example: How long will this take? What level of commitment is expected?
14
14 Plan of Action Upon agreement of the participants the POA is Identify the elements available from previous DS4P pilots Scope level of effort, decide on extended scenario Review standards available for returning information on requests Determine gaps or extensions required in standards Create XDS.b repository holding PCD Stand up information holders and requestors Identify remaining pieces Document and update IG with results of our experience 04/09/2013
15
1504/09/2013 Timeline General Timeline, conditioned on agreement of stakeholders MilestoneTarget DateResponsible Party Kick off and LogisticsApril 2013Jericho Systems Basic InfrastructureJune 2013Members AuthN via RepositoryAugust 2013Members Reporting CapabilityOctober 2013Members CompleteNovember 2013Members
16
1604/09/2013 DS4P References Use Case: http://wiki.siframework.org/Data+Segmentation+for+Privacy+Use+C ases http://wiki.siframework.org/Data+Segmentation+for+Privacy+Use+C ases Implementation Guide: http://wiki.siframework.org/Data+Segmentation+for+Privacy+IG+Co nsensus http://wiki.siframework.org/Data+Segmentation+for+Privacy+IG+Co nsensus Pilots Wiki Page: http://wiki.siframework.org/Data+Segmentation+for+Privacy+RI+and +Pilots+Sub-Workgroup http://wiki.siframework.org/Data+Segmentation+for+Privacy+RI+and +Pilots+Sub-Workgroup
17
1704/09/2013 Backup Slides
18
1804/09/2013
19
1904/09/2013
20
2004/09/2013 Additional Success Criteria Exchange and enforcement of privacy metadata (e.g. refrain, POU, sensitivity, confidentiality) Exchange of PCD location and credential metadata Exchange of access reporting information to patient Exchange and enforcement of updated PCD
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.