SlideShare a Scribd company logo
1 of 10
Download to read offline
Health Relationship Trust
(HEART) Working Group
Eve Maler, WG co-chair
eve.maler@forgerock.com| @xmlgrrl
15 May 2018
http://openid.net/wg/heart/
1
Why HEART?
• Health data is some of the most personal and private consumer data
• It is increasingly digital, either at the source or when transcribed
• The Internet of Healthy Things and genomic data are having an impact
• Individuals want to be in control of gathering and sharing this data
• Including giving permission for access – and revoking permission
• Especially if they have complex conditions or have moved frequently
• Clinicians, insurers, and researchers seek data access to diagnose,
plan care, and pay for care, and need to know it’s authorized for use
• HEART puts the individual back at the center of the health data-
sharing conversation
2
What does HEART do?
To achieve RESTful, patient-centric, privacy-sensitive
health data sharing…
• It profiles OAuth, OpenID Connect, UMA, and the
HL7 FHIR (Fast Healthcare Interoperability
Resources) API
• It provides the official FHIR API security mechanism
• It is also aligning over time with the SMART on FHIR
API effort developed for use with EHR systems,
health portals, and Health Information Exchanges
3
Who is involved?
• Health/health IT subject matter experts
• Doctors, government health agency reps…
• Technology experts
• Implementers, health startups, spec authors…
• Leadership team:
• Co-chair Debbie Bucci (US Health and Human Services
Office of the National Coordinator)
• Co-chair Eve Maler (ForgeRock)
• Spec editor Justin Richer (Bespoke Engineering)
4
Current state of the deliverables
(see https://openid.bitbucket.io/HEART/)
5
• Mechanical = security profile
• Semantic = API-specific profile
• Considering whether to deprecate the UMA1 profiles
New white paper and use case work
(unpublished as yet)
• Focused on new urgency in the quest for patient-mediated health
data exchange solutions, e.g., in the US:
• MyHealthEData
• Promoting Interoperability (was “Meaningful Use”)
• White paper: Enabling Patient-Mediated Health Data Exchange
• With assistance from Jan Oldenburg of Participatory Healthcare
• Use cases under review:
• Alice electronically shares data from her PHR
• Alice controls sharing of sensitive clinical data
• Alice delegates to a personal representative
6
HEART scope mechanisms
Confidentiality and sensitivity
• HL7 defines many codes for
sensitive data types
• E.g., sens/ETH for substance abuse
• Similarly, it defines some codes for
confidentiality levels
• HEART allows an RS to use these as
scopes
• If such a scope is not associated
with an access token, the RS
SHOULD filter out the relevant
data before delivering it, if at all
possible
Break-the-glass
• HL7 defines a code btg for
situations where the resource
owner is unavailable
• HEART allows an RS to use this as a
scope
• If such a scope is associated with
an access token, the RS MUST log
access made on this basis in an
auditable format available to the
resource owner
7
Note: All policy-setting UX options are “outside the scope of scope mechanisms” (e.g., policy defaulting).
A potential third scope mechanism:
de-identification
• We are currently discussing whether to add a similar scope
mechanism for enabling a patient to instruct the RS to deliver
resources in de-identified form
8
The Move Health Data Forward challenges
(https://www.challenge.gov/challenge/move-health-data-forward-challenge/)
• Starting mid-2016, HHS ONC challenged
industry to create API solutions to help
individuals authorize the movement of their
health data
• Three phases later, several winners have
won awards, including for some solutions
based on the HEART profiles
9
Thank you!
Questions?
Join us!
Eve Maler, WG co-chair
eve.maler@forgerock.com| @xmlgrrl
15 May 2018
http://openid.net/wg/heart/
10

More Related Content

What's hot

Mobile monday mhealth
Mobile monday mhealthMobile monday mhealth
Mobile monday mhealth
Joe Drumgoole
 
secured storage of Personal health record in cloude
secured storage of Personal health record in cloudesecured storage of Personal health record in cloude
secured storage of Personal health record in cloude
Mahaveer kandgule
 

What's hot (20)

The state of healthcare (ill)legality
The state of healthcare (ill)legalityThe state of healthcare (ill)legality
The state of healthcare (ill)legality
 
Centrifuge Systems Overview 2 14
Centrifuge Systems Overview 2 14Centrifuge Systems Overview 2 14
Centrifuge Systems Overview 2 14
 
Hardman 2 med hx data strategy - v2.1 diagram
Hardman 2   med hx data strategy - v2.1 diagramHardman 2   med hx data strategy - v2.1 diagram
Hardman 2 med hx data strategy - v2.1 diagram
 
Why Do Federally Qualified Health Centers Need A Referral Management Software...
Why Do Federally Qualified Health Centers Need A Referral Management Software...Why Do Federally Qualified Health Centers Need A Referral Management Software...
Why Do Federally Qualified Health Centers Need A Referral Management Software...
 
Mobile monday mhealth
Mobile monday mhealthMobile monday mhealth
Mobile monday mhealth
 
Centrifuge Systems Overview
Centrifuge Systems OverviewCentrifuge Systems Overview
Centrifuge Systems Overview
 
VINCI_poster
VINCI_posterVINCI_poster
VINCI_poster
 
Cloud EMR software
Cloud EMR softwareCloud EMR software
Cloud EMR software
 
Blockchain in Healthcare: An Overview
Blockchain in Healthcare: An OverviewBlockchain in Healthcare: An Overview
Blockchain in Healthcare: An Overview
 
HXR 2016: Free the Data Access & Integration -Jonathan Hare, WebShield
HXR 2016: Free the Data Access & Integration -Jonathan Hare, WebShieldHXR 2016: Free the Data Access & Integration -Jonathan Hare, WebShield
HXR 2016: Free the Data Access & Integration -Jonathan Hare, WebShield
 
Brisbane Health-y Data: Queensland Data Linkage Framework
Brisbane Health-y Data: Queensland Data Linkage FrameworkBrisbane Health-y Data: Queensland Data Linkage Framework
Brisbane Health-y Data: Queensland Data Linkage Framework
 
National Services Scotland Business Intelligence
National Services Scotland Business IntelligenceNational Services Scotland Business Intelligence
National Services Scotland Business Intelligence
 
Blockchain Technology for Patients Medical Records
Blockchain Technology for Patients Medical RecordsBlockchain Technology for Patients Medical Records
Blockchain Technology for Patients Medical Records
 
How blockchain is revolutionising healthcare industry’s challenges of genomic...
How blockchain is revolutionising healthcare industry’s challenges of genomic...How blockchain is revolutionising healthcare industry’s challenges of genomic...
How blockchain is revolutionising healthcare industry’s challenges of genomic...
 
Federated architecture
Federated architectureFederated architecture
Federated architecture
 
Efficient sharing of personal health records using encryption in cloud computing
Efficient sharing of personal health records using encryption in cloud computingEfficient sharing of personal health records using encryption in cloud computing
Efficient sharing of personal health records using encryption in cloud computing
 
Data cycle health
Data cycle healthData cycle health
Data cycle health
 
Role Of Blockchain Technology In Healthcare Sector
Role Of Blockchain Technology In Healthcare SectorRole Of Blockchain Technology In Healthcare Sector
Role Of Blockchain Technology In Healthcare Sector
 
secured storage of Personal health record in cloude
secured storage of Personal health record in cloudesecured storage of Personal health record in cloude
secured storage of Personal health record in cloude
 
Healthcare Highlights: HIT Drivers and Trends
Healthcare Highlights: HIT Drivers and TrendsHealthcare Highlights: HIT Drivers and Trends
Healthcare Highlights: HIT Drivers and Trends
 

Similar to OpenID Foundation Workshop at EIC 2018 - HEART Working Group Update

Przybysz, reinhardt ph rgroupproject_fall_2012
Przybysz, reinhardt ph rgroupproject_fall_2012Przybysz, reinhardt ph rgroupproject_fall_2012
Przybysz, reinhardt ph rgroupproject_fall_2012
jlreinhardt
 
Ensuring Data IntegrityIn Health Information Exchange
Ensuring Data IntegrityIn Health Information ExchangeEnsuring Data IntegrityIn Health Information Exchange
Ensuring Data IntegrityIn Health Information Exchange
TanaMaeskm
 
In search of a digital health compass: My data, my decision, our power
In search of a digital health compass: My data, my decision, our powerIn search of a digital health compass: My data, my decision, our power
In search of a digital health compass: My data, my decision, our power
chronaki
 

Similar to OpenID Foundation Workshop at EIC 2018 - HEART Working Group Update (20)

A12_Beyond_HIPAA_PPT1
A12_Beyond_HIPAA_PPT1A12_Beyond_HIPAA_PPT1
A12_Beyond_HIPAA_PPT1
 
HIE Practicum
HIE PracticumHIE Practicum
HIE Practicum
 
Healthcare Data Ecosystem 101
Healthcare Data Ecosystem 101Healthcare Data Ecosystem 101
Healthcare Data Ecosystem 101
 
Panel: Achieving Interoperability Dr. John Loonsk & Janet King
Panel: Achieving Interoperability Dr. John Loonsk & Janet KingPanel: Achieving Interoperability Dr. John Loonsk & Janet King
Panel: Achieving Interoperability Dr. John Loonsk & Janet King
 
In Electronic Health Records We Trust - IPPOSI Outcome Report - March 2017
In Electronic Health Records We Trust - IPPOSI Outcome Report - March 2017In Electronic Health Records We Trust - IPPOSI Outcome Report - March 2017
In Electronic Health Records We Trust - IPPOSI Outcome Report - March 2017
 
8.2 Demonstration Health - IT benifits - Bagmishika Puhan ( Session 8)
8.2   Demonstration Health - IT benifits - Bagmishika Puhan ( Session 8)8.2   Demonstration Health - IT benifits - Bagmishika Puhan ( Session 8)
8.2 Demonstration Health - IT benifits - Bagmishika Puhan ( Session 8)
 
Hipaa and social media using new
Hipaa and social media using newHipaa and social media using new
Hipaa and social media using new
 
3.0 FHIR Deep Dive AMIA SA 2022.pdf
3.0 FHIR Deep Dive AMIA SA 2022.pdf3.0 FHIR Deep Dive AMIA SA 2022.pdf
3.0 FHIR Deep Dive AMIA SA 2022.pdf
 
APIsecure 2023 - FHIR API Security, Grahame Grieve (Health Intersections)
APIsecure 2023 - FHIR API Security, Grahame Grieve (Health Intersections)APIsecure 2023 - FHIR API Security, Grahame Grieve (Health Intersections)
APIsecure 2023 - FHIR API Security, Grahame Grieve (Health Intersections)
 
DVHIMSS Ensuring Privacy and Security of HIEs in PA
DVHIMSS Ensuring Privacy and Security of HIEs in PADVHIMSS Ensuring Privacy and Security of HIEs in PA
DVHIMSS Ensuring Privacy and Security of HIEs in PA
 
Przybysz, reinhardt ph rgroupproject_fall_2012
Przybysz, reinhardt ph rgroupproject_fall_2012Przybysz, reinhardt ph rgroupproject_fall_2012
Przybysz, reinhardt ph rgroupproject_fall_2012
 
Big Data in Healthcare -- What Does it Mean?
Big Data in Healthcare -- What Does it Mean?Big Data in Healthcare -- What Does it Mean?
Big Data in Healthcare -- What Does it Mean?
 
Ensuring Data IntegrityIn Health Information Exchange
Ensuring Data IntegrityIn Health Information ExchangeEnsuring Data IntegrityIn Health Information Exchange
Ensuring Data IntegrityIn Health Information Exchange
 
Standards and Best Practices for Confidentiality of Electronic Health Records
Standards and Best Practices for Confidentiality of Electronic Health RecordsStandards and Best Practices for Confidentiality of Electronic Health Records
Standards and Best Practices for Confidentiality of Electronic Health Records
 
Trusted! Quest for data-driven and fair health solutions
Trusted! Quest for data-driven and fair health solutions Trusted! Quest for data-driven and fair health solutions
Trusted! Quest for data-driven and fair health solutions
 
EHRs, PHRs, EMRs: Making Sense of the Alphabet Soup
EHRs, PHRs, EMRs: Making Sense of the Alphabet SoupEHRs, PHRs, EMRs: Making Sense of the Alphabet Soup
EHRs, PHRs, EMRs: Making Sense of the Alphabet Soup
 
In search of a digital health compass: My data, my decision, our power
In search of a digital health compass: My data, my decision, our powerIn search of a digital health compass: My data, my decision, our power
In search of a digital health compass: My data, my decision, our power
 
Health IT and OpenMRS
Health IT and OpenMRSHealth IT and OpenMRS
Health IT and OpenMRS
 
ni2009 Phr Workshop Peter Part1
ni2009 Phr Workshop Peter Part1ni2009 Phr Workshop Peter Part1
ni2009 Phr Workshop Peter Part1
 
The Internet of Healthy Things (IoHT) for Healthcare Organizations Webinar
The Internet of Healthy Things (IoHT) for Healthcare Organizations WebinarThe Internet of Healthy Things (IoHT) for Healthcare Organizations Webinar
The Internet of Healthy Things (IoHT) for Healthcare Organizations Webinar
 

More from MikeLeszcz

More from MikeLeszcz (16)

OpenID Foundation Workshop at EIC 2018 - Introduction to the FAPI Read & Writ...
OpenID Foundation Workshop at EIC 2018 - Introduction to the FAPI Read & Writ...OpenID Foundation Workshop at EIC 2018 - Introduction to the FAPI Read & Writ...
OpenID Foundation Workshop at EIC 2018 - Introduction to the FAPI Read & Writ...
 
OpenID Foundation Workshop at EIC 2018 - Mobile Driver's License Presentantion
OpenID Foundation Workshop at EIC 2018 - Mobile Driver's License PresentantionOpenID Foundation Workshop at EIC 2018 - Mobile Driver's License Presentantion
OpenID Foundation Workshop at EIC 2018 - Mobile Driver's License Presentantion
 
OpenID Foundation Workshop at EIC 2018 - OpenID Enhanced Authentication Profi...
OpenID Foundation Workshop at EIC 2018 - OpenID Enhanced Authentication Profi...OpenID Foundation Workshop at EIC 2018 - OpenID Enhanced Authentication Profi...
OpenID Foundation Workshop at EIC 2018 - OpenID Enhanced Authentication Profi...
 
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group Update
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group UpdateOpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group Update
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group Update
 
OpenID Foundation Workshop at EIC 2018 - OpenID Certification Update
OpenID Foundation Workshop at EIC 2018 - OpenID Certification UpdateOpenID Foundation Workshop at EIC 2018 - OpenID Certification Update
OpenID Foundation Workshop at EIC 2018 - OpenID Certification Update
 
OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group Update
OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group UpdateOpenID Foundation Workshop at EIC 2018 - MODRNA Working Group Update
OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group Update
 
CIBA Profile Overview - OpenID Foundation/Open Banking Workshop - March 21, 2018
CIBA Profile Overview - OpenID Foundation/Open Banking Workshop - March 21, 2018CIBA Profile Overview - OpenID Foundation/Open Banking Workshop - March 21, 2018
CIBA Profile Overview - OpenID Foundation/Open Banking Workshop - March 21, 2018
 
OpenID Foundation RISC WG Update - 2018-04-02
OpenID Foundation RISC WG Update - 2018-04-02OpenID Foundation RISC WG Update - 2018-04-02
OpenID Foundation RISC WG Update - 2018-04-02
 
OpenID Certification Program Update - 2018-04-02
OpenID Certification Program Update - 2018-04-02OpenID Certification Program Update - 2018-04-02
OpenID Certification Program Update - 2018-04-02
 
OpenID Foundation's Risk Incident and Sharing Communication (RISC) Work Group...
OpenID Foundation's Risk Incident and Sharing Communication (RISC) Work Group...OpenID Foundation's Risk Incident and Sharing Communication (RISC) Work Group...
OpenID Foundation's Risk Incident and Sharing Communication (RISC) Work Group...
 
OpenID Foundation/Open Banking Workshop - OpenID Foundation Overview
OpenID Foundation/Open Banking Workshop - OpenID Foundation OverviewOpenID Foundation/Open Banking Workshop - OpenID Foundation Overview
OpenID Foundation/Open Banking Workshop - OpenID Foundation Overview
 
OpenID Foundation/Open Banking Workshop - Open Banking Update
OpenID Foundation/Open Banking Workshop - Open Banking UpdateOpenID Foundation/Open Banking Workshop - Open Banking Update
OpenID Foundation/Open Banking Workshop - Open Banking Update
 
OpenID Certification Program Update - 2017-10-16
OpenID Certification Program Update - 2017-10-16OpenID Certification Program Update - 2017-10-16
OpenID Certification Program Update - 2017-10-16
 
Banking is Now More Open: Open Banking Update
Banking is Now More Open: Open Banking UpdateBanking is Now More Open: Open Banking Update
Banking is Now More Open: Open Banking Update
 
OpenID Foundation FastFed Working Group Update - 2017-10-16
OpenID Foundation FastFed Working Group Update - 2017-10-16OpenID Foundation FastFed Working Group Update - 2017-10-16
OpenID Foundation FastFed Working Group Update - 2017-10-16
 
OpenID Foundation RISC WG Update - 2017-10-16
OpenID Foundation RISC WG Update - 2017-10-16OpenID Foundation RISC WG Update - 2017-10-16
OpenID Foundation RISC WG Update - 2017-10-16
 

Recently uploaded

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Recently uploaded (20)

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source Milvus
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 

OpenID Foundation Workshop at EIC 2018 - HEART Working Group Update

  • 1. Health Relationship Trust (HEART) Working Group Eve Maler, WG co-chair eve.maler@forgerock.com| @xmlgrrl 15 May 2018 http://openid.net/wg/heart/ 1
  • 2. Why HEART? • Health data is some of the most personal and private consumer data • It is increasingly digital, either at the source or when transcribed • The Internet of Healthy Things and genomic data are having an impact • Individuals want to be in control of gathering and sharing this data • Including giving permission for access – and revoking permission • Especially if they have complex conditions or have moved frequently • Clinicians, insurers, and researchers seek data access to diagnose, plan care, and pay for care, and need to know it’s authorized for use • HEART puts the individual back at the center of the health data- sharing conversation 2
  • 3. What does HEART do? To achieve RESTful, patient-centric, privacy-sensitive health data sharing… • It profiles OAuth, OpenID Connect, UMA, and the HL7 FHIR (Fast Healthcare Interoperability Resources) API • It provides the official FHIR API security mechanism • It is also aligning over time with the SMART on FHIR API effort developed for use with EHR systems, health portals, and Health Information Exchanges 3
  • 4. Who is involved? • Health/health IT subject matter experts • Doctors, government health agency reps… • Technology experts • Implementers, health startups, spec authors… • Leadership team: • Co-chair Debbie Bucci (US Health and Human Services Office of the National Coordinator) • Co-chair Eve Maler (ForgeRock) • Spec editor Justin Richer (Bespoke Engineering) 4
  • 5. Current state of the deliverables (see https://openid.bitbucket.io/HEART/) 5 • Mechanical = security profile • Semantic = API-specific profile • Considering whether to deprecate the UMA1 profiles
  • 6. New white paper and use case work (unpublished as yet) • Focused on new urgency in the quest for patient-mediated health data exchange solutions, e.g., in the US: • MyHealthEData • Promoting Interoperability (was “Meaningful Use”) • White paper: Enabling Patient-Mediated Health Data Exchange • With assistance from Jan Oldenburg of Participatory Healthcare • Use cases under review: • Alice electronically shares data from her PHR • Alice controls sharing of sensitive clinical data • Alice delegates to a personal representative 6
  • 7. HEART scope mechanisms Confidentiality and sensitivity • HL7 defines many codes for sensitive data types • E.g., sens/ETH for substance abuse • Similarly, it defines some codes for confidentiality levels • HEART allows an RS to use these as scopes • If such a scope is not associated with an access token, the RS SHOULD filter out the relevant data before delivering it, if at all possible Break-the-glass • HL7 defines a code btg for situations where the resource owner is unavailable • HEART allows an RS to use this as a scope • If such a scope is associated with an access token, the RS MUST log access made on this basis in an auditable format available to the resource owner 7 Note: All policy-setting UX options are “outside the scope of scope mechanisms” (e.g., policy defaulting).
  • 8. A potential third scope mechanism: de-identification • We are currently discussing whether to add a similar scope mechanism for enabling a patient to instruct the RS to deliver resources in de-identified form 8
  • 9. The Move Health Data Forward challenges (https://www.challenge.gov/challenge/move-health-data-forward-challenge/) • Starting mid-2016, HHS ONC challenged industry to create API solutions to help individuals authorize the movement of their health data • Three phases later, several winners have won awards, including for some solutions based on the HEART profiles 9
  • 10. Thank you! Questions? Join us! Eve Maler, WG co-chair eve.maler@forgerock.com| @xmlgrrl 15 May 2018 http://openid.net/wg/heart/ 10