SlideShare une entreprise Scribd logo
1  sur  33
Healthcare Identity Management and  Role-Based Access  in a  Federated NHIN   The e-Authentication Project Phase 4 Co-presenters: Richard Moore, President eHealth Ohio and John Fraser, CEO MEDNETWorld.com Session 246  HIMSS 2010 Atlanta, GA Thursday, March 4, 11:15 AM - 12:15 PM
Conflict of Interest Disclosure   Rick Moore and John Fraser ,[object Object],[object Object]
Abstract ,[object Object],[object Object],[object Object],[object Object],[object Object]
Talk Outline ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Key Problems ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Opportunity ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Key Benefits ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
 
Past projects - eHealth Ohio and MN ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],Phase 1 - HIMSS/GSA eAuthentication Project
Phase 1  – 8 Participants - 2006 ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Phase 2 – 5 Participants - 2007/2008 ,[object Object],[object Object],[object Object],[object Object],[object Object]
Phase 3 – 2008/2009 ,[object Object],[object Object],[object Object],[object Object],[object Object]
Phase 4 – 2009  ,[object Object],[object Object],[object Object],[object Object],[object Object]
 
eHealth Ohio Developments 2009 ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
RLS Service Service Provider MEDNET Gateway MEDNET NHIN Gateway MEDNET Gateway MEDNET Gateway MEDNET NHIN Gateway MEDNET HIE Identity Provider Identity Provider TechColumbus Platform Lab Physician  Portal eHealth  Rubicon Service  Service Provider EHR/EMR SOAP/HTTPS Firewall Firewall eHealth Ohio Developments 2009
 
MEDNET HIE-Bridge Case Study ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
MEDNET HIE-Bridge Case Study (cont) ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
CHIC & eHealth Ohio – Record Locator Service & NHIN CHIC SISU / St.Luke’s  VRMC Users NHIN Backbone connecting HIEs Community Security/ Privacy Officers Log Reviews Personal Health Record (PHR) Role Based Access Control Service Community Patient Privacy Manager Audit Database XDS Registry and Repository Patient Clinical Info Retrieval Lookup MEDNET GRID SERVER Immunization Connection eHealth Ohio,  Rubicon TechColumbus Test server  LOGIN MEDNET NHIN Gateway Record Locator Service Federated Identity Management Service
 
What is the Nationwide Health Information Network - NHIN ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
NHIN Connectivity Overview Your existing sites Your organizations network Feds: SSA, DoD, VA, CDC, etc Nationwide Health Information Network - NHIN INTERNET Payers Providers State & Local Health Information Exchanges (HIE)
NHIN Needs ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
NHIN Message Security ,[object Object],[object Object],[object Object],[object Object],[object Object],Messages between HIEs must be:
NHIN Message Security* Required in all NHIN SOAP messages (*) standard SAML-secured SOAP message – not NHIN specific Example payload: HL7v3 CCD Message in XML format
Who am I on NHIN? ,[object Object],[object Object],[object Object],[object Object]
CHIC & eHealth Ohio – Record Locator Service & NHIN CHIC SISU / St.Luke’s  VRMC Users NHIN Backbone connecting HIEs Community Security/ Privacy Officers Log Reviews Personal Health Record (PHR) Role Based Access Control Service Community Patient Privacy Manager Audit Database XDS Registry and Repository Patient Clinical Info Retrieval Lookup MEDNET GRID SERVER Immunization Connection eHealth Ohio,  Rubicon TechColumbus Test server  LOGIN MEDNET NHIN Gateway Record Locator Service Federated Identity Management Service
Recommendations and Future Vision ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Kantara Initiative – Leading the Way ,[object Object],[object Object],[object Object],[object Object],[object Object]
Resources To learn more about NHIN: Visit:  http://blog.mednetworld.com/survey to complete a two question survey on our talk, and download a free copy of an e-Book that we've developed on the topic.
Presenter information: ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]

Contenu connexe

Tendances

UplinQ - enhance qualcomm® snapdragon™ audio using android audio ap_is
UplinQ - enhance qualcomm® snapdragon™ audio using android audio ap_isUplinQ - enhance qualcomm® snapdragon™ audio using android audio ap_is
UplinQ - enhance qualcomm® snapdragon™ audio using android audio ap_isSatya Harish
 
Etude des Vulnérabilités dans les réseaux 3G,4G et simulation d’attaques des ...
Etude des Vulnérabilités dans les réseaux 3G,4G et simulation d’attaques des ...Etude des Vulnérabilités dans les réseaux 3G,4G et simulation d’attaques des ...
Etude des Vulnérabilités dans les réseaux 3G,4G et simulation d’attaques des ...Danaelmousawi
 
Sécurité de la VoIP : quels risques et quelles solutions pour votre entrepris...
Sécurité de la VoIP : quels risques et quelles solutions pour votre entrepris...Sécurité de la VoIP : quels risques et quelles solutions pour votre entrepris...
Sécurité de la VoIP : quels risques et quelles solutions pour votre entrepris...Ava Axialys
 
Simulation d’un système à temps partagé
Simulation d’un système à temps partagéSimulation d’un système à temps partagé
Simulation d’un système à temps partagéBachir Benyammi
 
Final show
Final showFinal show
Final showflorenzo
 
Codesys v3.5 découverte du logiciel
Codesys v3.5 découverte du logicielCodesys v3.5 découverte du logiciel
Codesys v3.5 découverte du logicielJulien Dubois
 
Fundamentals of EtherNet/IP Network Technology
Fundamentals of EtherNet/IP Network TechnologyFundamentals of EtherNet/IP Network Technology
Fundamentals of EtherNet/IP Network TechnologyRockwell Automation
 
Capitalisation dans le Projet de Développement des Filières du Safran et du P...
Capitalisation dans le Projet de Développement des Filières du Safran et du P...Capitalisation dans le Projet de Développement des Filières du Safran et du P...
Capitalisation dans le Projet de Développement des Filières du Safran et du P...BTC CTB
 
Cablage structuré
Cablage structuréCablage structuré
Cablage structuréaziz rafa
 
L\'authentification forte : Concept et Technologies
L\'authentification forte : Concept et TechnologiesL\'authentification forte : Concept et Technologies
L\'authentification forte : Concept et TechnologiesIbrahima FALL
 

Tendances (20)

mis en place dun vpn site à site
mis en place dun vpn site à site mis en place dun vpn site à site
mis en place dun vpn site à site
 
UplinQ - enhance qualcomm® snapdragon™ audio using android audio ap_is
UplinQ - enhance qualcomm® snapdragon™ audio using android audio ap_isUplinQ - enhance qualcomm® snapdragon™ audio using android audio ap_is
UplinQ - enhance qualcomm® snapdragon™ audio using android audio ap_is
 
Etude des Vulnérabilités dans les réseaux 3G,4G et simulation d’attaques des ...
Etude des Vulnérabilités dans les réseaux 3G,4G et simulation d’attaques des ...Etude des Vulnérabilités dans les réseaux 3G,4G et simulation d’attaques des ...
Etude des Vulnérabilités dans les réseaux 3G,4G et simulation d’attaques des ...
 
IPsec
IPsecIPsec
IPsec
 
Sécurité de la VoIP : quels risques et quelles solutions pour votre entrepris...
Sécurité de la VoIP : quels risques et quelles solutions pour votre entrepris...Sécurité de la VoIP : quels risques et quelles solutions pour votre entrepris...
Sécurité de la VoIP : quels risques et quelles solutions pour votre entrepris...
 
2 codage source
2 codage source2 codage source
2 codage source
 
Présentation VOIP
Présentation  VOIPPrésentation  VOIP
Présentation VOIP
 
Telephonie ip
Telephonie ipTelephonie ip
Telephonie ip
 
Ccna4
Ccna4Ccna4
Ccna4
 
Simulation d’un système à temps partagé
Simulation d’un système à temps partagéSimulation d’un système à temps partagé
Simulation d’un système à temps partagé
 
Fortran
FortranFortran
Fortran
 
Switches and LEDs interface to the 8051 microcontroller
Switches and LEDs interface to the 8051 microcontrollerSwitches and LEDs interface to the 8051 microcontroller
Switches and LEDs interface to the 8051 microcontroller
 
Final show
Final showFinal show
Final show
 
Codesys v3.5 découverte du logiciel
Codesys v3.5 découverte du logicielCodesys v3.5 découverte du logiciel
Codesys v3.5 découverte du logiciel
 
Fundamentals of EtherNet/IP Network Technology
Fundamentals of EtherNet/IP Network TechnologyFundamentals of EtherNet/IP Network Technology
Fundamentals of EtherNet/IP Network Technology
 
Capitalisation dans le Projet de Développement des Filières du Safran et du P...
Capitalisation dans le Projet de Développement des Filières du Safran et du P...Capitalisation dans le Projet de Développement des Filières du Safran et du P...
Capitalisation dans le Projet de Développement des Filières du Safran et du P...
 
MPLS VPN
MPLS VPNMPLS VPN
MPLS VPN
 
Cablage structuré
Cablage structuréCablage structuré
Cablage structuré
 
L\'authentification forte : Concept et Technologies
L\'authentification forte : Concept et TechnologiesL\'authentification forte : Concept et Technologies
L\'authentification forte : Concept et Technologies
 
Ethernet
EthernetEthernet
Ethernet
 

En vedette

eHealth Governance, Security and Privacy a UK Perspective
eHealthGovernance, Security and Privacya UK PerspectiveeHealthGovernance, Security and Privacya UK Perspective
eHealth Governance, Security and Privacy a UK PerspectiveHealth Informatics New Zealand
 
The Role of Content Management in Electronic Health Records (EMR)
The Role of Content Management in Electronic Health Records (EMR)The Role of Content Management in Electronic Health Records (EMR)
The Role of Content Management in Electronic Health Records (EMR)John Wang
 
2015 Cyber security solutions vs cyber criminals @WOHIT2015 (EU eHealth week)
2015 Cyber security solutions vs cyber criminals @WOHIT2015 (EU eHealth week)2015 Cyber security solutions vs cyber criminals @WOHIT2015 (EU eHealth week)
2015 Cyber security solutions vs cyber criminals @WOHIT2015 (EU eHealth week)Andris Soroka
 
Tellerpass - an OTP SIM applet for Banking
Tellerpass - an OTP SIM applet for BankingTellerpass - an OTP SIM applet for Banking
Tellerpass - an OTP SIM applet for BankingYiannis Hatzopoulos
 
Aleksandar Zivaljevic - Annotation of clinical datasets using openEHR Archety...
Aleksandar Zivaljevic - Annotation of clinical datasets using openEHR Archety...Aleksandar Zivaljevic - Annotation of clinical datasets using openEHR Archety...
Aleksandar Zivaljevic - Annotation of clinical datasets using openEHR Archety...Health Informatics New Zealand
 
Role based access control - RBAC
Role based access control - RBACRole based access control - RBAC
Role based access control - RBACAjit Dadresa
 
New Access Models for Healthcare
New Access Models for HealthcareNew Access Models for Healthcare
New Access Models for HealthcareTyrone Grandison
 

En vedette (8)

Lukas - Ancaman E-Health Security
Lukas - Ancaman E-Health SecurityLukas - Ancaman E-Health Security
Lukas - Ancaman E-Health Security
 
eHealth Governance, Security and Privacy a UK Perspective
eHealthGovernance, Security and Privacya UK PerspectiveeHealthGovernance, Security and Privacya UK Perspective
eHealth Governance, Security and Privacy a UK Perspective
 
The Role of Content Management in Electronic Health Records (EMR)
The Role of Content Management in Electronic Health Records (EMR)The Role of Content Management in Electronic Health Records (EMR)
The Role of Content Management in Electronic Health Records (EMR)
 
2015 Cyber security solutions vs cyber criminals @WOHIT2015 (EU eHealth week)
2015 Cyber security solutions vs cyber criminals @WOHIT2015 (EU eHealth week)2015 Cyber security solutions vs cyber criminals @WOHIT2015 (EU eHealth week)
2015 Cyber security solutions vs cyber criminals @WOHIT2015 (EU eHealth week)
 
Tellerpass - an OTP SIM applet for Banking
Tellerpass - an OTP SIM applet for BankingTellerpass - an OTP SIM applet for Banking
Tellerpass - an OTP SIM applet for Banking
 
Aleksandar Zivaljevic - Annotation of clinical datasets using openEHR Archety...
Aleksandar Zivaljevic - Annotation of clinical datasets using openEHR Archety...Aleksandar Zivaljevic - Annotation of clinical datasets using openEHR Archety...
Aleksandar Zivaljevic - Annotation of clinical datasets using openEHR Archety...
 
Role based access control - RBAC
Role based access control - RBACRole based access control - RBAC
Role based access control - RBAC
 
New Access Models for Healthcare
New Access Models for HealthcareNew Access Models for Healthcare
New Access Models for Healthcare
 

Similaire à Healthcare Identity Management and Role-Based Access in a Federated NHIN - The e-Authentication Project Phase 4

Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...Richard Moore
 
HIMSS GSA e-Authentication whitepaper June 2007
HIMSS GSA e-Authentication whitepaper June 2007HIMSS GSA e-Authentication whitepaper June 2007
HIMSS GSA e-Authentication whitepaper June 2007Richard Moore
 
Open source’s role in CONNECTing the public and private sector healthcare com...
Open source’s role in CONNECTing the public and private sector healthcare com...Open source’s role in CONNECTing the public and private sector healthcare com...
Open source’s role in CONNECTing the public and private sector healthcare com...Brian Ahier
 
Privacy on FHIR Demo at HIMSS!5
Privacy on FHIR Demo at HIMSS!5Privacy on FHIR Demo at HIMSS!5
Privacy on FHIR Demo at HIMSS!5agropper
 
Evaluating How Blockchain Can Transform the Pharmaceutical and Healthcare Ind...
Evaluating How Blockchain Can Transform the Pharmaceutical and Healthcare Ind...Evaluating How Blockchain Can Transform the Pharmaceutical and Healthcare Ind...
Evaluating How Blockchain Can Transform the Pharmaceutical and Healthcare Ind...Kate Barlow
 
Creating a target architecture for a learning health
Creating a target architecture for a learning healthCreating a target architecture for a learning health
Creating a target architecture for a learning healthWessex AHSN
 
Ndhm presentation-for-stakeholder-consultation-hospitals-diagnostic-centres-i...
Ndhm presentation-for-stakeholder-consultation-hospitals-diagnostic-centres-i...Ndhm presentation-for-stakeholder-consultation-hospitals-diagnostic-centres-i...
Ndhm presentation-for-stakeholder-consultation-hospitals-diagnostic-centres-i...Manish Nachnani
 
Webinar digitally transforming healthcare with blockchain
Webinar   digitally transforming healthcare with blockchainWebinar   digitally transforming healthcare with blockchain
Webinar digitally transforming healthcare with blockchainKaleido
 
Health Information Flows Technical Standards - V 0.5
Health Information Flows Technical Standards - V 0.5Health Information Flows Technical Standards - V 0.5
Health Information Flows Technical Standards - V 0.5ProductNation/iSPIRT
 
CONNECT: An Open Source Platform for Promoting Military Health
CONNECT: An Open Source Platform for Promoting Military HealthCONNECT: An Open Source Platform for Promoting Military Health
CONNECT: An Open Source Platform for Promoting Military HealthJoshua L. Davis
 
Mobile monday mhealth
Mobile monday mhealthMobile monday mhealth
Mobile monday mhealthJoe Drumgoole
 
Data systems web_integration_v0 1
Data systems web_integration_v0 1Data systems web_integration_v0 1
Data systems web_integration_v0 1Arnulfo Jr Rosario
 
iUZ.Talk - Cross-border Interoperability
iUZ.Talk - Cross-border InteroperabilityiUZ.Talk - Cross-border Interoperability
iUZ.Talk - Cross-border InteroperabilityiUZ_Technologies
 
MiHIN Direct Webinar for EHR Intelligence v10 11 12-14
MiHIN Direct Webinar for EHR Intelligence v10 11 12-14MiHIN Direct Webinar for EHR Intelligence v10 11 12-14
MiHIN Direct Webinar for EHR Intelligence v10 11 12-14mihinpr
 
N ye c-rfp-two-factor-authentication
N ye c-rfp-two-factor-authenticationN ye c-rfp-two-factor-authentication
N ye c-rfp-two-factor-authenticationHai Nguyen
 
Direct Project HITSC Update 03.29.11
Direct Project HITSC Update 03.29.11Direct Project HITSC Update 03.29.11
Direct Project HITSC Update 03.29.11Brian Ahier
 
Blockchain in Health Care
Blockchain in Health CareBlockchain in Health Care
Blockchain in Health CarePolsinelli PC
 

Similaire à Healthcare Identity Management and Role-Based Access in a Federated NHIN - The e-Authentication Project Phase 4 (20)

Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
 
HIMSS GSA e-Authentication whitepaper June 2007
HIMSS GSA e-Authentication whitepaper June 2007HIMSS GSA e-Authentication whitepaper June 2007
HIMSS GSA e-Authentication whitepaper June 2007
 
Open source’s role in CONNECTing the public and private sector healthcare com...
Open source’s role in CONNECTing the public and private sector healthcare com...Open source’s role in CONNECTing the public and private sector healthcare com...
Open source’s role in CONNECTing the public and private sector healthcare com...
 
Privacy on FHIR Demo at HIMSS!5
Privacy on FHIR Demo at HIMSS!5Privacy on FHIR Demo at HIMSS!5
Privacy on FHIR Demo at HIMSS!5
 
Evaluating How Blockchain Can Transform the Pharmaceutical and Healthcare Ind...
Evaluating How Blockchain Can Transform the Pharmaceutical and Healthcare Ind...Evaluating How Blockchain Can Transform the Pharmaceutical and Healthcare Ind...
Evaluating How Blockchain Can Transform the Pharmaceutical and Healthcare Ind...
 
CMS III and eHR
CMS III and eHRCMS III and eHR
CMS III and eHR
 
Creating a target architecture for a learning health
Creating a target architecture for a learning healthCreating a target architecture for a learning health
Creating a target architecture for a learning health
 
Ehealth
EhealthEhealth
Ehealth
 
Ndhm presentation-for-stakeholder-consultation-hospitals-diagnostic-centres-i...
Ndhm presentation-for-stakeholder-consultation-hospitals-diagnostic-centres-i...Ndhm presentation-for-stakeholder-consultation-hospitals-diagnostic-centres-i...
Ndhm presentation-for-stakeholder-consultation-hospitals-diagnostic-centres-i...
 
Webinar digitally transforming healthcare with blockchain
Webinar   digitally transforming healthcare with blockchainWebinar   digitally transforming healthcare with blockchain
Webinar digitally transforming healthcare with blockchain
 
Health Information Flows Technical Standards - V 0.5
Health Information Flows Technical Standards - V 0.5Health Information Flows Technical Standards - V 0.5
Health Information Flows Technical Standards - V 0.5
 
CONNECT: An Open Source Platform for Promoting Military Health
CONNECT: An Open Source Platform for Promoting Military HealthCONNECT: An Open Source Platform for Promoting Military Health
CONNECT: An Open Source Platform for Promoting Military Health
 
Mobile monday mhealth
Mobile monday mhealthMobile monday mhealth
Mobile monday mhealth
 
Data systems web_integration_v0 1
Data systems web_integration_v0 1Data systems web_integration_v0 1
Data systems web_integration_v0 1
 
iUZ.Talk - Cross-border Interoperability
iUZ.Talk - Cross-border InteroperabilityiUZ.Talk - Cross-border Interoperability
iUZ.Talk - Cross-border Interoperability
 
2016 iHT2 Miami Health IT Summit
2016 iHT2 Miami Health IT Summit2016 iHT2 Miami Health IT Summit
2016 iHT2 Miami Health IT Summit
 
MiHIN Direct Webinar for EHR Intelligence v10 11 12-14
MiHIN Direct Webinar for EHR Intelligence v10 11 12-14MiHIN Direct Webinar for EHR Intelligence v10 11 12-14
MiHIN Direct Webinar for EHR Intelligence v10 11 12-14
 
N ye c-rfp-two-factor-authentication
N ye c-rfp-two-factor-authenticationN ye c-rfp-two-factor-authentication
N ye c-rfp-two-factor-authentication
 
Direct Project HITSC Update 03.29.11
Direct Project HITSC Update 03.29.11Direct Project HITSC Update 03.29.11
Direct Project HITSC Update 03.29.11
 
Blockchain in Health Care
Blockchain in Health CareBlockchain in Health Care
Blockchain in Health Care
 

Plus de Richard Moore

HIMSS18 HIMSS SPOT Making an Impact on State Health Policy, Ohio HIT Day 2017...
HIMSS18 HIMSS SPOT Making an Impact on State Health Policy, Ohio HIT Day 2017...HIMSS18 HIMSS SPOT Making an Impact on State Health Policy, Ohio HIT Day 2017...
HIMSS18 HIMSS SPOT Making an Impact on State Health Policy, Ohio HIT Day 2017...Richard Moore
 
Making an Impact on Critical Healthcare Public Policy Issues: National & Stat...
Making an Impact on Critical Healthcare Public Policy Issues: National & Stat...Making an Impact on Critical Healthcare Public Policy Issues: National & Stat...
Making an Impact on Critical Healthcare Public Policy Issues: National & Stat...Richard Moore
 
OHIT Day 2016 Report for HIMSS Chapter Advocacy RMoore
OHIT Day 2016 Report for HIMSS Chapter Advocacy RMooreOHIT Day 2016 Report for HIMSS Chapter Advocacy RMoore
OHIT Day 2016 Report for HIMSS Chapter Advocacy RMooreRichard Moore
 
OHIT Day 2015 Report for HIMSS Chapter Advocacy Roundtable
OHIT Day 2015 Report for HIMSS Chapter Advocacy RoundtableOHIT Day 2015 Report for HIMSS Chapter Advocacy Roundtable
OHIT Day 2015 Report for HIMSS Chapter Advocacy RoundtableRichard Moore
 
Ohio Healthcare Information Technology (OHIT) Day 2014 Report
Ohio Healthcare Information Technology (OHIT) Day 2014 Report Ohio Healthcare Information Technology (OHIT) Day 2014 Report
Ohio Healthcare Information Technology (OHIT) Day 2014 Report Richard Moore
 
Richard Moore Resume 2016
Richard Moore Resume 2016Richard Moore Resume 2016
Richard Moore Resume 2016Richard Moore
 
CSOHIMSS - OSU HIMS Students 20100920
CSOHIMSS - OSU HIMS Students 20100920CSOHIMSS - OSU HIMS Students 20100920
CSOHIMSS - OSU HIMS Students 20100920Richard Moore
 
HIMSS State Government Advocacy Day Roundtable - HIMSS Annual Meeting 2009 Ch...
HIMSS State Government Advocacy Day Roundtable - HIMSS Annual Meeting 2009 Ch...HIMSS State Government Advocacy Day Roundtable - HIMSS Annual Meeting 2009 Ch...
HIMSS State Government Advocacy Day Roundtable - HIMSS Annual Meeting 2009 Ch...Richard Moore
 

Plus de Richard Moore (8)

HIMSS18 HIMSS SPOT Making an Impact on State Health Policy, Ohio HIT Day 2017...
HIMSS18 HIMSS SPOT Making an Impact on State Health Policy, Ohio HIT Day 2017...HIMSS18 HIMSS SPOT Making an Impact on State Health Policy, Ohio HIT Day 2017...
HIMSS18 HIMSS SPOT Making an Impact on State Health Policy, Ohio HIT Day 2017...
 
Making an Impact on Critical Healthcare Public Policy Issues: National & Stat...
Making an Impact on Critical Healthcare Public Policy Issues: National & Stat...Making an Impact on Critical Healthcare Public Policy Issues: National & Stat...
Making an Impact on Critical Healthcare Public Policy Issues: National & Stat...
 
OHIT Day 2016 Report for HIMSS Chapter Advocacy RMoore
OHIT Day 2016 Report for HIMSS Chapter Advocacy RMooreOHIT Day 2016 Report for HIMSS Chapter Advocacy RMoore
OHIT Day 2016 Report for HIMSS Chapter Advocacy RMoore
 
OHIT Day 2015 Report for HIMSS Chapter Advocacy Roundtable
OHIT Day 2015 Report for HIMSS Chapter Advocacy RoundtableOHIT Day 2015 Report for HIMSS Chapter Advocacy Roundtable
OHIT Day 2015 Report for HIMSS Chapter Advocacy Roundtable
 
Ohio Healthcare Information Technology (OHIT) Day 2014 Report
Ohio Healthcare Information Technology (OHIT) Day 2014 Report Ohio Healthcare Information Technology (OHIT) Day 2014 Report
Ohio Healthcare Information Technology (OHIT) Day 2014 Report
 
Richard Moore Resume 2016
Richard Moore Resume 2016Richard Moore Resume 2016
Richard Moore Resume 2016
 
CSOHIMSS - OSU HIMS Students 20100920
CSOHIMSS - OSU HIMS Students 20100920CSOHIMSS - OSU HIMS Students 20100920
CSOHIMSS - OSU HIMS Students 20100920
 
HIMSS State Government Advocacy Day Roundtable - HIMSS Annual Meeting 2009 Ch...
HIMSS State Government Advocacy Day Roundtable - HIMSS Annual Meeting 2009 Ch...HIMSS State Government Advocacy Day Roundtable - HIMSS Annual Meeting 2009 Ch...
HIMSS State Government Advocacy Day Roundtable - HIMSS Annual Meeting 2009 Ch...
 

Dernier

VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...jageshsingh5554
 
VIP Call Girls Indore Kirti 💚😋 9256729539 🚀 Indore Escorts
VIP Call Girls Indore Kirti 💚😋  9256729539 🚀 Indore EscortsVIP Call Girls Indore Kirti 💚😋  9256729539 🚀 Indore Escorts
VIP Call Girls Indore Kirti 💚😋 9256729539 🚀 Indore Escortsaditipandeya
 
Call Girls Faridabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Faridabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Faridabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Faridabad Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
💎VVIP Kolkata Call Girls Parganas🩱7001035870🩱Independent Girl ( Ac Rooms Avai...
💎VVIP Kolkata Call Girls Parganas🩱7001035870🩱Independent Girl ( Ac Rooms Avai...💎VVIP Kolkata Call Girls Parganas🩱7001035870🩱Independent Girl ( Ac Rooms Avai...
💎VVIP Kolkata Call Girls Parganas🩱7001035870🩱Independent Girl ( Ac Rooms Avai...Taniya Sharma
 
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls AvailableVip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls AvailableNehru place Escorts
 
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...astropune
 
Call Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore Escorts
Call Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore EscortsCall Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore Escorts
Call Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore Escortsvidya singh
 
Call Girls Varanasi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Varanasi Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Varanasi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Varanasi Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Siliguri Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Siliguri Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Siliguri Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Siliguri Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Chandrapur Call girls 8617370543 Provides all area service COD available
Chandrapur Call girls 8617370543 Provides all area service COD availableChandrapur Call girls 8617370543 Provides all area service COD available
Chandrapur Call girls 8617370543 Provides all area service COD availableDipal Arora
 
VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...
VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...
VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...Garima Khatri
 
VIP Russian Call Girls in Varanasi Samaira 8250192130 Independent Escort Serv...
VIP Russian Call Girls in Varanasi Samaira 8250192130 Independent Escort Serv...VIP Russian Call Girls in Varanasi Samaira 8250192130 Independent Escort Serv...
VIP Russian Call Girls in Varanasi Samaira 8250192130 Independent Escort Serv...Neha Kaur
 
Call Girls Ooty Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ooty Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Ooty Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ooty Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...chandars293
 
High Profile Call Girls Coimbatore Saanvi☎️ 8250192130 Independent Escort Se...
High Profile Call Girls Coimbatore Saanvi☎️  8250192130 Independent Escort Se...High Profile Call Girls Coimbatore Saanvi☎️  8250192130 Independent Escort Se...
High Profile Call Girls Coimbatore Saanvi☎️ 8250192130 Independent Escort Se...narwatsonia7
 
Call Girls Jabalpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Jabalpur Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Jabalpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Jabalpur Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Service Jaipur Grishma WhatsApp ❤8445551418 VIP Call Girls Jaipur
Call Girls Service Jaipur Grishma WhatsApp ❤8445551418 VIP Call Girls JaipurCall Girls Service Jaipur Grishma WhatsApp ❤8445551418 VIP Call Girls Jaipur
Call Girls Service Jaipur Grishma WhatsApp ❤8445551418 VIP Call Girls Jaipurparulsinha
 
Top Rated Bangalore Call Girls Richmond Circle ⟟ 8250192130 ⟟ Call Me For Gen...
Top Rated Bangalore Call Girls Richmond Circle ⟟ 8250192130 ⟟ Call Me For Gen...Top Rated Bangalore Call Girls Richmond Circle ⟟ 8250192130 ⟟ Call Me For Gen...
Top Rated Bangalore Call Girls Richmond Circle ⟟ 8250192130 ⟟ Call Me For Gen...narwatsonia7
 
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Lucknow Call girls - 8800925952 - 24x7 service with hotel room
Lucknow Call girls - 8800925952 - 24x7 service with hotel roomLucknow Call girls - 8800925952 - 24x7 service with hotel room
Lucknow Call girls - 8800925952 - 24x7 service with hotel roomdiscovermytutordmt
 

Dernier (20)

VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
 
VIP Call Girls Indore Kirti 💚😋 9256729539 🚀 Indore Escorts
VIP Call Girls Indore Kirti 💚😋  9256729539 🚀 Indore EscortsVIP Call Girls Indore Kirti 💚😋  9256729539 🚀 Indore Escorts
VIP Call Girls Indore Kirti 💚😋 9256729539 🚀 Indore Escorts
 
Call Girls Faridabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Faridabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Faridabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Faridabad Just Call 9907093804 Top Class Call Girl Service Available
 
💎VVIP Kolkata Call Girls Parganas🩱7001035870🩱Independent Girl ( Ac Rooms Avai...
💎VVIP Kolkata Call Girls Parganas🩱7001035870🩱Independent Girl ( Ac Rooms Avai...💎VVIP Kolkata Call Girls Parganas🩱7001035870🩱Independent Girl ( Ac Rooms Avai...
💎VVIP Kolkata Call Girls Parganas🩱7001035870🩱Independent Girl ( Ac Rooms Avai...
 
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls AvailableVip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
 
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...
 
Call Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore Escorts
Call Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore EscortsCall Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore Escorts
Call Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore Escorts
 
Call Girls Varanasi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Varanasi Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Varanasi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Varanasi Just Call 9907093804 Top Class Call Girl Service Available
 
Call Girls Siliguri Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Siliguri Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Siliguri Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Siliguri Just Call 9907093804 Top Class Call Girl Service Available
 
Chandrapur Call girls 8617370543 Provides all area service COD available
Chandrapur Call girls 8617370543 Provides all area service COD availableChandrapur Call girls 8617370543 Provides all area service COD available
Chandrapur Call girls 8617370543 Provides all area service COD available
 
VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...
VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...
VIP Mumbai Call Girls Hiranandani Gardens Just Call 9920874524 with A/C Room ...
 
VIP Russian Call Girls in Varanasi Samaira 8250192130 Independent Escort Serv...
VIP Russian Call Girls in Varanasi Samaira 8250192130 Independent Escort Serv...VIP Russian Call Girls in Varanasi Samaira 8250192130 Independent Escort Serv...
VIP Russian Call Girls in Varanasi Samaira 8250192130 Independent Escort Serv...
 
Call Girls Ooty Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ooty Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Ooty Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ooty Just Call 9907093804 Top Class Call Girl Service Available
 
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...
The Most Attractive Hyderabad Call Girls Kothapet 𖠋 6297143586 𖠋 Will You Mis...
 
High Profile Call Girls Coimbatore Saanvi☎️ 8250192130 Independent Escort Se...
High Profile Call Girls Coimbatore Saanvi☎️  8250192130 Independent Escort Se...High Profile Call Girls Coimbatore Saanvi☎️  8250192130 Independent Escort Se...
High Profile Call Girls Coimbatore Saanvi☎️ 8250192130 Independent Escort Se...
 
Call Girls Jabalpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Jabalpur Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Jabalpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Jabalpur Just Call 9907093804 Top Class Call Girl Service Available
 
Call Girls Service Jaipur Grishma WhatsApp ❤8445551418 VIP Call Girls Jaipur
Call Girls Service Jaipur Grishma WhatsApp ❤8445551418 VIP Call Girls JaipurCall Girls Service Jaipur Grishma WhatsApp ❤8445551418 VIP Call Girls Jaipur
Call Girls Service Jaipur Grishma WhatsApp ❤8445551418 VIP Call Girls Jaipur
 
Top Rated Bangalore Call Girls Richmond Circle ⟟ 8250192130 ⟟ Call Me For Gen...
Top Rated Bangalore Call Girls Richmond Circle ⟟ 8250192130 ⟟ Call Me For Gen...Top Rated Bangalore Call Girls Richmond Circle ⟟ 8250192130 ⟟ Call Me For Gen...
Top Rated Bangalore Call Girls Richmond Circle ⟟ 8250192130 ⟟ Call Me For Gen...
 
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
 
Lucknow Call girls - 8800925952 - 24x7 service with hotel room
Lucknow Call girls - 8800925952 - 24x7 service with hotel roomLucknow Call girls - 8800925952 - 24x7 service with hotel room
Lucknow Call girls - 8800925952 - 24x7 service with hotel room
 

Healthcare Identity Management and Role-Based Access in a Federated NHIN - The e-Authentication Project Phase 4

  • 1. Healthcare Identity Management and Role-Based Access in a Federated NHIN The e-Authentication Project Phase 4 Co-presenters: Richard Moore, President eHealth Ohio and John Fraser, CEO MEDNETWorld.com Session 246 HIMSS 2010 Atlanta, GA Thursday, March 4, 11:15 AM - 12:15 PM
  • 2.
  • 3.
  • 4.
  • 5.
  • 6.
  • 7.
  • 8.  
  • 9.
  • 10.
  • 11.
  • 12.
  • 13.
  • 14.
  • 15.  
  • 16.
  • 17. RLS Service Service Provider MEDNET Gateway MEDNET NHIN Gateway MEDNET Gateway MEDNET Gateway MEDNET NHIN Gateway MEDNET HIE Identity Provider Identity Provider TechColumbus Platform Lab Physician Portal eHealth Rubicon Service Service Provider EHR/EMR SOAP/HTTPS Firewall Firewall eHealth Ohio Developments 2009
  • 18.  
  • 19.
  • 20.
  • 21. CHIC & eHealth Ohio – Record Locator Service & NHIN CHIC SISU / St.Luke’s VRMC Users NHIN Backbone connecting HIEs Community Security/ Privacy Officers Log Reviews Personal Health Record (PHR) Role Based Access Control Service Community Patient Privacy Manager Audit Database XDS Registry and Repository Patient Clinical Info Retrieval Lookup MEDNET GRID SERVER Immunization Connection eHealth Ohio, Rubicon TechColumbus Test server LOGIN MEDNET NHIN Gateway Record Locator Service Federated Identity Management Service
  • 22.  
  • 23.
  • 24. NHIN Connectivity Overview Your existing sites Your organizations network Feds: SSA, DoD, VA, CDC, etc Nationwide Health Information Network - NHIN INTERNET Payers Providers State & Local Health Information Exchanges (HIE)
  • 25.
  • 26.
  • 27. NHIN Message Security* Required in all NHIN SOAP messages (*) standard SAML-secured SOAP message – not NHIN specific Example payload: HL7v3 CCD Message in XML format
  • 28.
  • 29. CHIC & eHealth Ohio – Record Locator Service & NHIN CHIC SISU / St.Luke’s VRMC Users NHIN Backbone connecting HIEs Community Security/ Privacy Officers Log Reviews Personal Health Record (PHR) Role Based Access Control Service Community Patient Privacy Manager Audit Database XDS Registry and Repository Patient Clinical Info Retrieval Lookup MEDNET GRID SERVER Immunization Connection eHealth Ohio, Rubicon TechColumbus Test server LOGIN MEDNET NHIN Gateway Record Locator Service Federated Identity Management Service
  • 30.
  • 31.
  • 32. Resources To learn more about NHIN: Visit: http://blog.mednetworld.com/survey to complete a two question survey on our talk, and download a free copy of an e-Book that we've developed on the topic.
  • 33.

Notes de l'éditeur

  1. Richard Moore is the owner and president of DME Consulting Services. He has over 30 years experience with Health Information Systems working with many public and private organizations. His broad-based knowledge of health information systems and operations comes from experience working directly with providers, payers, software manufacturers, electronic data interchange organizations, billing services, clearinghouses and government agencies. He is the current president of eHealth Ohio, Inc., a non-profit regional affiliate of the national standards development organization Workgroup for Electronic Data Interchange (WEDI). His primary WEDI focus is HIPAA X12 EDI transactions and he has participated as an author on WEDI testing whitepapers. He is an active participant in the Healthcare Information and Management Systems Society (HIMSS) and is the current Chair of the HIMSS RHIO Liaison Roundtable. He is also a member of the Board of the Central and Southern Ohio HIMSS (CSOHIMSS) Chapter and is the Chapter Advocacy Chairman and the RHIO Liaison for the State of Ohio. He is involved in the Healthcare Information Technology Standards Panel (HITSP) on the Security, Privacy and Infrastructure technical committee (SPI-TC). Also he is a founding member of the Liberty Alliance Health Identity Management Special Interest Group (HIM-SIG). The last three years he has been a project lead for the study on the use of the GSA e-Authentication model for the Nationwide Health Information Network (NHIN) focusing on electronic identity management, secure electronic health information exchange and federated single sign-on. John Fraser founded and is CEO of MEDNETWorld.com based in Minneapolis, Minnesota. MEDNETWorld.com is wiring up health care by providing Record Locator Services, security and privacy technologies and national connectivity to current and emerging health information exchanges. Prior to founding MEDNET in 2006, John Fraser was the co-founder and former CEO of VisionShare Inc, a company building a secure, national infrastructure for claims connectivity and Medicare billing services with over 50% of all U.S. hospitals using their software. Prior to VisionShare, John built MEDNET, a state-wide medical network in Minnesota at the Minnesota Health Data Institute. Prior to the Institute, John built a state-wide Cancer Surveillance system at the Minnesota Department of Health. John has also done stints at Honeywell and Control Data Corporations. John is the co-chair of the Health Identity Management Special Interest Group of the Liberty Alliance (HIM-SIG). John is an avid bicyclist, diver and swimmer, with an undergraduate degree from the University of Minnesota. John holds a private pilot’s license and a 1st degree black belt in Tae Kwon Doe Karate.
  2. First, we need to show that we do not have any conflict of interest related to our presentation. I would also point out that almost all of the work for this project has been either donated or given in-kind. We have attempted to use Open Source solutions when available.
  3. Nationwide Health Information Network (NHIN) requires the secure connection of health organizations within and across state borders. The goal of Phase 4 of the e-Authentication Pilot Study is to investigate a specific solution to this issue. In 2006 HIMSS sponsored Phase 1 of the e-Authentication Pilot Study which modeled the use of the General Services Administration (GSA) electronic authentication certificates using PKI and SAML in a healthcare information exchange (HIE) environment by 6 Regional Health Information Organizations (RHIOs) located in 5 different states. Phase 2 extended the work of Phase 1 to model federated single sign-on into a distributed multi-state HIE using PKI certificates for secure identity management, open source Internet2 middleware (Shibboleth and Shibboleth tools) for the authorization architecture and single sign-on capability and OASIS defined Security Assertion Markup Language (SAML) for access control. Phase 2 concluded in the development of a healthcare specific configuration of a Shibboleth network architecture and the development of healthcare related directory objects for role-based authorization. The technology was successfully demonstrated at the HIMSS 2008 IHE Showcase and is a part of the NHIN2. Phase 3 software improvements include Shibboleth 2.x and SAML 2.x for protocol, assertions and bindings. Phase 3 extended the network to include NHIN connectivity as a participant in the NHIN2 project. Advancements included: Record Location Services (RLS); proprietary Electronic Health Records (EHR); Personal Health Record Service (PHR); Public Health Immunization Record Service and VMWare virtual server technology. The technology was demonstrated at the HIMSS 2009 IHE showcase. Phase 4 extends the use of NHIN Connector for Clinical and Administrative transactions, connection to OpenVISTA, work with the Voluntary Universal Healthcare Identifier (VUHID) and the growth of the network to 18 hospitals. Liberty Alliance/Kantara Workgroup for Health Identity and Assurance continues to participate to define Health Identity Management best practices and Role-based Authentication. The technology was demonstrated at the HIMSS 2010 in the Federal Healthcare Architecture FHA showcase working with Medicaid and Medicaid Information Technology Architecture (MITA).
  4. Talk Outline Problems & Opportunity Key Benefits of the study Project Review and History Case Studies: Building a Federated NHIN eHealth Ohio HIE-Bridge HIE in Minnesota NHIN Federated HIE Model Recommendations
  5. Key Problems When doctors connect nationally or outside their HIE, how do they know who is on other end of a request for medical information? At a local network level users are known to the system for access, but in a situation where a request is coming from outside the network the requestor is not typically known. A Trust framework needs to be established. Usernames and passwords problems Too many – I have a spreadsheet with over 200 username passwords. Lose track Very frustrating to remember them all Very unsecure - Need to share username/passwords between apps – You might require access to multiple applications to get the complete medical history.
  6. Key Benefits Providers and Staff: Simplify the process Modernize user authentication Help link systems together Managers and Technologists Manage to national standards Use open standards – vendor neutral Benefits to Patients More secure systems Protection of patient privacy Easier interaction with systems  
  7. Looking forward we anticipate future connection and collaboration between MN and OH into Phase 4.
  8. The GSA was given the assignment under the Bush administration to develop a secure infrastructure for electronic government (eGov) for all federal agencies. Their solution incorporated national and international standards and was developed jointly with the National Institute of Standards and Technology (NIST). The security solution for the Federal Trust Model for Federated Identity included Public Key Infrastructure (PKI) and Third Party Certification services. To permit scalability and useablity across all the agencies, businesses and individuals involved in eGov, the Federal Bridge Certificate Authority was created. Following 9/11 and the creation of the Homeland Security Department, these standards were put into use following the Homeland Security Presidential Directive, HSPD-12 in August 2004. In 2005 HIMSS and the GSA, began development of a pilot project to demonstrate the adoption of the GSA’s secure and interoperable technical architecture for sharing information across multiple healthcare providers. The pilot utilized the GSA‘s e-Authentication Service Component program to provide digital certificates, technical architecture development support, and certificate validation services. The Pilot Project began in 2006 with Seven Regional Health Information Organizations (RHIOs)/health information exchanges (IHEs) and ORC, Inc. Federal Certificate Authority. The HIMSS e-Authentication Whitepaper was produced. http://www.himss.org/content/files/GSAwhitepaper.pdf
  9. Phase 1 Participants GSA: ORC, Inc. ACES Certificate Authority CT: e-Health Connecticut MI: Michigan Data Sharing & Transaction Infrastructure Project TX: CHRISTUS Health, Health eCities of Texas Project MN: Community Health Information Collaborative OH: eHealth Ohio/OSC Bioinformatics OH: Virtual Medical Network NV: Single Portal Medical Record Project Results of Phase 1 Multiple RHIOs can agree and implement a common framework for the policies, procedures, and standards for federated identity authentication across multiple use cases. The Federal e-Authentication infrastructure is relevant and applicable to use cases for RHIOs in diverse operational environments. PKI, as a standard for strong authentication, can be deployed uniformly across multiple RHIOs. The Federal PKI and its trusted Federal Credential Service Providers can be leveraged for use in multiple use cases across multiple RHIOs. For RHIOs, local registration authorities and local enrollment are viable for larger scale deployments to provide for strong authentication using Federal e-Authentication components. Hardware tokens (i.e., smart cards, flash drives) are viable for RHIO deployment of level 4 authentication assurance. The results were published in the HIMSS Whitepaper: HIMSS/GSA National e-Authentication Project Whitepaper, 6/2007
  10. Phase 2 Participants CT: e-Health Connecticut MN: MEDNET, USA MN: Community Health Information Collaborative (CHIC) OH: eHealth Ohio OH: Virtual Medical Network Phase 2 Participants CT: e-Health Connecticut MN: MEDNET, USA MN: Community Health Information Collaborative (CHIC) OH: eHealth Ohio OH: Virtual Medical Network Following the success of the e-Authentication phase 1, the participants met following HIMSS 2007 annual meeting and a group was formed to focus on extending the project to investigate authorization and access control. The participants agreed to run Shibboleth open source software and test federated connectivity between themselves. The Shibboleth middleware would accommodate the PKI authentication services studied in phase 1 and add the capability to authorize access for authenticated users. The guiding principles of phase 2 were to provide Federated Single Sign-on, adhere to existing and developing standards, utilize open source software solutions wherever possible, provide connectivity to all – even proprietary solutions and publish/present discovered solutions to inform stakeholders. Phase 2 Results Shibboleth network servers for Identity and Service Provders were established. Simplified Role-Based Access for Referrals and Emergency scenarios were tested successfully. The Shibboleth solution was incorporated into the IHE Interoperability Showcase for The HIMSS Annual Meeting in 2/2008.
  11. Phase 3 – Activities and results The Original Focus of Phase Three was to extend the Role-Based Access Model and scalability. But in May 2008 CHIC was selection for the NHIN2 development and NHIN work took precedence for 2008. All efforts were directed to assure interoperability with the 18 NHIN participants. Based on the participation in the NHIN, the e-Authentication project is now a portal to the NHIN. Because of NHIN connectivity and PKI authentication capability, the CDC is participating in an ongoing project with CHIC in Minnesota. Scalability gains were achieved by using virtualization of servers to reduce maintenance and application deployment. A search for ways to streamline PKI certificate provisioning led to a relationship with Safe BioPharma.
  12. Phase 4 – 2009 Case Studies - Implement lessons learned in HIE Work with other Open Source solutions Implement a federated identity management system that can be shared between HIEs and states Connect to NHIN to exchange clinical and Administrative transactions With Kantara develop a reference implementation for federated identity
  13. Ohio developments: eHealth Ohio is working jointly with a Provider General Purchase Organization, The Rubicon Group (TRG). Our HIE platform is located at TechColumbus a state run tech-business incubator. We established the HIE in the PlatForm Laboratory VMWare Cloud. TRG works with 50 practices and 200 physicians. The practices have varying capability from fully functioning EMR to no EMR. We are establishing a record locator service that will enable the practices to find patient records, even those in paper. The physician can query the system and it will respond with a listing of possible locations for the patient records, give the records department information and phone numbers. The beta test case has multiple pediatric physicians, a pediatric urgent care and the local Children’s hospital. We are also working at developing a connection for a Hospitalist to help with her rounding, patient management and charge capture.
  14. Current eHealth Ohio platform.
  15. This shows how MEDNETWorld.com (MEDNET) added the NHIN backbone connectivity to an existing HIE, CHIC and eHealth Ohio. CHIC is the Community Health Information Collaborative, a nonprofit corporation formed in 1997 with 420 member hospitals, clinics, public health and tribal health departments, long-term care facilities and higher education institutions in northeastern Minnesota. CHIC is the lead organization for our regional HIE designed to provide secure access to electronic health records through applications developed with MEDNETWorld. eHealth Ohio and VMN participate as a part of the e-Authentication Project testbed. In 2008 CHIC and MEDNET were awarded one of 6 pilot projects to connect CHIC to the NHIN backbone for trial usage. In this project we demonstrated connectivity to other federal agencies (CDC, VA, DoD, SSA) and the other 18 participants all over the US. MEDNET developed and implemented it’s own NHIN gateway for the NHIN project.
  16. NHIN Developed by Department of Health and Human Services 18 initial participants Internet-based, uses existing Internet standards Web Services based with SAML security No centralized servers / control Moving into production in 2009
  17. This diagram shows how NHIN runs over the Internet. Take note that only one connection is required to link your organization to other NHIN participating organizations. Also note that at this point all connections are point-to-point, there is no centralized server to connect thru. The slide also shows some of the federal participants and types of participants involved in the 2008 Trial Implementations. Participants in NHIN CHIC (Community Health Information Collaborative) with MEDNETWorld.com as technology provider Department of Veterans Affairs Department of Defense Social Security Administration Kaiser Permanente Cleveland Clinic MedVA Indiana University HealthLINC/Bloomington Hospital HealthBridge Wright State University NYeC (New York eHealth Collaborative) DHIN (Delaware Health Information Network) CareSpark WVHIN (West Virginia Health Information Network) NCHICA (North Carolina Healthcare Information and Communications Alliance, Inc.) Lovelace Clinic Foundation LBNH (Long Beach Network for Health)
  18. Here we articulate our vision for a fully interconnect and trusted health care security system. A combination of federation between participants, using some agreed-to frameworks and certificate authorities, should allow access to standardized services, such as NHIN and other, non-standardized web services.
  19. This slide describes the standard NHIN Message Security standards. Note that it requires a PKI environment to sign and encrypt messages and connections. Username/password security is not welcome here!
  20. This diagram shows a standard SOAP message, with a SAML Assertion in it’s header. This is a standard way to carry a SAML 2.0 assertion, which tells the receiving system who sent the message. Since the SAML message must be signed by a trusted CA, the receiver can trust the SAML assertion. The receiver can then read the SAML assertion and make it’s own decisions as to whether it wants to allow this person into their systems for this transaction. If receiver is free to reject any messages if: 1. There is no SAML Assertion, 2. The SAML Assertion is not signed, or signed by a CA that the recipient does not recognize, 3. The Assertion describes a user or system that the recipient doesn’t trust or know. Note that the recipient is always in control of accepting a message, there is no “automatic” trust in the system.
  21. These are our thoughts about how NHIN can adopt federation technology to support NHIN and other services using the single sign-on supported by federations. Federations are different groups of organizations, managing and supporting their own directories of users, that agree to exchange user information and authentication information between organizations. No centralized registry is then needed, however, Role-based authorization is then usually needed to support allowing people to access different services by only knowing their roles. This is important to be able to scale federations to multiple organizations, since different organizations can never really know all the different users that might come thru the federation system.
  22. This shows how MEDNETWorld.com (MEDNET) added the NHIN backbone connectivity to an existing HIE, CHIC and eHealth Ohio. CHIC is the Community Health Information Collaborative, a nonprofit corporation formed in 1997 with 420 member hospitals, clinics, public health and tribal health departments, long-term care facilities and higher education institutions in northeastern Minnesota. CHIC is the lead organization for our regional HIE designed to provide secure access to electronic health records through applications developed with MEDNETWorld. eHealth Ohio and VMN participate as a part of the e-Authentication Project testbed. In 2008 CHIC and MEDNET were awarded one of 6 pilot projects to connect CHIC to the NHIN backbone for trial usage. In this project we demonstrated connectivity to other federal agencies (CDC, VA, DoD, SSA) and the other 18 participants all over the US. MEDNET developed and implemented it’s own NHIN gateway for the NHIN project.