SlideShare uma empresa Scribd logo
1 de 7
Baixar para ler offline
Privacy and Security Tiger Team
Summary of Recommendations on Provider and
Patient Identity Management
May 21, 2013
Deven McGraw, Center for Democracy & Technology (Co-Chair, Tiger Team)
Walter Suarez, Kaiser Permanente, (Co-Chair, Privacy & Security Working Group, HITSC)
Peter Tippett, Chief Medical Officer, Verizon
Elizabeth Franchi, Director, Veterans Health Administration Data Quality Program
Paul Uhrig, Chief Administrative, Legal & Privacy Officer, Surescripts
Providers (September 26, 2012)
1. Providers should continue to ID proof professional &
staff per HIPAA.
2. By Meaningful Use Stage 3, ONC should move
toward requiring multi-factor authentication
(meeting NIST Level of Assurance (LOA) 3) for remote
access to protected health information; entities can
identify other access environments necessitating
higher authentication levels.
3. ONC’s work to implement these recommendations
should continue to be informed by NSTIC and
technology developments, and appropriately
account for provider workflow needs while
establishing a secure environment.
2
Patients (May 3, 2013)
• ONC should develop and disseminate best practices on
patient ID management; such best practices should be
easy for patients to use, leverage solutions in other
sectors (like banking), provide protections
commensurate with risk.
• Patients should be able to ID proof both in person and
remotely (ideally)
• Authentication should be more than user name and
password but not set the bar too high (“Level 2.5”).
• Solutions should evolve with technology and be
informed by NSTIC developments.
3
HIT Standards Committee
Patient Identity Management
• Need to uniquely identify patients for various purposes
– Query of patient data, linking data from multiple sources,
authorize patient access to data, other
• Lack of reliable means to identify patients continues to be
seen broadly as a significant challenge to care delivery,
continuity of care, and health care quality
• Multiple efforts currently underway to adopt/use ‘voluntary’
patient identifiers within secure systems
• No formal recommendations developed yet
– Important that regulations allow progress and innovation
to occur in this arena
4
HIT Standards Committee
Provider Identity Management
• Per policy direction, the overall expectation is to follow
NIST criteria for LOA using SP-800-63-2.
• EHR technology should be configurable to enable an
organization to require different levels of authentication
and identity proofing, based on role within organization
• For example
– Physicians and other providers with full access and
write/edit capabilities should have IDP to at least
NIST Level 3
– Non-clinical staff without write/edit capabilities
might more appropriately have IDP to NIST Level 2
5
HIT Standards Committee
Provider Identity Management (cont.)
• NSTIC offers benefits for authenticating both consumers and
providers
• For MU Stage 3, EHR certification can require EHRs to support 2-
factor authentication and permit one of the factors to be a third-
party solution, in anticipation of NSTIC credentials becoming
available
• We also may see consumers presenting NSTIC credentials before
NSTIC has been broadly adopted by providers
• Not sure that a fully operational NSTIC approach will be ready in
time for MU stage 3
6
Roundtable Discussion
Deven McGraw
Walter Suarez
Peter Tippett
Elizabeth Franchi
Paul Uhrig

Mais conteúdo relacionado

Mais procurados

Provider-led Health Plans (Payviders)
Provider-led Health Plans (Payviders)Provider-led Health Plans (Payviders)
Provider-led Health Plans (Payviders)CitiusTech
 
DoD onboarding slides
DoD onboarding slidesDoD onboarding slides
DoD onboarding slidesBrian Ahier
 
2015 Edition Proposed Rule Modifications to the ONC Health IT Certification ...
2015 Edition Proposed RuleModifications to the ONC Health IT Certification ...2015 Edition Proposed RuleModifications to the ONC Health IT Certification ...
2015 Edition Proposed Rule Modifications to the ONC Health IT Certification ...Brian Ahier
 
Frisse - One Step at a Time
Frisse  - One Step at a TimeFrisse  - One Step at a Time
Frisse - One Step at a TimeBrian Ahier
 
FHIR Adoption Framework for Payers
FHIR Adoption Framework for PayersFHIR Adoption Framework for Payers
FHIR Adoption Framework for PayersCitiusTech
 
Freyr Pharmacolvigilance Brochure
Freyr Pharmacolvigilance BrochureFreyr Pharmacolvigilance Brochure
Freyr Pharmacolvigilance BrochureFaiz Shariff
 
Dialogue on HIPAA/HITECH Compliance
Dialogue on HIPAA/HITECH  ComplianceDialogue on HIPAA/HITECH  Compliance
Dialogue on HIPAA/HITECH ComplianceBrian Ahier
 
Consumers' Checkbook Submission to RWJF & HHS Provider Network Challenge
Consumers' Checkbook Submission to RWJF & HHS Provider Network ChallengeConsumers' Checkbook Submission to RWJF & HHS Provider Network Challenge
Consumers' Checkbook Submission to RWJF & HHS Provider Network Challengehealth2dev
 
AMA Digital Health Study
AMA Digital Health Study AMA Digital Health Study
AMA Digital Health Study Brian Ahier
 
Direct Boot Camp 2.0 - Tennesse Directories
Direct Boot Camp 2.0 - Tennesse DirectoriesDirect Boot Camp 2.0 - Tennesse Directories
Direct Boot Camp 2.0 - Tennesse DirectoriesBrian Ahier
 
IBM Smarter Healthcare presentation - Angus Campbell - Smarter planet comes t...
IBM Smarter Healthcare presentation - Angus Campbell - Smarter planet comes t...IBM Smarter Healthcare presentation - Angus Campbell - Smarter planet comes t...
IBM Smarter Healthcare presentation - Angus Campbell - Smarter planet comes t...Smarter Planet Students for a
 
ONC 2015 Edition EHR Certification Criteria
ONC 2015 Edition EHR Certification CriteriaONC 2015 Edition EHR Certification Criteria
ONC 2015 Edition EHR Certification CriteriaBrian Ahier
 
Accountable Care Workgroup: Draft Recommendations
Accountable Care Workgroup: Draft RecommendationsAccountable Care Workgroup: Draft Recommendations
Accountable Care Workgroup: Draft RecommendationsBrian Ahier
 
Big Data and VistA Evolution, Theresa A. Cullen, MD, MS
Big Data and VistA Evolution, Theresa A. Cullen, MD, MSBig Data and VistA Evolution, Theresa A. Cullen, MD, MS
Big Data and VistA Evolution, Theresa A. Cullen, MD, MSBrian Ahier
 
Informatics Standards And Interoperability20090325
Informatics Standards And Interoperability20090325Informatics Standards And Interoperability20090325
Informatics Standards And Interoperability20090325Abdul-Malik Shakir
 
DocSpot Plan Compare
DocSpot Plan CompareDocSpot Plan Compare
DocSpot Plan Comparehealth2dev
 
Interoperability in health care information systems
Interoperability in health care information systemsInteroperability in health care information systems
Interoperability in health care information systemsAlexander Ask
 
ACR Select: Clinical Decision Support Imaging Guidelines
ACR Select: Clinical Decision Support Imaging GuidelinesACR Select: Clinical Decision Support Imaging Guidelines
ACR Select: Clinical Decision Support Imaging GuidelinesACR Select
 

Mais procurados (20)

Provider-led Health Plans (Payviders)
Provider-led Health Plans (Payviders)Provider-led Health Plans (Payviders)
Provider-led Health Plans (Payviders)
 
DoD onboarding slides
DoD onboarding slidesDoD onboarding slides
DoD onboarding slides
 
2016 iHT2 San Diego Health IT Summit
2016 iHT2 San Diego Health IT Summit2016 iHT2 San Diego Health IT Summit
2016 iHT2 San Diego Health IT Summit
 
2015 Edition Proposed Rule Modifications to the ONC Health IT Certification ...
2015 Edition Proposed RuleModifications to the ONC Health IT Certification ...2015 Edition Proposed RuleModifications to the ONC Health IT Certification ...
2015 Edition Proposed Rule Modifications to the ONC Health IT Certification ...
 
Frisse - One Step at a Time
Frisse  - One Step at a TimeFrisse  - One Step at a Time
Frisse - One Step at a Time
 
FHIR Adoption Framework for Payers
FHIR Adoption Framework for PayersFHIR Adoption Framework for Payers
FHIR Adoption Framework for Payers
 
Freyr Pharmacolvigilance Brochure
Freyr Pharmacolvigilance BrochureFreyr Pharmacolvigilance Brochure
Freyr Pharmacolvigilance Brochure
 
Dialogue on HIPAA/HITECH Compliance
Dialogue on HIPAA/HITECH  ComplianceDialogue on HIPAA/HITECH  Compliance
Dialogue on HIPAA/HITECH Compliance
 
Consumers' Checkbook Submission to RWJF & HHS Provider Network Challenge
Consumers' Checkbook Submission to RWJF & HHS Provider Network ChallengeConsumers' Checkbook Submission to RWJF & HHS Provider Network Challenge
Consumers' Checkbook Submission to RWJF & HHS Provider Network Challenge
 
AMA Digital Health Study
AMA Digital Health Study AMA Digital Health Study
AMA Digital Health Study
 
Vericred
VericredVericred
Vericred
 
Direct Boot Camp 2.0 - Tennesse Directories
Direct Boot Camp 2.0 - Tennesse DirectoriesDirect Boot Camp 2.0 - Tennesse Directories
Direct Boot Camp 2.0 - Tennesse Directories
 
IBM Smarter Healthcare presentation - Angus Campbell - Smarter planet comes t...
IBM Smarter Healthcare presentation - Angus Campbell - Smarter planet comes t...IBM Smarter Healthcare presentation - Angus Campbell - Smarter planet comes t...
IBM Smarter Healthcare presentation - Angus Campbell - Smarter planet comes t...
 
ONC 2015 Edition EHR Certification Criteria
ONC 2015 Edition EHR Certification CriteriaONC 2015 Edition EHR Certification Criteria
ONC 2015 Edition EHR Certification Criteria
 
Accountable Care Workgroup: Draft Recommendations
Accountable Care Workgroup: Draft RecommendationsAccountable Care Workgroup: Draft Recommendations
Accountable Care Workgroup: Draft Recommendations
 
Big Data and VistA Evolution, Theresa A. Cullen, MD, MS
Big Data and VistA Evolution, Theresa A. Cullen, MD, MSBig Data and VistA Evolution, Theresa A. Cullen, MD, MS
Big Data and VistA Evolution, Theresa A. Cullen, MD, MS
 
Informatics Standards And Interoperability20090325
Informatics Standards And Interoperability20090325Informatics Standards And Interoperability20090325
Informatics Standards And Interoperability20090325
 
DocSpot Plan Compare
DocSpot Plan CompareDocSpot Plan Compare
DocSpot Plan Compare
 
Interoperability in health care information systems
Interoperability in health care information systemsInteroperability in health care information systems
Interoperability in health care information systems
 
ACR Select: Clinical Decision Support Imaging Guidelines
ACR Select: Clinical Decision Support Imaging GuidelinesACR Select: Clinical Decision Support Imaging Guidelines
ACR Select: Clinical Decision Support Imaging Guidelines
 

Semelhante a Summary of Recommendations on Provider and Patient Identity Management

Privacy and Security Tiger Team 010813
Privacy and Security Tiger Team 010813Privacy and Security Tiger Team 010813
Privacy and Security Tiger Team 010813Brian Ahier
 
Running head EFFECTIVENESS OF HEALTH CARE IT SYSTEMS 1EFFE.docx
Running head EFFECTIVENESS OF HEALTH CARE IT SYSTEMS 1EFFE.docxRunning head EFFECTIVENESS OF HEALTH CARE IT SYSTEMS 1EFFE.docx
Running head EFFECTIVENESS OF HEALTH CARE IT SYSTEMS 1EFFE.docxsusanschei
 
Best_practices-_Access_controls_for_medical_devices (1).pdf
Best_practices-_Access_controls_for_medical_devices (1).pdfBest_practices-_Access_controls_for_medical_devices (1).pdf
Best_practices-_Access_controls_for_medical_devices (1).pdfJacob Li
 
Technology Considerations to Enable the Risk-Based Monitoring Methodology
Technology Considerations to Enable the Risk-Based Monitoring MethodologyTechnology Considerations to Enable the Risk-Based Monitoring Methodology
Technology Considerations to Enable the Risk-Based Monitoring Methodologywww.datatrak.com
 
Privacy and Security Tiger Team Authentication Recommendations
Privacy and Security Tiger Team Authentication RecommendationsPrivacy and Security Tiger Team Authentication Recommendations
Privacy and Security Tiger Team Authentication RecommendationsBrian Ahier
 
Defining a Central Monitoring Capability: Sharing the Experience of TransCele...
Defining a Central Monitoring Capability: Sharing the Experience of TransCele...Defining a Central Monitoring Capability: Sharing the Experience of TransCele...
Defining a Central Monitoring Capability: Sharing the Experience of TransCele...www.datatrak.com
 
Electronic Health Record (EHR)
Electronic Health Record (EHR)Electronic Health Record (EHR)
Electronic Health Record (EHR)sourav goswami
 
Patient Identification and Matching Initiative Stakeholder Meeting
Patient Identification and Matching Initiative Stakeholder MeetingPatient Identification and Matching Initiative Stakeholder Meeting
Patient Identification and Matching Initiative Stakeholder MeetingBrian Ahier
 
Optimizing the value of digital data in the life sciences
Optimizing the value of digital data in the life sciencesOptimizing the value of digital data in the life sciences
Optimizing the value of digital data in the life sciencesSollers College
 
HCS 483 Final Project
HCS 483 Final ProjectHCS 483 Final Project
HCS 483 Final Projectikearne
 
Challenges and Opportunities Around Integration of Clinical Trials Data
Challenges and Opportunities Around Integration of Clinical Trials DataChallenges and Opportunities Around Integration of Clinical Trials Data
Challenges and Opportunities Around Integration of Clinical Trials DataCitiusTech
 
Standards and Best Practices for Confidentiality of Electronic Health Records
Standards and Best Practices for Confidentiality of Electronic Health RecordsStandards and Best Practices for Confidentiality of Electronic Health Records
Standards and Best Practices for Confidentiality of Electronic Health RecordsMEASURE Evaluation
 
What is Healthcare Technology Consulting and Why is it Neces1.pdf
What is Healthcare Technology Consulting and Why is it Neces1.pdfWhat is Healthcare Technology Consulting and Why is it Neces1.pdf
What is Healthcare Technology Consulting and Why is it Neces1.pdfDashTechnologiesInc
 
Clinical Data Standards and Data Portability
Clinical Data Standards and Data Portability Clinical Data Standards and Data Portability
Clinical Data Standards and Data Portability Nrip Nihalani
 
Health IT Summit Boston - Presentation "HIT Roadmapping for Accountable Care"...
Health IT Summit Boston - Presentation "HIT Roadmapping for Accountable Care"...Health IT Summit Boston - Presentation "HIT Roadmapping for Accountable Care"...
Health IT Summit Boston - Presentation "HIT Roadmapping for Accountable Care"...Health IT Conference – iHT2
 
Patient Centered Care | Unit 9b Lecture
Patient Centered Care | Unit 9b LecturePatient Centered Care | Unit 9b Lecture
Patient Centered Care | Unit 9b LectureCMDLMS
 
Rural Hospital HIT Adoption
Rural Hospital HIT AdoptionRural Hospital HIT Adoption
Rural Hospital HIT Adoptionlearfield
 

Semelhante a Summary of Recommendations on Provider and Patient Identity Management (20)

Privacy and Security Tiger Team 010813
Privacy and Security Tiger Team 010813Privacy and Security Tiger Team 010813
Privacy and Security Tiger Team 010813
 
Running head EFFECTIVENESS OF HEALTH CARE IT SYSTEMS 1EFFE.docx
Running head EFFECTIVENESS OF HEALTH CARE IT SYSTEMS 1EFFE.docxRunning head EFFECTIVENESS OF HEALTH CARE IT SYSTEMS 1EFFE.docx
Running head EFFECTIVENESS OF HEALTH CARE IT SYSTEMS 1EFFE.docx
 
Best_practices-_Access_controls_for_medical_devices (1).pdf
Best_practices-_Access_controls_for_medical_devices (1).pdfBest_practices-_Access_controls_for_medical_devices (1).pdf
Best_practices-_Access_controls_for_medical_devices (1).pdf
 
Technology Considerations to Enable the Risk-Based Monitoring Methodology
Technology Considerations to Enable the Risk-Based Monitoring MethodologyTechnology Considerations to Enable the Risk-Based Monitoring Methodology
Technology Considerations to Enable the Risk-Based Monitoring Methodology
 
Privacy and Security Tiger Team Authentication Recommendations
Privacy and Security Tiger Team Authentication RecommendationsPrivacy and Security Tiger Team Authentication Recommendations
Privacy and Security Tiger Team Authentication Recommendations
 
Defining a Central Monitoring Capability: Sharing the Experience of TransCele...
Defining a Central Monitoring Capability: Sharing the Experience of TransCele...Defining a Central Monitoring Capability: Sharing the Experience of TransCele...
Defining a Central Monitoring Capability: Sharing the Experience of TransCele...
 
2016 LabHIT Vision
2016 LabHIT Vision2016 LabHIT Vision
2016 LabHIT Vision
 
Electronic Health Record (EHR)
Electronic Health Record (EHR)Electronic Health Record (EHR)
Electronic Health Record (EHR)
 
Patient Identification and Matching Initiative Stakeholder Meeting
Patient Identification and Matching Initiative Stakeholder MeetingPatient Identification and Matching Initiative Stakeholder Meeting
Patient Identification and Matching Initiative Stakeholder Meeting
 
Slide it
Slide itSlide it
Slide it
 
Optimizing the value of digital data in the life sciences
Optimizing the value of digital data in the life sciencesOptimizing the value of digital data in the life sciences
Optimizing the value of digital data in the life sciences
 
Health technology
Health technologyHealth technology
Health technology
 
HCS 483 Final Project
HCS 483 Final ProjectHCS 483 Final Project
HCS 483 Final Project
 
Challenges and Opportunities Around Integration of Clinical Trials Data
Challenges and Opportunities Around Integration of Clinical Trials DataChallenges and Opportunities Around Integration of Clinical Trials Data
Challenges and Opportunities Around Integration of Clinical Trials Data
 
Standards and Best Practices for Confidentiality of Electronic Health Records
Standards and Best Practices for Confidentiality of Electronic Health RecordsStandards and Best Practices for Confidentiality of Electronic Health Records
Standards and Best Practices for Confidentiality of Electronic Health Records
 
What is Healthcare Technology Consulting and Why is it Neces1.pdf
What is Healthcare Technology Consulting and Why is it Neces1.pdfWhat is Healthcare Technology Consulting and Why is it Neces1.pdf
What is Healthcare Technology Consulting and Why is it Neces1.pdf
 
Clinical Data Standards and Data Portability
Clinical Data Standards and Data Portability Clinical Data Standards and Data Portability
Clinical Data Standards and Data Portability
 
Health IT Summit Boston - Presentation "HIT Roadmapping for Accountable Care"...
Health IT Summit Boston - Presentation "HIT Roadmapping for Accountable Care"...Health IT Summit Boston - Presentation "HIT Roadmapping for Accountable Care"...
Health IT Summit Boston - Presentation "HIT Roadmapping for Accountable Care"...
 
Patient Centered Care | Unit 9b Lecture
Patient Centered Care | Unit 9b LecturePatient Centered Care | Unit 9b Lecture
Patient Centered Care | Unit 9b Lecture
 
Rural Hospital HIT Adoption
Rural Hospital HIT AdoptionRural Hospital HIT Adoption
Rural Hospital HIT Adoption
 

Mais de Brian Ahier

Remarks to Public Forum on National Health IT Policy
Remarks to Public Forum on National Health IT PolicyRemarks to Public Forum on National Health IT Policy
Remarks to Public Forum on National Health IT PolicyBrian Ahier
 
FTC Spring Privacy Series: Consumer Generated and Controlled Health Data
FTC Spring Privacy Series: Consumer Generated and Controlled Health DataFTC Spring Privacy Series: Consumer Generated and Controlled Health Data
FTC Spring Privacy Series: Consumer Generated and Controlled Health DataBrian Ahier
 
Mobile Device Tracking Seminar
Mobile Device Tracking SeminarMobile Device Tracking Seminar
Mobile Device Tracking SeminarBrian Ahier
 
Meaningful Use Workgroup Stage 3 Recommendations
Meaningful Use Workgroup Stage 3 Recommendations Meaningful Use Workgroup Stage 3 Recommendations
Meaningful Use Workgroup Stage 3 Recommendations Brian Ahier
 
Mark Bertolini of Aetna at JP Morgan Healthcare 2014
Mark Bertolini of Aetna at JP Morgan Healthcare 2014Mark Bertolini of Aetna at JP Morgan Healthcare 2014
Mark Bertolini of Aetna at JP Morgan Healthcare 2014Brian Ahier
 
DeSalvo Remarks to HIT Policy Committee 1-14-13
DeSalvo Remarks to HIT Policy Committee 1-14-13DeSalvo Remarks to HIT Policy Committee 1-14-13
DeSalvo Remarks to HIT Policy Committee 1-14-13Brian Ahier
 
The Pulse of Liquid Health Data
The Pulse of Liquid Health DataThe Pulse of Liquid Health Data
The Pulse of Liquid Health DataBrian Ahier
 
Direct20: Modular Specifications - Provider Directories
Direct20: Modular Specifications - Provider DirectoriesDirect20: Modular Specifications - Provider Directories
Direct20: Modular Specifications - Provider DirectoriesBrian Ahier
 
ONC – CMS Principles and Strategy for Accelerating Health Information Exch...
ONC – CMS  Principles and Strategy for  Accelerating Health Information  Exch...ONC – CMS  Principles and Strategy for  Accelerating Health Information  Exch...
ONC – CMS Principles and Strategy for Accelerating Health Information Exch...Brian Ahier
 
Redwood Mednet - Mark Frisse
Redwood Mednet - Mark FrisseRedwood Mednet - Mark Frisse
Redwood Mednet - Mark FrisseBrian Ahier
 
OrHIMA Meaningful Use Stage 2 Presentation
OrHIMA Meaningful Use Stage 2 PresentationOrHIMA Meaningful Use Stage 2 Presentation
OrHIMA Meaningful Use Stage 2 PresentationBrian Ahier
 
HIMSS Oregon Spring Conference - HIE
HIMSS Oregon Spring Conference - HIEHIMSS Oregon Spring Conference - HIE
HIMSS Oregon Spring Conference - HIEBrian Ahier
 
Federal Strategy for Advancing Consumer Engagement via eHealth
Federal Strategy for Advancing Consumer Engagement via eHealthFederal Strategy for Advancing Consumer Engagement via eHealth
Federal Strategy for Advancing Consumer Engagement via eHealthBrian Ahier
 

Mais de Brian Ahier (15)

Draft TEFCA
Draft TEFCADraft TEFCA
Draft TEFCA
 
Future is Now
Future is NowFuture is Now
Future is Now
 
Remarks to Public Forum on National Health IT Policy
Remarks to Public Forum on National Health IT PolicyRemarks to Public Forum on National Health IT Policy
Remarks to Public Forum on National Health IT Policy
 
FTC Spring Privacy Series: Consumer Generated and Controlled Health Data
FTC Spring Privacy Series: Consumer Generated and Controlled Health DataFTC Spring Privacy Series: Consumer Generated and Controlled Health Data
FTC Spring Privacy Series: Consumer Generated and Controlled Health Data
 
Mobile Device Tracking Seminar
Mobile Device Tracking SeminarMobile Device Tracking Seminar
Mobile Device Tracking Seminar
 
Meaningful Use Workgroup Stage 3 Recommendations
Meaningful Use Workgroup Stage 3 Recommendations Meaningful Use Workgroup Stage 3 Recommendations
Meaningful Use Workgroup Stage 3 Recommendations
 
Mark Bertolini of Aetna at JP Morgan Healthcare 2014
Mark Bertolini of Aetna at JP Morgan Healthcare 2014Mark Bertolini of Aetna at JP Morgan Healthcare 2014
Mark Bertolini of Aetna at JP Morgan Healthcare 2014
 
DeSalvo Remarks to HIT Policy Committee 1-14-13
DeSalvo Remarks to HIT Policy Committee 1-14-13DeSalvo Remarks to HIT Policy Committee 1-14-13
DeSalvo Remarks to HIT Policy Committee 1-14-13
 
The Pulse of Liquid Health Data
The Pulse of Liquid Health DataThe Pulse of Liquid Health Data
The Pulse of Liquid Health Data
 
Direct20: Modular Specifications - Provider Directories
Direct20: Modular Specifications - Provider DirectoriesDirect20: Modular Specifications - Provider Directories
Direct20: Modular Specifications - Provider Directories
 
ONC – CMS Principles and Strategy for Accelerating Health Information Exch...
ONC – CMS  Principles and Strategy for  Accelerating Health Information  Exch...ONC – CMS  Principles and Strategy for  Accelerating Health Information  Exch...
ONC – CMS Principles and Strategy for Accelerating Health Information Exch...
 
Redwood Mednet - Mark Frisse
Redwood Mednet - Mark FrisseRedwood Mednet - Mark Frisse
Redwood Mednet - Mark Frisse
 
OrHIMA Meaningful Use Stage 2 Presentation
OrHIMA Meaningful Use Stage 2 PresentationOrHIMA Meaningful Use Stage 2 Presentation
OrHIMA Meaningful Use Stage 2 Presentation
 
HIMSS Oregon Spring Conference - HIE
HIMSS Oregon Spring Conference - HIEHIMSS Oregon Spring Conference - HIE
HIMSS Oregon Spring Conference - HIE
 
Federal Strategy for Advancing Consumer Engagement via eHealth
Federal Strategy for Advancing Consumer Engagement via eHealthFederal Strategy for Advancing Consumer Engagement via eHealth
Federal Strategy for Advancing Consumer Engagement via eHealth
 

Summary of Recommendations on Provider and Patient Identity Management

  • 1. Privacy and Security Tiger Team Summary of Recommendations on Provider and Patient Identity Management May 21, 2013 Deven McGraw, Center for Democracy & Technology (Co-Chair, Tiger Team) Walter Suarez, Kaiser Permanente, (Co-Chair, Privacy & Security Working Group, HITSC) Peter Tippett, Chief Medical Officer, Verizon Elizabeth Franchi, Director, Veterans Health Administration Data Quality Program Paul Uhrig, Chief Administrative, Legal & Privacy Officer, Surescripts
  • 2. Providers (September 26, 2012) 1. Providers should continue to ID proof professional & staff per HIPAA. 2. By Meaningful Use Stage 3, ONC should move toward requiring multi-factor authentication (meeting NIST Level of Assurance (LOA) 3) for remote access to protected health information; entities can identify other access environments necessitating higher authentication levels. 3. ONC’s work to implement these recommendations should continue to be informed by NSTIC and technology developments, and appropriately account for provider workflow needs while establishing a secure environment. 2
  • 3. Patients (May 3, 2013) • ONC should develop and disseminate best practices on patient ID management; such best practices should be easy for patients to use, leverage solutions in other sectors (like banking), provide protections commensurate with risk. • Patients should be able to ID proof both in person and remotely (ideally) • Authentication should be more than user name and password but not set the bar too high (“Level 2.5”). • Solutions should evolve with technology and be informed by NSTIC developments. 3
  • 4. HIT Standards Committee Patient Identity Management • Need to uniquely identify patients for various purposes – Query of patient data, linking data from multiple sources, authorize patient access to data, other • Lack of reliable means to identify patients continues to be seen broadly as a significant challenge to care delivery, continuity of care, and health care quality • Multiple efforts currently underway to adopt/use ‘voluntary’ patient identifiers within secure systems • No formal recommendations developed yet – Important that regulations allow progress and innovation to occur in this arena 4
  • 5. HIT Standards Committee Provider Identity Management • Per policy direction, the overall expectation is to follow NIST criteria for LOA using SP-800-63-2. • EHR technology should be configurable to enable an organization to require different levels of authentication and identity proofing, based on role within organization • For example – Physicians and other providers with full access and write/edit capabilities should have IDP to at least NIST Level 3 – Non-clinical staff without write/edit capabilities might more appropriately have IDP to NIST Level 2 5
  • 6. HIT Standards Committee Provider Identity Management (cont.) • NSTIC offers benefits for authenticating both consumers and providers • For MU Stage 3, EHR certification can require EHRs to support 2- factor authentication and permit one of the factors to be a third- party solution, in anticipation of NSTIC credentials becoming available • We also may see consumers presenting NSTIC credentials before NSTIC has been broadly adopted by providers • Not sure that a fully operational NSTIC approach will be ready in time for MU stage 3 6
  • 7. Roundtable Discussion Deven McGraw Walter Suarez Peter Tippett Elizabeth Franchi Paul Uhrig