SlideShare uma empresa Scribd logo
1 de 14
DirectTrust.org
Building the Trust Framework for Directed

                Exchange


         David C. Kibbe, MD MBA
      NeHC University, February 8, 2012
          kibbedavid@mac.com
Today’s talk
• About DirectTrust.org
• Our mission and goals
• Brief overview of Directed exchange
 • Why e-mail? Why ‘push’ ?
• The importance of security and trust
• Components of the Trust Framework
 • It’s all about identity!
About DirectTrust.org
• DirectTrust.org is being organized as an
  independent, non-profit, and
  competitively neutral entity created by
  and for Direct community participants.
• Our goal is to develop, promote and, as
  necessary, help enforce the rules and
  best practices necessary to maintain
  trust within the Direct exchange
  community, and to foster widespread
  public confidence in the Direct
  exchange of health information.
• Our web presence:
      About DirectTrust.org
  www.directtrust.wikispaces.com
• ~80 members of the wiki, representing
  HISPs, HIEs, EHR technology vendors,
  Certificate Authorities, Identity Providers,
  state officials, patient advocacy
  organizations, providers, consultants,
  others.
• Please join if you wish to contribute to the
  effort!
About DirectTrust.org
• Two active workgroups:  Security and Trust
  Compliance; Certificate Policy and
  Practices
• Organizational Committee Members
 • AAFP, Arcadia Solutions, Cerner, DigiCert,
    Gorge Health Connect, Relay Health,
    Rhode Island Quality Institute, SAFE-
    BioPharma, Surescripts
The Direct Project
 Created a set of protocols,
 specifications, and standards, that,
 with a policy and trust framework,
 enables simple, secure transport
 over the Internet, to be used for
 exchange between known
 participants in support of
 meaningful use.
Meaningful Use, Quality Care
   Direct Project facilitates the communication of many different kinds of content
   necessary to fulfill meaningful use requirements.
                                                              Examples of Meaningful Use

                                                      Other Providers/Authorized Entities:
                                                         Clinical information for care coordination
                                                         Labs – test results
                                         DIRECT          Referrals – summary of care record
                                         EXCH ANGE
                                                      Patients:
                                                         Health information
                                                         Discharge instructions
                                                         Clinical summaries
    b.wells@direct.aclinic.org                           Reminders

1 Get a Direct Address ( e-mail-like) and a
 )
    security certificate                              Public Health:
2) Send mail securely using most e-mail                  Immunization registries
    clients OR contract with a HIO or HISP               Syndromic surveillance
    that performs authentication, encryption
    and trust verification on your behalf                Laboratory Reporting
Specific HISP duties:
- provide subscribers with account and Direct addresses
     - provide web portal or EHR/PHR integration
 - arrange for identity verification - org and individual
 - arrange for digital certificate issuance, management
  - maintain integrity of trust and security framework
   - stay current with federal policies and regulations
Security and Trust
      are Essential!
• We trust our doctors and nurses with our
  health information.
• We will need to be able to trust HISPs
  with our health information.
• Without a high level of trust accompanied
  by the requisite levels of security and
  privacy protection, health data exchange of
  any type or technology will likely fail.
Desirable HISP attributes:
         - strong, validated security practices
           - a track record in data exchange
   - working relationship with one or more RA/CA
- able and willing to interoperably exchange with other
                          HISPs
             - robust subscriber directory
Why Digital Certificates are So
        Important to Directed Exchange

• Digital certificates “stand in” for the
  individual/organizational identity in cyberspace
• They are issued by an RA/CA only after identity
  verification proves you are who you say you are
• They are used to sign, validate, and encrypt Direct
  exchange messages and attachments
• Any breach of trust with respect to certificate
  issuance or use threatens the integrity of exchange
Direct Identity, Trust, and Address Provisioning

                                                              Certificate Authority (CA)
                                                                Identity/Trust                 Certificate
                                                                 Verification              Validation Service

                                                             Certificate Signing                Revocation
                                                                  Services                       Services


                                                                                                                                    The CA and RA enforce the
                                                           6. Certificate Signing          7. Direct Organization                     policies specified in the
                                                              Request                         Certificate
                                                                                                                                     DirectTrust.org and FBCA
                                    2. Request Direct                                                                                Certificate Policies (CPs).
                                       Organization
 Assume has
Digital Identity
                                       Certificate
                                                            Registration Authority (RA)
  Certificate
                                    3. Credentials and
                                       Documentation             Compile/Validate Identity and Trust
                       HCO                                                Documentation
                                      Representative
                   Representative      FBCA Credentials
                                      Representative
    Healthcare                         Authorization
Organization (HCO)                    Legal Entity
                                       Documents
                                                          4. Direct
                                                                                    5. Public      8. Direct Organization
                                                             Organization
                                      Membership/Trust      Domain                    Key            Certificate
                                       Agreement
                                      HIPAA status
                                                                                                                                         Domain Name System
                                                                                                                                                (DNS)
                                    1. Enroll with HISP                                                             9. Direct Address/
                                                                Health Information Service                             Org Certificate

                                                                     Provider (HISP)                                                     LDAP Name System



                                                                                                       Source: DirectTrust.org February, 2012
Issues Remaining to be Resolved with
Respect to the Direct Exchange Trust
             Framework

• Who will be acceptable (ie. trustworthy) as
  Certificate Authorities?
• What level(s) of identity verification is
  required for groups; professionals;
  patients?
• What will be decided at a federal policy
  level, and what at an industry level?
Questions, Comments

• David C. Kibbe, MD MBA
• kibbedavid@mac.com
• 913 205 7968

Mais conteúdo relacionado

Semelhante a David Kibbe of DirectTrust.org at 2012 eCollaboration Forum

Updates on the Western States Consortium
Updates on the Western States ConsortiumUpdates on the Western States Consortium
Updates on the Western States Consortium
CHeQ-IPHI
 
Issa fi xs briefing
Issa fi xs briefingIssa fi xs briefing
Lc 08-2011-reg requirements
Lc 08-2011-reg requirementsLc 08-2011-reg requirements
Lc 08-2011-reg requirements
eyepacs
 
Managing PIV Card Lifecycle and Converging Physical & Logical Access Control
Managing PIV Card Lifecycle and Converging Physical & Logical Access ControlManaging PIV Card Lifecycle and Converging Physical & Logical Access Control
Managing PIV Card Lifecycle and Converging Physical & Logical Access Control
Ramesh Nagappan
 
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
Richard Moore
 
Security Patterns with the WSO2 ESB
Security Patterns with the WSO2 ESBSecurity Patterns with the WSO2 ESB
Security Patterns with the WSO2 ESB
WSO2
 
Electronic credential authentication_standard
Electronic credential authentication_standardElectronic credential authentication_standard
Electronic credential authentication_standard
Hai Nguyen
 

Semelhante a David Kibbe of DirectTrust.org at 2012 eCollaboration Forum (20)

Identity Proofing to provision accurately
Identity Proofing to provision accuratelyIdentity Proofing to provision accurately
Identity Proofing to provision accurately
 
"NSTIC Pilots on the trust network" Webinar Slides 10-12-2012
"NSTIC Pilots on the trust network" Webinar Slides 10-12-2012"NSTIC Pilots on the trust network" Webinar Slides 10-12-2012
"NSTIC Pilots on the trust network" Webinar Slides 10-12-2012
 
HIE 101
HIE 101HIE 101
HIE 101
 
HIMSS GSA e-Authentication whitepaper June 2007
HIMSS GSA e-Authentication whitepaper June 2007HIMSS GSA e-Authentication whitepaper June 2007
HIMSS GSA e-Authentication whitepaper June 2007
 
Updates on the Western States Consortium
Updates on the Western States ConsortiumUpdates on the Western States Consortium
Updates on the Western States Consortium
 
Ecm sales training sample day 1
Ecm sales training sample  day 1Ecm sales training sample  day 1
Ecm sales training sample day 1
 
Issa fi xs briefing
Issa fi xs briefingIssa fi xs briefing
Issa fi xs briefing
 
EHR Certification HIMSS Presentation
EHR Certification HIMSS PresentationEHR Certification HIMSS Presentation
EHR Certification HIMSS Presentation
 
Hitpc.20090716.Certification Workgroup
Hitpc.20090716.Certification WorkgroupHitpc.20090716.Certification Workgroup
Hitpc.20090716.Certification Workgroup
 
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
 
Can Blockchain Enable Identity Management?
Can Blockchain Enable Identity Management?Can Blockchain Enable Identity Management?
Can Blockchain Enable Identity Management?
 
Lc 08-2011-reg requirements
Lc 08-2011-reg requirementsLc 08-2011-reg requirements
Lc 08-2011-reg requirements
 
November 2008 E Newsletter
November 2008 E NewsletterNovember 2008 E Newsletter
November 2008 E Newsletter
 
Managing PIV Card Lifecycle and Converging Physical & Logical Access Control
Managing PIV Card Lifecycle and Converging Physical & Logical Access ControlManaging PIV Card Lifecycle and Converging Physical & Logical Access Control
Managing PIV Card Lifecycle and Converging Physical & Logical Access Control
 
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
 
Security patterns with wso2 esb
Security patterns with wso2 esbSecurity patterns with wso2 esb
Security patterns with wso2 esb
 
Security Patterns with the WSO2 ESB
Security Patterns with the WSO2 ESBSecurity Patterns with the WSO2 ESB
Security Patterns with the WSO2 ESB
 
21 CFR part 11- ELECTRONIC RECORDS; ELECTRONIC SIGNATURES
21 CFR part 11-ELECTRONIC RECORDS;ELECTRONIC SIGNATURES21 CFR part 11-ELECTRONIC RECORDS;ELECTRONIC SIGNATURES
21 CFR part 11- ELECTRONIC RECORDS; ELECTRONIC SIGNATURES
 
M12S18 - Records and Information Management: What Healthcare Should be Learni...
M12S18 - Records and Information Management: What Healthcare Should be Learni...M12S18 - Records and Information Management: What Healthcare Should be Learni...
M12S18 - Records and Information Management: What Healthcare Should be Learni...
 
Electronic credential authentication_standard
Electronic credential authentication_standardElectronic credential authentication_standard
Electronic credential authentication_standard
 

Mais de Collaborative Health Consortium

Himss e collaboration forum closing session (kuraitis, shah) final
Himss e collaboration forum closing session (kuraitis, shah) finalHimss e collaboration forum closing session (kuraitis, shah) final
Himss e collaboration forum closing session (kuraitis, shah) final
Collaborative Health Consortium
 

Mais de Collaborative Health Consortium (14)

John Freedman - All-payer claims databases - CHC Pilots & Collaborations
John Freedman - All-payer claims databases - CHC Pilots & CollaborationsJohn Freedman - All-payer claims databases - CHC Pilots & Collaborations
John Freedman - All-payer claims databases - CHC Pilots & Collaborations
 
Dave Chase, Avado CEO, presents to CHC
Dave Chase, Avado CEO, presents to CHCDave Chase, Avado CEO, presents to CHC
Dave Chase, Avado CEO, presents to CHC
 
E-Innovations to Support Primary Care
E-Innovations to Support Primary CareE-Innovations to Support Primary Care
E-Innovations to Support Primary Care
 
From Silo's to Legos
From Silo's to LegosFrom Silo's to Legos
From Silo's to Legos
 
Ahier himss 2012 - direct project overview presentation
Ahier   himss 2012 - direct project overview presentationAhier   himss 2012 - direct project overview presentation
Ahier himss 2012 - direct project overview presentation
 
Salesforce ecollab himss2 copy
Salesforce ecollab himss2 copySalesforce ecollab himss2 copy
Salesforce ecollab himss2 copy
 
Nobel payer panel e collaborationforum 2.23.12
Nobel payer panel e collaborationforum 2.23.12Nobel payer panel e collaborationforum 2.23.12
Nobel payer panel e collaborationforum 2.23.12
 
E collaborationforumjoemiller (jmiller v1)
E collaborationforumjoemiller (jmiller v1)E collaborationforumjoemiller (jmiller v1)
E collaborationforumjoemiller (jmiller v1)
 
120223 e collaborationforum ppt_migliori
120223 e collaborationforum ppt_migliori120223 e collaborationforum ppt_migliori
120223 e collaborationforum ppt_migliori
 
Kolodner2 e collaborationforum
Kolodner2 e collaborationforumKolodner2 e collaborationforum
Kolodner2 e collaborationforum
 
E collaborationforum ppt_jmandel
E collaborationforum ppt_jmandelE collaborationforum ppt_jmandel
E collaborationforum ppt_jmandel
 
Blatt e collaborative himss 2012 final
Blatt   e collaborative himss 2012 finalBlatt   e collaborative himss 2012 final
Blatt e collaborative himss 2012 final
 
Himss e collaboration forum closing session (kuraitis, shah) final
Himss e collaboration forum closing session (kuraitis, shah) finalHimss e collaboration forum closing session (kuraitis, shah) final
Himss e collaboration forum closing session (kuraitis, shah) final
 
Dave Whitlinger - NYeHC - eCollaborationForum 2012 - 02/23/12
Dave Whitlinger - NYeHC - eCollaborationForum 2012 - 02/23/12Dave Whitlinger - NYeHC - eCollaborationForum 2012 - 02/23/12
Dave Whitlinger - NYeHC - eCollaborationForum 2012 - 02/23/12
 

Último

Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 

Último (20)

How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 

David Kibbe of DirectTrust.org at 2012 eCollaboration Forum

  • 1. DirectTrust.org Building the Trust Framework for Directed Exchange David C. Kibbe, MD MBA NeHC University, February 8, 2012 kibbedavid@mac.com
  • 2. Today’s talk • About DirectTrust.org • Our mission and goals • Brief overview of Directed exchange • Why e-mail? Why ‘push’ ? • The importance of security and trust • Components of the Trust Framework • It’s all about identity!
  • 3. About DirectTrust.org • DirectTrust.org is being organized as an independent, non-profit, and competitively neutral entity created by and for Direct community participants. • Our goal is to develop, promote and, as necessary, help enforce the rules and best practices necessary to maintain trust within the Direct exchange community, and to foster widespread public confidence in the Direct exchange of health information.
  • 4. • Our web presence: About DirectTrust.org www.directtrust.wikispaces.com • ~80 members of the wiki, representing HISPs, HIEs, EHR technology vendors, Certificate Authorities, Identity Providers, state officials, patient advocacy organizations, providers, consultants, others. • Please join if you wish to contribute to the effort!
  • 5. About DirectTrust.org • Two active workgroups: Security and Trust Compliance; Certificate Policy and Practices • Organizational Committee Members • AAFP, Arcadia Solutions, Cerner, DigiCert, Gorge Health Connect, Relay Health, Rhode Island Quality Institute, SAFE- BioPharma, Surescripts
  • 6. The Direct Project  Created a set of protocols, specifications, and standards, that, with a policy and trust framework, enables simple, secure transport over the Internet, to be used for exchange between known participants in support of meaningful use.
  • 7. Meaningful Use, Quality Care Direct Project facilitates the communication of many different kinds of content necessary to fulfill meaningful use requirements. Examples of Meaningful Use  Other Providers/Authorized Entities:  Clinical information for care coordination  Labs – test results DIRECT  Referrals – summary of care record EXCH ANGE  Patients:  Health information  Discharge instructions  Clinical summaries b.wells@direct.aclinic.org  Reminders 1 Get a Direct Address ( e-mail-like) and a ) security certificate  Public Health: 2) Send mail securely using most e-mail  Immunization registries clients OR contract with a HIO or HISP  Syndromic surveillance that performs authentication, encryption and trust verification on your behalf  Laboratory Reporting
  • 8. Specific HISP duties: - provide subscribers with account and Direct addresses - provide web portal or EHR/PHR integration - arrange for identity verification - org and individual - arrange for digital certificate issuance, management - maintain integrity of trust and security framework - stay current with federal policies and regulations
  • 9. Security and Trust are Essential! • We trust our doctors and nurses with our health information. • We will need to be able to trust HISPs with our health information. • Without a high level of trust accompanied by the requisite levels of security and privacy protection, health data exchange of any type or technology will likely fail.
  • 10. Desirable HISP attributes: - strong, validated security practices - a track record in data exchange - working relationship with one or more RA/CA - able and willing to interoperably exchange with other HISPs - robust subscriber directory
  • 11. Why Digital Certificates are So Important to Directed Exchange • Digital certificates “stand in” for the individual/organizational identity in cyberspace • They are issued by an RA/CA only after identity verification proves you are who you say you are • They are used to sign, validate, and encrypt Direct exchange messages and attachments • Any breach of trust with respect to certificate issuance or use threatens the integrity of exchange
  • 12. Direct Identity, Trust, and Address Provisioning Certificate Authority (CA) Identity/Trust Certificate Verification Validation Service Certificate Signing Revocation Services Services The CA and RA enforce the 6. Certificate Signing 7. Direct Organization policies specified in the Request Certificate DirectTrust.org and FBCA 2. Request Direct Certificate Policies (CPs). Organization Assume has Digital Identity Certificate Registration Authority (RA) Certificate 3. Credentials and Documentation Compile/Validate Identity and Trust HCO Documentation  Representative Representative FBCA Credentials  Representative Healthcare Authorization Organization (HCO)  Legal Entity Documents 4. Direct 5. Public 8. Direct Organization Organization  Membership/Trust Domain Key Certificate Agreement  HIPAA status Domain Name System (DNS) 1. Enroll with HISP 9. Direct Address/ Health Information Service Org Certificate Provider (HISP) LDAP Name System Source: DirectTrust.org February, 2012
  • 13. Issues Remaining to be Resolved with Respect to the Direct Exchange Trust Framework • Who will be acceptable (ie. trustworthy) as Certificate Authorities? • What level(s) of identity verification is required for groups; professionals; patients? • What will be decided at a federal policy level, and what at an industry level?
  • 14. Questions, Comments • David C. Kibbe, MD MBA • kibbedavid@mac.com • 913 205 7968