Health Information Security and Privacy Collaboration (HISPC) National Conference

Size: px
Start display at page:

Download "Health Information Security and Privacy Collaboration (HISPC) National Conference"

Transcription

1 Health Information Security and Privacy Collaboration (HISPC) National Conference Privacy and Security Technology Standards: An Update from HITSP, CCHIT and NHIN March 5, 2009 Bethesda, MD Presenters Glen Marshall Co-Chair, HITSP Security, Privacy and Infrastructure (SPI) Technical Committee Rick Brady Co-Chair, CCHIT Security Don Bechtel Co-Chair, CCHIT Privacy and Compliance Erik Rolf Co-Chair, NHIN Privacy and Security Sub- Moderator Walter G. Suarez, MD Member, NCVHS; Co-Chair, HITSP SPI TC and HITSP Education Committee; Member, CCHIT Privacy and Compliance

2 Report from the Security, Privacy, and Infrastructure Domain Technical Committee Bethesda, MD March 5, 2009 Presented by: Glen F. Marshall, HITSP SPI TC Co Chair enabling healthcare interoperability 2

3 Report from the HITSP Security, Privacy, and Infrastructure Domain Technical Committee Pre-2008 constructs and maintenance in 2008 New constructs developed for 2008 use cases Other activities in 2008 Activities planned for 2009 HITSP enabling healthcare interoperability Slide 3

4 Overview Volunteer-driven, consensus-based organization that is funded through a contract from the Department of Health and Human Services The Panel brings together experts from across the healthcare community... from consumers to doctors, nurses, and hospitals; from those who develop healthcare IT products to those who use them; and from the government agencies who monitor the U.S. healthcare system to those organizations that are actually writing healthcare IT standards. HITSP enabling healthcare interoperability Slide 4

5 Roles and Responsibilities To harmonize and recommend the technical standards that are necessary to assure the interoperability of electronic health records Create HITSP-recommended Interoperability Specifications (IS) that specify how and what standards should be used for a particular Use Case Support deployment and implementation of these HITSP-recommended Interoperability Specifications Help Standards Development Organizations (SDOs) maintain, revise or develop new standards as required to support the HITSP-recommended Interoperability Specifications HITSP enabling healthcare interoperability Slide 5

6 Organizational Structure HITSP enabling healthcare interoperability Slide 6

7 HITSP Security, Privacy and Infrastructure (SPI) - Core Components of the HITSP Work HITPS SPI Goal: To identity, evaluate and recommend security, privacy and infrastructure constructs that address interoperability needs and requirements defined by the NeHC (AHIC) and ONC Uses Cases Process: Identify Security, Privacy and Infrastructure needs (requirements) from NeHC (AHIC) use-cases/value cases Identify Candidate Standards and evaluate/select standards for interoperability, based on HITSP Tier 2 Criteria Identify and document constructs which describe implementation of the selected standards and maximize the potential for re-use in future AHIC Use Cases Recommend the selected constructs for acceptance and recognition by the Secretary of Health and Human Services Incorporate the applicable constructs throughout all HITSP Interoperability Specifications (ISs) Maintain/update constructs periodically (and develop new ones, as needed) based on new use cases and value cases issued by NeHC (AHIC) and ONC HITSP enabling healthcare interoperability Slide 7

8 Existing Constructs T15 - Collect and Communicate Security Audit Trail T16 - Consistent Time T17 - Secured Communication Channel C19 - Entity Identity Assertion TP20 - Access Control C26 - Nonrepudiation of Origin TP30 - Manage Consent Directives TP13 - Manage Sharing of Documents T14 - Send Lab Result Message TP21 - Query for Existing Data TP22 - Patient ID Cross-Referencing T23 - Patient Demographics Query T24 Pseudonymize C25 - Anonymize T29 - Notification of Document Availability T31 - Document Reliable Interchange T33 - Transfer of Documents on Media C44 - Secure Web Connection TP50 - Retrieve Form for Data Capture TN900 S&P Technical Note HITSP enabling healthcare interoperability Slide 8

9 Maintenance in 2008 Minor updates to reflect new underlying standards versions, improve readability and usability, and correct minor editorial and technical issues: TP13 - Manage Sharing of Documents T15 - Collect and Communicate Security Audit Trail T17 Secured Communication Channel T23 - Patient Demographics Query TP22 - Query for Existing Data C26 - Nonrepudiation of Origin T29 - Notification of Document Availability T31 Document Reliable Interchange T33 - HITSP Transfer of Documents on Media TP50 - Retrieve Form for Data Capture Transaction Package HITSP enabling healthcare interoperability Slide 9

10 Maintenance in 2008 More extensive updates TP20 Access Control o o Extensive updates for readability and usability Minor updates to reflect new underlying standards versions and correct minor editorial and technical issues TP21 - Query for Existing Data o Major update to reference the most recent version of the IHE QED Integration Profile supplement o Additional updates to reflect changes in the underlying standard with respect to the technical actors that are referenced, the transactions that are used by the technical actors, and a further refinement of the HL7 V3.0 standard HITSP enabling healthcare interoperability Slide 10

11 Other Activities in 2008 Renamed from Security and Privacy Technical Committee to Security, Privacy and Infrastructure (SPI) Domain Technical Committee Inherited and became responsible for 11 pre-existing Infrastructure constructs Also, during the year Identity Credentials Management Work Group (WG tasks now complete) Webinars and outreach activities NHIN clarification requests Foundations Committee Privacy and Security Matrices FHAs Security Strategy Subgroup National Governors Association (NGA) State Alliance for ehealth CCHIT, including Co-chair/Expert Panel participation HITSP enabling healthcare interoperability Slide 11

12 New Constructs C62- Unstructured Document T63 - Emergency Message Distribution Element T64 - Identify Communication Recipients T66 - Retrieve Value Set T67 - Clinical Referral Request T81 - Retrieval of Medical Knowledge T85 - Administrative Transport to Health Plan C87 - Anonymize for PHCR C88 - Anonymize for IRM HITSP enabling healthcare interoperability Slide 12

13 Activities Planned for 2009 TN900: Significant restructuring of the document is being undertaken to: Improve overall readability, Decrease emphasis on initial 3 use cases Include additional clarification resulting from user community feedback TP20: Access Control Provide greater clarity of previously specified OASIS standards and explain when standards should be used Specify profiles for SAML, WS-Trust, etc (Initial draft of XSPA due in May) TP20 will be a focus of a HITSP demo at HIMSS 2009 TP30: Manage Consent Directives Transaction package upgrade based in part on the resolution of identified gaps Work with SDO to update HL7 Confidentiality codes, and ontology of roles C19: Entity Identity Assertion Component Update to support Level of Assurance T24: Pseudonymize Transaction Update to support provider and organizational pseudonyms 2009 Use Case / Gaps / Extensions work HITSP enabling healthcare interoperability Slide 13

14 Conclusion The HITSP SPI TC continues to make progress on Privacy, Security, and Interoperability standards, working within the multiplicity of jurisdictional constrained policies. New Use-Cases were well satisfied through re-use of existing SPI constructs. Look forward to practical feedback from NHIN experience with SPI constructs. Need to continue to expand our membership and expand the base of active members. HITSP enabling healthcare interoperability Slide 14

15 Join HITSP in developing a safe and secure health information network for the United States. Visit or contact... Michelle Deane, ANSI mmaasdeane@ansi.org Re: HITSP, its Board and Coordinating Committees Jessica Kant, HIMSS jkant@himss.org Theresa Wisdom, HIMSS twisdom@himss.org Re: HITSP Technical Committees HITSP enabling healthcare interoperability Slide 15

16 Certification Commission for Healthcare Information Technology Privacy & Security Technology Standards: Update from HITSP, CCHIT, NHIN Don Bechtel Privacy Officer, HDX, Siemens Medical Solutions And Co-Chair, CCHIT Privacy & Compliance Work Group Rick Brady President & CTO, BSTI and Co-Chair, Security Work Group March 5, :00 5:00 pm Eastern Time HISPC National Conference Bethesda, MD

17 Today s Topics CCHIT Background CCHIT s Security Work Group and Privacy & Compliance Work Group Scope of work and accomplishments Future directions for 2009 and beyond Harmonization with HITSP& NHIN How to Participate Q & A

18 Background

19 Mission and Goals Mission: Accelerate the adoption of robust, interoperable health IT by creating an efficient, credible certification process. Goals: Reduce the risks of investing in health IT Facilitate interoperability of health IT Unlock adoption incentives and regulatory relief Protect the privacy of health information A Federally Recognized Certification Body 2009 Slide 4

20 Role of Health IT Certification (*see American Recovery & Reinvestment Act of 2009) Office of the National Coordinator New Structures* Standards Harmonization HITSP NHIN Prototype & Implementation Projects Privacy & Security Policies, Laws, Regulations Harmonized Standards Network Architecture Privacy Policies Strategic Direction CCHIT: Certifying Standards Compliance of Health IT Certification of EHRs, PHRs and HIEs Governance and Consensus Process Engaging Public and Private Sector Stakeholders Accelerated adoption of robust, interoperable, privacy-enhancing health IT Certification is a voluntary mechanism to accelerate the adoption of standards and 2007 interoperability Slide 5 Oct 13, 2008

21 Volunteer Organization Develop Criteria for Optional Additional Certifications Child Health Developing 09 Criteria (Planned for launch in July 2009) Cardiovascular Medicine Developing 10 Criteria (Planned for launch in July 2010) Contribute Criteria for Specific Attributes Security Interoperability Privacy & Compliance Behavioral Health Long Term Care ( not yet formed) Develop Base Criteria for a Domain Ambulatory EHR Inpatient EHR Emergency Dept EHR HIE PHR Stand-alone eprescribing Over 200 volunteers currently serving 2009 Slide 6

22 09 Criteria Development Process and Timeline Inputs: (Developed Feb to June) * Scope Guidance from Commission * Roadmap (from previous year) * Future Directions (from previous year) * Environmental Scan: - Use Cases - Standards from HITSP, SDOs - Market research - More (e.g., NHIN coordination) Public Comment periods Develop Draft Criteria Refine Criteria and Develop Draft Test Scripts Proposed Final Criteria and Test Scripts Final Criteria and Test Scripts Launch Certification July Sept Dec March May Work Group Harmonization Pilot Test July 2009 Slide 7

23 Certification Commission for Healthcare Information Technology Security Work Group Co-chairs: Khalid Al-Maskari, CIO, COPE Community Services, Inc Rick Brady, President & CTO, BSTI Staff: Soloman Appavu,

24 Scope of Work Develop conformance criteria addressing security (confidentiality, integrity and availability) of health IT Design criteria so they are adaptable across many domains (care settings, populations specialties) Evaluate changes in the marketplace, technology capabilities and standards Provide a resource to work groups and security jurors Clarify criteria through public comment response Prepare stakeholders for future needs through the roadmap and future directions documents 2009 Slide 9

25 Categories of Criteria Access control Audit Authentication Reliability Security documentation Technical services Inter-domain Backup and recovery 2009 Slide 10

26 Accomplishments Set a baseline for the basic requirements for security Basic transport security Encryption of portable media deals with "headline news re: loss of PHI on backup tapes or stolen notebooks Two factor authentication (on roadmap) Created an inspection process accepted by stakeholders Enabling EHRs to meet future needs, regulatory or otherwise, to avoid a compliance crunch 2009 Slide 11

27 Future Directions Enhance the rigor of testing to secure public confidence Address the needs of diverse stakeholders Offer advanced labeled certification for products meeting an optional higher level of requirements Explore development of an open standards-based method to review health IT security, enabling the growing need for security audits 2009 Slide 12

28 09 Work Group Harmonization Develop Criteria for Optional Additional Certifications Child Health Cardiovascular Medicine Contribute Criteria for Specific Attributes Security Interoperability Privacy & Compliance Develop Base Criteria for a Domain Ambulatory EHR Inpatient EHR Emergency Dept EHR HIE PHR Stand-alone eprescribing 2009 Slide 13

29 Harmonization Perform research to add, incorporate or revise criteria Base criteria on US & international standards, and best practices Work closely with HITSP (overlapping WG members) Incorporate HITSP constructs into extant security criteria to clarify the intent and methods for meeting compliance Guide the HIE WG (coordinates with the NHIN initiative) 09 HIE requirements include physical security, time synchronization, audit control and log, internal and external scanning, virus protection, regular system audit, remote access control, business entity ID 2009 Slide 14

30 HITSP in 08 Criteria 2009 Slide 15

31 Certification Commission for Healthcare Information Technology Privacy & Compliance Work Group Co-chairs: Donald Bechtel, Privacy Officer, HDX Siemens Medical Solutions Cassi Birnbaum, RHIA, CPHQ, Director of Health Information/Privacy Officer, Rady Children's Hospital, San Diego Staff: Bonnie Cassidy:

32 A Developing Focus 2007: An expert panel guided work groups on privacy and compliance issues but did not develop 08 criteria 2008: A work group established for 09 certification Develop criteria that cut across all domains Re-evaluate existing 08 privacy criteria in the domains Harmonize future development to move cross-cutting privacy requirements to the Privacy and Compliance Work Group New criterion should appear on the road map 18 months prior to being required in the current year s criteria 2009 Slide 17

33 Scope of Work The Privacy and Compliance Work Group is tasked with developing criteria needed in all health IT systems for the protection of privacy and ensuring compliance with applicable laws. The Commission has provided guidance to the work group regarding the importance of avoiding requirements that have an adverse impact on the cost and/or usability of systems, and that might threaten the mission of accelerating health IT adoption Slide 18

34 Accomplishments Developed criteria addressing confidentiality, integrity and availability for 09 ambulatory EHR test scripts Added pending Records Management and Evidentiary Support (RM-ES) requirements to the road map Prepared stakeholders for future needs through the roadmap and future directions documents Prepared preliminary glossary of privacy terms 2008 Slide 19

35 09 Criteria Categories Privacy and data integrity in the management of clinical documentation, the extent to which data is complete, consistent and accurate Amendments alteration of health information by modification, correction, addition, or deletion Authentication and Authorship validation of correctness for both the information itself and the person who is the author or user of the information (JCAHO), or the provision of assurance of the claimed identity of an entity, receiver or subject (ASTM) 2009 Slide 20

36 Future Directions 10 Criteria Road Map Amendments add to ED and inpatient Consent Management EHR Trace-ability document event auditing Metadata Display of Clinical Notes Record Preservation Break the Glass 11 Criteria Road Map User Defined Alerts related to patient consents and authorizations Legal Business Record ability to view the complete order and medication history (HITSP) prevent a user s ability to deny the origination, receipt, or authorization of a data exchange (HITSP, HL7) 2008 Slide 21

37 09 Work Group Harmonization Develop Criteria for Optional Additional Certifications Child Health Cardiovascular Medicine Contribute Criteria for Specific Attributes Security Interoperability Privacy & Compliance Develop Base Criteria for a Domain Ambulatory EHR Inpatient EHR Emergency Dept EHR HIE PHR Stand-alone eprescribing 2009 Slide 22

38 Future Challenges Understanding and incorporating the privacy provisions of the HITECH Act in the ARRA of 2009 Existing regulations or best practices do not clearly differentiate paper vs. electronic EHRs What is practical for electronic records? Recognizing efficiencies and eliminating unnecessary processes Understanding the variations in federal and state requirements 2009 Slide 23

39 Certification Commission for Healthcare Information Technology Participating in the Process

40 Opportunities to Participate Work group applications open Mar 23 Apr 20 Commission nominations open every July Public comment periods (30 days) open in September, December, and March Town Call teleconferences on specific topics Town Halls at major meetings Apr 5-6, HIMSS09 (includes technical sessions) Watch for announcements of events Sign up for CCHIT enews at the website 2009 Slide 25

41 Nationwide Health Information Network Security and Privacy in the NHIN Erik Rolf, CISA, CISSP Co-Chair, NHIN Security and Privacy Sub- Security Architect, CareSpark HIE March 5, 2009

42 Agenda Project Scope and Goals Privacy and Security in the NHIN Parallel Work Threat Analysis Future Work 2

43 NHIN Network of Networks Health Bank or PHR Support Organization Community Health Centers Community #1 CDC IHS Common Dial Tone & Chain of Trust among NHIEs Enabled by Governance Structure & VA Integrated Delivery System DoD NCI CMS SSA Community #2 The Internet Standards, Specifications and Agreements for Secure Connections 3

44 Background and Scope NHIN Trial Implementation work began in October of Privacy and Security were tasked as key focus areas. Privacy context was defined based on NHIN guiding principles. Threat and vulnerability analysis was conducted on the Core Services specifications. 4

45 Parallel and Complimentary Work NHIN Cooperative Technical and Security Core Services Work Group Federal Security Strategy for Health Information Exchange AHIC Confidentiality, Security and Privacy Work Group Certification Commission for Health IT (CCHIT) Health Information Technology Standards Panel (HITSP) Health Information Security and Privacy Collaboration (HISPC) National Institute of Standards and Technology (NIST) Standards Development Organizations Defines functional and technical specifications for key services to be used in implementing health information exchanges. Develops guidance that enables the adoption of secure, scalable health information exchanges among Federal and private sector healthcare organizations. Makes recommendations on the protection of personal health information in order to secure trust, and support appropriate interoperable electronic health information exchange. Private-sector collaboration launched by AHIMA, HIMSS, and the National Alliance to certify health IT products. Public-private partnership chartered to identify, recommend, and harmonize data and technical standards for healthcare. Federal and state partnership working to harmonize laws and policies related to security and privacy. Develops federal security standards, guidelines, and procedures under authority from FISMA. Broad range of consortia, associations, and other bodies that create and maintain individual technical and data standards. 5

46 Privacy Context The NHIN is comprised of: Covered Entities (HIPAA) Business Associates of Covered Entities (HIPAA) Governmental agencies subject to varying privacy laws HIPAA non-covered Entities subject to other privacy laws The NHIN is an organizing concept, and therefore is not subject to privacy laws Privacy compliance is mandated by the Participants through a governing body and the Data Use and Reciprocal Support Agreement (DURSA) 6

47 Current Privacy Landscape of the NHIN Participating NHIEs play an important role in protecting privacy by: Obtaining authorization to share data across the NHIN Authenticating participant users Enforcing participant access for permitted purposes The NHIN Trial Implementations focused on developing and implementing technology that supports core privacy principles 7

48 Status of the NHIN Security & Privacy Protections Messaging Platform Supports data Confidentiality and Integrity Audit Log Query Interface Supports accounting of disclosures Authorization Framework Interface Supports authorization for access, purpose requests and verification of user 8

49 Status of the NHIN Security & Privacy Protections Consumer Preferences Interface Supports restrictions on access Authorized Case Follow-Up Supports requests for de-identified data and case follow-up DURSA Important component of the trust fabric: Supports access, accounting, restrictions, de-identification, verification of requestor, safeguards, incident reporting & mitigation 9

50 Web Services Threat Matrix The threats expected in the interoperability environment closely model those of web services and web service constructs. NHIN is closely correlated with web service mitigation strategies and mechanisms to address existing and emergent threats. 10

51 NHIN Privacy & Security Next Steps Development of governing body NHIE certification criteria (application, evaluation & testing) Centralized service registry Policy development regarding: Requirements for initial authorization & ongoing maintenance Resolution of outstanding interface issues Data elements Internal NHIE processing & auditing Criteria for queries outside treatment Support for varying authorization requirements Further interface development Policy choices in existing interfaces New interfaces as necessary to support future use cases 11

52 NHIN Privacy & Security Next Steps Define a baseline for consistent security standards among participants based on: Harmonization of security standards Industry best practices Common security policies and technology among HIEs 12

53 Future Work Further enhancement of controls in the areas of data integrity and nonrepudiation. Refine requirements for implementation of enhanced NHIE audit trails. Development of distributed access management capabilities for both data providers and consumers. Enhance service registration and discovery to facilitate data availability. Further strengthen of message initiator and receiver authentication 13

54 Future Work Analyze security dependencies and processes of NHIN participants Collaborate with HITSP on interoperability standards Collaborate with parallel workgroups regarding privacy and security implementation guidance Continue security control development to defend against continually evolving threat landscape 14

55 Final thoughts Expanding the discovery capabilities of the NHIN beyond NHIEs to address specific entities within an NHIE such as providers, labs, pharmacies, etc. As the NHIN moves into production in 2009, additional technical issues associated with maintaining a large scale dynamic network need to be addressed Certificate authorities and service registries must be accountable to the governance of the NHIN 15

56 Q&A Questions Answers 16

Four Goals of Certification

Four Goals of Certification Mission CCHIT is an independent, nonprofit organization with the mission of accelerating the adoption of robust, interoperable health IT by creating an efficient, credible certification process 2008 Slide

More information

CCHIT: A Progress Report on Behavioral Health EHR Certification

CCHIT: A Progress Report on Behavioral Health EHR Certification Certification Commission for Healthcare Information Technology CCHIT: A Progress Report on Behavioral Health EHR Certification Memo Keswick, MPA, Consultant and Co-Chair, Behavioral Health Work Group,

More information

Certification and Meaningful Use: EHR Product Certification

Certification and Meaningful Use: EHR Product Certification Certification Commission for Healthcare Information Technology Certification and Meaningful Use: EHR Product Certification Testimony before the NCVHS Executive Subcommittee Hearing on Meaningful Use Panel

More information

Understanding Certification: Evaluating Certified EHR Technology

Understanding Certification: Evaluating Certified EHR Technology Understanding Certification: Evaluating Certified EHR Technology Alisa Ray, Executive Director, Certification Commission for Health Information Technology Marisa L Wilson, DNSc, MHSc, RN-BC, Assistant

More information

Health IT Interoperability: HITSP Overview, Update and Discussion

Health IT Interoperability: HITSP Overview, Update and Discussion Health IT Interoperability: HITSP Overview, Update and Discussion July, 2008 Jamie Ferguson KP Health IT Strategy & Policy Health IT Strategy & Policy Agenda Overview Introductory Overview of HITSP HITSP

More information

CONNECTing to the Nationwide Health Information Network (NHIN)

CONNECTing to the Nationwide Health Information Network (NHIN) CONNECTing to the Nationwide Health Information Network (NHIN) Craig Miller (Contractor) CONNECT Chief Architect April 30, 2009 NHIN Mission Mission To achieve better quality, value, and affordability

More information

Identity Management for Interoperable Health Information Exchanges

Identity Management for Interoperable Health Information Exchanges Identity Management for Interoperable Health Information Exchanges Presented to the NASMD Medicaid Transformation Grants HIE Workgroup - March 26, 2008 Presented by: John (Mike) Davis, Department of Veterans

More information

EHR Certification and Meaningul Use: Sorting it Out. Karen Bell, MD Chair, CCHIT REC Summit October 4, 2010 San Francisco, California

EHR Certification and Meaningul Use: Sorting it Out. Karen Bell, MD Chair, CCHIT REC Summit October 4, 2010 San Francisco, California EHR Certification and Meaningul Use: Sorting it Out Karen Bell, MD Chair, CCHIT REC Summit October 4, 2010 San Francisco, California Topics The importance of establishing goals for EHR investment Types

More information

Electronic Health Record

Electronic Health Record Webinar Series Emergency Responder Electronic Health Record Emergency Information Infrastructure t Project HITSP Contacts: Stephen Hufnagel PhD, Co-chair Michael Glickman, Facilitator Jessica Kant, HIMSS

More information

ConnectVirginia EXCHANGE Onboarding and Certification Guide. Version 1.4

ConnectVirginia EXCHANGE Onboarding and Certification Guide. Version 1.4 ConnectVirginia EXCHANGE Onboarding and Certification Guide Version 1.4 July 18, 2012 CONTENTS 1 Overview... 5 2 Intended Audience... 5 3 ConnectVirginia Background... 5 3.1 Federated... 5 3.2 Secure...

More information

Board Presentation: Overview of Current Activity

Board Presentation: Overview of Current Activity enabling healthcare interoperability 0 0 Document Number: HITSP 09 N 405 Date: June, 2009 Board Presentation: Overview of Current Activity June, 2009 Presented by: LeRoy Jones, HITSP Program Manager enabling

More information

HL7 EHR System Functional Model and Standard (ISO/HL7 10781), Release 2

HL7 EHR System Functional Model and Standard (ISO/HL7 10781), Release 2 HL7 EHR System Functional Model and Standard (ISO/HL7 10781), Release 2 Health Information Management Systems Society (HIMSS) Las Vegas, NV 20 Feb 2012 Presented by: Mark G. Janczewski, MD, MPH Deloitte

More information

MFI 4 Extended Registry SC32/WG2

MFI 4 Extended Registry SC32/WG2 ISO/IEC 19763 44 MFI 4 Extended Registry Masaharu Obayashi SC32/WG2 2010.05.20 The relationship between Part 4 and the other parts (1) Specialization approach The metamodels of MFI 3,5,6,7,8,9,,,, are

More information

ISO/HL7 10781 EHR System Functional Model Standard

ISO/HL7 10781 EHR System Functional Model Standard ISO/HL7 10781 EHR System Functional Model Standard Presented by: Gary Dickinson Director, Healthcare Standards CentriHealth Co-Chair, HL7 EHR Work Group Lead, S&I Framework Cross-Initiative Simplification

More information

Patient Controlled Health Records Standards and Technical Track

Patient Controlled Health Records Standards and Technical Track Patient Controlled Health Records Standards and Technical Track Keith W. Boone Lead Interoperability System Designer - GE Healthcare Co-chair IHE Patient Care Coordination TC Member IHE IT Infrastructure

More information

Software Certification for Electronic Health Records: The Certification Commission for Healthcare Information Technology (CCHIT)

Software Certification for Electronic Health Records: The Certification Commission for Healthcare Information Technology (CCHIT) Software Certification for Electronic Health Records: The Certification Commission for Healthcare Information Technology (CCHIT) James J. Cimino, M.D. Columbia University, New York For the Health Information

More information

Health IT Certification: Implementing ICD-10 and SNOMED-CT in the United States

Health IT Certification: Implementing ICD-10 and SNOMED-CT in the United States Certification Commission for Healthcare Information Technology Health IT Certification: Implementing ICD-10 and SNOMED-CT in the United States Alisa Ray, Executive Director, CCHIT FPS-Health, Food Chain

More information

ehealth News from the NITC ehealth Council

ehealth News from the NITC ehealth Council NEBRASKA INFORMATION TECHNOLOGY COMMISSION NEBRASKA INFORMATION TECHNOLOGY COMMISSION January 2009 www.nitc.ne.gov from the NITC ehealth Council Contents Nebraska News Nebraska News NeHII prepares for

More information

Testimony of Michael Raymer Vice President and General Manager of Global Product Strategy GE Healthcare Integrated IT Solutions. in Support of HR 2406

Testimony of Michael Raymer Vice President and General Manager of Global Product Strategy GE Healthcare Integrated IT Solutions. in Support of HR 2406 GE Healthcare IITS Testimony for House Sci/Tech Subcommittee FINAL September 24, 2007 Firmani + Associates, Inc. Testimony of Michael Raymer Vice President and General Manager of Global Product Strategy

More information

Newborn Screening Interoperability Specification

Newborn Screening Interoperability Specification Newborn Screening Interoperability Specification Alan E Zuckerman MD Department of Pediatrics, Georgetown University National Library of Medicine, Lister Hill Center Washington DC aez@georgetown.edu 1

More information

Health Information Technology Initiative

Health Information Technology Initiative U.S. Department of Health and Human Services Health Information Technology Initiative Major Accomplishments: 2004-2006 In 2006, HHS achieved several major milestones to meet the President s call for most

More information

HIMSS Interoperability Showcase 2011

HIMSS Interoperability Showcase 2011 Interoperability will bind together a wide network of real-time life critical data that not only transform but become healthcare. Health Information Interoperability Challenges Healthcare and healthcare

More information

Leveraging Health Information Exchange to Improve Quality and Efficiency

Leveraging Health Information Exchange to Improve Quality and Efficiency Leveraging Health Information Exchange to Improve Quality and Efficiency Presentation for the TIGER Initiative November 1, 2007 Joyce Sensmeier MS, RN-BC, CPHIMS, FHIMSS Objectives Examine the role of

More information

The HITECH Act: Implications to HIPAA Covered Entities and Business Associates. Linn F. Freedman, Esq.

The HITECH Act: Implications to HIPAA Covered Entities and Business Associates. Linn F. Freedman, Esq. The HITECH Act: Implications to HIPAA Covered Entities and Business Associates Linn F. Freedman, Esq. Introduction and Overview On February 17, 2009, President Obama signed P.L. 111-05, the American Recovery

More information

Wireless and Mobile Technologies for Healthcare: Ensuring Privacy, Security, and Availability

Wireless and Mobile Technologies for Healthcare: Ensuring Privacy, Security, and Availability Wireless and Mobile Technologies for Healthcare: Ensuring Privacy, Security, and Availability T. Jepsen, N. Buckley, D. Witters, K. Stine INTRODUCTION The IEEE-USA Medical Technology Policy Committee sponsored

More information

HIPAA for HIT and EHRs. Latest on Meaningful Use and EHR Certification: For Privacy and Security Professionals

HIPAA for HIT and EHRs. Latest on Meaningful Use and EHR Certification: For Privacy and Security Professionals HIPAA for HIT and EHRs Latest on Meaningful Use and EHR Certification: For Privacy and Security Professionals Donald Bechtel, CHP Siemens Health Services Patient Privacy Officer Fair Information Practices

More information

National Web Resources related to the Minnesota Model for Adopting Interoperable Electronic Health Records

National Web Resources related to the Minnesota Model for Adopting Interoperable Electronic Health Records related to the Minnesota Model for Adopting Interoperable Electronic Health Records The resources listed below are organized by the Minnesota Model for Adopting Interoperable Electronic Health Records

More information

Interoperability Testing and Certification. Lisa Carnahan Computer Scientist Standards Coordination Office

Interoperability Testing and Certification. Lisa Carnahan Computer Scientist Standards Coordination Office Interoperability Testing and Certification Lisa Carnahan Computer Scientist Standards Coordination Office Discussion Topics US National Institute of Standards & Technology American Recovery & Reinvestment

More information

Identity: The Key to the Future of Healthcare

Identity: The Key to the Future of Healthcare Identity: The Key to the Future of Healthcare Chief Medical Officer Anakam Identity Services July 14, 2011 Why is Health Information Technology Critical? Avoids medical errors. Up to 98,000 avoidable hospital

More information

HIPAA 203: Security. An Introduction to the Draft HIPAA Security Regulations

HIPAA 203: Security. An Introduction to the Draft HIPAA Security Regulations HIPAA 203: Security An Introduction to the Draft HIPAA Security Regulations Presentation Agenda Security Introduction Security Component Requirements and Impacts Administrative Procedures Physical Safeguards

More information

HL7 Electronic Health Record System (EHR-S) Functional Model and Standard

HL7 Electronic Health Record System (EHR-S) Functional Model and Standard HL7 Electronic Health Record System (EHR-S) Functional Model and Standard Ambassador Briefing Gary Dickinson Co-Chair, HL7 EHR WG gary.dickinson@ehr-standards.co 2002-2009 Health Level Seven, Inc. All

More information

Healthcare Information Technology Standards Panel

Healthcare Information Technology Standards Panel Healthcare Information Technology Stards Panel 2006, 2007 Beyond John D. Halamka MD Chair, HITSP A public-private Community was established to serve as the focal point for America s health information

More information

HL7 EHR-S Records Management & Evidentiary Support Functional Profile

HL7 EHR-S Records Management & Evidentiary Support Functional Profile HL7 EHR-S Records Management & Evidentiary Support Functional Profile Michelle Dougherty, RHIA, CHP HIT Standards AHIMA for the Legal EHR michelle.dougherty@ahima.org An educational update to the HIMSS

More information

Healthcare Software Testing

Healthcare Software Testing Healthcare Software Testing AFour Technologies Pvt. Ltd. May 20, 2009 AFour Technologies 2009 1 Healthcare Background With increasing healthcare costs and looming Medicare bankruptcy, President George

More information

HL7 EHR System Functional Model and Standard

HL7 EHR System Functional Model and Standard HL7 EHR System Functional Model and Standard Presented by: Donald T. Mon, PhD Vice President, Practice Leadership American Health Information Management Association (AHIMA) Co-Chair, HL7 EHR WG HIMSS Annual

More information

Data Security and Integrity of e-phi. MLCHC Annual Clinical Conference Worcester, MA Wednesday, November 12, 2014 2:15pm 3:30pm

Data Security and Integrity of e-phi. MLCHC Annual Clinical Conference Worcester, MA Wednesday, November 12, 2014 2:15pm 3:30pm Electronic Health Records: Data Security and Integrity of e-phi Worcester, MA Wednesday, 2:15pm 3:30pm Agenda Introduction Learning Objectives Overview of HIPAA HIPAA: Privacy and Security HIPAA: The Security

More information

CONNECTing to the Nationwide Health Information Network (NHIN): The Road Ahead

CONNECTing to the Nationwide Health Information Network (NHIN): The Road Ahead CONNECTing to the Nationwide Health Information Network (NHIN): The Road Ahead An Interview with Dave Riley, Enaptics Consulting, LLC FHA CONNECT Initiative Lead NHIN Mission Achieve better quality, value,

More information

HEALTH INFORMATION TECHNOLOGY*

HEALTH INFORMATION TECHNOLOGY* GLOSSARY of COMMON TERMS and ACRONYMS In HEALTH INFORMATION TECHNOLOGY* (April 2011) AHIC American Health Information Community The AHIC was a federal advisory panel created by HHS to make recommendations

More information

HITSP/TN904. July 8, 2009 Version 1.0. Healthcare Information Technology Standards Panel. Harmonization Framework and Exchange Architecture Tiger Team

HITSP/TN904. July 8, 2009 Version 1.0. Healthcare Information Technology Standards Panel. Harmonization Framework and Exchange Architecture Tiger Team July 8, 2009 Version 1.0 Technical Note HITSP/TN904 Submitted to: Healthcare Information Technology Standards Panel Submitted by: Harmonization Framework and Exchange Architecture Tiger Team 20090708 V1.0

More information

Health Level Seven International Unlocking the Power of Health Information

Health Level Seven International Unlocking the Power of Health Information Health Level Seven International Unlocking the Power of Health Information An ANSI accredited standards developer March 15, 2010 Centers for Medicare and Medicaid Services Department of Health and Human

More information

Healthcare Information Exchange Software Testing

Healthcare Information Exchange Software Testing Healthcare Information Exchange Software Testing AFour Technologies May 20, 2009 AFour Technologies 2009 1 Healthcare Background With increasing healthcare costs and looming Medicare bankruptcy, President

More information

The Role of SOA in the Nationwide Health Information Network: An Update

The Role of SOA in the Nationwide Health Information Network: An Update The Role of SOA in the Nationwide Health Information Network: An Update OMG SOA in Healthcare Conference July 15, 2011 Dr. Douglas Fridsma Director, Office of Standards & Interoperability ONC Today s Agenda

More information

HIMSS Interoperability Showcase 2011

HIMSS Interoperability Showcase 2011 Interoperability will bind together a wide network of real-time life critical data that not only transform but become healthcare. Health Information Interoperability Challenges and Integrating Healthcare

More information

[Year] State of Michigan MiHIN Shared Services Operational Plan

[Year] State of Michigan MiHIN Shared Services Operational Plan [Year] State of Michigan MiHIN Shared Services Operational Plan Table of Contents 1 Stakeholder Approvals...1 2 Executive Summary...1 2.1 Governance...2 2.2 Finance...2 2.3 Technical Infrastructure...3

More information

Certification Handbook. CCHIT Certified 2011 Certification Program

Certification Handbook. CCHIT Certified 2011 Certification Program Certification Handbook CCHIT Certified 2011 Certification Program April 7, 2010 Table of Contents 1. OVERVIEW OF CCHIT CERTIFIED 2011 CERTIFICATION PROGRAMS... 4 1.1. Ambulatory EHR 2011 Certification...

More information

Version: January 2008 ASTM E-31: EHR and Informatics Standards Education For Health Professional Disciplines. Background

Version: January 2008 ASTM E-31: EHR and Informatics Standards Education For Health Professional Disciplines. Background Version: January 2008 ASTM E-31: EHR and Informatics Standards Education For Health Professional Disciplines Background Work on standards for the EHR in the context of all such standards for the Health

More information

Certification and Meaningful Use of Electronic Health Records what. care leaders must know

Certification and Meaningful Use of Electronic Health Records what. care leaders must know Certification and Meaningful Use of Electronic Health Records what hospice and home care leaders must know OBJECTIVES Define meaningful use requirements of electronic health records Explain certification

More information

Using SOA to deliver a Healthcare Interoperability Platform that improves medical outcomes and enables public health surveillance

Using SOA to deliver a Healthcare Interoperability Platform that improves medical outcomes and enables public health surveillance Using SOA to deliver a Healthcare Interoperability Platform that improves medical outcomes and enables public health surveillance Bart Harmon, M.D, M.P.H, Chief Medical Officer Nagesh Bashyam, Chief Architect

More information

Empowering Patients and Enabling Providers

Empowering Patients and Enabling Providers Empowering Patients and Enabling Providers WITH HEALTH INFORMATION PRIVACY Terry Callahan - Managing Director Agenda About HIPAAT Provider of consent management and auditing for personal/protected health

More information

Chapter 15 The Electronic Medical Record

Chapter 15 The Electronic Medical Record Chapter 15 The Electronic Medical Record 8 th edition 1 Lesson 15.1 Introduction to the Electronic Medical Record Define, spell, and pronounce the terms listed in the vocabulary. Discuss the presidential

More information

Appendix B: Existing Guidance to Support HIE Implementation Opportunities

Appendix B: Existing Guidance to Support HIE Implementation Opportunities Appendix B: Existing Guidance to Support HIE Implementation Opportunities APPENDIX B: EXISTING GUIDANCE TO SUPPORT HIE IMPLEMENTATION OPPORTUNITIES There is an important opportunity for the states and

More information

Testimony for National Committee on Vital and Health Statistics Subcommittee on Standards February 24, 2009

Testimony for National Committee on Vital and Health Statistics Subcommittee on Standards February 24, 2009 Testimony for National Committee on Vital and Health Statistics Subcommittee on Standards February 24, 2009 Rosemary Kennedy, MBA, RN, FAAN ANI - Alliance for Nursing Informatics Chief Nursing Informatics

More information

RECOMMENDED CHARTER FOR THE IDENTITY ECOSYSTEM STEERING GROUP

RECOMMENDED CHARTER FOR THE IDENTITY ECOSYSTEM STEERING GROUP RECOMMENDED CHARTER FOR THE IDENTITY ECOSYSTEM STEERING GROUP 1. Identity Ecosystem Steering Group Charter The National Strategy for Trusted Identities in Cyberspace (NSTIC or Strategy), signed by President

More information

Nationwide Health Information Network Overview

Nationwide Health Information Network Overview Nationwide Health Information Network Overview Ginger Price Program Director, Nationwide Health Information Network Office of the National Coordinator for Health IT Presentation to the Secretary s Advisory

More information

An Introduction to Health Level 7

An Introduction to Health Level 7 An Introduction to Health Level 7 Charles Jaffe, MD, PhD Chief Executive Officer American National Standards Institute April 21, 2011 Arlington, VA How much easier it is to be critical than to be correct.

More information

Overcoming EHR Certification Hurdles & Gaps

Overcoming EHR Certification Hurdles & Gaps Overcoming EHR Certification Hurdles & Gaps Karen Bell, MD, MMS Chair, CCHIT CMIO Summit June 10, 2011 1:00 2:00 PM Omni Parker House Hotel Boston, MA Topics Why Certification? Current Certification Programs

More information

Adoption of Standard Policies Collaborative Showcase Presentation March 6, 2009 Bethesda, MD

Adoption of Standard Policies Collaborative Showcase Presentation March 6, 2009 Bethesda, MD Health Information Security and Privacy Collaboration (HISPC) National Conference Adoption of Standard Policies Collaborative Showcase Presentation March 6, 2009 Bethesda, MD ASPC Showcase Agenda I. Introduction

More information

2/9/2012. 2012 HIPAA Privacy and Security Audit Readiness. Table of contents

2/9/2012. 2012 HIPAA Privacy and Security Audit Readiness. Table of contents 2012 HIPAA Privacy and Security Audit Readiness Mark M. Johnson National HIPAA Services Director Table of contents Page Background 2 Regulatory Background and HITECH Impacts 3 Office of Civil Rights (OCR)

More information

Business Associates, HITECH & the Omnibus HIPAA Final Rule

Business Associates, HITECH & the Omnibus HIPAA Final Rule Business Associates, HITECH & the Omnibus HIPAA Final Rule HIPAA Omnibus Final Rule Changes Business Associates Marissa Gordon-Nguyen, JD, MPH Health Information Privacy Specialist Office for Civil Rights/HHS

More information

Nationwide and Regional Health Information Networks and Federated Identity for Authentication and HIPAA Compliance

Nationwide and Regional Health Information Networks and Federated Identity for Authentication and HIPAA Compliance Nationwide and Regional Health Information Networks and Federated Identity for Authentication and HIPAA Compliance Christina Stephan, MD Co-Chair Liberty Alliance ehealth SIG National Library of Medicine

More information

An Introduction to Health IT Certification

An Introduction to Health IT Certification January 2009 Table of Contents Wanted: a mechanism to speed up health IT adoption... 3 What CCHIT demands of EHRs... 4 Summarizing the scope of functionality... 5 Building national priorities into EHRs...

More information

NISTIR 7497 Security Architecture Design Process for Health Information Exchanges (HIEs)

NISTIR 7497 Security Architecture Design Process for Health Information Exchanges (HIEs) NISTIR 7497 Security Architecture Design Process for Health Information Exchanges (HIEs) Matthew Scholl Kevin Stine Kenneth Lin Daniel Steinberg NISTIR 7497 Security Architecture Design Process for Health

More information

What is interoperability?

What is interoperability? The Path to Interoperability through Testing and Certification Joyce Sensmeier, President, IHE USA Anuj Desai, Vice President, New York ehealth Collaborative April 14, 2015 Learning Objectives Learn core

More information

The Privacy and Security Gaps in Health Information Exchanges

The Privacy and Security Gaps in Health Information Exchanges The Privacy and Security Gaps in Health Information Exchanges A White Paper by the AHIMA/HIMSS HIE Privacy & Security Joint Work Group April 2011 Table of Contents Executive Summary... 4 Regulatory Issues...

More information

Request for Proposal (RFP) Supporting Efficient Care Coordination for New Yorkers: Bulk Purchase of EHR Interfaces for Health Information

Request for Proposal (RFP) Supporting Efficient Care Coordination for New Yorkers: Bulk Purchase of EHR Interfaces for Health Information Request for Proposal (RFP) Supporting Efficient Care Coordination for New Yorkers: Bulk Purchase of EHR Interfaces for Health Information ISSUE DATE: April 10, 2013 RESPONSE DUE DATE: May 3, 2013 Region:

More information

EHR Association Recommendations for ARRA Meaningful User and EHR Certification Criteria for Hospitals. Meaningful User for Hospitals

EHR Association Recommendations for ARRA Meaningful User and EHR Certification Criteria for Hospitals. Meaningful User for Hospitals 230 E. Ohio Street Suite 500 Chicago, IL 60611 Phone: 734-477-0852 Fax: 734-973-6996 E-mail: himssehra@himss.org Abraxas Medical Solutions Allscripts Healthcare Solutions Amazing Charts BlueWare Inc. CHARTCARE,

More information

Privacy and Security: Meaningful Use in Healthcare Organizations

Privacy and Security: Meaningful Use in Healthcare Organizations Privacy and Security: Meaningful Use in Healthcare Organizations Phyllis A. Patrick, MBA, FACHE, CHC July 20, 2011 Webinar Essentials 1. Session is currently being recorded, and will be available on our

More information

AT&T Healthcare Community Online - Enabling Greater Access with Stronger Security

AT&T Healthcare Community Online - Enabling Greater Access with Stronger Security AT&T Healthcare Community Online: Enabling Greater Access with Stronger Security Overview/Executive Summary With a nationwide move to electronic health record (EHR) systems, healthcare organizations and

More information

Harmonized Use Case for Electronic Health Records (Laboratory Result Reporting) March 19, 2006

Harmonized Use Case for Electronic Health Records (Laboratory Result Reporting) March 19, 2006 Harmonized Use Case for Electronic Health Records (Laboratory Result Reporting) March 19, 2006 Office of the National Coordinator for Health Information Technology (ONC) Table of Contents American Health

More information

May 7, 2012. Re: RIN 0991-AB82. Dear Secretary Sebelius:

May 7, 2012. Re: RIN 0991-AB82. Dear Secretary Sebelius: May 7, 2012 Department of Health and Human Services Office of the National Coordinator for Health Information Technology Attention: 2014 Edition EHR Standards and Certification Proposed Rule Hubert H.

More information

Len Bowes, MD, MS, Intermountain Healthcare Medical Informatics Jan 2010. *ARRA = American Recovery and Reinvestment Act

Len Bowes, MD, MS, Intermountain Healthcare Medical Informatics Jan 2010. *ARRA = American Recovery and Reinvestment Act Len Bowes, MD, MS, Intermountain Healthcare Medical Informatics Jan 2010 *ARRA = American Recovery and Reinvestment Act What are HITECH and ARRA? The Health Information Technology for Economic and Clinical

More information

GAO. HEALTH INFORMATION TECHNOLOGY Efforts Continue but Comprehensive Privacy Approach Needed for National Strategy. Testimony

GAO. HEALTH INFORMATION TECHNOLOGY Efforts Continue but Comprehensive Privacy Approach Needed for National Strategy. Testimony GAO For Release on Delivery Expected at 2:00 p.m. EDT Tuesday, June 19, 2007 United States Government Accountability Office Testimony Before the Subcommittee on Information Policy, Census, and National

More information

Understanding EHRs: Common Features and Strategic Approaches for Medicaid/SCHIP

Understanding EHRs: Common Features and Strategic Approaches for Medicaid/SCHIP Understanding EHRs: Common Features and Strategic Approaches for Medicaid/SCHIP Presented by: Karen M. Bell MD, MMS, Director, HIT Adoption W. David Patterson PhD, Deputy Chief, Health and Demographics

More information

Ensuring Privacy and Security of Health Information Exchange in Pennsylvania

Ensuring Privacy and Security of Health Information Exchange in Pennsylvania Ensuring Privacy and Security of Health Information Exchange in Pennsylvania MARCH 31, 2009 1 Ensuring Privacy and Security of Health Information Exchange in Pennsylvania Prepared For: Pennsylvania Health

More information

HL7 PHR System Functional Model

HL7 PHR System Functional Model HL7 PHR System Functional Model Presented by: Donald T. Mon, PhD Co-Chair, EHR Work Group HIMSS, 2013 2013 Health Level Seven International. All Rights Reserved. HL7 and Health Level Seven are registered

More information

NATIONAL HEALTH POLICY FORUM. January 2010

NATIONAL HEALTH POLICY FORUM. January 2010 NATIONAL HEALTH POLICY FORUM January 2010 TAKE 1: OVERY ACT FUNDING FLOWS Funding Source Program Distribution Agency Funding Use Fund Recipients / Beneficiaries Entitlement Funds Appropriated Funds Medicare

More information

LEGAL HEALTH RECORD: Definition and Standards

LEGAL HEALTH RECORD: Definition and Standards LEGAL HEALTH RECORD: Definition and Standards DEVELOPING YOUR STRATEGY & Tool Kit Diane Premeau, MBA, MCIS, RHIA, RHIT, CHP, A.C.E. OBJECTIVES Define Legal Health Record Differentiate between Designated

More information

ehealth Exchange Onboarding Overview Jennifer Rosas, ehealth Exchange Director Kati Odom, ehealth Exchange Implementation Manager

ehealth Exchange Onboarding Overview Jennifer Rosas, ehealth Exchange Director Kati Odom, ehealth Exchange Implementation Manager ehealth Exchange Onboarding Overview Jennifer Rosas, ehealth Exchange Director Kati Odom, ehealth Exchange Implementation Manager Introduction to the ehealth Exchange Rapidly growing network for securely

More information

HL7 Personal Health Record System Functional Model and Standard & Industry Update

HL7 Personal Health Record System Functional Model and Standard & Industry Update HL7 Personal Health Record System Functional Model and Standard & Industry Update Presented by: R. Lenel James, CPHIT, CPEHR HL7 Co-Lead, EHR WG, Publishing HL7 Co-Lead, PHR WG, Conformance HIMSS, Member

More information

IHE IT Infrastructure Technical Framework Supplement 2007-2008

IHE IT Infrastructure Technical Framework Supplement 2007-2008 ACC, HIMSS and RSNA Integrating the Healthcare Enterprise 5 10 IHE IT Infrastructure Technical Framework Supplement 2007-2008 Template for XDS Affinity Domain Deployment Planning 15 20 Draft for Trial

More information

EHR Glossary of Terms

EHR Glossary of Terms EHR Glossary of Terms American Recovery and Reinvestment Act of 2009 (ARRA): budget bill enacted by Congress and signed by President Obama on February 17, 2009 that was designed to provide an economic

More information

Health Level Seven Records Management & Evidentiary Support (RM-ES) Supporting Clinical Documentation for Legal and Billing Purposes

Health Level Seven Records Management & Evidentiary Support (RM-ES) Supporting Clinical Documentation for Legal and Billing Purposes Health Level Seven Records Management & Evidentiary Support (RM-ES) Supporting Clinical Documentation for Legal and Billing Purposes HIT Policy Committee Meaningful Use WG/Certification & Adoption WG Public

More information

National Electronic Health Record Interoperability Chronology

National Electronic Health Record Interoperability Chronology MILITARY MEDICINE, 174, 5:35, 2009 National Electronic Health Record Interoperability Chronology Stephen P. Hufnagel, PhD ABSTRACT The federal initiative for electronic health record (EHR) interoperability

More information

Direct Secure Messaging: Improving the Secure and Interoperable Exchange of Health Information

Direct Secure Messaging: Improving the Secure and Interoperable Exchange of Health Information Direct Secure Messaging: Improving the Secure and Interoperable Exchange of Health Information Within the healthcare industry, the exchange of protected health information (PHI) is governed by regulations

More information

County of Los Angeles Department of Mental Health Office of the Medical Director Managed Care Division Provider Relations Unit

County of Los Angeles Department of Mental Health Office of the Medical Director Managed Care Division Provider Relations Unit County of Los Angeles Department of Mental Health Office of the Medical Director Managed Care Division Provider Relations Unit FEE-FOR-SERVICES ISSUES WORK GROUP MEETING Welcome and Introductions Wednesday,

More information

a GAO-07-238 GAO HEALTH INFORMATION TECHNOLOGY Early Efforts Initiated but Comprehensive Privacy Approach Needed for National Strategy

a GAO-07-238 GAO HEALTH INFORMATION TECHNOLOGY Early Efforts Initiated but Comprehensive Privacy Approach Needed for National Strategy GAO United States Government Accountability Office Report to Congressional Requesters January 2007 HEALTH INFORMATION TECHNOLOGY Early Efforts Initiated but Comprehensive Privacy Approach Needed for National

More information

The ONC-Coordinated Federal Health IT Strategic Plan: 2008-2012

The ONC-Coordinated Federal Health IT Strategic Plan: 2008-2012 The ONC-Coordinated Federal Health IT Strategic Plan: 2008-2012 June 3, 2008 Table of Contents Executive Summary...iii Strategic Plan Overview... 1 Tabular Summary of Plan... 8 Goal 1: Patient-focused

More information

ARRA HITECH Stimulus HIPAA Security Compliance Reporter. White Paper

ARRA HITECH Stimulus HIPAA Security Compliance Reporter. White Paper ARRA HITECH Stimulus HIPAA Security Compliance Reporter White Paper ARRA HITECH AND ACR2 HIPAA SECURITY The healthcare industry is in a time of great transition, with a government mandate for EHR/EMR systems,

More information

Demonstrating Meaningful Use of EHRs: The top 10 compliance challenges for Stage 1 and what s new with 2

Demonstrating Meaningful Use of EHRs: The top 10 compliance challenges for Stage 1 and what s new with 2 Demonstrating Meaningful Use of EHRs: The top 10 compliance challenges for Stage 1 and what s new with 2 Today s discussion A three-stage approach to achieving Meaningful Use Top 10 compliance challenges

More information

Office of the National Coordinator for Health Information Technology

Office of the National Coordinator for Health Information Technology Office of the National Coordinator for Health Information Technology Kelly Cronin Director, Office of Programs and Coordination Visit our website at: http://www. www.hhs.gov/healthit/ Office of the National

More information

To: CHIME Members From: CHIME Public Policy Staff Re: Summary - Interoperability Section (Sec. 3001) of the 21 st Century Cures Legislation

To: CHIME Members From: CHIME Public Policy Staff Re: Summary - Interoperability Section (Sec. 3001) of the 21 st Century Cures Legislation To: CHIME Members From: CHIME Public Policy Staff Re: Summary - Interoperability Section (Sec. 3001) of the 21 st Century Cures Legislation Purpose: Below is an overview of the section of the 21 st Century

More information

DEPARTMENT OF HEALTH AND HUMAN SERVICES. Health Information Technology: Initial Set of Standards, Implementation

DEPARTMENT OF HEALTH AND HUMAN SERVICES. Health Information Technology: Initial Set of Standards, Implementation DEPARTMENT OF HEALTH AND HUMAN SERVICES Office of the Secretary 45 CFR Part 170 RIN 0991-AB58 Health Information Technology: Initial Set of Standards, Implementation Specifications, and Certification Criteria

More information

HEALTH IT! LAW & INDUSTRY

HEALTH IT! LAW & INDUSTRY A BNA, INC. HEALTH IT! LAW & INDUSTRY Meaningful Use REPORT VOL. 2, NO. 15 APRIL 12, 2010 BNA Insights: Toward Achieving Meaningful Use: HHS Establishes Certification Criteria for Electronic Health Record

More information

Vermont s Roadmap for Health Information Technology to Support Health Care Reform

Vermont s Roadmap for Health Information Technology to Support Health Care Reform VERMONT INFORMATION TECHNOLOGY LEADERS Vermont s Roadmap for Health Information Technology to Support Health Care Reform State Alliance for E-Health State Learning Forum September 25-26, 2008 Paul Forlenza,

More information

Decrypting the Security Risk Assessment (SRA) Requirement for Meaningful Use

Decrypting the Security Risk Assessment (SRA) Requirement for Meaningful Use Click to edit Master title style Decrypting the Security Risk Assessment (SRA) Requirement for Meaningful Use Andy Petrovich, MHSA, MPH M-CEITA / Altarum Institute April 8, 2015 4/8/2015 1 1 Who is M-CEITA?

More information

ELECTRONIC HEALTH RECORDS. Nonfederal Efforts to Help Achieve Health Information Interoperability

ELECTRONIC HEALTH RECORDS. Nonfederal Efforts to Help Achieve Health Information Interoperability United States Government Accountability Office Report to Congressional Requesters September 2015 ELECTRONIC HEALTH RECORDS Nonfederal Efforts to Help Achieve Health Information Interoperability GAO-15-817

More information

Meaningful Use HL7 Version 2

Meaningful Use HL7 Version 2 Meaningful Use HL7 Version 2 HL7 Version 2 and Immunization Registries, HIMSS 2011, Orlando, FL John Quinn, HL7 CTO February 2011 Attribution of this content In addition to ONC final rules, this presentation

More information

Get Confidence in Mission Security with IV&V Information Assurance

Get Confidence in Mission Security with IV&V Information Assurance Get Confidence in Mission Security with IV&V Information Assurance September 10, 2014 Threat Landscape Regulatory Framework Life-cycles IV&V Rigor and Independence Threat Landscape Continuously evolving

More information

INFORMATION TECHNOLOGY POLICY

INFORMATION TECHNOLOGY POLICY COMMONWEALTH OF PENNSYLVANIA DEPARTMENT OF PUBLIC WELFARE INFORMATION TECHNOLOGY POLICY Name Of : DPW Information Security and Privacy Policies Domain: Security Date Issued: 05/09/2011 Date Revised: 11/07/2013

More information

HealthTECH Workforce Forum Presents: Electronic Health Records Adoption: Driving to 2015 and Beyond

HealthTECH Workforce Forum Presents: Electronic Health Records Adoption: Driving to 2015 and Beyond HealthTECH Workforce Forum Presents: Electronic Health Records Adoption: Driving to 2015 and Beyond May 19 th, 2011 EHR Implementation Panel Moderator: Paula J. Magnanti, MT(ASCP) Founder & Managing Principal

More information