SlideShare a Scribd company logo
1 of 18
Download to read offline
Privacy On FHIR®
Enabling Patient Controlled Privacy
Using Emerging Technology
DISCLAIMER: The views and opinions expressed in this presentation are those of the author and do not necessarily represent official policy or position of HIMSS.
Johnathan Coleman, ONC
Duane DeCouteau, VA
Adrian Gropper MD, PPR
We are on the cusp of a sea change in interoperability, population
management, and clinical decision support. CCD led to CCDA which
leads to FHIR® for content summary exchange. The Direct protocol
will evolve to a RESTful interface using OAuth/OpenID for trust fabric
creation.
However, we're not going to make the move to FHIR® and REST
unless pilots (followed by agile development of implementation guides)
are funded to enable incremental progress. FHIR® is too new and
REST has too many industry skeptics. The pilots will create a tipping
point which mitigates risk and enables progress. Dr. John Halamka
Privacy on FHIR® Vision
Introduction
The Office of the National Coordinator (ONC), in
collaboration with Department of Veterans Affairs (VA),
Health Level Seven® and other stakeholders, has initiated
the first pilot/demonstration project of HL7® and Health
Information Technology Standards Committee (HITSC)
recommended standards to support patient mediated
exchange and patient consent. The effort is called Privacy
on FHIR® (PoF) and is the underlying effort behind the
HIMSS demonstrations that you can see here today.
It was a Very Good Year…
• In 2014, HL7® approved New, Core Security and Privacy Standards for:
– Privacy and Security Healthcare Classification System (HCS)
– Privacy and Security Services: Security Labeling Services
– Privacy and Security Ontology
– Data Segmentation for Privacy Implementation Guide
– Patient Friendly Consent Directive (Draft in progress for May 2015 ballot)
• Health Information Technology Standards Committee (HITSC) made
Recommendations that:
– OpenID Foundation’s OpenID Connect,
– Internet Engineering Task Force’s OAuth 2.0, and
– HL7® ’s FHIR® comprised a reasonable and appropriate set of
standards to use as building blocks for more complicated
healthcare applications
• Kantara User Managed Access V1.0 approved as Kantara
recommendation March 26, 2015
• ONC Nationwide Interoperability Roadmap
• ONC Meaningful Use Certification Criteria NPRM
• PCAST: “Realizing the Full Potential of Health Information
Technology to Improve Healthcare for Americans: The Path
Forward”
• AHRQ Jason Report: “ A Robust Health Data Infrastructure“
FHIR® Pilot Technical Drivers :
Embrace FHIR®, JSON, REST, Oauth and
Kantara UMA
ONC/VA Privacy on FHIR® Pilot:
Summary
1. What is it? On-Demand bi-directional exchange of Health Information with your
selected Apps…What, When and How You Want it
2. Why do it? Test technical feasibility of using FHIR® and associated privacy and
security protocols to provide Patients with meaningful access, management and
use of their own information.
3. Deliverables?
• ONC sponsored HIMSS 2015 Interoperability Booths,
• Post-Conference Open Source Reference Model for implementers.
4. Who will do it? Collaborative of stakeholders dedicated to demonstrating the
benefits of HIT cloud capabilities for consumers and providers including:
ONC, VA, HL7®, SAMHSA, Patient Privacy Rights, Jericho Systems Corp,
MITRE, MIT
ONC/VA Privacy on FHIR® Pilot [PoF]:
What is HL7® FHIR® ?
Fast Healthcare Interoperability Resources
• FHIR® defines a set of "Resources" that
represent granular clinical concepts managed
in isolation, or aggregated into complex
documents.
• FHIR® is designed for the web:
― Simple XML or JSON structures,
― http-based RESTful protocol,
― Each resource has a predictable URL.
• FHIR® Security and Privacy follows HL7®
Security Labeling, Data Segmentation, and
Consent Directive standards
• FHIR® is under development and has not yet
reached full standard status
http://hl7.org/fhir/2015May/
Applying User Managed Access (UMA)-
Oauth 2.0 Profile
Patient controls Who gets What
PoF Architecture leverages cloud Privacy and Security Services that Patients use
daily as Online Consumers
User Managed Access
(UMA)
OpenID Connect / OAuth 2.0
Privacy on FHIR®
Share Health Information Among
Your Providers, Organizations, Apps,
and Individuals.
IOTIOT
Privacy…Share Only What You Want.
Your Sensitive Healthcare Information
Stays Secure.
Simple one-stop management of your privacy
choices from one place for all your providers
and Apps. Get a report of all disclosures
• Privacy by Design
• Manage Your Apps
• Choose what to Share
MY Consent Directives on FHIR
IOT
1. Create Consent Directive
2. Submit Consent Directive
3. Create Application Authorization
Provisioning
Use your Information for
Healthy Living, Wellness
Management
and Talking to Your Doctor
Online:
MY Apps on FHIR®
Share Health Information with Your
Selected Apps…What, When and How
You Want it…All 24/7
Smart Phone ----- Tablet ----- Personal Computer
IOT
• Fitness Apps
• Vitals Monitoring
• Your Personal Health Record
Apply
Resource
Privacy Marks
invokes
Privacy & Security Protective Services
Apply
Resource
Protections
invokes
Request
Policy
Submit
Policy
Policy
Management
Policy
Management
invokes
Policy
Enforcement Point
Policy
Enforcement Point
Enforce
Resource
Obligations
My “Apps on FHIR® ”
Policy
MY Apps on FHIR® Policy Enforcement
Restrictions enforced by
Resource Server Privacy
Protective Service
Resource Server
(e.g.,Redact, Mask, Anonymize, Pseudononymize)
Patient creates their
own personal
sensitivities list (e.g.,
HIV, ETH, Other, …)
Privacy Protected
My Health Information Exchange on FHIR®
Share Health Information Among
Your Providers.
IOT
• HL7 Fast Healthcare Interoperability Resources
Specification (FHIR™), Release 2 (Draft)
• HL7 Healthcare Privacy and Security
Classification System (HCS)
• HL7 Implementation Guide: Data Segmentation
for Privacy (DS4P), Release 1
• HL7® Patient Friendly Consent Directive
(Draft)
• HL7 Version 3 Standard: Privacy, Access and
Security Services; Security Labeling Service,
Release 1 (SLS)
• HL7 Version 3 Standard: Security and Privacy
Ontology, Release 1
• Kantara User Managed Access (UMA) V 1.0
• OpenID Foundation OpenID Connect
• IETF RFC 6749 The OAuth 2.0 Authorization
Framework
My Standards on FHIR®
Closing Remarks
• Perspective
– Solve the “Multiple Portals Problem” for Control of Personal
Information
– Bridge the gap between HIPAA and non-HIPAA Apps and
services
– Promote fair information practice: Data Minimization and
Persistence Minimization
– Provide total transparency and accounting for disclosures-no
hidden use of personal data
• “Privacy on FHIR” is an enormous step forward in
enabling patient control over personal health
information.
http://patientprivacyrights.org/
Questions?
UMA Protocol
• Phase 1 of the UMA core protocol involves the
resource owner introducing the resource server and
authorization server so they can work together.
• Phases 2 and 3 together involve the requesting
party, using a client, making an access attempt,
being tested for suitability by the authorization
server to receive permission, and ultimately
succeeding or failing in the attempt by presenting a
token with permissions associated with it.
Verify Token
Label/Transform Data9
RequestingOrg.
ProviderOrg.
HIE on FHIR® (detail)
Resource
Server
(Receiving)
FHIR®Client
Authorization client
CDMS
GUI
Approve
CD
1
Submit
CD
07
Set Resource Authz
Policy
3
Resource
Server
(Providing)
Protection
client
FHIR®API
10 Provide Data
Out of Band:
UMA Protection Flow:
UMA Authz. Flow:
Data Access Flow:
2
Acquire Protection Access Token
(PAT)
a
Register Resources &
Scopes
b
Acquire Authorization Access Token
(AAT)
a
Request Requesting Party Token
(RPT)
b
Issue and send
RPT
c
ACS
PPS/SLSRequest for Data + Authz
Token
8
RPT
Check Overarching
Policies
5
Redirect to AS6
Authorizatio
nAPI
Authorizatio
n Server
Protection
API
GUI
Request for Data4
Patient
AAT
a7
AAT
b7
RPT
c7
PAT
b2
PAT
a2

More Related Content

What's hot

secured storage of Personal health record in cloude
secured storage of Personal health record in cloudesecured storage of Personal health record in cloude
secured storage of Personal health record in cloudeMahaveer kandgule
 
C2 s presentation to beacons 2013 05-28 v1.1
C2 s presentation to beacons 2013 05-28 v1.1C2 s presentation to beacons 2013 05-28 v1.1
C2 s presentation to beacons 2013 05-28 v1.1Tony Calice ☁
 
Anish Arora - Playing With FHIR - A Practical Approach
Anish Arora - Playing With FHIR - A Practical ApproachAnish Arora - Playing With FHIR - A Practical Approach
Anish Arora - Playing With FHIR - A Practical ApproachHealthDev
 
IRDAI - NHA Joint Working Group: Sub Group on IT
IRDAI - NHA Joint Working Group: Sub Group on ITIRDAI - NHA Joint Working Group: Sub Group on IT
IRDAI - NHA Joint Working Group: Sub Group on ITPankaj Gupta
 
UMA as Authorization mechanism for IoT: a healthcare scenario
UMA as Authorization mechanism for IoT: a healthcare scenarioUMA as Authorization mechanism for IoT: a healthcare scenario
UMA as Authorization mechanism for IoT: a healthcare scenarioDomenico Catalano
 
Security & Privacy - Lecture E
Security & Privacy - Lecture ESecurity & Privacy - Lecture E
Security & Privacy - Lecture ECMDLearning
 
Google Cloud healthcare data platform and FHIR APIs by Kalyan Pamarthy
Google Cloud healthcare data platform and FHIR APIs by Kalyan PamarthyGoogle Cloud healthcare data platform and FHIR APIs by Kalyan Pamarthy
Google Cloud healthcare data platform and FHIR APIs by Kalyan PamarthyHealthDev
 
Personal Health Records - An Overview
Personal Health Records - An OverviewPersonal Health Records - An Overview
Personal Health Records - An Overviewrcostantini
 
Hl7 interface development
Hl7 interface developmentHl7 interface development
Hl7 interface developmentzionallen
 
Six pillars of security and privacy in telemedicine
Six pillars of security and privacy in telemedicineSix pillars of security and privacy in telemedicine
Six pillars of security and privacy in telemedicineirvinbalagosa
 
HIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An OverviewHIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An OverviewClearDATACloud
 
HIPAA Compliance Dangers for Digital Doctors
HIPAA Compliance Dangers for Digital DoctorsHIPAA Compliance Dangers for Digital Doctors
HIPAA Compliance Dangers for Digital Doctorsrobertpracticefusion
 
iTel Brochure 2015
iTel Brochure 2015 iTel Brochure 2015
iTel Brochure 2015 Ron Richard
 

What's hot (19)

secured storage of Personal health record in cloude
secured storage of Personal health record in cloudesecured storage of Personal health record in cloude
secured storage of Personal health record in cloude
 
C2 s presentation to beacons 2013 05-28 v1.1
C2 s presentation to beacons 2013 05-28 v1.1C2 s presentation to beacons 2013 05-28 v1.1
C2 s presentation to beacons 2013 05-28 v1.1
 
Anish Arora - Playing With FHIR - A Practical Approach
Anish Arora - Playing With FHIR - A Practical ApproachAnish Arora - Playing With FHIR - A Practical Approach
Anish Arora - Playing With FHIR - A Practical Approach
 
Hip hiu policy
Hip hiu policyHip hiu policy
Hip hiu policy
 
IRDAI - NHA Joint Working Group: Sub Group on IT
IRDAI - NHA Joint Working Group: Sub Group on ITIRDAI - NHA Joint Working Group: Sub Group on IT
IRDAI - NHA Joint Working Group: Sub Group on IT
 
UMA as Authorization mechanism for IoT: a healthcare scenario
UMA as Authorization mechanism for IoT: a healthcare scenarioUMA as Authorization mechanism for IoT: a healthcare scenario
UMA as Authorization mechanism for IoT: a healthcare scenario
 
Security & Privacy - Lecture E
Security & Privacy - Lecture ESecurity & Privacy - Lecture E
Security & Privacy - Lecture E
 
Google Cloud healthcare data platform and FHIR APIs by Kalyan Pamarthy
Google Cloud healthcare data platform and FHIR APIs by Kalyan PamarthyGoogle Cloud healthcare data platform and FHIR APIs by Kalyan Pamarthy
Google Cloud healthcare data platform and FHIR APIs by Kalyan Pamarthy
 
Personal Health Records - An Overview
Personal Health Records - An OverviewPersonal Health Records - An Overview
Personal Health Records - An Overview
 
Telemedicine: safety and security
Telemedicine: safety and securityTelemedicine: safety and security
Telemedicine: safety and security
 
Hl7 interface development
Hl7 interface developmentHl7 interface development
Hl7 interface development
 
Six pillars of security and privacy in telemedicine
Six pillars of security and privacy in telemedicineSix pillars of security and privacy in telemedicine
Six pillars of security and privacy in telemedicine
 
Aehin 2016 backup
Aehin 2016 backupAehin 2016 backup
Aehin 2016 backup
 
HIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An OverviewHIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An Overview
 
FHIR
FHIRFHIR
FHIR
 
HIPAA Compliance Dangers for Digital Doctors
HIPAA Compliance Dangers for Digital DoctorsHIPAA Compliance Dangers for Digital Doctors
HIPAA Compliance Dangers for Digital Doctors
 
BEMR
BEMRBEMR
BEMR
 
Federated architecture
Federated architectureFederated architecture
Federated architecture
 
iTel Brochure 2015
iTel Brochure 2015 iTel Brochure 2015
iTel Brochure 2015
 

Viewers also liked

Introdução ao Instituto HL7 Brasil
Introdução ao Instituto  HL7 BrasilIntrodução ao Instituto  HL7 Brasil
Introdução ao Instituto HL7 BrasilInstituto HL7 Brasil
 
FHIR Documents by Lloyd McKenzie
FHIR Documents by Lloyd McKenzieFHIR Documents by Lloyd McKenzie
FHIR Documents by Lloyd McKenzieFHIR Developer Days
 
A Baptism of FHIR - The Layman's intro to HL7 FHIR
A Baptism of FHIR - The Layman's intro to HL7 FHIRA Baptism of FHIR - The Layman's intro to HL7 FHIR
A Baptism of FHIR - The Layman's intro to HL7 FHIRMark Scrimshire
 
Rim derived and influenced hl7 standards
Rim derived and influenced hl7 standardsRim derived and influenced hl7 standards
Rim derived and influenced hl7 standardsAbdul-Malik Shakir
 
Hl7 Standards, Reference Information Model & Clinical Document Architecture
Hl7 Standards, Reference Information Model & Clinical Document ArchitectureHl7 Standards, Reference Information Model & Clinical Document Architecture
Hl7 Standards, Reference Information Model & Clinical Document ArchitectureNawanan Theera-Ampornpunt
 
Introduction to FHIR™
Introduction to FHIR™Introduction to FHIR™
Introduction to FHIR™Grahame Grieve
 

Viewers also liked (8)

Introdução ao Instituto HL7 Brasil
Introdução ao Instituto  HL7 BrasilIntrodução ao Instituto  HL7 Brasil
Introdução ao Instituto HL7 Brasil
 
FHIR Documents by Lloyd McKenzie
FHIR Documents by Lloyd McKenzieFHIR Documents by Lloyd McKenzie
FHIR Documents by Lloyd McKenzie
 
A Baptism of FHIR - The Layman's intro to HL7 FHIR
A Baptism of FHIR - The Layman's intro to HL7 FHIRA Baptism of FHIR - The Layman's intro to HL7 FHIR
A Baptism of FHIR - The Layman's intro to HL7 FHIR
 
Rim derived and influenced hl7 standards
Rim derived and influenced hl7 standardsRim derived and influenced hl7 standards
Rim derived and influenced hl7 standards
 
Interoperability, the rise of HL7 and FHIR
Interoperability, the rise of HL7 and FHIRInteroperability, the rise of HL7 and FHIR
Interoperability, the rise of HL7 and FHIR
 
Introduction to HL7 FHIR
Introduction to HL7 FHIRIntroduction to HL7 FHIR
Introduction to HL7 FHIR
 
Hl7 Standards, Reference Information Model & Clinical Document Architecture
Hl7 Standards, Reference Information Model & Clinical Document ArchitectureHl7 Standards, Reference Information Model & Clinical Document Architecture
Hl7 Standards, Reference Information Model & Clinical Document Architecture
 
Introduction to FHIR™
Introduction to FHIR™Introduction to FHIR™
Introduction to FHIR™
 

Similar to Privacy on FHIR Demo at HIMSS!5

Health Information Flows Technical Standards - V 0.5
Health Information Flows Technical Standards - V 0.5Health Information Flows Technical Standards - V 0.5
Health Information Flows Technical Standards - V 0.5ProductNation/iSPIRT
 
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...Richard Moore
 
Building an Integrated Healthcare Platform with FHIR®
Building an Integrated Healthcare Platform with FHIR®Building an Integrated Healthcare Platform with FHIR®
Building an Integrated Healthcare Platform with FHIR®WSO2
 
IHE on FHIR and DICOMweb 2017
IHE on FHIR and DICOMweb 2017IHE on FHIR and DICOMweb 2017
IHE on FHIR and DICOMweb 2017Brad Genereaux
 
Edifecs- warming up to fhir
Edifecs- warming up to fhirEdifecs- warming up to fhir
Edifecs- warming up to fhirEdifecs Inc
 
7 PROVEN REASONS THAT SHOWS YOU WHY FHIR IS BETTER
7 PROVEN REASONS THAT SHOWS YOU WHY FHIR IS BETTER7 PROVEN REASONS THAT SHOWS YOU WHY FHIR IS BETTER
7 PROVEN REASONS THAT SHOWS YOU WHY FHIR IS BETTERThiyagu2
 
Fast Healthcare Interoperability Resources is a draft standard descr.pdf
Fast Healthcare Interoperability Resources is a draft standard descr.pdfFast Healthcare Interoperability Resources is a draft standard descr.pdf
Fast Healthcare Interoperability Resources is a draft standard descr.pdfanuradhaartjwellery
 
Enabling Interoperability through Standards & Architecture
Enabling Interoperability through Standards & ArchitectureEnabling Interoperability through Standards & Architecture
Enabling Interoperability through Standards & ArchitectureHealth Informatics New Zealand
 
Introduction to Digital Health Standards with HL7 FHIR
Introduction to Digital Health Standards with HL7 FHIRIntroduction to Digital Health Standards with HL7 FHIR
Introduction to Digital Health Standards with HL7 FHIRJanaka Peiris
 
The need for interoperability in blockchain-based initiatives to facilitate c...
The need for interoperability in blockchain-based initiatives to facilitate c...The need for interoperability in blockchain-based initiatives to facilitate c...
The need for interoperability in blockchain-based initiatives to facilitate c...Massimiliano Masi
 
INTERFACE by apidays - Healthcare Interoperability: From Buzzword to APIs by ...
INTERFACE by apidays - Healthcare Interoperability: From Buzzword to APIs by ...INTERFACE by apidays - Healthcare Interoperability: From Buzzword to APIs by ...
INTERFACE by apidays - Healthcare Interoperability: From Buzzword to APIs by ...apidays
 
Using FHIR for Interoperability
Using FHIR for InteroperabilityUsing FHIR for Interoperability
Using FHIR for InteroperabilityIatric Systems
 
SMART on FHIR by Scot Post van der Burg
SMART on FHIR by Scot Post van der BurgSMART on FHIR by Scot Post van der Burg
SMART on FHIR by Scot Post van der BurgFurore_com
 
SMART on FHIR by Scot Post van der Burg
SMART on FHIR by Scot Post van der BurgSMART on FHIR by Scot Post van der Burg
SMART on FHIR by Scot Post van der BurgFHIR Developer Days
 
Why HL7 FHIR is Hot & SNOMED CT Is Cool - For Healthcare CIOs
Why HL7 FHIR is Hot & SNOMED CT Is Cool - For Healthcare CIOsWhy HL7 FHIR is Hot & SNOMED CT Is Cool - For Healthcare CIOs
Why HL7 FHIR is Hot & SNOMED CT Is Cool - For Healthcare CIOsPeter Jordan
 
Health IT Summit Beverly Hills 2014 – “A Use Case…Thoughts on How to Leverage...
Health IT Summit Beverly Hills 2014 – “A Use Case…Thoughts on How to Leverage...Health IT Summit Beverly Hills 2014 – “A Use Case…Thoughts on How to Leverage...
Health IT Summit Beverly Hills 2014 – “A Use Case…Thoughts on How to Leverage...Health IT Conference – iHT2
 
20110706 PIDSプロジェクト中間報告
20110706 PIDSプロジェクト中間報告20110706 PIDSプロジェクト中間報告
20110706 PIDSプロジェクト中間報告Nat Sakimura
 
Integrating with the epic platform fhir dev days 17
Integrating with the epic platform fhir dev days 17Integrating with the epic platform fhir dev days 17
Integrating with the epic platform fhir dev days 17DevDays
 
APIs, data formats and the growing might of FHIR
APIs, data formats and the growing might of FHIRAPIs, data formats and the growing might of FHIR
APIs, data formats and the growing might of FHIRVlad Stirbu
 

Similar to Privacy on FHIR Demo at HIMSS!5 (20)

Health Information Flows Technical Standards - V 0.5
Health Information Flows Technical Standards - V 0.5Health Information Flows Technical Standards - V 0.5
Health Information Flows Technical Standards - V 0.5
 
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
 
Building an Integrated Healthcare Platform with FHIR®
Building an Integrated Healthcare Platform with FHIR®Building an Integrated Healthcare Platform with FHIR®
Building an Integrated Healthcare Platform with FHIR®
 
IHE on FHIR and DICOMweb 2017
IHE on FHIR and DICOMweb 2017IHE on FHIR and DICOMweb 2017
IHE on FHIR and DICOMweb 2017
 
Edifecs- warming up to fhir
Edifecs- warming up to fhirEdifecs- warming up to fhir
Edifecs- warming up to fhir
 
7 PROVEN REASONS THAT SHOWS YOU WHY FHIR IS BETTER
7 PROVEN REASONS THAT SHOWS YOU WHY FHIR IS BETTER7 PROVEN REASONS THAT SHOWS YOU WHY FHIR IS BETTER
7 PROVEN REASONS THAT SHOWS YOU WHY FHIR IS BETTER
 
Fast Healthcare Interoperability Resources is a draft standard descr.pdf
Fast Healthcare Interoperability Resources is a draft standard descr.pdfFast Healthcare Interoperability Resources is a draft standard descr.pdf
Fast Healthcare Interoperability Resources is a draft standard descr.pdf
 
Enabling Interoperability through Standards & Architecture
Enabling Interoperability through Standards & ArchitectureEnabling Interoperability through Standards & Architecture
Enabling Interoperability through Standards & Architecture
 
Introduction to Digital Health Standards with HL7 FHIR
Introduction to Digital Health Standards with HL7 FHIRIntroduction to Digital Health Standards with HL7 FHIR
Introduction to Digital Health Standards with HL7 FHIR
 
The need for interoperability in blockchain-based initiatives to facilitate c...
The need for interoperability in blockchain-based initiatives to facilitate c...The need for interoperability in blockchain-based initiatives to facilitate c...
The need for interoperability in blockchain-based initiatives to facilitate c...
 
INTERFACE by apidays - Healthcare Interoperability: From Buzzword to APIs by ...
INTERFACE by apidays - Healthcare Interoperability: From Buzzword to APIs by ...INTERFACE by apidays - Healthcare Interoperability: From Buzzword to APIs by ...
INTERFACE by apidays - Healthcare Interoperability: From Buzzword to APIs by ...
 
Using FHIR for Interoperability
Using FHIR for InteroperabilityUsing FHIR for Interoperability
Using FHIR for Interoperability
 
SMART on FHIR by Scot Post van der Burg
SMART on FHIR by Scot Post van der BurgSMART on FHIR by Scot Post van der Burg
SMART on FHIR by Scot Post van der Burg
 
SMART on FHIR by Scot Post van der Burg
SMART on FHIR by Scot Post van der BurgSMART on FHIR by Scot Post van der Burg
SMART on FHIR by Scot Post van der Burg
 
Why HL7 FHIR is Hot & SNOMED CT Is Cool - For Healthcare CIOs
Why HL7 FHIR is Hot & SNOMED CT Is Cool - For Healthcare CIOsWhy HL7 FHIR is Hot & SNOMED CT Is Cool - For Healthcare CIOs
Why HL7 FHIR is Hot & SNOMED CT Is Cool - For Healthcare CIOs
 
Health IT Summit Beverly Hills 2014 – “A Use Case…Thoughts on How to Leverage...
Health IT Summit Beverly Hills 2014 – “A Use Case…Thoughts on How to Leverage...Health IT Summit Beverly Hills 2014 – “A Use Case…Thoughts on How to Leverage...
Health IT Summit Beverly Hills 2014 – “A Use Case…Thoughts on How to Leverage...
 
2016 iHT2 San Diego Health IT Summit
2016 iHT2 San Diego Health IT Summit2016 iHT2 San Diego Health IT Summit
2016 iHT2 San Diego Health IT Summit
 
20110706 PIDSプロジェクト中間報告
20110706 PIDSプロジェクト中間報告20110706 PIDSプロジェクト中間報告
20110706 PIDSプロジェクト中間報告
 
Integrating with the epic platform fhir dev days 17
Integrating with the epic platform fhir dev days 17Integrating with the epic platform fhir dev days 17
Integrating with the epic platform fhir dev days 17
 
APIs, data formats and the growing might of FHIR
APIs, data formats and the growing might of FHIRAPIs, data formats and the growing might of FHIR
APIs, data formats and the growing might of FHIR
 

Recently uploaded

Call Girls Kanakapura Road Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Kanakapura Road Just Call 7001305949 Top Class Call Girl Service A...Call Girls Kanakapura Road Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Kanakapura Road Just Call 7001305949 Top Class Call Girl Service A...narwatsonia7
 
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...narwatsonia7
 
Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...
Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...
Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...Miss joya
 
Call Girls In Andheri East Call 9920874524 Book Hot And Sexy Girls
Call Girls In Andheri East Call 9920874524 Book Hot And Sexy GirlsCall Girls In Andheri East Call 9920874524 Book Hot And Sexy Girls
Call Girls In Andheri East Call 9920874524 Book Hot And Sexy Girlsnehamumbai
 
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...narwatsonia7
 
Mumbai Call Girls Service 9910780858 Real Russian Girls Looking Models
Mumbai Call Girls Service 9910780858 Real Russian Girls Looking ModelsMumbai Call Girls Service 9910780858 Real Russian Girls Looking Models
Mumbai Call Girls Service 9910780858 Real Russian Girls Looking Modelssonalikaur4
 
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Call Girls Hebbal Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hebbal Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Hebbal Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hebbal Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...
Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...
Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...narwatsonia7
 
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...narwatsonia7
 
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% SafeBangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safenarwatsonia7
 
Call Girl Lucknow Mallika 7001305949 Independent Escort Service Lucknow
Call Girl Lucknow Mallika 7001305949 Independent Escort Service LucknowCall Girl Lucknow Mallika 7001305949 Independent Escort Service Lucknow
Call Girl Lucknow Mallika 7001305949 Independent Escort Service Lucknownarwatsonia7
 
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service MumbaiLow Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbaisonalikaur4
 
call girls in green park DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in green park  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in green park  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in green park DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
Call Girls Service Chennai Jiya 7001305949 Independent Escort Service Chennai
Call Girls Service Chennai Jiya 7001305949 Independent Escort Service ChennaiCall Girls Service Chennai Jiya 7001305949 Independent Escort Service Chennai
Call Girls Service Chennai Jiya 7001305949 Independent Escort Service ChennaiNehru place Escorts
 
VIP Call Girls Pune Vrinda 9907093804 Short 1500 Night 6000 Best call girls S...
VIP Call Girls Pune Vrinda 9907093804 Short 1500 Night 6000 Best call girls S...VIP Call Girls Pune Vrinda 9907093804 Short 1500 Night 6000 Best call girls S...
VIP Call Girls Pune Vrinda 9907093804 Short 1500 Night 6000 Best call girls S...Miss joya
 
See the 2,456 pharmacies on the National E-Pharmacy Platform
See the 2,456 pharmacies on the National E-Pharmacy PlatformSee the 2,456 pharmacies on the National E-Pharmacy Platform
See the 2,456 pharmacies on the National E-Pharmacy PlatformKweku Zurek
 
Russian Call Girls Chickpet - 7001305949 Booking and charges genuine rate for...
Russian Call Girls Chickpet - 7001305949 Booking and charges genuine rate for...Russian Call Girls Chickpet - 7001305949 Booking and charges genuine rate for...
Russian Call Girls Chickpet - 7001305949 Booking and charges genuine rate for...narwatsonia7
 

Recently uploaded (20)

Call Girls Kanakapura Road Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Kanakapura Road Just Call 7001305949 Top Class Call Girl Service A...Call Girls Kanakapura Road Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Kanakapura Road Just Call 7001305949 Top Class Call Girl Service A...
 
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
 
Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...
Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...
Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...
 
Call Girls In Andheri East Call 9920874524 Book Hot And Sexy Girls
Call Girls In Andheri East Call 9920874524 Book Hot And Sexy GirlsCall Girls In Andheri East Call 9920874524 Book Hot And Sexy Girls
Call Girls In Andheri East Call 9920874524 Book Hot And Sexy Girls
 
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
 
Mumbai Call Girls Service 9910780858 Real Russian Girls Looking Models
Mumbai Call Girls Service 9910780858 Real Russian Girls Looking ModelsMumbai Call Girls Service 9910780858 Real Russian Girls Looking Models
Mumbai Call Girls Service 9910780858 Real Russian Girls Looking Models
 
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
 
Call Girls Hebbal Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hebbal Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Hebbal Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hebbal Just Call 7001305949 Top Class Call Girl Service Available
 
Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...
Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...
Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...
 
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
 
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
 
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
 
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% SafeBangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
 
Call Girl Lucknow Mallika 7001305949 Independent Escort Service Lucknow
Call Girl Lucknow Mallika 7001305949 Independent Escort Service LucknowCall Girl Lucknow Mallika 7001305949 Independent Escort Service Lucknow
Call Girl Lucknow Mallika 7001305949 Independent Escort Service Lucknow
 
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service MumbaiLow Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
 
call girls in green park DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in green park  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in green park  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in green park DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
Call Girls Service Chennai Jiya 7001305949 Independent Escort Service Chennai
Call Girls Service Chennai Jiya 7001305949 Independent Escort Service ChennaiCall Girls Service Chennai Jiya 7001305949 Independent Escort Service Chennai
Call Girls Service Chennai Jiya 7001305949 Independent Escort Service Chennai
 
VIP Call Girls Pune Vrinda 9907093804 Short 1500 Night 6000 Best call girls S...
VIP Call Girls Pune Vrinda 9907093804 Short 1500 Night 6000 Best call girls S...VIP Call Girls Pune Vrinda 9907093804 Short 1500 Night 6000 Best call girls S...
VIP Call Girls Pune Vrinda 9907093804 Short 1500 Night 6000 Best call girls S...
 
See the 2,456 pharmacies on the National E-Pharmacy Platform
See the 2,456 pharmacies on the National E-Pharmacy PlatformSee the 2,456 pharmacies on the National E-Pharmacy Platform
See the 2,456 pharmacies on the National E-Pharmacy Platform
 
Russian Call Girls Chickpet - 7001305949 Booking and charges genuine rate for...
Russian Call Girls Chickpet - 7001305949 Booking and charges genuine rate for...Russian Call Girls Chickpet - 7001305949 Booking and charges genuine rate for...
Russian Call Girls Chickpet - 7001305949 Booking and charges genuine rate for...
 

Privacy on FHIR Demo at HIMSS!5

  • 1. Privacy On FHIR® Enabling Patient Controlled Privacy Using Emerging Technology DISCLAIMER: The views and opinions expressed in this presentation are those of the author and do not necessarily represent official policy or position of HIMSS. Johnathan Coleman, ONC Duane DeCouteau, VA Adrian Gropper MD, PPR
  • 2. We are on the cusp of a sea change in interoperability, population management, and clinical decision support. CCD led to CCDA which leads to FHIR® for content summary exchange. The Direct protocol will evolve to a RESTful interface using OAuth/OpenID for trust fabric creation. However, we're not going to make the move to FHIR® and REST unless pilots (followed by agile development of implementation guides) are funded to enable incremental progress. FHIR® is too new and REST has too many industry skeptics. The pilots will create a tipping point which mitigates risk and enables progress. Dr. John Halamka Privacy on FHIR® Vision
  • 3. Introduction The Office of the National Coordinator (ONC), in collaboration with Department of Veterans Affairs (VA), Health Level Seven® and other stakeholders, has initiated the first pilot/demonstration project of HL7® and Health Information Technology Standards Committee (HITSC) recommended standards to support patient mediated exchange and patient consent. The effort is called Privacy on FHIR® (PoF) and is the underlying effort behind the HIMSS demonstrations that you can see here today.
  • 4. It was a Very Good Year… • In 2014, HL7® approved New, Core Security and Privacy Standards for: – Privacy and Security Healthcare Classification System (HCS) – Privacy and Security Services: Security Labeling Services – Privacy and Security Ontology – Data Segmentation for Privacy Implementation Guide – Patient Friendly Consent Directive (Draft in progress for May 2015 ballot) • Health Information Technology Standards Committee (HITSC) made Recommendations that: – OpenID Foundation’s OpenID Connect, – Internet Engineering Task Force’s OAuth 2.0, and – HL7® ’s FHIR® comprised a reasonable and appropriate set of standards to use as building blocks for more complicated healthcare applications • Kantara User Managed Access V1.0 approved as Kantara recommendation March 26, 2015
  • 5. • ONC Nationwide Interoperability Roadmap • ONC Meaningful Use Certification Criteria NPRM • PCAST: “Realizing the Full Potential of Health Information Technology to Improve Healthcare for Americans: The Path Forward” • AHRQ Jason Report: “ A Robust Health Data Infrastructure“ FHIR® Pilot Technical Drivers : Embrace FHIR®, JSON, REST, Oauth and Kantara UMA
  • 6. ONC/VA Privacy on FHIR® Pilot: Summary 1. What is it? On-Demand bi-directional exchange of Health Information with your selected Apps…What, When and How You Want it 2. Why do it? Test technical feasibility of using FHIR® and associated privacy and security protocols to provide Patients with meaningful access, management and use of their own information. 3. Deliverables? • ONC sponsored HIMSS 2015 Interoperability Booths, • Post-Conference Open Source Reference Model for implementers. 4. Who will do it? Collaborative of stakeholders dedicated to demonstrating the benefits of HIT cloud capabilities for consumers and providers including: ONC, VA, HL7®, SAMHSA, Patient Privacy Rights, Jericho Systems Corp, MITRE, MIT
  • 7. ONC/VA Privacy on FHIR® Pilot [PoF]: What is HL7® FHIR® ? Fast Healthcare Interoperability Resources • FHIR® defines a set of "Resources" that represent granular clinical concepts managed in isolation, or aggregated into complex documents. • FHIR® is designed for the web: ― Simple XML or JSON structures, ― http-based RESTful protocol, ― Each resource has a predictable URL. • FHIR® Security and Privacy follows HL7® Security Labeling, Data Segmentation, and Consent Directive standards • FHIR® is under development and has not yet reached full standard status http://hl7.org/fhir/2015May/
  • 8. Applying User Managed Access (UMA)- Oauth 2.0 Profile Patient controls Who gets What PoF Architecture leverages cloud Privacy and Security Services that Patients use daily as Online Consumers User Managed Access (UMA) OpenID Connect / OAuth 2.0
  • 9. Privacy on FHIR® Share Health Information Among Your Providers, Organizations, Apps, and Individuals. IOTIOT
  • 10. Privacy…Share Only What You Want. Your Sensitive Healthcare Information Stays Secure. Simple one-stop management of your privacy choices from one place for all your providers and Apps. Get a report of all disclosures • Privacy by Design • Manage Your Apps • Choose what to Share MY Consent Directives on FHIR IOT 1. Create Consent Directive 2. Submit Consent Directive 3. Create Application Authorization Provisioning
  • 11. Use your Information for Healthy Living, Wellness Management and Talking to Your Doctor Online: MY Apps on FHIR® Share Health Information with Your Selected Apps…What, When and How You Want it…All 24/7 Smart Phone ----- Tablet ----- Personal Computer IOT • Fitness Apps • Vitals Monitoring • Your Personal Health Record
  • 12. Apply Resource Privacy Marks invokes Privacy & Security Protective Services Apply Resource Protections invokes Request Policy Submit Policy Policy Management Policy Management invokes Policy Enforcement Point Policy Enforcement Point Enforce Resource Obligations My “Apps on FHIR® ” Policy MY Apps on FHIR® Policy Enforcement Restrictions enforced by Resource Server Privacy Protective Service Resource Server (e.g.,Redact, Mask, Anonymize, Pseudononymize) Patient creates their own personal sensitivities list (e.g., HIV, ETH, Other, …) Privacy Protected
  • 13. My Health Information Exchange on FHIR® Share Health Information Among Your Providers. IOT
  • 14. • HL7 Fast Healthcare Interoperability Resources Specification (FHIR™), Release 2 (Draft) • HL7 Healthcare Privacy and Security Classification System (HCS) • HL7 Implementation Guide: Data Segmentation for Privacy (DS4P), Release 1 • HL7® Patient Friendly Consent Directive (Draft) • HL7 Version 3 Standard: Privacy, Access and Security Services; Security Labeling Service, Release 1 (SLS) • HL7 Version 3 Standard: Security and Privacy Ontology, Release 1 • Kantara User Managed Access (UMA) V 1.0 • OpenID Foundation OpenID Connect • IETF RFC 6749 The OAuth 2.0 Authorization Framework My Standards on FHIR®
  • 15. Closing Remarks • Perspective – Solve the “Multiple Portals Problem” for Control of Personal Information – Bridge the gap between HIPAA and non-HIPAA Apps and services – Promote fair information practice: Data Minimization and Persistence Minimization – Provide total transparency and accounting for disclosures-no hidden use of personal data • “Privacy on FHIR” is an enormous step forward in enabling patient control over personal health information. http://patientprivacyrights.org/
  • 17. UMA Protocol • Phase 1 of the UMA core protocol involves the resource owner introducing the resource server and authorization server so they can work together. • Phases 2 and 3 together involve the requesting party, using a client, making an access attempt, being tested for suitability by the authorization server to receive permission, and ultimately succeeding or failing in the attempt by presenting a token with permissions associated with it.
  • 18. Verify Token Label/Transform Data9 RequestingOrg. ProviderOrg. HIE on FHIR® (detail) Resource Server (Receiving) FHIR®Client Authorization client CDMS GUI Approve CD 1 Submit CD 07 Set Resource Authz Policy 3 Resource Server (Providing) Protection client FHIR®API 10 Provide Data Out of Band: UMA Protection Flow: UMA Authz. Flow: Data Access Flow: 2 Acquire Protection Access Token (PAT) a Register Resources & Scopes b Acquire Authorization Access Token (AAT) a Request Requesting Party Token (RPT) b Issue and send RPT c ACS PPS/SLSRequest for Data + Authz Token 8 RPT Check Overarching Policies 5 Redirect to AS6 Authorizatio nAPI Authorizatio n Server Protection API GUI Request for Data4 Patient AAT a7 AAT b7 RPT c7 PAT b2 PAT a2