SlideShare a Scribd company logo
Direct Project Boot Camp Chicago, Illinois
What is Direct? A project to create the set ofstandardsand services that, with a policy framework, enable simple, directed, routed, scalable transport over the Internet to be used for secure and meaningful exchange between known participants in support of meaningful use 2
Secure Internet-based Direct Communications Direct Project specifies a simple, secure, scalable, standards-based way for participants to send encrypted health information directly to known, trusted recipients over the Internet. h.elthie@direct.ahospital.org b.wells@direct.aclinic.org  Simple.Connects healthcare stakeholders through universal addressing using simple push of information. Secure. Users can easily verify messages are complete and not tampered with in travel. Scalable. Enables Internet scale with no need for central network authority.  Standards-based. Built on common Internet standards for secure e-mail communication.
Why Direct? When current methods of health information exchange are inadequate: Communication of health information among providers and patients still mainly relies on mail or fax Slow, inconvenient, expensive Health information and history is lost or hard to find in paper charts Current forms of electronic communication may not be secure Encryption features of off-the-shelf e-mail clients not often used in healthcare communications today  	Physicians need to transport and share clinical content electronically in order to satisfy Stage 1 Meaningful Use requirements. Need to meet physicians where they are now Direct will be one of the communication methods in the Nationwide Health Information Network Sources: http://www.flickr.com/photos/dougww/922328173/ http://www.flickr.com/photos/greenlagirl/154148230/sizes/o/ http://www.flickr.com/photos/kenjonbro/3418425029/sizes/m/
Who is Direct? (as of November 2010)  The Direct Project represents over 50 organizations and over 200 participants. Members participate in the Implementation Group and one or more of 6 workgroups. Implementation Group (50+ organizations, 200+ participants) Security and Trust Communications Documentation  and Testing Implementation Geographies Reference Implementation Best Practices
What do you need to enable Direct? Direct Addresses Security & Trust Services Direct Messages Message Transport & Delivery
Direct Addresses Direct Addresses are used to route information Look like email addresses Used only for health information exchange b.wells@direct.aclinic.org An individual may have multiple Direct addresses Domain Endpoint Direct Address
Security & Trust: Certificates Each Direct Address must have at least one digital certificate associated with it in order to securely transmit and receive health information Certificate may be tied to either the specific Direct Address or the Domain that is part of that address X.509v3 digital certificate standards By using certificates to securely transmit and receive information… The Sender has a strong mathematical certainty that only the Receiver or explicitly authorized delegates can view the message The Receiver has a strong mathematical certainty that only the Sender sent the message Both Sender and Receiver have confidence that nothing happened to the message in transit (e.g., tampering, disclosure, etc.)
Security & Trust: Certificate Discovery Certificate discovery must occur prior to a Direct message being sent in order to fulfill the encryption functions of the S/MIME format Discovery based on existing Internet protocols Existing specifications exist for discovery via DNS  Address-bound certificates must be associated with a Direct-formatted address Organization-bound certificates are stored under the Health Domain Name If DNS is not supported, an alternate method must be offered
Security & Trust: Trust Anchors ,[object Object]
Trust Anchors are Certificate Authorities (CAs)
Certificates are issued to parties that agree to abide by policies set and/or enforced by the Trust Anchor,[object Object]
Message Transport & Delivery Direct specifies Simple Mail Transport Protocol (SMTP) as its primary mechanism for delivering healthcare content from a sender to a receiver This choice supports environments that have minimal capabilities in terms of using Web Services and generating detailed metadataand allows for more advanced interoperability
Direct Project Compliance Compliance is defined in the Applicability Statement for Secure Health Transport Core set of requirements for using SMTP, S/MIME, and X509 certificates in an interoperable way However, it’s recognized that communities may use other standards or proprietary mechanisms internally Will generally have Direct-compliant gateways that implement the Applicability specification while harmonizing local standards/mechanisms to Direct-equivalents XDR and XDM for Direct Messaging specifies such a solution when using IHE XDR for local transport
SOAP, IHE and XD* Conversions While SMTP is the primary delivery method for Direct, some healthcare environments have existing SOAP-based Web Services that provide detailed metadata and have adopted a family of IHE profiles SOAP – format for exchanging structured information, based on XML for message format XDR and XDM for Direct Messaging XDR – supports a direct push model using Web Services transport XDM – supports a direct push model with SMTP as a transport option, among several XD* Conversion Enables interoperability between Direct participants who may be using SOAP+XDR, SMTP+XDM, or SMTP+MIME
XD* Conversion Processes XD* Conversion involves both transport and metadata ,[object Object]
Metadata may be created or transformedThree cases each for Senders and Receivers: ,[object Object]
SMTP+XDM (RFC5322+XDM)
SOAP+XDR,[object Object]
HIE Strategy should drive the approach to implementing Direct  Orchestrator Elevator Public Utility Capacity-Builder $ $ Rapid facilitation of directed exchange capabilities to support Stage 1 MU Develops and bolsters local exchange capabilities Connects local exchange activities with thin layer of statewide infrastructure Directly connects providers into centralized HIE solution Direct Approach #1: Market-based solns Direct Approach #3: Fill in the gaps Direct Approach #3: Fill in the gaps Direct Approach #2:  Offer complete svcs Direct Approach #2:  Offer complete svcs Individual States may adopt multiple strategies
User InterfacesOverview of Options Email Client S/MIME Encryption is popularly supported Downloadable Plug-in for Direct Web Portal (or Webmail) Web Portal can be set up by HISP or HIE Webmail with plugin for Direct EHR Module that enables Direct messaging Message generated and sent by EHR without intermediate steps @ EHR Individual communities are likely to include instances of all user interfaces, depending on provider preferences and choices in the local market

More Related Content

What's hot

iaetsd Shared authority based privacy preserving protocol
iaetsd Shared authority based privacy preserving protocoliaetsd Shared authority based privacy preserving protocol
iaetsd Shared authority based privacy preserving protocol
Iaetsd Iaetsd
 
Canarie Federated Non Web Signon
Canarie Federated Non Web SignonCanarie Federated Non Web Signon
Canarie Federated Non Web SignonChris Phillips
 
Ch12(revised 20071226)
Ch12(revised 20071226)Ch12(revised 20071226)
Ch12(revised 20071226)
華穗 徐
 
Distributed Systems
Distributed SystemsDistributed Systems
Distributed Systems
mitali.ray
 
Advantage of WCF Over Web Services
Advantage of WCF Over Web ServicesAdvantage of WCF Over Web Services
Advantage of WCF Over Web Services
Siva Tharun Kola
 
Business Data Communications and Networking 12th Edition FitzGerald Solutions...
Business Data Communications and Networking 12th Edition FitzGerald Solutions...Business Data Communications and Networking 12th Edition FitzGerald Solutions...
Business Data Communications and Networking 12th Edition FitzGerald Solutions...
TylerYuli
 
An Enhanced P2P Architecture for Dispersed Service Discovery
An Enhanced P2P Architecture for Dispersed Service DiscoveryAn Enhanced P2P Architecture for Dispersed Service Discovery
An Enhanced P2P Architecture for Dispersed Service Discovery
IJRES Journal
 
A MALICIOUS USERS DETECTING MODEL BASED ON FEEDBACK CORRELATIONS
A MALICIOUS USERS DETECTING MODEL BASED  ON FEEDBACK CORRELATIONSA MALICIOUS USERS DETECTING MODEL BASED  ON FEEDBACK CORRELATIONS
A MALICIOUS USERS DETECTING MODEL BASED ON FEEDBACK CORRELATIONS
IJCNC
 
Soa unit iv
Soa unit ivSoa unit iv
Soa unit iv
smitha273566
 
CISSPills #1.03
CISSPills #1.03CISSPills #1.03
Computer security module 4
Computer security module 4Computer security module 4
Computer security module 4
Deepak John
 
Secure Multi-Party Negotiation: An Analysis for Electronic Payments in Mobile...
Secure Multi-Party Negotiation: An Analysis for Electronic Payments in Mobile...Secure Multi-Party Negotiation: An Analysis for Electronic Payments in Mobile...
Secure Multi-Party Negotiation: An Analysis for Electronic Payments in Mobile...
IDES Editor
 
A SYNCHRONIZED DISTRIBUTED DENIAL OF SERVICE PREVENTION SYSTEM
A SYNCHRONIZED DISTRIBUTED DENIAL OF SERVICE PREVENTION SYSTEMA SYNCHRONIZED DISTRIBUTED DENIAL OF SERVICE PREVENTION SYSTEM
A SYNCHRONIZED DISTRIBUTED DENIAL OF SERVICE PREVENTION SYSTEM
cscpconf
 
H1085863
H1085863H1085863
H1085863
IJERD Editor
 
Trust Based Content Distribution for Peer-ToPeer Overlay Networks
Trust Based Content Distribution for Peer-ToPeer Overlay NetworksTrust Based Content Distribution for Peer-ToPeer Overlay Networks
Trust Based Content Distribution for Peer-ToPeer Overlay Networks
IJNSA Journal
 
XML Encryption and Signature for Securing Web Services
XML Encryption and Signature for Securing Web ServicesXML Encryption and Signature for Securing Web Services
XML Encryption and Signature for Securing Web Services
AIRCC Publishing Corporation
 
IRJET- Design of Anonymous Publish-Subscribe Messaging System in a P2P Networ...
IRJET- Design of Anonymous Publish-Subscribe Messaging System in a P2P Networ...IRJET- Design of Anonymous Publish-Subscribe Messaging System in a P2P Networ...
IRJET- Design of Anonymous Publish-Subscribe Messaging System in a P2P Networ...
IRJET Journal
 
A New Method to Stop Spam Emails in Sender Side
A New Method to Stop Spam Emails in Sender SideA New Method to Stop Spam Emails in Sender Side
A New Method to Stop Spam Emails in Sender Side
IDES Editor
 

What's hot (18)

iaetsd Shared authority based privacy preserving protocol
iaetsd Shared authority based privacy preserving protocoliaetsd Shared authority based privacy preserving protocol
iaetsd Shared authority based privacy preserving protocol
 
Canarie Federated Non Web Signon
Canarie Federated Non Web SignonCanarie Federated Non Web Signon
Canarie Federated Non Web Signon
 
Ch12(revised 20071226)
Ch12(revised 20071226)Ch12(revised 20071226)
Ch12(revised 20071226)
 
Distributed Systems
Distributed SystemsDistributed Systems
Distributed Systems
 
Advantage of WCF Over Web Services
Advantage of WCF Over Web ServicesAdvantage of WCF Over Web Services
Advantage of WCF Over Web Services
 
Business Data Communications and Networking 12th Edition FitzGerald Solutions...
Business Data Communications and Networking 12th Edition FitzGerald Solutions...Business Data Communications and Networking 12th Edition FitzGerald Solutions...
Business Data Communications and Networking 12th Edition FitzGerald Solutions...
 
An Enhanced P2P Architecture for Dispersed Service Discovery
An Enhanced P2P Architecture for Dispersed Service DiscoveryAn Enhanced P2P Architecture for Dispersed Service Discovery
An Enhanced P2P Architecture for Dispersed Service Discovery
 
A MALICIOUS USERS DETECTING MODEL BASED ON FEEDBACK CORRELATIONS
A MALICIOUS USERS DETECTING MODEL BASED  ON FEEDBACK CORRELATIONSA MALICIOUS USERS DETECTING MODEL BASED  ON FEEDBACK CORRELATIONS
A MALICIOUS USERS DETECTING MODEL BASED ON FEEDBACK CORRELATIONS
 
Soa unit iv
Soa unit ivSoa unit iv
Soa unit iv
 
CISSPills #1.03
CISSPills #1.03CISSPills #1.03
CISSPills #1.03
 
Computer security module 4
Computer security module 4Computer security module 4
Computer security module 4
 
Secure Multi-Party Negotiation: An Analysis for Electronic Payments in Mobile...
Secure Multi-Party Negotiation: An Analysis for Electronic Payments in Mobile...Secure Multi-Party Negotiation: An Analysis for Electronic Payments in Mobile...
Secure Multi-Party Negotiation: An Analysis for Electronic Payments in Mobile...
 
A SYNCHRONIZED DISTRIBUTED DENIAL OF SERVICE PREVENTION SYSTEM
A SYNCHRONIZED DISTRIBUTED DENIAL OF SERVICE PREVENTION SYSTEMA SYNCHRONIZED DISTRIBUTED DENIAL OF SERVICE PREVENTION SYSTEM
A SYNCHRONIZED DISTRIBUTED DENIAL OF SERVICE PREVENTION SYSTEM
 
H1085863
H1085863H1085863
H1085863
 
Trust Based Content Distribution for Peer-ToPeer Overlay Networks
Trust Based Content Distribution for Peer-ToPeer Overlay NetworksTrust Based Content Distribution for Peer-ToPeer Overlay Networks
Trust Based Content Distribution for Peer-ToPeer Overlay Networks
 
XML Encryption and Signature for Securing Web Services
XML Encryption and Signature for Securing Web ServicesXML Encryption and Signature for Securing Web Services
XML Encryption and Signature for Securing Web Services
 
IRJET- Design of Anonymous Publish-Subscribe Messaging System in a P2P Networ...
IRJET- Design of Anonymous Publish-Subscribe Messaging System in a P2P Networ...IRJET- Design of Anonymous Publish-Subscribe Messaging System in a P2P Networ...
IRJET- Design of Anonymous Publish-Subscribe Messaging System in a P2P Networ...
 
A New Method to Stop Spam Emails in Sender Side
A New Method to Stop Spam Emails in Sender SideA New Method to Stop Spam Emails in Sender Side
A New Method to Stop Spam Emails in Sender Side
 

Viewers also liked

Kurzweil ~ Humanity+
Kurzweil ~ Humanity+Kurzweil ~ Humanity+
Kurzweil ~ Humanity+Brian Ahier
 
Healthcare Innovation Challenge Webinar #4
Healthcare Innovation Challenge Webinar #4Healthcare Innovation Challenge Webinar #4
Healthcare Innovation Challenge Webinar #4
Brian Ahier
 
Enrollment Workgroup 06-28-10
Enrollment Workgroup 06-28-10Enrollment Workgroup 06-28-10
Enrollment Workgroup 06-28-10Brian Ahier
 
ACEP Massachusetts Emergency Physicians Survey Results
ACEP Massachusetts Emergency Physicians Survey ResultsACEP Massachusetts Emergency Physicians Survey Results
ACEP Massachusetts Emergency Physicians Survey Results
Brian Ahier
 
Governance Workgroup 9-3-10
Governance Workgroup 9-3-10Governance Workgroup 9-3-10
Governance Workgroup 9-3-10Brian Ahier
 
Privacy and Security Tiger Team Authentication Recommendations
Privacy and Security Tiger Team Authentication RecommendationsPrivacy and Security Tiger Team Authentication Recommendations
Privacy and Security Tiger Team Authentication RecommendationsBrian Ahier
 
David Blumenthal 092210
David Blumenthal 092210David Blumenthal 092210
David Blumenthal 092210
Brian Ahier
 
Enrollemt workgroup
Enrollemt workgroupEnrollemt workgroup
Enrollemt workgroupBrian Ahier
 
Patient Engagement Power Team Comments – Leslie Kelly Hall, Chair
Patient Engagement Power Team Comments – Leslie Kelly Hall, ChairPatient Engagement Power Team Comments – Leslie Kelly Hall, Chair
Patient Engagement Power Team Comments – Leslie Kelly Hall, Chair
Brian Ahier
 
Budget Cuts
Budget CutsBudget Cuts
Budget Cuts
Brian Ahier
 
Secondary uses data flow by entity type
Secondary uses data flow by entity typeSecondary uses data flow by entity type
Secondary uses data flow by entity typeBrian Ahier
 
Putting the 'IT' in Care Transitions
Putting the 'IT' in Care TransitionsPutting the 'IT' in Care Transitions
Putting the 'IT' in Care Transitions
Brian Ahier
 
PCAST Report Workgroup 01-14-11
PCAST Report Workgroup 01-14-11PCAST Report Workgroup 01-14-11
PCAST Report Workgroup 01-14-11
Brian Ahier
 
Open source’s role in CONNECTing the public and private sector healthcare com...
Open source’s role in CONNECTing the public and private sector healthcare com...Open source’s role in CONNECTing the public and private sector healthcare com...
Open source’s role in CONNECTing the public and private sector healthcare com...
Brian Ahier
 
Innovation Through the Lenses of HITECH and Health Reform
Innovation Through the Lenses of HITECH and Health ReformInnovation Through the Lenses of HITECH and Health Reform
Innovation Through the Lenses of HITECH and Health Reform
Brian Ahier
 
What Lies Ahead for ONC: Meaningful Use and Beyond
What Lies Ahead for ONC: Meaningful Use and BeyondWhat Lies Ahead for ONC: Meaningful Use and Beyond
What Lies Ahead for ONC: Meaningful Use and Beyond
Brian Ahier
 
S&I Framework Transitions of Care
S&I Framework Transitions of CareS&I Framework Transitions of Care
S&I Framework Transitions of Care
Brian Ahier
 
Remarks to Public Forum on National Health IT Policy
Remarks to Public Forum on National Health IT PolicyRemarks to Public Forum on National Health IT Policy
Remarks to Public Forum on National Health IT Policy
Brian Ahier
 
Hospital EHR Incentive Program
Hospital EHR Incentive ProgramHospital EHR Incentive Program
Hospital EHR Incentive ProgramBrian Ahier
 

Viewers also liked (19)

Kurzweil ~ Humanity+
Kurzweil ~ Humanity+Kurzweil ~ Humanity+
Kurzweil ~ Humanity+
 
Healthcare Innovation Challenge Webinar #4
Healthcare Innovation Challenge Webinar #4Healthcare Innovation Challenge Webinar #4
Healthcare Innovation Challenge Webinar #4
 
Enrollment Workgroup 06-28-10
Enrollment Workgroup 06-28-10Enrollment Workgroup 06-28-10
Enrollment Workgroup 06-28-10
 
ACEP Massachusetts Emergency Physicians Survey Results
ACEP Massachusetts Emergency Physicians Survey ResultsACEP Massachusetts Emergency Physicians Survey Results
ACEP Massachusetts Emergency Physicians Survey Results
 
Governance Workgroup 9-3-10
Governance Workgroup 9-3-10Governance Workgroup 9-3-10
Governance Workgroup 9-3-10
 
Privacy and Security Tiger Team Authentication Recommendations
Privacy and Security Tiger Team Authentication RecommendationsPrivacy and Security Tiger Team Authentication Recommendations
Privacy and Security Tiger Team Authentication Recommendations
 
David Blumenthal 092210
David Blumenthal 092210David Blumenthal 092210
David Blumenthal 092210
 
Enrollemt workgroup
Enrollemt workgroupEnrollemt workgroup
Enrollemt workgroup
 
Patient Engagement Power Team Comments – Leslie Kelly Hall, Chair
Patient Engagement Power Team Comments – Leslie Kelly Hall, ChairPatient Engagement Power Team Comments – Leslie Kelly Hall, Chair
Patient Engagement Power Team Comments – Leslie Kelly Hall, Chair
 
Budget Cuts
Budget CutsBudget Cuts
Budget Cuts
 
Secondary uses data flow by entity type
Secondary uses data flow by entity typeSecondary uses data flow by entity type
Secondary uses data flow by entity type
 
Putting the 'IT' in Care Transitions
Putting the 'IT' in Care TransitionsPutting the 'IT' in Care Transitions
Putting the 'IT' in Care Transitions
 
PCAST Report Workgroup 01-14-11
PCAST Report Workgroup 01-14-11PCAST Report Workgroup 01-14-11
PCAST Report Workgroup 01-14-11
 
Open source’s role in CONNECTing the public and private sector healthcare com...
Open source’s role in CONNECTing the public and private sector healthcare com...Open source’s role in CONNECTing the public and private sector healthcare com...
Open source’s role in CONNECTing the public and private sector healthcare com...
 
Innovation Through the Lenses of HITECH and Health Reform
Innovation Through the Lenses of HITECH and Health ReformInnovation Through the Lenses of HITECH and Health Reform
Innovation Through the Lenses of HITECH and Health Reform
 
What Lies Ahead for ONC: Meaningful Use and Beyond
What Lies Ahead for ONC: Meaningful Use and BeyondWhat Lies Ahead for ONC: Meaningful Use and Beyond
What Lies Ahead for ONC: Meaningful Use and Beyond
 
S&I Framework Transitions of Care
S&I Framework Transitions of CareS&I Framework Transitions of Care
S&I Framework Transitions of Care
 
Remarks to Public Forum on National Health IT Policy
Remarks to Public Forum on National Health IT PolicyRemarks to Public Forum on National Health IT Policy
Remarks to Public Forum on National Health IT Policy
 
Hospital EHR Incentive Program
Hospital EHR Incentive ProgramHospital EHR Incentive Program
Hospital EHR Incentive Program
 

Similar to ONC Direct Project Boot Camp

The Direct Project @ Quantified Self
The Direct Project @ Quantified SelfThe Direct Project @ Quantified Self
The Direct Project @ Quantified Selfaliemami
 
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
Richard Moore
 
OpenAthens and the future of access and identity management
OpenAthens and the future of access and identity managementOpenAthens and the future of access and identity management
OpenAthens and the future of access and identity management
Eduserv Foundation
 
Ch08 Authentication
Ch08 AuthenticationCh08 Authentication
Ch08 Authentication
Information Technology
 
TECHNOLOGY IN COMMUNICATION
TECHNOLOGY  IN  COMMUNICATION TECHNOLOGY  IN  COMMUNICATION
TECHNOLOGY IN COMMUNICATION
Abhishek Pachisia
 
Interoperability Between Healthcare Applications
Interoperability Between Healthcare ApplicationsInteroperability Between Healthcare Applications
Interoperability Between Healthcare ApplicationsJohn Gillson
 
Comptia security+ (sy0-601) exam dumps 2022
Comptia security+ (sy0-601) exam dumps 2022Comptia security+ (sy0-601) exam dumps 2022
Comptia security+ (sy0-601) exam dumps 2022
SkillCertProExams
 
International Journal on Web Service Computing (IJWSC)
International Journal on Web Service Computing (IJWSC)International Journal on Web Service Computing (IJWSC)
International Journal on Web Service Computing (IJWSC)
ijwscjournal
 
A Literature Review on Trust Management in Web Services Access Control
A Literature Review on Trust Management in Web Services Access ControlA Literature Review on Trust Management in Web Services Access Control
A Literature Review on Trust Management in Web Services Access Control
ijwscjournal
 
A Literature Review on Trust Management in Web Services Access Control
A Literature Review on Trust Management in Web Services Access ControlA Literature Review on Trust Management in Web Services Access Control
A Literature Review on Trust Management in Web Services Access Control
ijwscjournal
 
Securing Web Application, Services and Servers
Securing Web Application, Services and ServersSecuring Web Application, Services and Servers
Securing Web Application, Services and Servers
Dr.S.Jagadeesh Kumar
 
Development of Digital Identity Systems
Development of Digital Identity Systems Development of Digital Identity Systems
Development of Digital Identity Systems
Maganathin Veeraragaloo
 
Patient Data Exchange Server
Patient Data Exchange ServerPatient Data Exchange Server
Patient Data Exchange Serverwatchdog
 
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
Richard Moore
 
ESB Overview
ESB OverviewESB Overview
ESB Overview
Hamid Ghorbani
 
Data Stream Controller for Enterprise Cloud Application
Data Stream Controller for Enterprise Cloud ApplicationData Stream Controller for Enterprise Cloud Application
Data Stream Controller for Enterprise Cloud Application
IJSRD
 

Similar to ONC Direct Project Boot Camp (20)

The Direct Project @ Quantified Self
The Direct Project @ Quantified SelfThe Direct Project @ Quantified Self
The Direct Project @ Quantified Self
 
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
Health Identity Management & Role-Based Access Control in a Federated NHIN - ...
 
OpenAthens and the future of access and identity management
OpenAthens and the future of access and identity managementOpenAthens and the future of access and identity management
OpenAthens and the future of access and identity management
 
Ch08 Authentication
Ch08 AuthenticationCh08 Authentication
Ch08 Authentication
 
TECHNOLOGY IN COMMUNICATION
TECHNOLOGY  IN  COMMUNICATION TECHNOLOGY  IN  COMMUNICATION
TECHNOLOGY IN COMMUNICATION
 
Overview of Microsoft Exchange Online
Overview of Microsoft Exchange OnlineOverview of Microsoft Exchange Online
Overview of Microsoft Exchange Online
 
Interoperability Between Healthcare Applications
Interoperability Between Healthcare ApplicationsInteroperability Between Healthcare Applications
Interoperability Between Healthcare Applications
 
Comptia security+ (sy0-601) exam dumps 2022
Comptia security+ (sy0-601) exam dumps 2022Comptia security+ (sy0-601) exam dumps 2022
Comptia security+ (sy0-601) exam dumps 2022
 
Lecture 02
Lecture 02Lecture 02
Lecture 02
 
International Journal on Web Service Computing (IJWSC)
International Journal on Web Service Computing (IJWSC)International Journal on Web Service Computing (IJWSC)
International Journal on Web Service Computing (IJWSC)
 
A Literature Review on Trust Management in Web Services Access Control
A Literature Review on Trust Management in Web Services Access ControlA Literature Review on Trust Management in Web Services Access Control
A Literature Review on Trust Management in Web Services Access Control
 
A Literature Review on Trust Management in Web Services Access Control
A Literature Review on Trust Management in Web Services Access ControlA Literature Review on Trust Management in Web Services Access Control
A Literature Review on Trust Management in Web Services Access Control
 
Securing Web Application, Services and Servers
Securing Web Application, Services and ServersSecuring Web Application, Services and Servers
Securing Web Application, Services and Servers
 
Development of Digital Identity Systems
Development of Digital Identity Systems Development of Digital Identity Systems
Development of Digital Identity Systems
 
Patient Data Exchange Server
Patient Data Exchange ServerPatient Data Exchange Server
Patient Data Exchange Server
 
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
 
Vinod Rebello
Vinod RebelloVinod Rebello
Vinod Rebello
 
Presentation6
Presentation6Presentation6
Presentation6
 
ESB Overview
ESB OverviewESB Overview
ESB Overview
 
Data Stream Controller for Enterprise Cloud Application
Data Stream Controller for Enterprise Cloud ApplicationData Stream Controller for Enterprise Cloud Application
Data Stream Controller for Enterprise Cloud Application
 

More from Brian Ahier

Draft TEFCA
Draft TEFCADraft TEFCA
Draft TEFCA
Brian Ahier
 
Future is Now
Future is NowFuture is Now
Future is Now
Brian Ahier
 
AMA Digital Health Study
AMA Digital Health Study AMA Digital Health Study
AMA Digital Health Study
Brian Ahier
 
DoD onboarding slides
DoD onboarding slidesDoD onboarding slides
DoD onboarding slides
Brian Ahier
 
2015 Edition Proposed Rule Modifications to the ONC Health IT Certification ...
2015 Edition Proposed RuleModifications to the ONC Health IT Certification ...2015 Edition Proposed RuleModifications to the ONC Health IT Certification ...
2015 Edition Proposed Rule Modifications to the ONC Health IT Certification ...
Brian Ahier
 
Accountable Care Workgroup: Draft Recommendations
Accountable Care Workgroup: Draft RecommendationsAccountable Care Workgroup: Draft Recommendations
Accountable Care Workgroup: Draft RecommendationsBrian Ahier
 
FTC Spring Privacy Series: Consumer Generated and Controlled Health Data
FTC Spring Privacy Series: Consumer Generated and Controlled Health DataFTC Spring Privacy Series: Consumer Generated and Controlled Health Data
FTC Spring Privacy Series: Consumer Generated and Controlled Health Data
Brian Ahier
 
Mobile Device Tracking Seminar
Mobile Device Tracking SeminarMobile Device Tracking Seminar
Mobile Device Tracking Seminar
Brian Ahier
 
HIT Policy Committee FDASIA Update
HIT Policy Committee FDASIA UpdateHIT Policy Committee FDASIA Update
HIT Policy Committee FDASIA Update
Brian Ahier
 
Big Data and VistA Evolution, Theresa A. Cullen, MD, MS
Big Data and VistA Evolution, Theresa A. Cullen, MD, MSBig Data and VistA Evolution, Theresa A. Cullen, MD, MS
Big Data and VistA Evolution, Theresa A. Cullen, MD, MS
Brian Ahier
 
Meaningful Use Workgroup Stage 3 Recommendations
Meaningful Use Workgroup Stage 3 Recommendations Meaningful Use Workgroup Stage 3 Recommendations
Meaningful Use Workgroup Stage 3 Recommendations Brian Ahier
 
ONC 2015 Edition EHR Certification Criteria
ONC 2015 Edition EHR Certification CriteriaONC 2015 Edition EHR Certification Criteria
ONC 2015 Edition EHR Certification Criteria
Brian Ahier
 
Mark Bertolini of Aetna at JP Morgan Healthcare 2014
Mark Bertolini of Aetna at JP Morgan Healthcare 2014Mark Bertolini of Aetna at JP Morgan Healthcare 2014
Mark Bertolini of Aetna at JP Morgan Healthcare 2014Brian Ahier
 
DeSalvo Remarks to HIT Policy Committee 1-14-13
DeSalvo Remarks to HIT Policy Committee 1-14-13DeSalvo Remarks to HIT Policy Committee 1-14-13
DeSalvo Remarks to HIT Policy Committee 1-14-13Brian Ahier
 
Patient Identification and Matching Initiative Stakeholder Meeting
Patient Identification and Matching Initiative Stakeholder MeetingPatient Identification and Matching Initiative Stakeholder Meeting
Patient Identification and Matching Initiative Stakeholder MeetingBrian Ahier
 
Frisse - One Step at a Time
Frisse  - One Step at a TimeFrisse  - One Step at a Time
Frisse - One Step at a Time
Brian Ahier
 
The Pulse of Liquid Health Data
The Pulse of Liquid Health DataThe Pulse of Liquid Health Data
The Pulse of Liquid Health DataBrian Ahier
 
Direct Boot Camp 2.0 - Tennesse Directories
Direct Boot Camp 2.0 - Tennesse DirectoriesDirect Boot Camp 2.0 - Tennesse Directories
Direct Boot Camp 2.0 - Tennesse DirectoriesBrian Ahier
 
Direct Boot Camp 2 0 IWG Provider Directory Pilots
Direct Boot Camp 2 0 IWG Provider Directory PilotsDirect Boot Camp 2 0 IWG Provider Directory Pilots
Direct Boot Camp 2 0 IWG Provider Directory PilotsBrian Ahier
 
Direct20: Modular Specifications - Provider Directories
Direct20: Modular Specifications - Provider DirectoriesDirect20: Modular Specifications - Provider Directories
Direct20: Modular Specifications - Provider DirectoriesBrian Ahier
 

More from Brian Ahier (20)

Draft TEFCA
Draft TEFCADraft TEFCA
Draft TEFCA
 
Future is Now
Future is NowFuture is Now
Future is Now
 
AMA Digital Health Study
AMA Digital Health Study AMA Digital Health Study
AMA Digital Health Study
 
DoD onboarding slides
DoD onboarding slidesDoD onboarding slides
DoD onboarding slides
 
2015 Edition Proposed Rule Modifications to the ONC Health IT Certification ...
2015 Edition Proposed RuleModifications to the ONC Health IT Certification ...2015 Edition Proposed RuleModifications to the ONC Health IT Certification ...
2015 Edition Proposed Rule Modifications to the ONC Health IT Certification ...
 
Accountable Care Workgroup: Draft Recommendations
Accountable Care Workgroup: Draft RecommendationsAccountable Care Workgroup: Draft Recommendations
Accountable Care Workgroup: Draft Recommendations
 
FTC Spring Privacy Series: Consumer Generated and Controlled Health Data
FTC Spring Privacy Series: Consumer Generated and Controlled Health DataFTC Spring Privacy Series: Consumer Generated and Controlled Health Data
FTC Spring Privacy Series: Consumer Generated and Controlled Health Data
 
Mobile Device Tracking Seminar
Mobile Device Tracking SeminarMobile Device Tracking Seminar
Mobile Device Tracking Seminar
 
HIT Policy Committee FDASIA Update
HIT Policy Committee FDASIA UpdateHIT Policy Committee FDASIA Update
HIT Policy Committee FDASIA Update
 
Big Data and VistA Evolution, Theresa A. Cullen, MD, MS
Big Data and VistA Evolution, Theresa A. Cullen, MD, MSBig Data and VistA Evolution, Theresa A. Cullen, MD, MS
Big Data and VistA Evolution, Theresa A. Cullen, MD, MS
 
Meaningful Use Workgroup Stage 3 Recommendations
Meaningful Use Workgroup Stage 3 Recommendations Meaningful Use Workgroup Stage 3 Recommendations
Meaningful Use Workgroup Stage 3 Recommendations
 
ONC 2015 Edition EHR Certification Criteria
ONC 2015 Edition EHR Certification CriteriaONC 2015 Edition EHR Certification Criteria
ONC 2015 Edition EHR Certification Criteria
 
Mark Bertolini of Aetna at JP Morgan Healthcare 2014
Mark Bertolini of Aetna at JP Morgan Healthcare 2014Mark Bertolini of Aetna at JP Morgan Healthcare 2014
Mark Bertolini of Aetna at JP Morgan Healthcare 2014
 
DeSalvo Remarks to HIT Policy Committee 1-14-13
DeSalvo Remarks to HIT Policy Committee 1-14-13DeSalvo Remarks to HIT Policy Committee 1-14-13
DeSalvo Remarks to HIT Policy Committee 1-14-13
 
Patient Identification and Matching Initiative Stakeholder Meeting
Patient Identification and Matching Initiative Stakeholder MeetingPatient Identification and Matching Initiative Stakeholder Meeting
Patient Identification and Matching Initiative Stakeholder Meeting
 
Frisse - One Step at a Time
Frisse  - One Step at a TimeFrisse  - One Step at a Time
Frisse - One Step at a Time
 
The Pulse of Liquid Health Data
The Pulse of Liquid Health DataThe Pulse of Liquid Health Data
The Pulse of Liquid Health Data
 
Direct Boot Camp 2.0 - Tennesse Directories
Direct Boot Camp 2.0 - Tennesse DirectoriesDirect Boot Camp 2.0 - Tennesse Directories
Direct Boot Camp 2.0 - Tennesse Directories
 
Direct Boot Camp 2 0 IWG Provider Directory Pilots
Direct Boot Camp 2 0 IWG Provider Directory PilotsDirect Boot Camp 2 0 IWG Provider Directory Pilots
Direct Boot Camp 2 0 IWG Provider Directory Pilots
 
Direct20: Modular Specifications - Provider Directories
Direct20: Modular Specifications - Provider DirectoriesDirect20: Modular Specifications - Provider Directories
Direct20: Modular Specifications - Provider Directories
 

Recently uploaded

POST OPERATIVE OLIGURIA and its management
POST OPERATIVE OLIGURIA and its managementPOST OPERATIVE OLIGURIA and its management
POST OPERATIVE OLIGURIA and its management
touseefaziz1
 
The POPPY STUDY (Preconception to post-partum cardiovascular function in prim...
The POPPY STUDY (Preconception to post-partum cardiovascular function in prim...The POPPY STUDY (Preconception to post-partum cardiovascular function in prim...
The POPPY STUDY (Preconception to post-partum cardiovascular function in prim...
Catherine Liao
 
Evaluation of antidepressant activity of clitoris ternatea in animals
Evaluation of antidepressant activity of clitoris ternatea in animalsEvaluation of antidepressant activity of clitoris ternatea in animals
Evaluation of antidepressant activity of clitoris ternatea in animals
Shweta
 
Report Back from SGO 2024: What’s the Latest in Cervical Cancer?
Report Back from SGO 2024: What’s the Latest in Cervical Cancer?Report Back from SGO 2024: What’s the Latest in Cervical Cancer?
Report Back from SGO 2024: What’s the Latest in Cervical Cancer?
bkling
 
micro teaching on communication m.sc nursing.pdf
micro teaching on communication m.sc nursing.pdfmicro teaching on communication m.sc nursing.pdf
micro teaching on communication m.sc nursing.pdf
Anurag Sharma
 
Prix Galien International 2024 Forum Program
Prix Galien International 2024 Forum ProgramPrix Galien International 2024 Forum Program
Prix Galien International 2024 Forum Program
Levi Shapiro
 
Ophthalmology Clinical Tests for OSCE exam
Ophthalmology Clinical Tests for OSCE examOphthalmology Clinical Tests for OSCE exam
Ophthalmology Clinical Tests for OSCE exam
KafrELShiekh University
 
Alcohol_Dr. Jeenal Mistry MD Pharmacology.pdf
Alcohol_Dr. Jeenal Mistry MD Pharmacology.pdfAlcohol_Dr. Jeenal Mistry MD Pharmacology.pdf
Alcohol_Dr. Jeenal Mistry MD Pharmacology.pdf
Dr Jeenal Mistry
 
Pulmonary Thromboembolism - etilogy, types, medical- Surgical and nursing man...
Pulmonary Thromboembolism - etilogy, types, medical- Surgical and nursing man...Pulmonary Thromboembolism - etilogy, types, medical- Surgical and nursing man...
Pulmonary Thromboembolism - etilogy, types, medical- Surgical and nursing man...
VarunMahajani
 
Antiulcer drugs Advance Pharmacology .pptx
Antiulcer drugs Advance Pharmacology .pptxAntiulcer drugs Advance Pharmacology .pptx
Antiulcer drugs Advance Pharmacology .pptx
Rohit chaurpagar
 
ANATOMY AND PHYSIOLOGY OF URINARY SYSTEM.pptx
ANATOMY AND PHYSIOLOGY OF URINARY SYSTEM.pptxANATOMY AND PHYSIOLOGY OF URINARY SYSTEM.pptx
ANATOMY AND PHYSIOLOGY OF URINARY SYSTEM.pptx
Swetaba Besh
 
How to Give Better Lectures: Some Tips for Doctors
How to Give Better Lectures: Some Tips for DoctorsHow to Give Better Lectures: Some Tips for Doctors
How to Give Better Lectures: Some Tips for Doctors
LanceCatedral
 
THOA 2.ppt Human Organ Transplantation Act
THOA 2.ppt Human Organ Transplantation ActTHOA 2.ppt Human Organ Transplantation Act
THOA 2.ppt Human Organ Transplantation Act
DrSathishMS1
 
MANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdf
MANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdfMANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdf
MANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdf
Jim Jacob Roy
 
KDIGO 2024 guidelines for diabetologists
KDIGO 2024 guidelines for diabetologistsKDIGO 2024 guidelines for diabetologists
KDIGO 2024 guidelines for diabetologists
د.محمود نجيب
 
Factory Supply Best Quality Pmk Oil CAS 28578–16–7 PMK Powder in Stock
Factory Supply Best Quality Pmk Oil CAS 28578–16–7 PMK Powder in StockFactory Supply Best Quality Pmk Oil CAS 28578–16–7 PMK Powder in Stock
Factory Supply Best Quality Pmk Oil CAS 28578–16–7 PMK Powder in Stock
rebeccabio
 
Lung Cancer: Artificial Intelligence, Synergetics, Complex System Analysis, S...
Lung Cancer: Artificial Intelligence, Synergetics, Complex System Analysis, S...Lung Cancer: Artificial Intelligence, Synergetics, Complex System Analysis, S...
Lung Cancer: Artificial Intelligence, Synergetics, Complex System Analysis, S...
Oleg Kshivets
 
HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...
HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...
HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...
GL Anaacs
 
Physiology of Special Chemical Sensation of Taste
Physiology of Special Chemical Sensation of TastePhysiology of Special Chemical Sensation of Taste
Physiology of Special Chemical Sensation of Taste
MedicoseAcademics
 
Maxilla, Mandible & Hyoid Bone & Clinical Correlations by Dr. RIG.pptx
Maxilla, Mandible & Hyoid Bone & Clinical Correlations by Dr. RIG.pptxMaxilla, Mandible & Hyoid Bone & Clinical Correlations by Dr. RIG.pptx
Maxilla, Mandible & Hyoid Bone & Clinical Correlations by Dr. RIG.pptx
Dr. Rabia Inam Gandapore
 

Recently uploaded (20)

POST OPERATIVE OLIGURIA and its management
POST OPERATIVE OLIGURIA and its managementPOST OPERATIVE OLIGURIA and its management
POST OPERATIVE OLIGURIA and its management
 
The POPPY STUDY (Preconception to post-partum cardiovascular function in prim...
The POPPY STUDY (Preconception to post-partum cardiovascular function in prim...The POPPY STUDY (Preconception to post-partum cardiovascular function in prim...
The POPPY STUDY (Preconception to post-partum cardiovascular function in prim...
 
Evaluation of antidepressant activity of clitoris ternatea in animals
Evaluation of antidepressant activity of clitoris ternatea in animalsEvaluation of antidepressant activity of clitoris ternatea in animals
Evaluation of antidepressant activity of clitoris ternatea in animals
 
Report Back from SGO 2024: What’s the Latest in Cervical Cancer?
Report Back from SGO 2024: What’s the Latest in Cervical Cancer?Report Back from SGO 2024: What’s the Latest in Cervical Cancer?
Report Back from SGO 2024: What’s the Latest in Cervical Cancer?
 
micro teaching on communication m.sc nursing.pdf
micro teaching on communication m.sc nursing.pdfmicro teaching on communication m.sc nursing.pdf
micro teaching on communication m.sc nursing.pdf
 
Prix Galien International 2024 Forum Program
Prix Galien International 2024 Forum ProgramPrix Galien International 2024 Forum Program
Prix Galien International 2024 Forum Program
 
Ophthalmology Clinical Tests for OSCE exam
Ophthalmology Clinical Tests for OSCE examOphthalmology Clinical Tests for OSCE exam
Ophthalmology Clinical Tests for OSCE exam
 
Alcohol_Dr. Jeenal Mistry MD Pharmacology.pdf
Alcohol_Dr. Jeenal Mistry MD Pharmacology.pdfAlcohol_Dr. Jeenal Mistry MD Pharmacology.pdf
Alcohol_Dr. Jeenal Mistry MD Pharmacology.pdf
 
Pulmonary Thromboembolism - etilogy, types, medical- Surgical and nursing man...
Pulmonary Thromboembolism - etilogy, types, medical- Surgical and nursing man...Pulmonary Thromboembolism - etilogy, types, medical- Surgical and nursing man...
Pulmonary Thromboembolism - etilogy, types, medical- Surgical and nursing man...
 
Antiulcer drugs Advance Pharmacology .pptx
Antiulcer drugs Advance Pharmacology .pptxAntiulcer drugs Advance Pharmacology .pptx
Antiulcer drugs Advance Pharmacology .pptx
 
ANATOMY AND PHYSIOLOGY OF URINARY SYSTEM.pptx
ANATOMY AND PHYSIOLOGY OF URINARY SYSTEM.pptxANATOMY AND PHYSIOLOGY OF URINARY SYSTEM.pptx
ANATOMY AND PHYSIOLOGY OF URINARY SYSTEM.pptx
 
How to Give Better Lectures: Some Tips for Doctors
How to Give Better Lectures: Some Tips for DoctorsHow to Give Better Lectures: Some Tips for Doctors
How to Give Better Lectures: Some Tips for Doctors
 
THOA 2.ppt Human Organ Transplantation Act
THOA 2.ppt Human Organ Transplantation ActTHOA 2.ppt Human Organ Transplantation Act
THOA 2.ppt Human Organ Transplantation Act
 
MANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdf
MANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdfMANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdf
MANAGEMENT OF ATRIOVENTRICULAR CONDUCTION BLOCK.pdf
 
KDIGO 2024 guidelines for diabetologists
KDIGO 2024 guidelines for diabetologistsKDIGO 2024 guidelines for diabetologists
KDIGO 2024 guidelines for diabetologists
 
Factory Supply Best Quality Pmk Oil CAS 28578–16–7 PMK Powder in Stock
Factory Supply Best Quality Pmk Oil CAS 28578–16–7 PMK Powder in StockFactory Supply Best Quality Pmk Oil CAS 28578–16–7 PMK Powder in Stock
Factory Supply Best Quality Pmk Oil CAS 28578–16–7 PMK Powder in Stock
 
Lung Cancer: Artificial Intelligence, Synergetics, Complex System Analysis, S...
Lung Cancer: Artificial Intelligence, Synergetics, Complex System Analysis, S...Lung Cancer: Artificial Intelligence, Synergetics, Complex System Analysis, S...
Lung Cancer: Artificial Intelligence, Synergetics, Complex System Analysis, S...
 
HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...
HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...
HOT NEW PRODUCT! BIG SALES FAST SHIPPING NOW FROM CHINA!! EU KU DB BK substit...
 
Physiology of Special Chemical Sensation of Taste
Physiology of Special Chemical Sensation of TastePhysiology of Special Chemical Sensation of Taste
Physiology of Special Chemical Sensation of Taste
 
Maxilla, Mandible & Hyoid Bone & Clinical Correlations by Dr. RIG.pptx
Maxilla, Mandible & Hyoid Bone & Clinical Correlations by Dr. RIG.pptxMaxilla, Mandible & Hyoid Bone & Clinical Correlations by Dr. RIG.pptx
Maxilla, Mandible & Hyoid Bone & Clinical Correlations by Dr. RIG.pptx
 

ONC Direct Project Boot Camp

  • 1. Direct Project Boot Camp Chicago, Illinois
  • 2. What is Direct? A project to create the set ofstandardsand services that, with a policy framework, enable simple, directed, routed, scalable transport over the Internet to be used for secure and meaningful exchange between known participants in support of meaningful use 2
  • 3. Secure Internet-based Direct Communications Direct Project specifies a simple, secure, scalable, standards-based way for participants to send encrypted health information directly to known, trusted recipients over the Internet. h.elthie@direct.ahospital.org b.wells@direct.aclinic.org Simple.Connects healthcare stakeholders through universal addressing using simple push of information. Secure. Users can easily verify messages are complete and not tampered with in travel. Scalable. Enables Internet scale with no need for central network authority. Standards-based. Built on common Internet standards for secure e-mail communication.
  • 4. Why Direct? When current methods of health information exchange are inadequate: Communication of health information among providers and patients still mainly relies on mail or fax Slow, inconvenient, expensive Health information and history is lost or hard to find in paper charts Current forms of electronic communication may not be secure Encryption features of off-the-shelf e-mail clients not often used in healthcare communications today Physicians need to transport and share clinical content electronically in order to satisfy Stage 1 Meaningful Use requirements. Need to meet physicians where they are now Direct will be one of the communication methods in the Nationwide Health Information Network Sources: http://www.flickr.com/photos/dougww/922328173/ http://www.flickr.com/photos/greenlagirl/154148230/sizes/o/ http://www.flickr.com/photos/kenjonbro/3418425029/sizes/m/
  • 5. Who is Direct? (as of November 2010) The Direct Project represents over 50 organizations and over 200 participants. Members participate in the Implementation Group and one or more of 6 workgroups. Implementation Group (50+ organizations, 200+ participants) Security and Trust Communications Documentation and Testing Implementation Geographies Reference Implementation Best Practices
  • 6. What do you need to enable Direct? Direct Addresses Security & Trust Services Direct Messages Message Transport & Delivery
  • 7. Direct Addresses Direct Addresses are used to route information Look like email addresses Used only for health information exchange b.wells@direct.aclinic.org An individual may have multiple Direct addresses Domain Endpoint Direct Address
  • 8. Security & Trust: Certificates Each Direct Address must have at least one digital certificate associated with it in order to securely transmit and receive health information Certificate may be tied to either the specific Direct Address or the Domain that is part of that address X.509v3 digital certificate standards By using certificates to securely transmit and receive information… The Sender has a strong mathematical certainty that only the Receiver or explicitly authorized delegates can view the message The Receiver has a strong mathematical certainty that only the Sender sent the message Both Sender and Receiver have confidence that nothing happened to the message in transit (e.g., tampering, disclosure, etc.)
  • 9. Security & Trust: Certificate Discovery Certificate discovery must occur prior to a Direct message being sent in order to fulfill the encryption functions of the S/MIME format Discovery based on existing Internet protocols Existing specifications exist for discovery via DNS Address-bound certificates must be associated with a Direct-formatted address Organization-bound certificates are stored under the Health Domain Name If DNS is not supported, an alternate method must be offered
  • 10.
  • 11. Trust Anchors are Certificate Authorities (CAs)
  • 12.
  • 13. Message Transport & Delivery Direct specifies Simple Mail Transport Protocol (SMTP) as its primary mechanism for delivering healthcare content from a sender to a receiver This choice supports environments that have minimal capabilities in terms of using Web Services and generating detailed metadataand allows for more advanced interoperability
  • 14. Direct Project Compliance Compliance is defined in the Applicability Statement for Secure Health Transport Core set of requirements for using SMTP, S/MIME, and X509 certificates in an interoperable way However, it’s recognized that communities may use other standards or proprietary mechanisms internally Will generally have Direct-compliant gateways that implement the Applicability specification while harmonizing local standards/mechanisms to Direct-equivalents XDR and XDM for Direct Messaging specifies such a solution when using IHE XDR for local transport
  • 15. SOAP, IHE and XD* Conversions While SMTP is the primary delivery method for Direct, some healthcare environments have existing SOAP-based Web Services that provide detailed metadata and have adopted a family of IHE profiles SOAP – format for exchanging structured information, based on XML for message format XDR and XDM for Direct Messaging XDR – supports a direct push model using Web Services transport XDM – supports a direct push model with SMTP as a transport option, among several XD* Conversion Enables interoperability between Direct participants who may be using SOAP+XDR, SMTP+XDM, or SMTP+MIME
  • 16.
  • 17.
  • 19.
  • 20. HIE Strategy should drive the approach to implementing Direct Orchestrator Elevator Public Utility Capacity-Builder $ $ Rapid facilitation of directed exchange capabilities to support Stage 1 MU Develops and bolsters local exchange capabilities Connects local exchange activities with thin layer of statewide infrastructure Directly connects providers into centralized HIE solution Direct Approach #1: Market-based solns Direct Approach #3: Fill in the gaps Direct Approach #3: Fill in the gaps Direct Approach #2: Offer complete svcs Direct Approach #2: Offer complete svcs Individual States may adopt multiple strategies
  • 21. User InterfacesOverview of Options Email Client S/MIME Encryption is popularly supported Downloadable Plug-in for Direct Web Portal (or Webmail) Web Portal can be set up by HISP or HIE Webmail with plugin for Direct EHR Module that enables Direct messaging Message generated and sent by EHR without intermediate steps @ EHR Individual communities are likely to include instances of all user interfaces, depending on provider preferences and choices in the local market
  • 23. Deployment ModelsOverview of Options 20 Encryption at Client Client does encryption/decryption locally Capabilities built into the EHR Relies on HISP for routing Encryption at HISPs HISP provides encryption/decryption HISP provides routing Client interacts through EHR, Email, or Portal Direct and XDR (optional) Some HIEs use the IHE XDR profile for push workflows This deployment model enables compatibility with the Direct Project DestHISP Src Dest DestHISP SrcHISP Src Dest HISP Src Dest Individual communities likely to employ all deployment models, depending on provider preferences and local EHR choices. States need to enable HISPs regardless.
  • 24. Deployment ModelsPros and Cons Threat Models for these deployments (including “Direct to/from XDR”) available at: http://wiki.directproject.org/Threat+Models

Editor's Notes

  1. http://www.flickr.com/photos/dougww/922328173/
  2. Need a way to route information to the right party. That’s where Direct addresses come in.Need a way to protect that information when you send it – Security & Trust Services.Need to be able to build a Direct Message that contains the health information you want to send.Finally, need a way to move that message.
  3. Can also mix and match these combinations; e.g., encryption on the client side for the sender, with decryption managed by HISP for the receiver