SlideShare a Scribd company logo
Health Identity Management and Role-Based Access Control  in a  Federated NHIN Model   The e-Authentication Project Phase 3  Co-presenters: Richard Moore, President eHealth Ohio and John Fraser, CEO MEDNETWorld.com Presented to: HIMSS 2009
Abstract Nationwide Health Information Network (NHIN) requires the secure connection of health organizations within and across state borders.  The e-Authentication Pilot Study Phase 2 concluded in the development of a healthcare specific configuration of a Shibboleth network architecture and the development of healthcare related directory objects for role-based authorization.  The technology was successfully demonstrated at the HIMSS 2008 IHE Showcase and is a part of the NHIN2.  Phase 3 software improvements include Shibboleth 2.x and SAML 2.x for protocol, assertions and bindings.  Phase 3 expands supported services including; Record Location Services (RLS), proprietary Electronic Health Records (EHR), Personal Health Record Service (PHR) and Public Health Immunization Record Services.  Also by incorporating virtual server technology Phase 3 reduces the time to implementation and ongoing administrative support of a network.
HIMSS description of benefits Primary Objective The e-Authentication Project investigates open source, national/international standards and virtual server solutions to a secure NHIN.  Benefits Audience will gain an understanding how Federal standards for Identity management and Authentication as defined by the GSA, NIST, ASTM, HL7, HITSP, IHE, OASIS, Internet2 and Liberty Alliance can be used by RHIOs for federated single sign-on. Learn how open source software developed by the International Internet2 project and funded by the National Science Foundation can be leveraged for role-based authorization by RHIOs. Learn how multiple state RHIOs can form a trust network that minimizes the burden on the user to securely access information. Learn how virtual server use can reduce the time to implementation and ongoing administrative support of a network.
Talk Outline The Vision e-Authentication Project Introducing Nationwide Health Information Network (NHIN) NHIN Security Overview Shibboleth introduction and recent projects Projects Phases 1-3 Federation and NHIN A connected health care system Phase 4 & Next Steps
The Vision Health information exchange is a pioneering effort Scouting Parties Established Communities Pioneering Settlers Established guidance and standards Federal Guidance – GSA, NIST, Agencies, ONC, HIPAA Standards – HITSP, HL7, IHE, OASIS, X12, ISO Solutions – Vendors, Open Source, Internet2 Accreditation – CCHIT, Liberty IAF/IAG e-Authentication Project focus “Rough consensus, running code.”
Who : HIMSS and The General Services Administration (GSA) When : 2006, early 2007 Purpose : Demonstrate federally approved authentication services What : Pilot used Electronic Authentication Service Components established under Homeland Security Presidential Directive HSPD 12, Policy for a Common Identification Standard for Federal Employees and Contractors. Pilot Participants :  Seven Regional Health Information Organizations (RHIOs)/health information exchanges (IHEs) and ORC, Inc. Federal Certificate Authority. HIMSS/GSA eAuthentication Project
Phase 1  – 8 Participants - 2006 GSA: ORC, Inc. ACES Certificate Authority CT: e-Health Connecticut  MI: Michigan Data Sharing & Transaction Infrastructure Project TX: CHRISTUS Health, Health eCities of Texas Project MN: Community Health Information Collaborative OH: eHealth Ohio/OSC Bioinformatics OH: Virtual Medical Network  NV: Single Portal Medical Record Project
Multiple RHIOs can agree and implement a common framework for the policies, procedures, and standards for federated identity authentication across multiple use cases. The Federal e-Authentication infrastructure is relevant and applicable to use cases for RHIOs in diverse operational environments.  PKI, as a standard for strong authentication, can be deployed uniformly across multiple RHIOs. The Federal PKI and its trusted Federal Credential Service Providers can be leveraged for use in multiple use cases across multiple RHIOs. For RHIOs, local registration authorities and local enrollment are viable for larger scale deployments  to provide for strong authentication using Federal e-Authentication components.  Hardware tokens (i.e., smart cards, flash drives) are viable for RHIO deployment of level 4 authentication assurance. The results were published in the HIMSS Whitepaper:  HIMSS/GSA National e-Authentication Project Whitepaper, 6/2007 Phase 1  – Results
Phase 2 – 5 Participants - 2007/2008 CT: e-Health Connecticut  MN: MEDNET, USA MN: Community Health Information Collaborative (CHIC) OH: eHealth Ohio OH: Virtual Medical Network
Shibboleth network servers for Identity and Service Provders were established. Simplified Role-Based Access for Referrals and Emergency scenarios were tested successfully. The Shibboleth solution was incorporated into the IHE Interoperability Showcase for The HIMSS Annual Meeting in 2/2008. The results were presented at the HIMSS Annual meeting 2/2008. Phase 2 – Results
Phase 2  Federation Test – MN & OH CHIC Hospital, Portal  CHIC Clinic,  Connecticut e-Health eHealth Ohio,  VMN Test server  MN Shibboleth IdP  Service Providers Internet Physician Users VMN Shibboleth IdP
Examples of Role Identification  397897005     146N00000X, 146M00000X, 146D00000X Emergency Medical Technician         Emergency Services 66862007 R   2085XX Radiologist 80584001 P   2084P0800X Psychiatrist 159034004   4 213EXX Podiatrist (DPM) 61207006 CLP   207ZXX Pathologist     33 175F00000X Naturopath       175L00000X Homeopath 112247003 GP 1 204XX, 207XX, 208XX, 209XX  MD/Allopath 76231001 GP 7 204XX, 207XX, 208XX, 209XX  DO/Osteopath 3842006   5 111NXX Chiropractor (DC) SNOMED CT ABMS CAQH ASTM - NUCC Taxonomy Physician
Selected ISO 21091 Directory OIDs  HcConsumer 1.0.21091.1.1 HcProfessional 1.0.21091.1.2 HcEmployee 1.0.21091.1.3 HcPayer 1.0.21091.1.5 HcStandardRole 1.0.21091.1.8 HcLocalRole 1.0.21091.1.9 HcDevice 1.0.21091.1.11
Example Roles between HIEs: User Role from Identity Providers HIE (1) HIE (2) HIE (3) John Fraser BasicMember Richard Moore Administrator Physician A Dr. Smith Physician B First Responder
Phase 3 – 2008/2009 The Original Focus of Phase 3 was to extend the Role-Based Access Model and scalability. A Record Locator Services was successfully added. CHIC was selected for the NHIN2 development and NHIN work took precedence for 2008. Based on the participation in the NHIN, the e-Authentication project is now a portal to the NHIN. Scalability gains were achieved by using virtualization of servers to reduce maintenance and application deployment. Streamlining certificate provisioning.
Secure & Federated Vision Who am I - Need to federate, or share identities Too many passwords – too little security! Do you trust me - standardized PKI security Liberty Alliance’s IAF framework SAFE Biopharma global infrastructure What do you want – standardize services NHIN Core Services Other standardized Web Services (SOAP)
Nationwide Health Information Network Developed by Department of Health and Human Services 18 initial participants Internet-based, uses existing Internet standards Web Services based with SAML security No centralized servers / control Moving into production in 2009
NHIN Connectivity Overview Your existing sites Your organizations network Feds: SSA, DoD, VA, CDC, etc Nationwide Health Information Network - NHIN INTERNET Payers Providers State & Local Health Information Exchanges (HIE)
NHIN Foundation - Web Services Provide a standard platform for health care messaging All communications are standardized SOAP/Web Services messages described with WSDL Leverage proven standards only  Web Services Interoperability (WS-I) Basic Profile 1.2 Basci Security Profile 1.1 Open Source implementations – no vendor lock
NHIN Foundation – Web Services Standards Used Standard Version Description SOAP (Simple Object Access Protocol) 1.1 Describes XML message standard WSDL (Web Services Description Language) 1.1 Describes the SOAP/Web Services messages MTOM (Message Transmission Optimization Mechanism ) 1.0 SOAP message attachments standard WS-Addressing 1.0 Message routing information HTTP 1.1 Standard web connection for SOAP message exchanges UDDI 3.0.2 Service Registry of NHIN services
NHIN Foundation – Web Services Security Standards Used Standard Version Description TLS (Transport Layer Security) 1.0 Similar to SSL – used to encrypt data per connection Digital Certificates x.509v3 Standard digital certificates XML Signature 1.0 Provides digital signature of messages SAML 2.0 Who am I – asserts identity of sender in small XML message
NHIN Foundation – Message Security Authenticated Secure Not subject to later repudiation NHIN implementing Public Key Infrastructure (PKI), based on X.509 certificates Basis of trust at the implementation level is a shared Certificate Authority chartered by NHIN governance body Messages between HIEs must be:
Example secure NHIN message* Required in all NHIN SOAP messages (*) standard SAML-secured SOAP message – not NHIN specific Example payload: HL7v3 CCD Message in XML format
Identity Management Federations and NHIN Goal: to be able to share and understand identities between health care organizations Goal: No central registry (big brother) Goal: Multiple providers of identities from small clinics to huge research centers Goal: Standardized “ROLES” so trust can be role-based as well
Identity Management Solution: Overview of Shibboleth Shibboleth* – an open-source federated identity management system Sponsored by Internet2 Compatible with standards SAML 2.0 / NHIN Liberty Alliance Standards (*) http://shibboleth.internet2.edu/
Shibboleth “Club” Shibboleth software has the concept of a “Club” A “Club” is a group of organizations that support single sign on between themselves. Club is common security and operational policies Simplifies trust between members Clarifies SAML assertion management Directory information can then be exchanged and  trusted between companies regarding identities.
CHIC & Ohio – Record Locator Service & NHIN CHIC SISU / St.Luke’s  VRMC Users NHIN Backbone connecting HIEs Community Security/ Privacy Officers Log Reviews Personal Health Record (PHR) Role Based Access Control Service Community Patient Privacy Manager Audit Database XDS Registry and Repository Patient Clinical Info Retrieval Lookup MEDNET GRID SERVER Immunization Connection eHealth Ohio,  VMN Test server  LOGIN MEDNET NHIN Gateway Record Locator Query Engine Federated Identity Management Service
Federation Example – eHealth Ohio and MN Completed HIMSS/GSA project in 2006 MN project implement Shibboleth Completed “Phase 2” - 2007 MN & OH linked 2007 pilot using Shibboleth Club Completed “Phase 3” - 2008 NHIN work in MN 2009 – Phase 4 and beyond?? Tying NHIN / Phase 3 work / HIE interests together
Phase 4 - Federation Architecture Develop SAML 2.0 federation pilots Partner with NHIN projects Develop standardized “ROLES” between HIEs Easy trust models Develop simple installations Open source solutions Simple solutions Virtual Server technologies (VMware, etc) Trust and replication between participants Goals:
The Possible Future Public Health – online disease investigations No more snail-mail, calls and faxes Immediate investigation of bad diseases / outbreaks Project starting with CDC this year! Ambulances look you up while enroute Treatment, allergies, drugs known beforehand MN Pilot being developed with Mayo and CHIC HIE! Emergency Departments “Preloaded” Insurance, emergency contacts, medical history, primary care docs – known before you arrive! Insurers on-line Immediate eligibility at any point of care Insurance and co-pays always known Medical Banking – fast payments HSA payments, co-pays happen at point of service
Help us build our vision! Contact us if interested in learning more about Phase 4 - Open invitation to learn about technology - Open invitation to join us in Phase 4
Thanks! Presenter information: Rick Moore eHealth Ohio +1 877.813.9750 [email_address] John Fraser MEDNETWorld.com +1 612.435.7602 [email_address] Co-chair of the Health Identity Management Special Interest Group of the Liberty Alliance (HIM-SIG), see:  http://wiki.projectliberty.org/index.php/Health_Identity_Management_SIG

More Related Content

PDF
Secure Cloud Storage
PPTX
Work Ethos, Purpose, and Productivity
PDF
Electronic Health Information- Guide to Privacy & Security
PDF
Health Information Privacy & Security for Medical Students: เรื่องเล่าจากรามา...
PDF
Security & Privacy for Health Data
PDF
Health Data Privacy and Security in the NZDF
PDF
Information security for health practitioners
Secure Cloud Storage
Work Ethos, Purpose, and Productivity
Electronic Health Information- Guide to Privacy & Security
Health Information Privacy & Security for Medical Students: เรื่องเล่าจากรามา...
Security & Privacy for Health Data
Health Data Privacy and Security in the NZDF
Information security for health practitioners

Viewers also liked (12)

PPTX
Health information system security
PDF
Health Information Privacy and Security (March 30, 2016)
PPT
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
PPTX
A Framework for Health Information Technology and Network Security
PDF
eHealth and digital health - Intro to learn
PPT
Information Security & Compliance in Healthcare: Beyond HIPAA and HITECH
PPTX
Pki for dummies
PPT
New Access Models for Healthcare
PDF
Can ehealth solve China's Healthcare challenges (McKinsey presentation)
PDF
eHealth ….. How to trust a cloud?
PDF
Top 10 eHealth trends and best practices
PDF
Information security for dummies
Health information system security
Health Information Privacy and Security (March 30, 2016)
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
A Framework for Health Information Technology and Network Security
eHealth and digital health - Intro to learn
Information Security & Compliance in Healthcare: Beyond HIPAA and HITECH
Pki for dummies
New Access Models for Healthcare
Can ehealth solve China's Healthcare challenges (McKinsey presentation)
eHealth ….. How to trust a cloud?
Top 10 eHealth trends and best practices
Information security for dummies
Ad

Similar to Health Identity Management & Role-Based Access Control in a Federated NHIN - e-Auth Phase 3 (20)

PPT
CONNECT: An Open Source Platform for Promoting Military Health
PPT
Open source’s role in CONNECTing the public and private sector healthcare com...
PDF
Privacy on FHIR Demo at HIMSS!5
PDF
HEALTHCHAIN: A Patient Centric Blockchain Based Web Application For Maintaini...
PDF
HIMSS GSA e-Authentication whitepaper June 2007
PDF
N ye c-rfp-two-factor-authentication
PPT
IHE and Connected Health in New Zealand
PDF
HP Whitepaper BYOD in Healthcare
PPTX
ONC Direct Project Boot Camp
PPTX
20110706 PIDSプロジェクト中間報告
PDF
ELECTRONIC HEALTH RECORD SYSTEM BY ADOPTING BLOCKCHAIN
PDF
Health Information Flows Technical Standards - V 0.5
PDF
IRJET- Blockchain Technology for Securing Healthcare Records
PDF
2016 iHT2 San Diego Health IT Summit
PPT
Ehealth
PPT
Harnessing and securing cloud in patient health monitoring
PDF
BLOCKMEDCARE: ADVANCING HEALTHCARE THROUGH BLOCKCHAIN INTEGRATION WITH AI AND...
PPT
HIT Fridsma NHIN Direct Project
PDF
Cloud Based Privacy Preserving Data Encryption
PDF
Blockchain in Health Records: Enhancing Security and Privacy (www.kiu.ac.ug)
CONNECT: An Open Source Platform for Promoting Military Health
Open source’s role in CONNECTing the public and private sector healthcare com...
Privacy on FHIR Demo at HIMSS!5
HEALTHCHAIN: A Patient Centric Blockchain Based Web Application For Maintaini...
HIMSS GSA e-Authentication whitepaper June 2007
N ye c-rfp-two-factor-authentication
IHE and Connected Health in New Zealand
HP Whitepaper BYOD in Healthcare
ONC Direct Project Boot Camp
20110706 PIDSプロジェクト中間報告
ELECTRONIC HEALTH RECORD SYSTEM BY ADOPTING BLOCKCHAIN
Health Information Flows Technical Standards - V 0.5
IRJET- Blockchain Technology for Securing Healthcare Records
2016 iHT2 San Diego Health IT Summit
Ehealth
Harnessing and securing cloud in patient health monitoring
BLOCKMEDCARE: ADVANCING HEALTHCARE THROUGH BLOCKCHAIN INTEGRATION WITH AI AND...
HIT Fridsma NHIN Direct Project
Cloud Based Privacy Preserving Data Encryption
Blockchain in Health Records: Enhancing Security and Privacy (www.kiu.ac.ug)
Ad

More from Richard Moore (8)

PPTX
HIMSS18 HIMSS SPOT Making an Impact on State Health Policy, Ohio HIT Day 2017...
PPTX
Making an Impact on Critical Healthcare Public Policy Issues: National & Stat...
PPTX
OHIT Day 2016 Report for HIMSS Chapter Advocacy RMoore
PPTX
OHIT Day 2015 Report for HIMSS Chapter Advocacy Roundtable
PPTX
Ohio Healthcare Information Technology (OHIT) Day 2014 Report
PDF
Richard Moore Resume 2016
PPTX
CSOHIMSS - OSU HIMS Students 20100920
PPT
HIMSS State Government Advocacy Day Roundtable - HIMSS Annual Meeting 2009 Ch...
HIMSS18 HIMSS SPOT Making an Impact on State Health Policy, Ohio HIT Day 2017...
Making an Impact on Critical Healthcare Public Policy Issues: National & Stat...
OHIT Day 2016 Report for HIMSS Chapter Advocacy RMoore
OHIT Day 2015 Report for HIMSS Chapter Advocacy Roundtable
Ohio Healthcare Information Technology (OHIT) Day 2014 Report
Richard Moore Resume 2016
CSOHIMSS - OSU HIMS Students 20100920
HIMSS State Government Advocacy Day Roundtable - HIMSS Annual Meeting 2009 Ch...

Recently uploaded (20)

PPTX
Electrolyte Disturbance in Paediatric - Nitthi.pptx
PPTX
Radiation Dose Management for Patients in Medical Imaging- Avinesh Shrestha
PPTX
CHEM421 - Biochemistry (Chapter 1 - Introduction)
PPTX
Introduction to Medical Microbiology for 400L Medical Students
PDF
OSCE Series Set 1 ( Questions & Answers ).pdf
PPTX
NRP and care of Newborn.pptx- APPT presentation about neonatal resuscitation ...
PDF
OSCE SERIES ( Questions & Answers ) - Set 5.pdf
PPT
HIV lecture final - student.pptfghjjkkejjhhge
PPTX
IMAGING EQUIPMENiiiiìiiiiiTpptxeiuueueur
PPTX
MANAGEMENT SNAKE BITE IN THE TROPICALS.pptx
PPTX
preoerative assessment in anesthesia and critical care medicine
PPTX
y4d nutrition and diet in pregnancy and postpartum
PDF
Lecture on Anesthesia for ENT surgery 2025pptx.pdf
PDF
The_EHRA_Book_of_Interventional Electrophysiology.pdf
PPTX
Epidemiology of diptheria, pertusis and tetanus with their prevention
PPT
Rheumatology Member of Royal College of Physicians.ppt
PDF
TISSUE LECTURE (anatomy and physiology )
PDF
OSCE SERIES - Set 7 ( Questions & Answers ).pdf
PPTX
Reading between the Rings: Imaging in Brain Infections
PPTX
Post Op complications in general surgery
Electrolyte Disturbance in Paediatric - Nitthi.pptx
Radiation Dose Management for Patients in Medical Imaging- Avinesh Shrestha
CHEM421 - Biochemistry (Chapter 1 - Introduction)
Introduction to Medical Microbiology for 400L Medical Students
OSCE Series Set 1 ( Questions & Answers ).pdf
NRP and care of Newborn.pptx- APPT presentation about neonatal resuscitation ...
OSCE SERIES ( Questions & Answers ) - Set 5.pdf
HIV lecture final - student.pptfghjjkkejjhhge
IMAGING EQUIPMENiiiiìiiiiiTpptxeiuueueur
MANAGEMENT SNAKE BITE IN THE TROPICALS.pptx
preoerative assessment in anesthesia and critical care medicine
y4d nutrition and diet in pregnancy and postpartum
Lecture on Anesthesia for ENT surgery 2025pptx.pdf
The_EHRA_Book_of_Interventional Electrophysiology.pdf
Epidemiology of diptheria, pertusis and tetanus with their prevention
Rheumatology Member of Royal College of Physicians.ppt
TISSUE LECTURE (anatomy and physiology )
OSCE SERIES - Set 7 ( Questions & Answers ).pdf
Reading between the Rings: Imaging in Brain Infections
Post Op complications in general surgery

Health Identity Management & Role-Based Access Control in a Federated NHIN - e-Auth Phase 3

  • 1. Health Identity Management and Role-Based Access Control in a Federated NHIN Model The e-Authentication Project Phase 3 Co-presenters: Richard Moore, President eHealth Ohio and John Fraser, CEO MEDNETWorld.com Presented to: HIMSS 2009
  • 2. Abstract Nationwide Health Information Network (NHIN) requires the secure connection of health organizations within and across state borders. The e-Authentication Pilot Study Phase 2 concluded in the development of a healthcare specific configuration of a Shibboleth network architecture and the development of healthcare related directory objects for role-based authorization. The technology was successfully demonstrated at the HIMSS 2008 IHE Showcase and is a part of the NHIN2. Phase 3 software improvements include Shibboleth 2.x and SAML 2.x for protocol, assertions and bindings. Phase 3 expands supported services including; Record Location Services (RLS), proprietary Electronic Health Records (EHR), Personal Health Record Service (PHR) and Public Health Immunization Record Services. Also by incorporating virtual server technology Phase 3 reduces the time to implementation and ongoing administrative support of a network.
  • 3. HIMSS description of benefits Primary Objective The e-Authentication Project investigates open source, national/international standards and virtual server solutions to a secure NHIN. Benefits Audience will gain an understanding how Federal standards for Identity management and Authentication as defined by the GSA, NIST, ASTM, HL7, HITSP, IHE, OASIS, Internet2 and Liberty Alliance can be used by RHIOs for federated single sign-on. Learn how open source software developed by the International Internet2 project and funded by the National Science Foundation can be leveraged for role-based authorization by RHIOs. Learn how multiple state RHIOs can form a trust network that minimizes the burden on the user to securely access information. Learn how virtual server use can reduce the time to implementation and ongoing administrative support of a network.
  • 4. Talk Outline The Vision e-Authentication Project Introducing Nationwide Health Information Network (NHIN) NHIN Security Overview Shibboleth introduction and recent projects Projects Phases 1-3 Federation and NHIN A connected health care system Phase 4 & Next Steps
  • 5. The Vision Health information exchange is a pioneering effort Scouting Parties Established Communities Pioneering Settlers Established guidance and standards Federal Guidance – GSA, NIST, Agencies, ONC, HIPAA Standards – HITSP, HL7, IHE, OASIS, X12, ISO Solutions – Vendors, Open Source, Internet2 Accreditation – CCHIT, Liberty IAF/IAG e-Authentication Project focus “Rough consensus, running code.”
  • 6. Who : HIMSS and The General Services Administration (GSA) When : 2006, early 2007 Purpose : Demonstrate federally approved authentication services What : Pilot used Electronic Authentication Service Components established under Homeland Security Presidential Directive HSPD 12, Policy for a Common Identification Standard for Federal Employees and Contractors. Pilot Participants : Seven Regional Health Information Organizations (RHIOs)/health information exchanges (IHEs) and ORC, Inc. Federal Certificate Authority. HIMSS/GSA eAuthentication Project
  • 7. Phase 1 – 8 Participants - 2006 GSA: ORC, Inc. ACES Certificate Authority CT: e-Health Connecticut MI: Michigan Data Sharing & Transaction Infrastructure Project TX: CHRISTUS Health, Health eCities of Texas Project MN: Community Health Information Collaborative OH: eHealth Ohio/OSC Bioinformatics OH: Virtual Medical Network NV: Single Portal Medical Record Project
  • 8. Multiple RHIOs can agree and implement a common framework for the policies, procedures, and standards for federated identity authentication across multiple use cases. The Federal e-Authentication infrastructure is relevant and applicable to use cases for RHIOs in diverse operational environments. PKI, as a standard for strong authentication, can be deployed uniformly across multiple RHIOs. The Federal PKI and its trusted Federal Credential Service Providers can be leveraged for use in multiple use cases across multiple RHIOs. For RHIOs, local registration authorities and local enrollment are viable for larger scale deployments to provide for strong authentication using Federal e-Authentication components. Hardware tokens (i.e., smart cards, flash drives) are viable for RHIO deployment of level 4 authentication assurance. The results were published in the HIMSS Whitepaper: HIMSS/GSA National e-Authentication Project Whitepaper, 6/2007 Phase 1 – Results
  • 9. Phase 2 – 5 Participants - 2007/2008 CT: e-Health Connecticut MN: MEDNET, USA MN: Community Health Information Collaborative (CHIC) OH: eHealth Ohio OH: Virtual Medical Network
  • 10. Shibboleth network servers for Identity and Service Provders were established. Simplified Role-Based Access for Referrals and Emergency scenarios were tested successfully. The Shibboleth solution was incorporated into the IHE Interoperability Showcase for The HIMSS Annual Meeting in 2/2008. The results were presented at the HIMSS Annual meeting 2/2008. Phase 2 – Results
  • 11. Phase 2 Federation Test – MN & OH CHIC Hospital, Portal CHIC Clinic, Connecticut e-Health eHealth Ohio, VMN Test server MN Shibboleth IdP Service Providers Internet Physician Users VMN Shibboleth IdP
  • 12. Examples of Role Identification 397897005     146N00000X, 146M00000X, 146D00000X Emergency Medical Technician         Emergency Services 66862007 R   2085XX Radiologist 80584001 P   2084P0800X Psychiatrist 159034004   4 213EXX Podiatrist (DPM) 61207006 CLP   207ZXX Pathologist     33 175F00000X Naturopath       175L00000X Homeopath 112247003 GP 1 204XX, 207XX, 208XX, 209XX MD/Allopath 76231001 GP 7 204XX, 207XX, 208XX, 209XX DO/Osteopath 3842006   5 111NXX Chiropractor (DC) SNOMED CT ABMS CAQH ASTM - NUCC Taxonomy Physician
  • 13. Selected ISO 21091 Directory OIDs HcConsumer 1.0.21091.1.1 HcProfessional 1.0.21091.1.2 HcEmployee 1.0.21091.1.3 HcPayer 1.0.21091.1.5 HcStandardRole 1.0.21091.1.8 HcLocalRole 1.0.21091.1.9 HcDevice 1.0.21091.1.11
  • 14. Example Roles between HIEs: User Role from Identity Providers HIE (1) HIE (2) HIE (3) John Fraser BasicMember Richard Moore Administrator Physician A Dr. Smith Physician B First Responder
  • 15. Phase 3 – 2008/2009 The Original Focus of Phase 3 was to extend the Role-Based Access Model and scalability. A Record Locator Services was successfully added. CHIC was selected for the NHIN2 development and NHIN work took precedence for 2008. Based on the participation in the NHIN, the e-Authentication project is now a portal to the NHIN. Scalability gains were achieved by using virtualization of servers to reduce maintenance and application deployment. Streamlining certificate provisioning.
  • 16. Secure & Federated Vision Who am I - Need to federate, or share identities Too many passwords – too little security! Do you trust me - standardized PKI security Liberty Alliance’s IAF framework SAFE Biopharma global infrastructure What do you want – standardize services NHIN Core Services Other standardized Web Services (SOAP)
  • 17. Nationwide Health Information Network Developed by Department of Health and Human Services 18 initial participants Internet-based, uses existing Internet standards Web Services based with SAML security No centralized servers / control Moving into production in 2009
  • 18. NHIN Connectivity Overview Your existing sites Your organizations network Feds: SSA, DoD, VA, CDC, etc Nationwide Health Information Network - NHIN INTERNET Payers Providers State & Local Health Information Exchanges (HIE)
  • 19. NHIN Foundation - Web Services Provide a standard platform for health care messaging All communications are standardized SOAP/Web Services messages described with WSDL Leverage proven standards only Web Services Interoperability (WS-I) Basic Profile 1.2 Basci Security Profile 1.1 Open Source implementations – no vendor lock
  • 20. NHIN Foundation – Web Services Standards Used Standard Version Description SOAP (Simple Object Access Protocol) 1.1 Describes XML message standard WSDL (Web Services Description Language) 1.1 Describes the SOAP/Web Services messages MTOM (Message Transmission Optimization Mechanism ) 1.0 SOAP message attachments standard WS-Addressing 1.0 Message routing information HTTP 1.1 Standard web connection for SOAP message exchanges UDDI 3.0.2 Service Registry of NHIN services
  • 21. NHIN Foundation – Web Services Security Standards Used Standard Version Description TLS (Transport Layer Security) 1.0 Similar to SSL – used to encrypt data per connection Digital Certificates x.509v3 Standard digital certificates XML Signature 1.0 Provides digital signature of messages SAML 2.0 Who am I – asserts identity of sender in small XML message
  • 22. NHIN Foundation – Message Security Authenticated Secure Not subject to later repudiation NHIN implementing Public Key Infrastructure (PKI), based on X.509 certificates Basis of trust at the implementation level is a shared Certificate Authority chartered by NHIN governance body Messages between HIEs must be:
  • 23. Example secure NHIN message* Required in all NHIN SOAP messages (*) standard SAML-secured SOAP message – not NHIN specific Example payload: HL7v3 CCD Message in XML format
  • 24. Identity Management Federations and NHIN Goal: to be able to share and understand identities between health care organizations Goal: No central registry (big brother) Goal: Multiple providers of identities from small clinics to huge research centers Goal: Standardized “ROLES” so trust can be role-based as well
  • 25. Identity Management Solution: Overview of Shibboleth Shibboleth* – an open-source federated identity management system Sponsored by Internet2 Compatible with standards SAML 2.0 / NHIN Liberty Alliance Standards (*) http://shibboleth.internet2.edu/
  • 26. Shibboleth “Club” Shibboleth software has the concept of a “Club” A “Club” is a group of organizations that support single sign on between themselves. Club is common security and operational policies Simplifies trust between members Clarifies SAML assertion management Directory information can then be exchanged and trusted between companies regarding identities.
  • 27. CHIC & Ohio – Record Locator Service & NHIN CHIC SISU / St.Luke’s VRMC Users NHIN Backbone connecting HIEs Community Security/ Privacy Officers Log Reviews Personal Health Record (PHR) Role Based Access Control Service Community Patient Privacy Manager Audit Database XDS Registry and Repository Patient Clinical Info Retrieval Lookup MEDNET GRID SERVER Immunization Connection eHealth Ohio, VMN Test server LOGIN MEDNET NHIN Gateway Record Locator Query Engine Federated Identity Management Service
  • 28. Federation Example – eHealth Ohio and MN Completed HIMSS/GSA project in 2006 MN project implement Shibboleth Completed “Phase 2” - 2007 MN & OH linked 2007 pilot using Shibboleth Club Completed “Phase 3” - 2008 NHIN work in MN 2009 – Phase 4 and beyond?? Tying NHIN / Phase 3 work / HIE interests together
  • 29. Phase 4 - Federation Architecture Develop SAML 2.0 federation pilots Partner with NHIN projects Develop standardized “ROLES” between HIEs Easy trust models Develop simple installations Open source solutions Simple solutions Virtual Server technologies (VMware, etc) Trust and replication between participants Goals:
  • 30. The Possible Future Public Health – online disease investigations No more snail-mail, calls and faxes Immediate investigation of bad diseases / outbreaks Project starting with CDC this year! Ambulances look you up while enroute Treatment, allergies, drugs known beforehand MN Pilot being developed with Mayo and CHIC HIE! Emergency Departments “Preloaded” Insurance, emergency contacts, medical history, primary care docs – known before you arrive! Insurers on-line Immediate eligibility at any point of care Insurance and co-pays always known Medical Banking – fast payments HSA payments, co-pays happen at point of service
  • 31. Help us build our vision! Contact us if interested in learning more about Phase 4 - Open invitation to learn about technology - Open invitation to join us in Phase 4
  • 32. Thanks! Presenter information: Rick Moore eHealth Ohio +1 877.813.9750 [email_address] John Fraser MEDNETWorld.com +1 612.435.7602 [email_address] Co-chair of the Health Identity Management Special Interest Group of the Liberty Alliance (HIM-SIG), see: http://wiki.projectliberty.org/index.php/Health_Identity_Management_SIG

Editor's Notes

  • #2: Richard Moore is the owner and president of DME Consulting Services. He has over 30 years experience with Healthcare Information Systems working with many public and private organizations. His broad-based knowledge of health information systems and operations comes from experience working directly with providers, payers, software manufacturers, electronic data interchange organizations, billing services, clearinghouses and government agencies. He is the current president of eHealth Ohio, Inc., a non-profit regional affiliate of the national standards development organization Workgroup for Electronic Data Interchange (WEDI). His primary WEDI focus is HIPAA X12 EDI transactions and he has participated as an author on WEDI testing whitepapers. He is an active participant in the Healthcare Information and Management Systems Society (HIMSS) and is the current Chair of the HIMSS RHIO Liaison Roundtable. He is also a member of the Board of the Central and Southern Ohio HIMSS (CSOHIMSS) Chapter and is the Chapter Advocacy Chairman and the RHIO Liaison for the State of Ohio. He is involved in the Healthcare Information Technology Standards Panel (HITSP) on the Security, Privacy and Infrastructure technical committee (SPI-TC). Also he is a founding member of the Liberty Alliance Health Identity Management Special Interest Group (HIM-SIG). The last three years he has been a project lead for the study on the use of the GSA e-Authentication model for the Nationwide Health Information Network (NHIN) focusing on electronic identity management, secure electronic health information exchange and federated single sign-on. John Fraser founded and is CEO of MEDNETWorld.com based in Minneapolis, Minnesota. MEDNETWorld.com is wiring up health care by providing Record Locator Services, security and privacy technologies and national connectivity to current and emerging health information exchanges. Prior to founding MEDNET in 2006, John Fraser was the co-founder and former CEO of VisionShare Inc, a company building a secure, national infrastructure for claims connectivity and Medicare billing services with over 50% of all U.S. hospitals using their software. Prior to VisionShare, John built MEDNET, a state-wide medical network in Minnesota at the Minnesota Health Data Institute. Prior to the Institute, John built a state-wide Cancer Surveillance system at the Minnesota Department of Health. John has also done stints at Honeywell and Control Data Corporations. John is the co-chair of the Health Identity Management Special Interest Group of the Liberty Alliance (HIM-SIG). John is an avid bicyclist, diver and swimmer, with an undergraduate degree from the University of Minnesota. John holds a private pilot’s license and a 1st degree black belt in Tae Kwon Doe Karate.