THE FRENCH «DOSSIER MÉDICAL PERSONNEL» (DMP) MAIN INFRASTRUCTURAL FEATURE: SECURITY AND INTEROPERABILITY

Size: px
Start display at page:

Download "THE FRENCH «DOSSIER MÉDICAL PERSONNEL» (DMP) MAIN INFRASTRUCTURAL FEATURE: SECURITY AND INTEROPERABILITY"

Transcription

1 Ehealth Conference 2007 Berlin April 17th-19th 2007 THE FRENCH «DOSSIER MÉDICAL PERSONNEL» (DMP) MAIN INFRASTRUCTURAL FEATURE: SECURITY AND INTEROPERABILITY Manuel METZ GIP DMP - France

2 DMP: a French national ehealth record DMP (Dossier Médical Personnel) will be: a private medical file digitalised aimed at favouring coordination, quality and continuity of care; a file shared by Healthcare professionals (HCP) but under the holder's control (i.e. The patient manages its access, the holder can hide documents...) not a substitute for professional files of HCP in ambulatory care or in Hospital accessed through : Web Portal for holder's Only through professional application for Healthcare professionals to maximize ergonomy and avoid time-consuming change of application consisting of data (structured or not) signed by the author (at first only by the HCP) ehealth Conference Berlin April

3 DMP: A health record needing adequate protection As a health record, the DMP needs to be: Available Opens 7/24 Availability 99,9% (total amount of interruption of 8 hours a year) Protective of data integrity and confidentiality Protected communications (SSL) Restrictive access to a DMP (esafe, HCP rights defined by law) Separation of trusted services (authentication) and data housing Good level authentication * Caisse des Dépôts et Consignations is a state-owned financial institution that performs public-interest missions on behalf of France s central, regional and local governments. ehealth Conference Berlin April

4 Overview of user authentication for DMP V1 HCP's authentication Holder's authentication (a) Authentication through HCP smart card (either server or personal certificate cf. Slide 7) (1) Password previously chosen by the holder (2) One time password sent through SMS to the holder (3) Completion of authentication through the one time password provided (b) Connexion through a SAML assertion given by the portal (4) Connexion through a SAML assertion given by the portal ehealth Conference Berlin April

5 Overview of user authentication for DMP V2 HCP's authentication (a) Authentication through own HCP smart card (personal certificate) Holder's authentication (1) Authentication through patient smart card (personal certificate) (b) Connexion through a SAML assertion given by the portal (2) Connexion through a SAML assertion given by the portal ehealth Conference Berlin April

6 DMP: A personal record controlled by its holder All data in the record must be available to the holder The holder is entitled to write personal data in the record (but not to modify data produced by a healthcare professional) The holder can complement the default rights of access by denying access to specific healthcare professional The patient can hide any document and nothing indicates to target healthcare professional that some documents have been hidden ehealth Conference Berlin April

7 Holder's control on his/her DMP (1) The holder allows named HCP to access his/her DMP (2) The holder can hide named documents from various types of HCP except their author Emergency services and main doctor may override those restrictions ehealth Conference Berlin April

8 Effect of holder's control on his/her DMP 1/3 (1) HCP α is authenticated and authorized to access the DMP of holder Z (2) HCP α can see all the documents of the DMP of holder Z ehealth Conference Berlin April

9 Effect of holder's control on his/her DMP 2/3 (1) HCP β is authenticated but not authorized to access the DMP of holder Z ehealth Conference Berlin April

10 Effect of holder's control on his/her DMP 3/3 (1) HCP γ is authenticated and authorized to access the DMP of holder Z (2) Document C is hidden to HCP γ ehealth Conference Berlin April

11 DMP: A record used by numerous actors ehealth Conference Berlin April

12 Levels of interoperability Interoperability is required on several levels and addressed through specified implementation of norms and standards: Medical application level: HL7, DICOM, CDA, HPRIM... Authentication level: use of HCP smart card and eventually patient s smart card Exchange level: IHE XDS Transport level: HTTP and SOAP over SSL and eventually WS A framework specifying each level will be published to insure interoperability of each component. ehealth Conference Berlin April

13 Conclusion DMP: a large scale project which success depends on trust and interoperability. The DMP will only be used if it is trusted by the users: Trusted by the holder: confidentiality and control Trusted by the HCP: integrity and traceability (=> digital signature) The DMP will only be successful if it achieves critical mass of ehealth records housed: Broadly used standards (HTTP, IHE...) favouring an easy access ehealth Conference Berlin April

14 THANK YOU VERY MUCH ehealth Conference Berlin April

Identity and capability management and federation

Identity and capability management and federation Identity and capability management and federation The need to manage identities - 1 Increment of digital identity complexity Password, dynamic password, one-time password, based on portable secure devices

More information

Implementation of cross-border eprescription services. Päivi Hämäläinen, THL, Finland 14 May ehealth Forum, Athens

Implementation of cross-border eprescription services. Päivi Hämäläinen, THL, Finland 14 May ehealth Forum, Athens Implementation of cross-border eprescription services Päivi Hämäläinen, THL, Finland 14 May 2014 2014 ehealth Forum, Athens 28.1.2014 Päivi Hämäläinen, THL, 2014 ehealth Forum, Athens, 14 May 2014 2 IHE

More information

Existing Healthcare Standards

Existing Healthcare Standards Existing Healthcare Standards Category Context (Information Model) Information Interchange Standard & Specific Elements ASN.1 Abstract Syntax Notation.1 ASTM E2369-05 Standard Specification for Continuity

More information

Interoperability, critical element for an ehealth Strategy

Interoperability, critical element for an ehealth Strategy Interoperability, critical element for an ehealth Strategy Forum e-zdrowia / ehealth Forum Gdansk - September 14-15, 2017 Charles Parisot, IHE-Services Chair IHE International Board Member, GE Healthcare

More information

Cookbook Generic Insurability Version 1.1

Cookbook Generic Insurability Version 1.1 Cookbook Generic Insurability Version 1.1 This document is provided to you free of charge by The ehealth platform Willebroekkaai 38 Quai de Willebroeck 38 1000 BRUSSELS All are free to circulate this document

More information

Health Information Exchange Clinical Data Repository Utility Services Architecture Building Block HISO

Health Information Exchange Clinical Data Repository Utility Services Architecture Building Block HISO Health Information Exchange Clinical Data Repository Utility Services Architecture Building Block HISO 10040.1 To be used in conjunction with HISO 10040.0 Health Information Exchange Overview and Glossary

More information

OHF ATNA Audit Client. Architecture & API Documentation. Version seknoop[at]us[dot]ibm[dot]com Sarah Knoop

OHF ATNA Audit Client. Architecture & API Documentation. Version seknoop[at]us[dot]ibm[dot]com Sarah Knoop OHF ATNA Audit Client Architecture & API Documentation Version 0.0.2 seknoop[at]us[dot]ibm[dot]com Sarah Knoop Page 1 of 14 Contents 1. Introduction...3 2. Getting Started...4 2.1 Platform Requirements...4

More information

Presentation to HL7 S&I Framework Data Segmentation for Privacy Initiative 9/25/2013

Presentation to HL7 S&I Framework Data Segmentation for Privacy Initiative 9/25/2013 Presentation to HL7 S&I Framework Data Segmentation for Privacy Initiative 9/25/2013 Johnathan Coleman, CISSP Initiative Coordinator, Data Segmentation for Privacy OCPO/ONC/HHS / (CTR) Tel: (843) 647-1556

More information

Workshop 2. > Interoperability <

Workshop 2. > Interoperability < Workshop 2 21 / 08 / 2011 > Interoperability < Heiko Zimmermann R&D Engineer, AHI CR Santec Heiko.Zimmermann@tudor.lu Interoperability definition Picture from NCI-Wiki (https://wiki.nci.nih.gov) 2 Interoperability

More information

The Estonian ehealth experience strategy and results. Piret Simmo Estonian ehealth Foundation Standardization manager

The Estonian ehealth experience strategy and results. Piret Simmo Estonian ehealth Foundation Standardization manager The Estonian ehealth experience strategy and results Piret Simmo Estonian ehealth Foundation Standardization manager 27.09.2011 Agenda Some history Legal environment ehealth Foundation Estonian central

More information

Estonian ehealth Experience Artur Novek Implementation manager and Architect Estonian ehealth Foundation

Estonian ehealth Experience Artur Novek Implementation manager and Architect Estonian ehealth Foundation Estonian ehealth Experience Artur Novek Implementation manager and Architect Estonian ehealth Foundation 2016 June 1st Estonia Area - 45 000 km2 1.33 mlj. Inhabitants Member of EU since 2004 Euro-zone

More information

MOBILE HEALTH & FHIR JÜRGEN BRANDSTÄTTER

MOBILE HEALTH & FHIR JÜRGEN BRANDSTÄTTER MOBILE HEALTH & FHIR JÜRGEN BRANDSTÄTTER Devices (Patient Managed) Mobile Apps Patient Empowerment, mhealth, ehealth Portals ehealth (Reg/Nat) Citizen Records ehealth (Care Delivery) Devices (In Care Delivery)

More information

Digital Healthcare. Yordan Iliev Director R&D Healthcare. Regional Cybersecurity Forum, November 2016, Grand Hotel Sofia, Bulgaria

Digital Healthcare. Yordan Iliev Director R&D Healthcare. Regional Cybersecurity Forum, November 2016, Grand Hotel Sofia, Bulgaria Digital Healthcare Yordan Iliev Director R&D Healthcare Regional Cybersecurity Forum, 29-30 November 2016, Grand Hotel Sofia, Bulgaria AGENDA Introduction Security challenges in healthcare IT Change ahead

More information

FORM 0928A Section O Hospitals

FORM 0928A Section O Hospitals FORM 0928A Section O Hospitals This information must be completed by any organization that indicated in Section H that it is a hospital described in 170(b)(1)(A)(iii). 1. Are all the doctors in your community

More information

Direct, DirectTrust, and FHIR: A Value Proposition

Direct, DirectTrust, and FHIR: A Value Proposition Direct, DirectTrust, and FHIR: A Value Proposition August 10, 2017 Authors: Grahame Grieve, HL7 Product Director for FHIR; David Kibbe, Luis Maas, Greg Meyer, and Bruce Schreiber, members of the DirectTrust

More information

M HEALTH SHARING INDUSTRIAL VISION AND EXPERIENCE. Dr Beatrice Falise Mirat COCIR Business and Innovation Committee ehealth Member Orange Healthcare

M HEALTH SHARING INDUSTRIAL VISION AND EXPERIENCE. Dr Beatrice Falise Mirat COCIR Business and Innovation Committee ehealth Member Orange Healthcare M HEALTH SHARING INDUSTRIAL VISION AND EXPERIENCE Dr Beatrice Falise Mirat COCIR Business and Innovation Committee ehealth Member Orange Healthcare M HEALTH : A REALITY Definition: Mobile health (m health)

More information

The HUMANE roadmaps towards future human-machine networks Oxford, UK 21 March 2017

The HUMANE roadmaps towards future human-machine networks Oxford, UK 21 March 2017 The HUMANE roadmaps towards future human-machine networks Oxford, UK 21 March 2017 Eva Jaho, ATC e.jaho@atc.gr 1 Outline HMNs Trends: How are HMNs evolving? The need for future-thinking and roadmaps of

More information

Symmetric Key Services Markup Language Use Cases

Symmetric Key Services Markup Language Use Cases Symmetric Key Services Markup Language Use Cases Document Version 1.1 - February 28, 2007 The OASIS Symmetric Key Services Markup Language (SKSML) is the proposed language/protocol that defines how a client

More information

The ehealth platform

The ehealth platform Cookbook How to call the Qermid Tuco web services and the test process Version 1.0 This document is provided to you free of charge by The ehealth platform Willebroekkaai 38 Quai de Willebroeck 38 1000

More information

Integrating the Healthcare Enterprise Patient Care Devices

Integrating the Healthcare Enterprise Patient Care Devices Integrating the Healthcare Enterprise Patient Care Devices Anything can be integrated Un-Interoperability: Highest Cause of Health IT project failures Base Standards The Hospital EHRs, CMMS, other ehealth

More information

Forcare B.V. Cross-Enterprise Document Sharing (XDS) Whitepaper

Forcare B.V. Cross-Enterprise Document Sharing (XDS) Whitepaper Cross-Enterprise Document Sharing (XDS) Copyright 2010 Forcare B.V. This publication may be distributed in its unmodified whole with references to the author and company name. Andries Hamster Forcare B.V.

More information

Datapower is both a security appliance & can provide a firewall mechanism to get into Systems of Record

Datapower is both a security appliance & can provide a firewall mechanism to get into Systems of Record 1 2 3 Datapower is both a security appliance & can provide a firewall mechanism to get into Systems of Record 5 White boxes show the access points for different kinds of security. That s what we will

More information

HWISC (TEHIK) and X-road

HWISC (TEHIK) and X-road HWISC (TEHIK) and X-road Artur Novek Health and Welfare Information Systems Center/ IT architect 07.09.2017 Health and Welfare Information Systems Center (HWISC, TEHIK) HWISC is a ICT competence center

More information

IHE Integration Statement for

IHE Integration Statement for 2/4/2015 IHE Integration Statement for MEDIC Client Registry RI Version 1.0 and above Prepared By MOHAWK MHEALTH AND EHEALTH DEVELOPMENT AND INNOVATION CENTRE (MEDIC) Contents 1. Introduction... 2 1.1.

More information

4.3 Case Study #09: National ehealth network in Denmark

4.3 Case Study #09: National ehealth network in Denmark 4.3 Case Study #09: National ehealth network in Denmark Author of case study within the estandards project: Morten Bruun-Rasmussen Project name: National ehealth network in Denmark Project

More information

April 25, Dear Secretary Sebelius,

April 25, Dear Secretary Sebelius, April 25, 2014 Department of Health and Human Services Office of the National Coordinator for Health Information Technology Attention: 2015 Edition EHR Standards and Certification Criteria Proposed Rule

More information

Sharing Value Sets (SVS Profile) Ana Estelrich

Sharing Value Sets (SVS Profile) Ana Estelrich Sharing Value Sets (SVS Profile) Ana Estelrich GIP-DMP Overall presentation of the profile The Sharing Value Sets (SVS) profile provides a way through which healthcare systems producing clinical or administrative

More information

Enterprise SOA Experience Workshop. Module 8: Operating an enterprise SOA Landscape

Enterprise SOA Experience Workshop. Module 8: Operating an enterprise SOA Landscape Enterprise SOA Experience Workshop Module 8: Operating an enterprise SOA Landscape Agenda 1. Authentication and Authorization 2. Web Services and Security 3. Web Services and Change Management 4. Summary

More information

Lesson 13 Securing Web Services (WS-Security, SAML)

Lesson 13 Securing Web Services (WS-Security, SAML) Lesson 13 Securing Web Services (WS-Security, SAML) Service Oriented Architectures Module 2 - WS Security Unit 1 Auxiliary Protocols Ernesto Damiani Università di Milano element This element

More information

HIPAA COMPLIANCE AND DATA PROTECTION Page 1

HIPAA COMPLIANCE AND DATA PROTECTION Page 1 HIPAA COMPLIANCE AND DATA PROTECTION info@resultstechnology.com 877.435.8877 Page 1 CONTENTS Introduction..... 3 The HIPAA Security Rule... 4 The HIPAA Omnibus Rule... 6 HIPAA Compliance and RESULTS Cloud

More information

e-health in Austria Experiences from Implementation of EHR and Supplemental Applications

e-health in Austria Experiences from Implementation of EHR and Supplemental Applications e-health in Austria Experiences from Implementation of EHR and Supplemental Applications DI Hans-Jörg Seeburger ITAPA 2008 International Congress Government 2.0 Breaking with Traditions Agenda e-health

More information

Standards Compliant PACS XDS-I Source & XDS/XDS-I Consumer. Ronan Kirby 25 th March 2011

Standards Compliant PACS XDS-I Source & XDS/XDS-I Consumer. Ronan Kirby 25 th March 2011 Ronan Kirby 25 th March 2011 Standards Compliance on Image Sharing - Why? Support for Clinical Pathways A patients healthcare journey may involve different hospitals / trusts depending on where specific

More information

Cloud-based Identity and Access Control for Diagnostic Imaging Systems

Cloud-based Identity and Access Control for Diagnostic Imaging Systems 320 Int'l Conf. Security and Management SAM'15 Cloud-based Identity and Access Control for Diagnostic Imaging Systems Weina Ma and Kamran Sartipi Department of Electrical, Computer and Software Engineering

More information

Good Practices in Social Security. Automatic generation of secure Web services for data exchange A case of the National Social Security Fund

Good Practices in Social Security. Automatic generation of secure Web services for data exchange A case of the National Social Security Fund Good practice in operation since: 2017 Good Practices in Social Security Automatic generation of secure Web services for data exchange A case of the National Social Security Fund National Social Security

More information

Interoperability Specifications and Conformance Testing Services Made Available on the Tukan Platform

Interoperability Specifications and Conformance Testing Services Made Available on the Tukan Platform Interoperability Specifications and Conformance Testing Services Made Available on the Tukan Platform Sebastian Bojanowski, HL7 Poland IHIC 2018 Portsmouth, 12 July 2018 Challenges of Polish health IT

More information

Network Security Essentials

Network Security Essentials Network Security Essentials Fifth Edition by William Stallings Chapter 4 Key Distribution and User Authentication No Singhalese, whether man or woman, would venture out of the house without a bunch of

More information

Patient User Guide. Create a MyChart Account Create and Use Lucy and MyChartCentral

Patient User Guide. Create a MyChart Account Create and Use Lucy and MyChartCentral Patient User Guide Create a MyChart Account Create and Use Lucy and MyChartCentral Table of Contents Creating a MyChart Account... 3 Introducing Lucy... 4 Introducing MyChart Central... 4 How do I sign

More information

Enterprise Architecture & Design Authority

Enterprise Architecture & Design Authority Enterprise Architecture & Design Authority Technical Architecture: Interoperability and its impact on healthcare systems ehealth Ireland: Eamon Coyne (HSE) and Dr. Alexander Berler (IHE/GNOMON) Driving

More information

Smart Card Alliance Update. Update to the Interagency Advisor Board (IAB) June 27, 2012

Smart Card Alliance Update. Update to the Interagency Advisor Board (IAB) June 27, 2012 Smart Card Alliance Update Update to the Interagency Advisor Board (IAB) June 27, 2012 Industry s Access Control Payments (NEW) Mobile & NFC Identity Industry s Healthcare Transportation Access Control

More information

(60 min) California State Updates

(60 min) California State Updates (60 min) California State Updates Presenters: 30 min Speranza Avram, CEO, CalHIPSO: EHR status & uptake in CA 20 min David A. Minch, President & COO, HealthShare Bay Area: HIE status 10 min Questions 1

More information

SMart esolutions Information Security

SMart esolutions Information Security Information Security Agenda What are SMart esolutions? What is Information Security? Definitions SMart esolutions Security Features Frequently Asked Questions 12/6/2004 2 What are SMart esolutions? SMart

More information

A Signing Proxy for Web Services Security

A Signing Proxy for Web Services Security A Signing Proxy for Web Services Security Dr. Ingo Melzer Prof. Mario Jeckle What is a Web Service? Web Service Directory Description UDDI/WSIL WSDL Transport Content Infrastructure SOAP XML Web Service

More information

Legal Regulations and Vulnerability Analysis

Legal Regulations and Vulnerability Analysis Legal Regulations and Vulnerability Analysis Bundesamt für Sicherheit in der Informationstechnik (BSI) (Federal Office for Information Security) Germany Introduction of the BSI National Authority for Information

More information

INTEROPERABILITY & STANDARDS IN EHEALTH KATRIEN VAN GUCHT PUBLIC

INTEROPERABILITY & STANDARDS IN EHEALTH KATRIEN VAN GUCHT PUBLIC INTEROPERABILITY & STANDARDS IN EHEALTH KATRIEN VAN GUCHT PUBLIC 2 EHEALTH IN BELGIUM DATA SHARING IN BELGIE WHAT IS ALREADY THERE Hospital Data Document repository from hospital to clinician hub & metahub

More information

ehealth Days ehealth in Austria Goals and Reality

ehealth Days ehealth in Austria Goals and Reality ehealth Days ehealth in Austria Goals and Reality Agenda Atos company profile Atos in ehealth Challenges and goals of the Austrian ehealth system Building blocks of the Austrian ehealth system Conclusion

More information

Interoperability Infrastructure Services

Interoperability Infrastructure Services Athens, October 23 rd, 2017 Interoperability Infrastructure Services to enable Secure, Cross-Border, Operational ehealth Services in Europe Dimitrios G. Katehakis, Foundation for Research and Technology

More information

Send and Receive Exchange Use Case Test Methods

Send and Receive Exchange Use Case Test Methods Send and Receive Exchange Use Case Test Methods Release 1 Version 1.0 October 1, 2017 Send and Receive Exchange Test Methods Release 1 Version 1.0 Technology Sponsor [Name] [Email] [Telephone] Signature

More information

The PwC ehealth Service Platform Study Lessons learned from other countries January 2012

The PwC ehealth Service Platform Study Lessons learned from other countries January 2012 www.pwc.com The ehealth Service Platform Study Lessons learned from other countries Philippe Pierre Christine von Reichenbach Agenda 1. Context and objectives 2. Scope of today s presentation 3. Approach

More information

The MovingLife Project

The MovingLife Project The MovingLife Project MObile ehealth for the VINdication of Global LIFEstyle change and disease management solutions Stakeholders Conference The MovingLife Roadmaps Brussels 18 April 2013 Alessio Gugliotta

More information

Pragmatic approach to PHR in Japan

Pragmatic approach to PHR in Japan Pragmatic approach to PHR in Japan ASIST(Advanced research center for Social Information Science and Technology) Institute of Innovative Research Tokyo Institute of Technology Prof. Nagaaki OHYAMA 1 Multi-application

More information

ENISA Cooperation in the EU / NIS Directive

ENISA Cooperation in the EU / NIS Directive ENISA Cooperation in the EU / NIS Directive Paulo Empadinhas Head of Administration & Stakeholders Relations IT STAR Milan, Italy 28 th October 2016 European Union Agency for Network and Information Security

More information

Technologies for Securing the Networked Supply Chain. Alex Deacon Advanced Products and Research Group VeriSign, Inc.

Technologies for Securing the Networked Supply Chain. Alex Deacon Advanced Products and Research Group VeriSign, Inc. Technologies for Securing the Networked Supply Chain Alex Deacon Advanced Products and Research Group VeriSign, Inc. Agenda Introduction Security challenges Security technologies in use today Applying

More information

Interoperability and Medical Communication Using "Patient Envelope"-Based Secure Messaging

Interoperability and Medical Communication Using Patient Envelope-Based Secure Messaging Interoperability and Medical Communication Using "Patient Envelope"-Based Secure Messaging Emmanuel Cordonnier a, Stéphane Croci a, Jean-François Laurent b, Bernard Gibaud c a Etiam, France b Cancer Regional

More information

Securing your Standards Based Services. Rüdiger Gartmann (con terra GmbH) Satish Sankaran (Esri)

Securing your Standards Based Services. Rüdiger Gartmann (con terra GmbH) Satish Sankaran (Esri) Securing your Standards Based Services Rüdiger Gartmann (con terra GmbH) Satish Sankaran (Esri) Agenda What are your security goals? Access control Standards and interoperability User management and authentication

More information

DEPLOYING MULTI-TIER APPLICATIONS ACROSS MULTIPLE SECURITY DOMAINS

DEPLOYING MULTI-TIER APPLICATIONS ACROSS MULTIPLE SECURITY DOMAINS DEPLOYING MULTI-TIER APPLICATIONS ACROSS MULTIPLE SECURITY DOMAINS Igor Balabine, Arne Koschel IONA Technologies, PLC 2350 Mission College Blvd #1200 Santa Clara, CA 95054 USA {igor.balabine, arne.koschel}

More information

WEB-202: Building End-to-end Security for XML Web Services Applied Techniques, Patterns and Best Practices

WEB-202: Building End-to-end Security for XML Web Services Applied Techniques, Patterns and Best Practices WEB-202: Building End-to-end Security for XML Web Services Applied Techniques, Patterns and Best Practices Chris Steel, Ramesh Nagappan, Ray Lai www.coresecuritypatterns.com February 16, 2005 15:25 16:35

More information

The ehealth Strategy of the Vysočina Region

The ehealth Strategy of the Vysočina Region RK-41-2011-60, Annex No. 1 Number of pages: 11 The ehealth Strategy of the Vysočina Region 2012 2015 Version 1.0 Tel: 564 602 125, Fax: 564 602 421, E-mail: posta@kr-vysocina.cz, Internet: www.kr-vysocina.cz

More information

Testing for Reliable and Dependable Health Information Exchange

Testing for Reliable and Dependable Health Information Exchange Testing for Reliable and Dependable Health Information Exchange Presented by Didi Davis, Testing Programs Director 1 Copyright 2016 The Sequoia Project. All rights reserved. Discussion Topics 1. ehealth

More information

This document is a preview generated by EVS

This document is a preview generated by EVS INTERNATIONAL STANDARD ISO 17090-1 Second edition 2013-05-01 Health informatics Public key infrastructure Part 1: Overview of digital certificate services Informatique de santé Infrastructure de clé publique

More information

Healthcare Security Success Story

Healthcare Security Success Story Regional Forum on Cybersecurity in the Era of Emerging Technologies & the Second Meeting of the Successful Administrative Practices -2017 Cairo, Egypt 28-29 November 2017 Healthcare Security Success Story

More information

Information Technology (CCHIT): Report on Activities and Progress

Information Technology (CCHIT): Report on Activities and Progress Certification Commission for Healthcare Information Technology Certification Commission for Healthcare Information Technology (CCHIT): Report on Activities and Progress Mark Leavitt, MD, PhD Chair, CCHIT

More information

NRG Oncology and VisionTree Optimal Care (VTOC) Frequently Asked Questions

NRG Oncology and VisionTree Optimal Care (VTOC) Frequently Asked Questions NRG Oncology and VisionTree Optimal Care (VTOC) Frequently Asked Questions Overview VisionTree Optimal Care (VTOC) v4.1 is a secure, encrypted cloud-based platform to collect/report patient reported outcomes

More information

Safdar Ali (PhD Candidate)

Safdar Ali (PhD Candidate) Architecting disparate ehealth systems interoperable through Web Services Safdar Ali (PhD Candidate) safdar.ali@ibmt.fraunhofer.de Fraunhofer-Institute for Biomedical Engineering (IBMT) St. Ingbert, Germany

More information

Cookbook ehealth platform Id Support web service Version 1.2

Cookbook ehealth platform Id Support web service Version 1.2 Cookbook ehealth platform Id Support web service Version 1.2 This document is provided to you free of charge by the ehealth platform Willebroekkaai 38, 38, Quai de Willebroeck 1000 BRUSSELS All are free

More information

ConCert FAQ s Last revised December 2017

ConCert FAQ s Last revised December 2017 ConCert FAQ s Last revised December 2017 What is ConCert by HIMSS? ConCert by HIMSS is a comprehensive interoperability testing and certification program governed by HIMSS and built on the work of the

More information

HIPAA AND SECURITY. For Healthcare Organizations

HIPAA AND  SECURITY. For Healthcare Organizations HIPAA AND EMAIL SECURITY For Healthcare Organizations Table of content Protecting patient information 03 Who is affected by HIPAA? 06 Why should healthcare 07 providers care? Email security & HIPPA 08

More information

California State Updates. Presenter: David A. Minch, President & COO, HealthShare Bay Area

California State Updates. Presenter: David A. Minch, President & COO, HealthShare Bay Area California State Updates Presenter: David A. Minch, President & COO, HealthShare Bay Area 1 Trust is the Foundation for Health Data Exchange Patients must trust the Providers to hold their data securely,

More information

HIPAA Compliance & Privacy What You Need to Know Now

HIPAA  Compliance & Privacy What You Need to Know Now HIPAA Email Compliance & Privacy What You Need to Know Now Introduction The Health Insurance Portability and Accountability Act of 1996 (HIPAA) places a number of requirements on the healthcare industry

More information

Integration Guide. SafeNet Authentication Service. Protecting SugarCRM with SAS

Integration Guide. SafeNet Authentication Service. Protecting SugarCRM with SAS SafeNet Authentication Service Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information

More information

Singapore s National Digital Identity (NDI):

Singapore s National Digital Identity (NDI): Singapore s National Digital Identity (NDI): Leaving no one behind Kwok Quek Sin Director, National Digital Identity Programme Government Technology Agency PART 1 INTRODUCTION TO NDI Better Living For

More information

PRODUCT UNDER TEST TEST EVENT RESULT. Quality Manual ISO Test Lab Test Report

PRODUCT UNDER TEST TEST EVENT RESULT. Quality Manual ISO Test Lab Test Report PRODUCT UNDER TEST Organization Name: Varian Medical Systems Address of Vendor: 3100 Hansen Way Palo Alto CA 94304 Test Product Name: 360 Oncology Patient Portal Test Product Version-with-Release: 1.0

More information

Frequently Asked Questions

Frequently Asked Questions Frequently Asked Questions What is FollowMyHealth? FollowMyHealth offers you personalized and secure online access to important information in your electronic medical record. FollowMyHealth is available

More information

GUIDE ON HOW TO SET UP AND USE YOUR PATIENT PORTAL

GUIDE ON HOW TO SET UP AND USE YOUR PATIENT PORTAL You will receive an email from Personalized Women s Healthcare once you have registered as a patient with our office and provided us with your personal email. When you receive your email click on the Register

More information

Lifeway Adult Information Form

Lifeway Adult Information Form Date / / Patient Name: First Lifeway Adult Information Form MI Last Date of Birth: / / Gender: M F Marital Status: M S D Address: City State: Zip: Primary Contact Phone: Secondary Contact Phone: Please

More information

IHE: Integrating the Healthcare Enterprise

IHE: Integrating the Healthcare Enterprise IHE: Integrating the Healthcare Enterprise Constantin Hofstetter (0650502) and Gerhard Kober (0215750) University of Vienna Abstract In this work, we provide an overview of the Cisco Medical Data Exchange

More information

The Business of Identity: Business Drivers and Use Cases of Identity Web Services

The Business of Identity: Business Drivers and Use Cases of Identity Web Services The Business of Identity: Business Drivers and Use Cases of Identity Web Services Roger Sullivan, Vice President, Liberty Alliance Vice President, Oracle Corporation Liberty s Architecture Liberty Identity

More information

Short Introduction. v

Short Introduction. v Short Introduction v. 9.10.2017 1. Warming Up 2. Dry facts about IHE 3. What is IHE? 4. IHE Process 5. Technical Frameworks and Profiles 6. Use of IHE Profiles in Finland 7. Summary 1. Warming Up IHE promotes

More information

Managing Trust in e-health with Federated Identity Management

Managing Trust in e-health with Federated Identity Management ehealth Workshop Konolfingen (CH) Dec 4--5, 2007 Managing Trust in e-health with Federated Identity Management Dr. rer. nat. Hellmuth Broda Distinguished Director and CTO, Global Government Strategy, Sun

More information

Jan 30,2018. PULSE: HIE Connectivity for Disaster Response Patient Unified Lookup System for Emergencies

Jan 30,2018. PULSE: HIE Connectivity for Disaster Response Patient Unified Lookup System for Emergencies Jan 30,2018 PULSE: HIE Connectivity for Disaster Response Patient Unified Lookup System for Emergencies PULSE Background History 2013: California Emergency Medical Services Authority (EMSA) holds its first

More information

Pennsylvania s HIE Journey

Pennsylvania s HIE Journey Pennsylvania s HIE Journey Alix Goss, Executive Director Pennsylvania ehealth Partnership Authority William Buddy Gillespie Director Healthcare Solutions DSS What is HIE? Health Information Exchange puts

More information

TIBCO ActiveMatrix Policy Director Administration

TIBCO ActiveMatrix Policy Director Administration TIBCO ActiveMatrix Policy Director Administration Software Release 2.0.0 November 2014 Document Updated: January 2015 Two-Second Advantage 2 Important Information SOME TIBCO SOFTWARE EMBEDS OR BUNDLES

More information

and Privacy HIPAA-Compliance Checklist

and Privacy HIPAA-Compliance Checklist Email and Privacy HIPAA-Compliance Checklist TBHI Checklist Copyright 2017 Telebehavioral Health Institute All rights reserved. Telebehavioral Health Institute www.telehealth.org No part of this publication

More information

The simplified guide to. HIPAA compliance

The simplified guide to. HIPAA compliance The simplified guide to HIPAA compliance Introduction HIPAA, the Health Insurance Portability and Accountability Act, sets the legal requirements for protecting sensitive patient data. It s also an act

More information

National Identity Exchange Federation. Web Services System- to- System Profile. Version 1.1

National Identity Exchange Federation. Web Services System- to- System Profile. Version 1.1 National Identity Exchange Federation Web Services System- to- System Profile Version 1.1 July 24, 2015 Table of Contents TABLE OF CONTENTS I 1. TARGET AUDIENCE AND PURPOSE 1 2. NIEF IDENTITY TRUST FRAMEWORK

More information

How to Overcome Web Services Security Obstacles

How to Overcome Web Services Security Obstacles How to Overcome Web Services Security Obstacles Dick Mackey SystemExperts Corporation Agenda Introduction to Web Services Web Services threats Web Services security standards What s here today What you

More information

HIC Standards Session Who is who in the zoo?

HIC Standards Session Who is who in the zoo? HIC Standards Session Who is who in the zoo? Professor Trish Williams Cisco Chair and Professor of Digital Health Systems School of Computer Science, Engineering and Mathematics Flinders University How

More information

QUALITY ASSURANCE amron

QUALITY ASSURANCE amron 0 Training Details Course Duration: 55-60 hours Training + Assignments + Actual Project Based Case Studies Training Materials: All attendees will receive: Assignment after each module, video recording

More information

Augusta University Health: Physician Portal User Guide. Improved Access to Patient Information from Augusta University Medical Center

Augusta University Health: Physician Portal User Guide. Improved Access to Patient Information from Augusta University Medical Center Augusta University Health: Physician Portal User Guide Improved Access to Patient Information from Augusta University Medical Center Rev. 7/06 User Guide Index. Accessing the AU Health Physician Portal.

More information

EHR Connectivity Integration Specification

EHR Connectivity Integration Specification EHR Connectivity Integration Specification HeC Contact information Name Phone Email Title/Role Jeremy Smith (315) 671 2241 x320 jsmith@healtheconnections.org Manager, HIE Integration OVERVIEW This document

More information

Department of Veterans Affairs Direct and My HealtheVet Blue Button. Glen Crandall VA Direct Program Manager

Department of Veterans Affairs Direct and My HealtheVet Blue Button. Glen Crandall VA Direct Program Manager Department of Veterans Affairs Direct and My HealtheVet Blue Button Glen Crandall VA Direct Program Manager July 24, 2013 1 What is VLER? On April 9, 2009, President Obama directed the Department of Defense

More information

Ensuring Privacy and Security of Health Information Exchange in Pennsylvania

Ensuring Privacy and Security of Health Information Exchange in Pennsylvania Ensuring Privacy and Security of Health Information Exchange in Pennsylvania The Pennsylvania ehealth Initiative in collaboration with the Pennsylvania ehealth Partnership Authority Introduction The Pennsylvania

More information

The Business Case for Electronic or Digital Signatures

The Business Case for Electronic or Digital Signatures The Business Case for Electronic or Digital Signatures Testimony Before the NCVHS Subcommittee on Standards and Security. October 26, 2000 Gunther Schadow, M.D. Regenstrief Institute for Health Care, Indianapolis,

More information

IHE IT Infrastructure Technical Framework Supplement Cross-Enterprise User Authentication (XUA) Integration Profile

IHE IT Infrastructure Technical Framework Supplement Cross-Enterprise User Authentication (XUA) Integration Profile ACC, HIMSS and RSNA Integrating the Healthcare Enterprise 5 IHE IT Infrastructure Technical Framework Supplement 2005-2006 10 Cross-Enterprise User Authentication (XUA) Integration Profile June 15, 2005

More information

MAIN MENU. Access to the main sections of the app 3 different parts : Views and sharing Health record sections Menu bar

MAIN MENU. Access to the main sections of the app 3 different parts : Views and sharing Health record sections Menu bar (EN) MAIN MENU 1 1 2 3 Access to the main sections of the app 3 different parts : 1. 2. 3. Views and sharing Health record sections Menu bar MAIN MENU- Views and sharing 1 1 The section view displays sections

More information

ONE ID Identification Information and User Name Standard

ONE ID Identification Information and User Name Standard ONE ID Identification Information and User Name Standard Copyright Notice Copyright 2014, ehealth Ontario All rights reserved No part of this document may be reproduced in any form, including photocopying

More information

Chapter 17 Web Services Additional Topics

Chapter 17 Web Services Additional Topics Prof. Dr.-Ing. Stefan Deßloch AG Heterogene Informationssysteme Geb. 36, Raum 329 Tel. 0631/205 3275 dessloch@informatik.uni-kl.de Chapter 17 Web Services Additional Topics Prof. Dr.-Ing. Stefan Deßloch

More information

SAP Security in a Hybrid World. Kiran Kola

SAP Security in a Hybrid World. Kiran Kola SAP Security in a Hybrid World Kiran Kola Agenda Cybersecurity SAP Cloud Platform Identity Provisioning service SAP Cloud Platform Identity Authentication service SAP Cloud Connector & how to achieve Principal

More information

SELF SERVICE INTERFACE CODE OF CONNECTION

SELF SERVICE INTERFACE CODE OF CONNECTION SELF SERVICE INTERFACE CODE OF CONNECTION Definitions SSI Administration User Identity Management System Identity Provider Service Policy Enforcement Point (or PEP) SAML Security Patch Smart Card Token

More information

OASIS Cross-Enterprise Security and Privacy Authorization (XSPA) WS- Trust Healthcare Profile. Working draft 20 August, 2008

OASIS Cross-Enterprise Security and Privacy Authorization (XSPA) WS- Trust Healthcare Profile. Working draft 20 August, 2008 OASIS Cross-Enterprise Security and Privacy Authorization (XSPA) WS- Trust Healthcare Profile Working draft 20 August, 2008 Document identifier: xspa-ws-trust-profile-01 Location: Editor: Brett Burley,

More information

DRAFT For Discussion Purposes Only

DRAFT For Discussion Purposes Only DRAFT For Discussion Purposes Only Statements or comments made by the ministry or information provided in the draft technical specifications are not binding on the ministry. In particular, the ministry

More information