Onboarding Overview. December 3, 2013

Size: px
Start display at page:

Download "Onboarding Overview. December 3, 2013"

Transcription

1 Onboarding Overview December 3,

2 2 Overview ehealth Exchange Overview Onboarding and Testing Process Resources and Tools

3 ehealth Exchange Health Bank or PHR Support Organization State and Local Gov Community Health Centers Community #1 Labs Shared trust framework and rules of the road Governed by Coordinating Committee SSA VA DoD CMS Integrated Delivery System The Internet Pharmacies Community #2 Supported by Healtheway Standards, Specifications and Data Use & Reciprocal Support Agreement (DURSA) for Secure Connections PHIN Conference 25 August 2008

4 ehealth Exchange Participants Alabama One Health Record Centers for Medicare and Medicaid Services (CMS) Childrens Hospital of Dallas Community Health Information Collaborative (CHIC) Conemaugh Health System Department of Defense (DOD) Department of Veterans Affairs Dignity Health Douglas County Individual Practice Association (DCIPA) Eastern Tennessee Health Information Network (ethin) EHR Doctors Hawaii Pacific Health Geisinger Health HealthBridge HealtheConnections RHIO Central New York HEALTHeLINK (Western New York) Idaho Health Data Exchange Indiana Health Information Exchange (IHIE) Inland Northwest Health Services (INHS) Kaiser Permanente Lancaster General Health Marshfield Clinic Medical University of South Carolina (MUSC) MedVirginia Michigan Health Information Network (MiHIN) MultiCare Health System National Renal Administrators Association (NRAA) New Mexico Health Information Collaborative (NMHIC) North Carolina Healthcare Information and Communications Alliance, Inc. (NCHICA) OCHIN Quality Health Network San Diego Beacon Social Security Administration (SSA) South Carolina Health Information Exchange (SCHIEx) South East Michigan Health Information Exchange (SEMHIE) Strategic Health Intelligence University of California, Davis Utah Health Information Network (UHIN) Walgreens Wright State University 4

5 ehealth Exchange Anchor Participants 5

6 Healtheway Members 6

7 ehealth Exchange Growth Participation reaching critical mass 40+ Participants 59 in testing phase Hundreds of hospitals, thousands of physician practices, millions of patients Dozens of others planning to onboard National-level coverage increasing; reaching tipping point of adoption Collaboration extending breadth and depth of connectivity Care Connectivity Consortium Kaiser Permanente, Mayo Clinic, Geisinger, Group Health Cooperative, Intermountain Healthcare Meaningful Use (Stage 2) is one factor driving adoption among vendors and providers 7

8 Benefits to Participating in the ehealth Exchange Enables exchange of data with other participants in the ehealth Exchange community without additional testing or one-off agreements Recognition as part of trusted community Confidence that the connection can be trusted since every participant is expected to meet the conditions for trust Cost-effective and efficient (national-level ROI) since all participants exchange under a common trust and interoperability framework Compliance enforced by contract and an oversight committee Functional and scalable shared services that help you find exchange partners Contributes toward measures for MU2 related to the transitions of care and referrals objective 8

9 Healtheway Support of ehealth Exchange Healtheway supports the ehealth Exchange community by: Supporting the Coordinating Committee Facilitating Task Groups which develop and maintain the rules of the road (e.g. implementation specifications, test cases, operating policies and procedures, legal agreement, etc.) Supporting product testing program that verifies product compliance with ehealth Exchange requirements Providing an efficient participant testing program to support onboarding to production ehealth Exchange community Issuing and managing digital certificates used by ehealth Exchange participants Managing the directory which enables ehealth Exchange participants to find other exchange partners 9

10 ACTIVATE TEST APPLY Onboarding Process Submit Application Package and testing agreement and fees Coordinating Committee (CC) determines eligibility Complete testing readiness checklist Complete practice tests Submit completed test results to Healtheway Test results presented for CC approval Issue digital certificate Add to service registry Countersign DURSA Go Live! 10

11 Submit Onboarding Package Onboarding Package Application for Participation Testing Services Agreement Data Use and Reciprocal Support Agreement (DURSA) ehealth Exchange Participant Agreement NOTE: The following materials may be submitted with the Application Package; however, they must be received by Healtheway in order for Applicant to complete testing Testing Readiness Checklist Testing Fees 11

12 Eligibility Criteria Be a valid business in good standing or a governmental agency, operating in the US; Meet all solvency and financial responsibility requirements imposed by statutes and regulatory authorities; Be an organization or agency that oversees and conducts, on its own behalf and/or on behalf of its Participant Users, electronic transactions or exchanges of health information among groups of persons or organizations; Have the organizational infrastructure and legal authority (through statutes, regulations, organizational agreements, contracts or binding policies) to comply with the obligations in the DURSA and to require its Participant Users to comply with applicable requirements of the DURSA; Is not aware of any information that would preclude the Applicant from fully complying with the provisions of the DURSA; Intend to Transact information with other Participants for a Permitted Purpose as defined in the DURSA; Have sufficient financial, technical and operational resources to support the testing and operation of transactions among Participants; Submit a completed Application, signed DURSA Joinder Agreement (Attachment 7 of the DURSA), and the ehealth Exchange Participation Agreement; Successfully complete testing and be accepted by the ehealth Exchange Coordinating Committee. 12

13 Determine what you want to support in production Lookup and Retrieve Documents (for Care Coordination for Treatment and/or Social Security eligibility: Send SSA clinical data electronically to allow SSA to make faster disability determinations. Required Specifications: Messaging Platform, Authorization Framework, Web Services Registry, Patient Discovery, Query for Documents, Retrieve Documents) Select which, if any, Optional Services Applicant will support for this use case Access Consent Deferred Messaging for Patient Discovery Identify the types of documents/ data you will exchange using lookup and retrieval of document functionality HL7, v Bridge C32 C-CDA Unstructured documents Other: Please specify 13

14 APPLY Submit Onboarding Package to including testing fees Document Who to Involve Summary Application & Testing Services Agreement Primary Business Contact Privacy Security Business Office Human Resources Complete Application, with careful attention to questions 8 & 9 (DURSA Flow-Down Provisions) Sign the Application and Testing Services Agreement Submit payment of testing fees to Healtheway DURSA Primary Business Contact Legal Privacy / Security Review Sections and 15.05: DURSA Flow-Down Provisions Complete the Contacts for Notice (Attachment 4) Sign the DURSA Joinder Agreement (Attachment 7) Participation Agreement Primary Business Contact Legal Sign the Participation Agreement 14

15 How to Tackle the DURSA Review DURSA and assure you have mechanisms in place to comply with all provisions Consult, as necessary, with the following Privacy Security Legal Business Office Human Resources Specifically address the DURSA flow-down provisions in Sections and See DURSA Webinar on the Healtheway Onboarding web page for details Sign the DURSA Joinder Agreement (Attachment 7 of the DURSA, with Attachment 4 Contacts for Notice) 15

16 Participation Agreement Testing Services Agreement The business agreement between Healtheway and the applicant for the provision of testing services to the applicant Required to proceed to testing Participation Agreement The business agreement between Healtheway and the Participant for the provision of services, once accepted as a Participant Managing digital certificates required for secure exchange Maintaining UDDI registry Enabling access to exchange with other participants Support of the Coordinating Committee and its processes (i.e., supporting the breach notification process, etc.). Countersigned by Healtheway only when applicant is accepted as Participant 16

17 ehealth Exchange Participation Fees Annual Revenue Annual Participation Fee < $1M $4,750 $1 - $10M $9,950 More than $10M $19,900 Fees take effect in Annual Revenue is based upon annual healthcare revenue. For governmental agencies and non-profit organizations, this should be based upon annual operating costs. 17

18 ehealth Exchange Participant Testing Fees Tests Testing Fee 2010 Smoke Tests 1 $ 11, Smoke Tests 1 $ 11, Security Tests $ 8,000 Content 2 $ 3,000 Notes: 1 Discounted testing fee if testing both 2010 and 2011 Smoke Test Cases - $4,500 for the second version tested. 2 Content testing options: 1) Basic C32; 2) Bridge C32 and 3) C-CDA. Content testing is waived if Applicant uses a product that was certified for the 2011 or 2014 edition of EHR certification for Stage 1 or Stage 2 meaningful use. Scenarios Total 2011 (no content) $ 19, (with content) $ 22, (no content) $ 23, (with content) $ 26,500 Additional Fees - Extension (beyond 60 days from Official Results Submission to Healtheway) 15% of testing fee - Retest Fee (per test result) - $2,000 18

19 Determine Eligibility Healtheway staff review applications to verify completeness and readiness for CC review. Clarifications and additional information may be requested Completed application packages presented for CC review in monthly meetings If eligible, Applicant notified and referred to begin practice testing If ineligible or if insufficient information to determine eligibility, Applicant notified, with recommended next steps 19

20 TEST Complete practice testing Notify Healtheway when results ready for official review Task Who to Involve Summary Set up in Testing Environment Primary Testing Contact Complete DIL set up checklist Register in DIL Set up with applicable tests Review & Conduct Practice Testing Technical Contact Technology Partner/Vendor Review and execute test cases Complete practice tests and address identified deficiencies Notify when practice testing completed Validate Official Test Results Technical Contact Technology Partner/Vendor Applicant notifies Healtheway Unique Execution IDs Healtheway tester validates the results and prepares testing results report 20

21 Participant Testing Process Applicant Prepare Onboarding Package Practice Testing: Ready for PRD? Participant No Healtheway Package Complete? Ready to Test? No Yes Validate Results / Prepare Report e Activate for Production: Cert / UDDI Set Up No No Coordinating Committee Eligibl e? Yes Accept as Partici pant? Yes Aegis Test Lab Environment (DIL) and NIST CDA validator tools Practice testing in DIL and with NIST Tools 21 ehealth Exchange Participant Testing

22 Coordinating Committee Determines Participation Healtheway presents Applicant s test results to the ehealth Exchange Coordinating Committee for approval on monthly basis ehealth Exchange Coordinating Committee (CC) determines whether applicant is accepted as ehealth Exchange Participant If approved, applicant progresses to Activation If not approved, Applicant notified Approved applicants must go into production and be capable of exchanging, once activated in the service registry and using the ehealth Exchange digital certificate, within 120 calendar days following the CC approval date 22

23 ACTIVATE Coordinating Committee approval Activate Go Live! Task Who to Involve Summary Activation Materials Technical/ Operational Contact Complete & sign digital certificate form and agreement Complete service registry form Process Activation Materials Technical/ Operational Contact If complete, issue production certificate and add entry to service registry. Participant activated, with system staged in production and ready to exchange If not complete, notify applicant or, if necessary, present to Coordinating Committee for resolution 23

24 Monitor New participants, or existing participants who retest, are subject to a probationary period once in production (e.g. 90 days) Participants and their partners report issues via a designated mechanism Issues are triaged to assess whether participant is meeting conformance and interoperability requirements If all issues resolved, probationary period ends Matters may be escalated, including disputes, to the Coordinating Committee for resolution 24

25 For More Information admin at healthewayinc.org Onboarding: Testing Process: DIL Test Lab: 25

ehealth Exchange Onboarding Overview

ehealth Exchange Onboarding Overview ehealth Exchange Onboarding Overview Jennifer Rosas, ehealth Exchange Director Kati Odom, ehealth Exchange Implementation Manager ehealth Exchange Core Values Lead in national-level exchange of health

More information

Testing for Reliable and Dependable Health Information Exchange

Testing for Reliable and Dependable Health Information Exchange Testing for Reliable and Dependable Health Information Exchange Presented by Didi Davis, Testing Programs Director 1 Copyright 2016 The Sequoia Project. All rights reserved. Discussion Topics 1. ehealth

More information

Health Information Exchange - A Critical Assessment: How Does it Work in the US and What Has Been Achieved?

Health Information Exchange - A Critical Assessment: How Does it Work in the US and What Has Been Achieved? Health Information Exchange - A Critical Assessment: How Does it Work in the US and What Has Been Achieved? Use cases, best practice and examples for successful implementations 1 Agenda Overview of The

More information

Product Testing Program

Product Testing Program Product Testing Program Vendor Forum January 9, 2014 1 Discussion Topics Purpose Desired outcomes Scope of product testing Testing process Retesting policy Proposed fee schedule Value Proposition Launch

More information

(60 min) California State Updates

(60 min) California State Updates (60 min) California State Updates Presenters: 30 min Speranza Avram, CEO, CalHIPSO: EHR status & uptake in CA 20 min David A. Minch, President & COO, HealthShare Bay Area: HIE status 10 min Questions 1

More information

Data Use and Reciprocal Support Agreement (DURSA) Overview

Data Use and Reciprocal Support Agreement (DURSA) Overview Data Use and Reciprocal Support Agreement (DURSA) Overview 1 Steve Gravely, Troutman Sanders LLP Jennifer Rosas, ehealth Exchange Director January 12, 2017 Introduction Steve Gravely Partner and Healthcare

More information

Participation Agreement for the ehealth Exchange

Participation Agreement for the ehealth Exchange Participation Agreement for the ehealth Exchange This Participation Agreement for the ehealth Exchange ("Agreement") is entered into as of the last date written below ( Effective Date ) by and between

More information

California State Updates. Presenter: David A. Minch, President & COO, HealthShare Bay Area

California State Updates. Presenter: David A. Minch, President & COO, HealthShare Bay Area California State Updates Presenter: David A. Minch, President & COO, HealthShare Bay Area 1 Trust is the Foundation for Health Data Exchange Patients must trust the Providers to hold their data securely,

More information

DRAFT FOR DISCUSSION ONLY REVISED OPTION FOR DRAFT PRELIMINARY RECOMMENDATION 1

DRAFT FOR DISCUSSION ONLY REVISED OPTION FOR DRAFT PRELIMINARY RECOMMENDATION 1 HIE Task Force REVISED OPTION FOR DRAFT PRELIMINARY RECOMMENDATION 1 Please note: This document reflects the research and activities completed as follow-up to questions and discussion draft preliminary

More information

President Obama s First Weekly Address Saturday, January 24th, 2009

President Obama s First Weekly Address Saturday, January 24th, 2009 Agenda The Winds of Change: people and resources The 2008 Health IT Strategic Plan: an enduring vision The Nationwide Health Information Network (NHIN): toward nationwide interoperability 2 President Obama

More information

Phase I CAQH CORE 102: Eligibility and Benefits Certification Policy version March 2011

Phase I CAQH CORE 102: Eligibility and Benefits Certification Policy version March 2011 Phase I CAQH CORE 102: Eligibility and Benefits Certification Policy GUIDING PRINCIPLES After signing the CORE Pledge, the entity has 180 days to complete CORE certification testing. CORE will not certify

More information

The HITECH Act. 5 things you can do Right Now to pave the road to compliance. 1. Secure PHI in motion.

The HITECH Act. 5 things you can do Right Now to pave the road to compliance. 1. Secure PHI in motion. The HITECH Act 5 things you can do Right Now to pave the road to compliance Beginning in 2011, HITECH Act financial incentives will create a $5,800,000 opportunity over four years for mid-size hospital

More information

CERT Symposium: Cyber Security Incident Management for Health Information Exchanges

CERT Symposium: Cyber Security Incident Management for Health Information Exchanges Pennsylvania ehealth Partnership Authority Pennsylvania s Journey for Health Information Exchange CERT Symposium: Cyber Security Incident Management for Health Information Exchanges June 26, 2013 Pittsburgh,

More information

2010 & ehealth Exchange Smoke Tests (Participant & Product Testing) 2010 & 2011 Smoke. Tests (Participant & Product)

2010 & ehealth Exchange Smoke Tests (Participant & Product Testing) 2010 & 2011 Smoke. Tests (Participant & Product) 2010 & 2011 ehealth Exchange Smoke Tests (Participant & Product Testing) 2010 & 2011 Smoke Copyright 2015 Healtheway, Inc All rights reserved Tests (Participant & Product) Table of Contents ehealth Exchange

More information

Carequality Principles of Trust

Carequality Principles of Trust Ratified Jan, 2015 TABLE OF CONTENTS 1 Introduction... 3 2 Carequality Overview... 3 3 The Role of the Trust Framework Work Group... 5 4 Universal Principles of Trust... 7 5 Customizable Principles of

More information

Phase II CAQH CORE 202 Certification Policy version March 2011 CAQH 2011

Phase II CAQH CORE 202 Certification Policy version March 2011 CAQH 2011 CAQH 2011 Phase II CAQH CORE 202 Certification Policy GUIDING PRINCIPLES Phase II CORE 202 Certification Policy After signing the CORE Pledge and/or Addendum, the entity has 180 days to complete CORE certification

More information

A Pilot Implementation of DIRECT Messaging and Provider Directory Services in the Palomar Health District

A Pilot Implementation of DIRECT Messaging and Provider Directory Services in the Palomar Health District A Pilot Implementation of DIRECT Messaging and Provider Directory Services in the Palomar Health District Project Overview and Plan Sujansky & Associates, LLC 1. Project Objectives Figure 1. High-level

More information

Redwood MedNet Established 2005

Redwood MedNet Established 2005 Redwood MedNet Established 2005 Health information exchange (HIE) services for healthcare facilities in Northern California 40 Outpatient Practices 5 Hospitals 1 Outpatient Surgery Center 5 Independent

More information

ConCert FAQ s Last revised December 2017

ConCert FAQ s Last revised December 2017 ConCert FAQ s Last revised December 2017 What is ConCert by HIMSS? ConCert by HIMSS is a comprehensive interoperability testing and certification program governed by HIMSS and built on the work of the

More information

Decrypting the Security Risk Assessment (SRA) Requirement for Meaningful Use

Decrypting the Security Risk Assessment (SRA) Requirement for Meaningful Use Click to edit Master title style Decrypting the Security Risk Assessment (SRA) Requirement for Meaningful Use Andy Petrovich, MHSA, MPH M-CEITA / Altarum Institute June 21, 2016 6/21/2016 1 1 Disclaimer

More information

Update from HIMSS National Privacy & Security. Lisa Gallagher, VP Technology Solutions November 14, 2013

Update from HIMSS National Privacy & Security. Lisa Gallagher, VP Technology Solutions November 14, 2013 Update from HIMSS National Privacy & Security Lisa Gallagher, VP Technology Solutions November 14, 2013 Agenda Update on HIMSS new Technology Solutions Department HIPAA Omnibus Rules Meaningful Use 2 P&S

More information

Federal-State Connections: Opportunities for Coordination and Collaboration

Federal-State Connections: Opportunities for Coordination and Collaboration Federal-State Connections: Opportunities for Coordination and Collaboration State Health Information Exchange Program October 23, 2012 Chris Muir Program Manager 1 ONC Overview Vision A health system that

More information

SLI Compliance ONC-ATL Testing Program Guide

SLI Compliance ONC-ATL Testing Program Guide SLI Compliance A Division of Gaming Laboratories International, LLC 4720 Independence St. Wheat Ridge, CO 80033 303-422-1566 www.slicompliance.com SLI Compliance ONC-ATL Testing Program Guide Document

More information

Security and Privacy Governance Program Guidelines

Security and Privacy Governance Program Guidelines Security and Privacy Governance Program Guidelines Effective Security and Privacy Programs start with attention to Governance. Governance refers to the roles and responsibilities that are established by

More information

Health Information Exchange: Can There Be ONE National Model?

Health Information Exchange: Can There Be ONE National Model? Health Information Exchange: Can There Be ONE National Model? Session 56, February 20, 2017 John P. Kansky, President & CEO, Indiana Health Information Exchange Keith W. Kelley, Vice President of Solution

More information

Public and Private Sector Partnerships to Promote HIT Adoption Across the United States

Public and Private Sector Partnerships to Promote HIT Adoption Across the United States Public and Private Sector Partnerships to Promote HIT Adoption Across the United States Community-Based Collaboratives Track Health Information Technology Summit October 20-23, 2004 Washington, D.C. Janet

More information

Certification Commission for Healthcare Information Technology. CCHIT A Catalyst for EHR Adoption

Certification Commission for Healthcare Information Technology. CCHIT A Catalyst for EHR Adoption Certification Commission for Healthcare Information Technology CCHIT A Catalyst for EHR Adoption Alisa Ray, Executive Director, CCHIT Sarah Corley, MD, Chief Medical Officer, NextGen Healthcare Systems;

More information

Sequoia Project Content Testing Pilot Didi Davis Director Testing Programs

Sequoia Project Content Testing Pilot Didi Davis Director Testing Programs Sequoia Project Content Testing Pilot Didi Davis Director Testing Programs An initiative of 1 Copyright 2016 The Sequoia Project. All rights reserved. Meet Today s Presenters Didi Davis Director, Testing

More information

MANUAL OF UNIVERSITY POLICIES PROCEDURES AND GUIDELINES. Applies to: faculty staff students student employees visitors contractors

MANUAL OF UNIVERSITY POLICIES PROCEDURES AND GUIDELINES. Applies to: faculty staff students student employees visitors contractors Page 1 of 6 Applies to: faculty staff students student employees visitors contractors Effective Date of This Revision: June 1, 2018 Contact for More Information: HIPAA Privacy Officer Board Policy Administrative

More information

California Trust Framework. Brief Report

California Trust Framework. Brief Report California Trust Framework Brief Report January 30, 2014 Katherine K. Kim San Francisco State University, Health Equity Institute Lori Hack ObjectHealth, LLC Prepared for California Health equality University

More information

Prior Authorization and Clinician Burden: Updates from ONC

Prior Authorization and Clinician Burden: Updates from ONC Prior Authorization and Clinician Burden: Updates from ONC Thomas A. Mason, MD, FACP Chief Medical Officer Office of the National Coordinator for Health Information Technology (ONC) U.S. Department of

More information

Meaningful Use Webcast

Meaningful Use Webcast MU Security Objectives Direct Messaging Questions MU Security Objective Security s Importance to Meaningful Use The Security Objective Satisfying the Objective Security Mechanisms in the EHR Software MU

More information

CLINICAL DIRECT MESSAGING FREQUENTLY ASKED QUESTIONS

CLINICAL DIRECT MESSAGING FREQUENTLY ASKED QUESTIONS Surescripts has the experience to handle all of your direct messaging needs. Serving the nation with the single most trusted and capable health information network since 2001, we seamlessly connect the

More information

Thank you, and enjoy the webinar.

Thank you, and enjoy the webinar. Disclaimer This webinar may be recorded. This webinar presents a sampling of best practices and overviews, generalities, and some laws. This should not be used as legal advice. Itentive recognizes that

More information

User Manual/Guide for Direct Using encompass 3.0. Prepared By: Arête Healthcare Services, LLC

User Manual/Guide for Direct Using encompass 3.0. Prepared By: Arête Healthcare Services, LLC User Manual/Guide for Direct Using encompass 3.0 Prepared By: Arête Healthcare Services, LLC Document Version: V1.0 10/02/2015 Contents Direct Overview... 3 What is Direct?... 3 Who uses Direct?... 3 Why

More information

Auditing and Monitoring for HIPAA Compliance. HCCA COMPLIANCE INSTITUTE 2003 April, Presented by: Suzie Draper Sheryl Vacca, CHC

Auditing and Monitoring for HIPAA Compliance. HCCA COMPLIANCE INSTITUTE 2003 April, Presented by: Suzie Draper Sheryl Vacca, CHC Auditing and Monitoring for HIPAA Compliance HCCA COMPLIANCE INSTITUTE 2003 April, 2003 Presented by: Suzie Draper Sheryl Vacca, CHC 1 The Elements of Corporate Compliance Program There are seven key elements

More information

MEDICITY NETWORK ONC CERTIFICATION COST AND LIMITATIONS

MEDICITY NETWORK ONC CERTIFICATION COST AND LIMITATIONS MEDICITY NETWORK ONC CERTIFICATION COST AND LIMITATIONS Medicity is proud to offer health IT solutions that are certified under the Office of the National Coordinator for Health Information Technology.

More information

Draft Applicant Guidebook, v3

Draft Applicant Guidebook, v3 Draft Applicant Guidebook, v3 Module 5 Please note that this is a discussion draft only. Potential applicants should not rely on any of the proposed details of the new gtld program as the program remains

More information

EHR SECURITY POLICIES & SECURITY SITE ASSESSMENT OVERVIEW WEBINAR. For Viewer Sites

EHR SECURITY POLICIES & SECURITY SITE ASSESSMENT OVERVIEW WEBINAR. For Viewer Sites EHR SECURITY POLICIES & SECURITY SITE ASSESSMENT OVERVIEW WEBINAR For Viewer Sites Agenda 1 Introduction and EHR Security Policies Background 2 EHR Security Policy Overview 3 EHR Security Policy Assessment

More information

April 25, Dear Secretary Sebelius,

April 25, Dear Secretary Sebelius, April 25, 2014 Department of Health and Human Services Office of the National Coordinator for Health Information Technology Attention: 2015 Edition EHR Standards and Certification Criteria Proposed Rule

More information

CHAPTER 13 ELECTRONIC COMMERCE

CHAPTER 13 ELECTRONIC COMMERCE CHAPTER 13 ELECTRONIC COMMERCE Article 13.1: Definitions For the purposes of this Chapter: computing facilities means computer servers and storage devices for processing or storing information for commercial

More information

North Carolina Health Information Exchange Authority. User Access Policy for NC HealthConnex

North Carolina Health Information Exchange Authority. User Access Policy for NC HealthConnex North Carolina Health Information Exchange Authority User Access Policy for NC HealthConnex North Carolina Health Information Exchange Authority User Access Policy for NC HealthConnex Introduction The

More information

Vocera Secure Texting 2.1 FAQ

Vocera Secure Texting 2.1 FAQ General Description Q. What is Vocera Secure Texting? A. Vocera Secure Texting (VST) combines convenience with privacy by providing a secure, easy to use, HIPAA-compliant alternative to SMS as well as

More information

Statement of HIPAA Readiness February 2003

Statement of HIPAA Readiness February 2003 Statement of HIPAA Readiness February 2003 Copyright 2003 WebMD Envoy Corporation. All Rights Reserved. Rev. 02/03 Table of Contents 1 Meeting the HIPAA Challenge...1 Overview...1 WebMD Envoy HIPAA Readiness...2

More information

Technical Trust Policy

Technical Trust Policy Technical Trust Policy Version 1.2 Last Updated: May 20, 2016 Introduction Carequality creates a community of trusted exchange partners who rely on each organization s adherence to the terms of the Carequality

More information

All Aboard the HIPAA Omnibus An Auditor s Perspective

All Aboard the HIPAA Omnibus An Auditor s Perspective All Aboard the HIPAA Omnibus An Auditor s Perspective Rick Dakin CEO & Chief Security Strategist February 20, 2013 1 Agenda Healthcare Security Regulations A Look Back What is the final Omnibus Rule? Changes

More information

New York Department of Financial Services Cybersecurity Regulation Compliance and Certification Deadlines

New York Department of Financial Services Cybersecurity Regulation Compliance and Certification Deadlines New York Department of Financial Services Cybersecurity Regulation Compliance and Certification Deadlines New York Department of Financial Services ( DFS ) Regulation 23 NYCRR 500 requires that entities

More information

Conference for Food Protection. Standards for Accreditation of Food Protection Manager Certification Programs. Frequently Asked Questions

Conference for Food Protection. Standards for Accreditation of Food Protection Manager Certification Programs. Frequently Asked Questions Conference for Food Protection Standards for Accreditation of Food Protection Manager Certification Programs Frequently Asked Questions Q. What was the primary purpose for the Conference for Food Protection

More information

RELIABILITY COMPLIANCE ENFORCEMENT IN ONTARIO

RELIABILITY COMPLIANCE ENFORCEMENT IN ONTARIO RELIABILITY COMPLIANCE ENFORCEMENT IN ONTARIO June 27, 2016 Training provided for Ontario market participants by the Market Assessment and Compliance Division of the IESO Module 1 A MACD training presentation

More information

EHR & HIPAA Managing Compliance & Progress. Agenda. Federal EHR Imperatives & Achieving Meaningful Use. EHR & HIPAA: Managing Compliance & Progress

EHR & HIPAA Managing Compliance & Progress. Agenda. Federal EHR Imperatives & Achieving Meaningful Use. EHR & HIPAA: Managing Compliance & Progress EHR & HIPAA Managing Compliance & Progress Presented by Rodney Walsh, Senior Managing Consultant May 20, 2010 Agenda Federal EHR imperatives Certification & meaningful use Management of EHR upgrades &

More information

Chapter 4 EDGE Approval Protocol for Auditors Version 3.0 June 2017

Chapter 4 EDGE Approval Protocol for Auditors Version 3.0 June 2017 Chapter 4 EDGE Approval Protocol for Auditors Version 3.0 June 2017 Copyright 2017 International Finance Corporation. All rights reserved. The material in this publication is copyrighted by International

More information

SOC 3 for Security and Availability

SOC 3 for Security and Availability SOC 3 for Security and Availability Independent Practioner s Trust Services Report For the Period October 1, 2015 through September 30, 2016 Independent SOC 3 Report for the Security and Availability Trust

More information

ELECTRONIC RECORDING MEMORANDUM OF UNDERSTANDING

ELECTRONIC RECORDING MEMORANDUM OF UNDERSTANDING ELECTRONIC RECORDING MEMORANDUM OF UNDERSTANDING THIS MEMORANDUM OF UNDERSTANDING, dated, is between the Davie County North Carolina Register of Deeds office ( COUNTY ), and ( COMPANY ) with offices located

More information

DoD/VA Interagency Program Office (IPO) Town Hall Meeting. April 27, 2017

DoD/VA Interagency Program Office (IPO) Town Hall Meeting. April 27, 2017 DoD/VA Interagency Program Office (IPO) Town Hall Meeting April 27, 2017 IPO Town Hall 27 Apr 2017 Distribution C: Distribution authorized to DoD and VA components only; Other requests for this document

More information

RSL NSW SUB-BRANCH STANDARD OPERATING PROCEDURES

RSL NSW SUB-BRANCH STANDARD OPERATING PROCEDURES RSL NSW SUB-BRANCH STANDARD OPERATING PROCEDURES ISSUED DECEMBER 2018 Table Of Contents 1. Model A sub-branches... 2 2. Model B sub-branches... 6 1 SUB-BRANCH STANDARD OPERATING PROCEDURES (SOPs) These

More information

Adopter s Site Support Guide

Adopter s Site Support Guide Adopter s Site Support Guide Provincial Client Registry Services Version: 1.0 Copyright Notice Copyright 2016, ehealth Ontario All rights reserved No part of this document may be reproduced in any form,

More information

HIPAA How to Comply with Limited Time & Resources. Jonathan Pantenburg, MHA, Senior Consultant August 17, 2017

HIPAA How to Comply with Limited Time & Resources. Jonathan Pantenburg, MHA, Senior Consultant August 17, 2017 HIPAA How to Comply with Limited Time & Resources Jonathan Pantenburg, MHA, Senior Consultant JPantenburg@Stroudwater.com August 17, 2017 Stroudwater Associates is a leading national healthcare consulting

More information

Open Source Software Quality Certification

Open Source Software Quality Certification Open Source Software Quality Certification The Emerging ANSI Standard Wes Turner Director, Open Source Operations OSEHRA Mike Henderson Director, Open Source Product Management OSEHRA Wednesday, September

More information

UNCONTROLLED IF PRINTED

UNCONTROLLED IF PRINTED 161Thorn Hill Road Warrendale, PA 15086-7527 1. Scope 2. Definitions PROGRAM DOCUMENT PD 1000 Issue Date: 19-Apr-2015 Revision Date: 26-May-2015 INDUSTRY MANAGED ACCREDITATION PROGRAM DOCUMENT Table of

More information

MNsure Privacy Program Strategic Plan FY

MNsure Privacy Program Strategic Plan FY MNsure Privacy Program Strategic Plan FY 2018-2019 July 2018 Table of Contents Introduction... 3 Privacy Program Mission... 4 Strategic Goals of the Privacy Office... 4 Short-Term Goals... 4 Long-Term

More information

Response to CMS. WEDI Attachment Forum Questions. August 9th Attachment Standard

Response to CMS. WEDI Attachment Forum Questions. August 9th Attachment Standard Response to CMS WEDI Attachment Forum Questions August 9th 2016 Attachment Standard August 25, 2016 Cooperative Exchange National Association of Clearinghouses 28 Clearinghouse member companies Represent

More information

The HIPAA Omnibus Rule

The HIPAA Omnibus Rule The HIPAA Omnibus Rule What You Should Know and Do as Enforcement Begins Rebecca Fayed, Associate General Counsel and Privacy Officer Eric Banks, Information Security Officer 3 Biographies Rebecca C. Fayed

More information

2016 e-mds, Inc.

2016 e-mds, Inc. Capability and Certification Criteria Electronic Prescribing of Medications Certification Criteria: 170.314(a)(1) Computerized provider order entry (CPOE) of Medications Description of capability Electronic

More information

Academic Medical Centers & Vendor Security: Most Comprehensive Study to Date

Academic Medical Centers & Vendor Security: Most Comprehensive Study to Date Academic Medical Centers & Vendor Security: Most Comprehensive Study to Date NCHICA Meeting June 2018 Michelle Allar, Quality and Risk Management Manager Wake Forest Baptist Medical Center MAllar@WakeHealth.edu

More information

Connected Health Principles

Connected Health Principles Version 2.1 Table of Contents 1 INTRODUCTION... 1 2 TERMINOLOGY... 1 3 CONNECTED HEALTH PRINCIPLES... 4 3.1 CONNECTED HEALTH FOUNDATION PRINCIPLES...5 3.2 CONNECTED HEALTH ARCHITECTURAL PRINCIPLES... 6

More information

COMPANY (MU1) FORM FILING - EXTENDED

COMPANY (MU1) FORM FILING - EXTENDED COMPANY (MU1) FORM FILING - EXTENDED Updated: 3/31/2014 Copyright 2008 State Regulatory Registry LLC Table of Contents General Overview 3 How to Submit the Company (MU1) Filing 4 Initial Account Login

More information

OnlineNIC PRIVACY Policy

OnlineNIC PRIVACY Policy OnlineNIC PRIVACY Policy ONLINENIC INC (ONLINENIC) TAKES YOUR PRIVACY SERIOUSLY. Our Privacy Policy is intended to describe to you how and what data we collect, and how and why we use your personal data.

More information

locuz.com SOC Services

locuz.com SOC Services locuz.com SOC Services 1 Locuz IT Security Lifecycle services combine people, processes and technologies to provide secure access to business applications, over any network and from any device. Our security

More information

National Renal Administrator s Association Health Information Exchange. CROWNWeb Data Submission User s Guide

National Renal Administrator s Association Health Information Exchange. CROWNWeb Data Submission User s Guide National Renal Administrator s Association Health Information Exchange CROWNWeb Data Submission User s Guide Table of Contents 1 Overview... 3 1.1 Purpose... 3 1.2 Intended Audience... 3 2 NRAA HIE and

More information

Medical Assistance Provider Incentive Repository. User Guide. For Eligible Professionals

Medical Assistance Provider Incentive Repository. User Guide. For Eligible Professionals Medical Assistance Provider Incentive Repository User Guide For Eligible Professionals February 25, 2013 Table of Contents Introduction...1 Before You Begin...2 Complete your R&A registration.... 2 Identify

More information

CTI BioPharma Privacy Notice

CTI BioPharma Privacy Notice CTI BioPharma Privacy Notice Effective: 29 November 2018 Introduction and Scope CTI BioPharma Corp. ( CTI, our, us ) takes the protection of your personal data very seriously. This Privacy Notice (this

More information

Customer Success Story. ZeOmega. ZeOmega and ClearDATA partner to help a large IDN achieve Meaningful Use

Customer Success Story. ZeOmega. ZeOmega and ClearDATA partner to help a large IDN achieve Meaningful Use Customer Success Story ZeOmega ZeOmega and ClearDATA partner to help a large IDN achieve Meaningful Use Page 2 of 5 ZeOmega and ClearDATA Partner to Help a Large IDN Achieve Meaningful Use Table of Contents

More information

DirectTrust Governmental Trust Anchor Bundle Standard Operating Procedure

DirectTrust Governmental Trust Anchor Bundle Standard Operating Procedure DirectTrust Governmental Trust Anchor Bundle Standard Operating Procedure Change Control Date Version Description of changes 15-December- 2016 1-December- 2016 17-March- 2016 4-February- 2016 3-February-

More information

Checklist for Applying ISO 27000, PCI DSS v2 & NIST to Address HIPAA & HITECH Mandates. Ali Pabrai, MSEE, CISSP (ISSAP, ISSMP)

Checklist for Applying ISO 27000, PCI DSS v2 & NIST to Address HIPAA & HITECH Mandates. Ali Pabrai, MSEE, CISSP (ISSAP, ISSMP) Checklist for Applying ISO 27000, PCI DSS v2 & NIST to Address HIPAA & HITECH Mandates Ali Pabrai, MSEE, CISSP (ISSAP, ISSMP) ecfirst, chief executive Member, InfraGard Compliance Mandates Key Regulations

More information

Setup of Direct Messaging Address and Referring Provider

Setup of Direct Messaging Address and Referring Provider Meaningful Use Related Modified Stage 2 Objective: Health Information Exchange (Summary of Care): The EP who transitions their patient to another setting of care or provider of care or refers their patient

More information

Chapter 35 ehealth Saskatchewan Sharing Patient Data 1.0 MAIN POINTS

Chapter 35 ehealth Saskatchewan Sharing Patient Data 1.0 MAIN POINTS ehealth Saskatchewan Sharing Patient Data 1.0 MAIN POINTS Since 1997, Saskatchewan has been developing a provincial electronic health records system for patients (called the provincial EHR) to allow for

More information

HIPAA Summit Day II Afternoon Plenary Session: HIPAA Security

HIPAA Summit Day II Afternoon Plenary Session: HIPAA Security The HIPAA Summit West IV HIPAA Summit Day II Afternoon Plenary Session: HIPAA Security October 5, 2010 John Parmigiani Summit Co Chair President John C. Parmigiani & Associates, LLC Agenda Important and

More information

Disclaimer This webinar may be recorded. This webinar presents a sampling of best practices and overviews, generalities, and some laws.

Disclaimer This webinar may be recorded. This webinar presents a sampling of best practices and overviews, generalities, and some laws. Disclaimer This webinar may be recorded. This webinar presents a sampling of best practices and overviews, generalities, and some laws. This should not be used as legal advice. Itentive recognizes that

More information

Swedish Scheme Update Dag Ströman, Head of CSEC

Swedish Scheme Update Dag Ströman, Head of CSEC Swedish Scheme Update Dag Ströman, Head of CSEC 1 CSEC - The Legal Base Swedish Parliament approval of the Government bill in May 2002, which stated: The Swedish Defence Materiel Administration, FMV, is

More information

Ensuring Privacy and Security of Health Information Exchange in Pennsylvania

Ensuring Privacy and Security of Health Information Exchange in Pennsylvania Ensuring Privacy and Security of Health Information Exchange in Pennsylvania The Pennsylvania ehealth Initiative in collaboration with the Pennsylvania ehealth Partnership Authority Introduction The Pennsylvania

More information

Chapter 1. Purpose, definitions and application

Chapter 1. Purpose, definitions and application Regulation on toll service provision for tolls and ferry tickets (the Toll service provider Regulation) Legal authority: Laid down by Royal Decree on dd.mm.yyyy pursuant to the Act of 21 June 1963 no.

More information

ANSI-CFP Accredited Food Protection Manager Certification Programs Education Outreach. Benefits of the ANSI-CFP Accredited Certification Programs

ANSI-CFP Accredited Food Protection Manager Certification Programs Education Outreach. Benefits of the ANSI-CFP Accredited Certification Programs ANSI-CFP Accredited Food Protection Manager Certification Programs Education Outreach Benefits of the ANSI-CFP Accredited Certification Programs ANSI-CFP Accredited Food Protection Manager Certification

More information

Trend Micro Professional Services Partner Program

Trend Micro Professional Services Partner Program Trend Micro Professional Services Partner Program PROGRAM OVERVIEW The Trend Micro Partner Program provides professional services companies with the certification, training, technical support and access

More information

Update on Statewide HIE Activities and 2015 HIT/HIE-Related Legislation

Update on Statewide HIE Activities and 2015 HIT/HIE-Related Legislation Update on Statewide HIE Activities and 2015 HIT/HIE-Related Legislation Presentation Summary THSA Background 2015 HIT/HIE-Related Legislation Legislative Interim Activities HIETexas Update Discussion of

More information

Decrypting the Security Risk Assessment (SRA) Requirement for Meaningful Use

Decrypting the Security Risk Assessment (SRA) Requirement for Meaningful Use Click to edit Master title style Decrypting the Security Risk Assessment (SRA) Requirement for Meaningful Use Andy Petrovich, MHSA, MPH M-CEITA / Altarum Institute October 1, 2014 10/1/2014 1 1 Who is

More information

Guidance for Exchange and Medicaid Information Technology (IT) Systems

Guidance for Exchange and Medicaid Information Technology (IT) Systems Department of Health and Human Services Office of Consumer Information and Insurance Oversight Centers for Medicare & Medicaid Services Guidance for Exchange and Medicaid Information Technology (IT) Systems

More information

HCISPP HealthCare Information Security and Privacy Practitioner

HCISPP HealthCare Information Security and Privacy Practitioner HCISPP HealthCare Information Security and Privacy Practitioner William Buddy Gillespie, HCISPP Global Academic Instructor (ISC)² Former Healthcare CIO Chair Advocacy Committee, CPAHIMSS budgill@aol.com

More information

Pennsylvania s HIE Journey

Pennsylvania s HIE Journey Pennsylvania s HIE Journey Alix Goss, Executive Director Pennsylvania ehealth Partnership Authority William Buddy Gillespie Director Healthcare Solutions DSS What is HIE? Health Information Exchange puts

More information

Health Information Exchange Coordinating Committee (HIECC) September 20, 2018

Health Information Exchange Coordinating Committee (HIECC) September 20, 2018 Health Information Exchange Coordinating Committee (HIECC) September 20, 2018 1 Agenda TIME ITEM PRESENTER 10:00-10:10 Welcome - Agency Updates Justin Senior, Chair Roll Call 10:10-10:20 Review & Approve

More information

HIPAA Case Study. Long Term Care (LTC) Industry. October 26, Presented by: James Pfeiffer Brian Zoeller

HIPAA Case Study. Long Term Care (LTC) Industry. October 26, Presented by: James Pfeiffer Brian Zoeller HIPAA Case Study Long Term Care (LTC) Industry October 26, 2001 Presented by: James Pfeiffer Brian Zoeller Overview LTC Industry Characteristics LTC HIPAA Compliance Issues Kindred Healthcare s HIPAA Compliance

More information

The Developers Integration Lab (DIL) Testing Overview for ehealth Exchange Testing Programs. (Participant and Product Testing)

The Developers Integration Lab (DIL) Testing Overview for ehealth Exchange Testing Programs. (Participant and Product Testing) The Developers Integration Lab (DIL) Testing Overview for ehealth Exchange Testing Programs (Participant and Product Testing) 2010 & 2011 Versions February 2015 January 2015 Copyright 2015 Page 1 of 13

More information

Florida Health Information Exchange Subscription Agreement for Event Notification Service

Florida Health Information Exchange Subscription Agreement for Event Notification Service Florida Health Information Exchange Subscription Agreement for Event Notification Service This Subscription Agreement is a multi-party agreement by and between the undersigned vendor, Audacious Inquiry,

More information

NEW YORK CYBERSECURITY REGULATION COMPLIANCE GUIDE

NEW YORK CYBERSECURITY REGULATION COMPLIANCE GUIDE COMPLIANCE ADVISOR NEW YORK CYBERSECURITY REGULATION COMPLIANCE GUIDE A PUBLICATION BY THE EXCESS LINE ASSOCIATION OF NEW YORK One Exchange Plaza 55 Broadway 29th Floor New York, New York 10006-3728 Telephone:

More information

KISH REMARKS APEC CBPR NOV 1 CYBER CONFERENCE KEIO Page 1 of 5 Revised 11/10/2016

KISH REMARKS APEC CBPR NOV 1 CYBER CONFERENCE KEIO Page 1 of 5 Revised 11/10/2016 Page 1 of 5 INTRODUCTION Jim, thank you for the kind introduction. It is an honor to join the panel. Congratulations to Dr. Murai and Dr. Tezuka for the success of the Keio Cybersecurity Center. Congratulations

More information

FOUNDED GOAL of New ORGANIZATION. CLEAR Annual Educational Conference Getting the Most Out of CLEAR. St. Louis October 3-5, 2013

FOUNDED GOAL of New ORGANIZATION. CLEAR Annual Educational Conference Getting the Most Out of CLEAR. St. Louis October 3-5, 2013 Deanna Williams FOUNDED 1980 In 1980, a group of professional and occupational regulators and private sector representatives met in New Orleans to discuss their need to share information. GOAL of New ORGANIZATION

More information

HIEs, CommonWell, Carequality Can Work Together: Here's How

HIEs, CommonWell, Carequality Can Work Together: Here's How HIEs, CommonWell, Carequality Can Work Together: Here's How Session 83, March 6, 2018 John P. Kansky, President & CEO, Indiana Health Information Exchange Keith W. Kelley, Chief Operating Officer, Indiana

More information

SECURETexas Health Information Privacy & Security Certification Program

SECURETexas Health Information Privacy & Security Certification Program Partners in Texas Health Informa3on Protec3on SECURETexas Health Information Privacy & Security Certification Program 2015 HITRUST, Frisco, TX. All Rights Reserved. Outline Introduction Background Benefits

More information

Mutual Recognition Agreement/Arrangement: General Introduction, Framework and Benefits

Mutual Recognition Agreement/Arrangement: General Introduction, Framework and Benefits Conformity and Interoperability Training for SADC Region on Type Approval testing for Mobile Terminals, Homologation Procedures and Market Surveillance Mutual Recognition Agreement/Arrangement: General

More information

CMS and ehealth. Robert Tagalicod Director, Office of ehealth Standards and Services (OESS)

CMS and ehealth. Robert Tagalicod Director, Office of ehealth Standards and Services (OESS) CMS and ehealth Robert Tagalicod Director, Office of ehealth Standards and Services (OESS) Robert Anthony Deputy Director, Health IT Initiatives Group, OESS September 16, 2013 www.cms.gov/ehealth 2 ehealth

More information

Certification for Meaningful Use Experiences and Observations from the Field June 2011

Certification for Meaningful Use Experiences and Observations from the Field June 2011 Certification for Meaningful Use Experiences and Observations from the Field June 2011 Principles for Certification to Support Meaningful Use Certification should promote EHR adoption by giving providers

More information