Department of Veterans Affairs Direct and My HealtheVet Blue Button. Glen Crandall VA Direct Program Manager

Size: px
Start display at page:

Download "Department of Veterans Affairs Direct and My HealtheVet Blue Button. Glen Crandall VA Direct Program Manager"

Transcription

1 Department of Veterans Affairs Direct and My HealtheVet Blue Button Glen Crandall VA Direct Program Manager July 24,

2 What is VLER? On April 9, 2009, President Obama directed the Department of Defense (DoD) and the Department of Veterans Affairs (VA) to create the Virtual Lifetime Electronic Record, which: will ultimately contain administrative and medical information from the day an individual enters military service throughout their military career and after they leave the military. - President Barack Obama 2

3 VLER Health Transport Mechanisms: Exchange vs. Direct ehealth Exchange Trusted network Query and retrieve methodology ( Pull ) Standards-based exchange of relevant clinical information Direct Secure Messaging Trusted network Point-to-Point Push of clinical information using secure Standard or non-structured notes and reports 3

4 Why is Direct Needed? VA was transmitting sensitive data, including PII and internal network routing information, over an unencrypted telecommunications carrier network. Without controls to encrypt the sensitive VA data transmitted, veterans information may be vulnerable to interception and misuse by malicious users as it traverses unencrypted telecommunications carrier networks. OIG Report: Review of Alleged Transmission of Sensitive VA Data Over Internet Connections - March 6,

5

6 What is Direct Secure Messaging? Direct: specifies a simple, secure, scalable, standards-based transportation mechanism that enables participants to send encrypted health information directly to known, trusted recipients over the Internet. Simply put, it is secure . For more detail on Direct from the Office of the National Coordinator (ONC), go to the following links: The Direct Project Overview pdf from Oct The Direct Project Wiki The Direct Project Website 6

7 Direct: Secure Directed Exchange via the Internet The Direct Project specifies a simple, secure, scalable, standards-based transportation mechanism that enables participants to send encrypted health information directly to known, trusted recipients over the Internet. Simple. Connects healthcare stakeholders through universal addressing using simple push of information. Secure. Users can easily verify messages are complete and not tampered with en route. Scalable. Enables Internet scale with no need for central network authority that must provide sophisticated services such as EMPI, distributed query/retrieve, or data storage. Standards-based. Built on well established Internet standards, commonly used for secure communication; i.e.,. SMTP for transport, S/MIME & X.509 certificates for encryption and integrity protection. 7

8 VA Direct Implementation In , VA developed our own Direct software. It did not meet the use cases and development was stopped in October Prior to stopping development, VA was working with partners in many communities to establish pilots. Now partnering with DoD to use its Direct software. The initial installation is scheduled for February Direct software includes: Security/Trust Agent (STA) software responsible for securing, routing, and processing Direct messages Web Portal software to send/receive Direct messages (similar to Gmail) 8

9 VA Direct Use Cases Initial High-Level VA Use Cases: (February 2014) Provider-to-Provider Messaging Referral authorization and results reporting (e.g. mammograms) Secure clinician-to-clinician messaging Patient Mediated Messaging Veteran sending own Continuity of Care Document (CCD) Through My HealtheVet/Blue Button, a Veteran can send personal Continuity of Care (CCD) document to non-va Direct addresses (e.g. non-va providers, PHR, etc.) Future Provider-to-Provider Use Cases: Creating, sending, receiving, and viewing Consolidated CDA (C-CDA) documents Rural health use cases Mental Health information exchange Women s Health Maternity 9

10 VLER Health Support of Certification/Meaningful Use (C/MU) 2014 Certification Requirements Support by VLER Health: Care Coordination Provider to Provider (b)(1) - Transitions of Care - Receive, Display, and Incorporate Transition of Care/Referral Summaries (b)(2) - Transitions of Care - Create and Transmit Transition of Care/Referral Summaries Patient Mediated Blue Button Direct (e)(1) - View, Download, & Transmit Care/Referral Summaries to 3 rd Party The required payload for the content is the Consolidated-CDA Document currently under development (analysis phase). 10

11 How Can Direct Be Accessed? Through a Direct Web Portal Provides basic functionality Requires going to separate application Not part of workflow May require separate login Using Direct as a Service (DaaS) Can be built into any application Part of workflow Uses login from primary application 11

12 DoD/VA Direct Web Portal The Direct software s basic functionality is similar to many webmail portals. 12

13 VA Use of Direct Secure Messaging for Referrals 13

14 DoD/VA Direct as a Service (DaaS) Vision Users DoD Systems Partners Service Members and Beneficiaries AHLTA HAIMS TRICARE Online Secure Messaging Referral Management System DoD VLER Exchange Purchased Care MTF Staff iehr Web Services Platform IPO Direct HISP Public Health Patients VAMC Staff Vista Fee Basis Application VA VLER Exchange Veterans MyHealtheVet VA Systems Secure Messaging Federal Partners 14 14

15

16

17 Direct Implementation Challenges and Opportunities

18 Blue Button Software Initial Direct Software for Patient Mediated Messaging (Blue Button): UI used by Veteran is created by My HealtheVet /Blue Button team the Veteran will not use the portal or have a VA supplied Direct address. The Veteran will only enter Direct address (destination) and approve sending his/her CCD (can preview before sending). No free text will be entered by the Veteran. CCD cannot be modified. No additional attachments can be added. One-way only message will indicate No Reply Once the message is created in Blue Button, it is sent to Direct for transport. Risks for Blue Button Software No Provider Directory Veteran must know Direct address (Directory planned) Few people to send Direct message to until VA increases trusted partners and more people using Direct. 18

19 Security/Certificates Key to Direct establishing trust with non-va partner organizations Once VA exchanges trust certificates with non-va organization, all users from both organizations can exchange Direct messages. Risks/Issues for Security/Certificates Security level for Direct certificates still not established Working with Federal partners on recommendation It will be higher level than what is currently being used (HIEs, states, etc.) Risk: If level is too high (expensive), potential partners may not want to do Direct messaging with Federal partners. Issue: what level of certificate is needed for patient mediated messaging? ONC interprets HIPAA to say that if a patient request data sent, it must be sent and can even be sent unencrypted. VA has higher requirements. Discussion continue within VA to answer this question. 19

20 Privacy For Patient Mediated Messaging (Blue Button): VA Direct system will send on behalf of Veteran same as if Veteran was sending from personal system. No Accounting of Disclosure required. Need to ensure Veteran can preview data being sent and that actual message contains same data as what was previewed. 20

21 Non-VA Partners Policies and Procedures Need to insure partners have proper policies and procedures in place. Partner end users need to be properly authenticated HISP needs to ensure end users will follow privacy/security rules Issue: How do we ensure that non-va partners have needed privacy/security policies in place? ONC says no DURSA-like agreement needed VA (like many others) are looking to put agreements in place 21

22 Non-VA Partners Technical Readiness Many organizations (e.g. HIEs) that are now doing Direct are only sharing within their HISP not across organizations. Exchanging between organizations opens up challenges organizations may not have dealt with including Federal rules for privacy, security, and trust. Testing/Validation between VA and Partners will be necessary. Still working to determine what that will be. Risks for Adding Non-VA Partners: Potential partners may not technically be able to become a trusted Direct partner with VA. Finding partners whose users are ready may be difficult. Many organizations using Direct have low usage it s not part of the end user s workflow yet. Everyone wants to do Direct a few say they are doing it not many are actually using it significantly. 22

23 Questions? Glen Crandall, VA Direct Program Manager - Glen.crandall@va.gov 23

User Manual/Guide for Direct Using encompass 3.0. Prepared By: Arête Healthcare Services, LLC

User Manual/Guide for Direct Using encompass 3.0. Prepared By: Arête Healthcare Services, LLC User Manual/Guide for Direct Using encompass 3.0 Prepared By: Arête Healthcare Services, LLC Document Version: V1.0 10/02/2015 Contents Direct Overview... 3 What is Direct?... 3 Who uses Direct?... 3 Why

More information

CLINICAL DIRECT MESSAGING FREQUENTLY ASKED QUESTIONS

CLINICAL DIRECT MESSAGING FREQUENTLY ASKED QUESTIONS Surescripts has the experience to handle all of your direct messaging needs. Serving the nation with the single most trusted and capable health information network since 2001, we seamlessly connect the

More information

Transport Mechanisms: Making it Possible to Share Your Health Story. Monday, April 4 th 12:00-1:00 pm ET

Transport Mechanisms: Making it Possible to Share Your Health Story. Monday, April 4 th 12:00-1:00 pm ET Transport Mechanisms: Making it Possible to Share Your Health Story Monday, April 4 th 12:00-1:00 pm ET Moderator Nick Mahurin CEO, InfraWare Co-chair, Health Story Project Transport 101 Why this Topic?

More information

(60 min) California State Updates

(60 min) California State Updates (60 min) California State Updates Presenters: 30 min Speranza Avram, CEO, CalHIPSO: EHR status & uptake in CA 20 min David A. Minch, President & COO, HealthShare Bay Area: HIE status 10 min Questions 1

More information

Date. Harris CareTracker Direct Messaging Overview

Date. Harris CareTracker Direct Messaging Overview Date Harris CareTracker Direct Messaging Overview Direct Messaging What it Is? Title Direct Mail is a secure health messaging solution that allows Providers or Patients to safely communicate and transmit

More information

DoD/VA Interagency Program Office (IPO) Town Hall Meeting. April 27, 2017

DoD/VA Interagency Program Office (IPO) Town Hall Meeting. April 27, 2017 DoD/VA Interagency Program Office (IPO) Town Hall Meeting April 27, 2017 IPO Town Hall 27 Apr 2017 Distribution C: Distribution authorized to DoD and VA components only; Other requests for this document

More information

Direct, DirectTrust, and FHIR: A Value Proposition

Direct, DirectTrust, and FHIR: A Value Proposition Direct, DirectTrust, and FHIR: A Value Proposition August 10, 2017 Authors: Grahame Grieve, HL7 Product Director for FHIR; David Kibbe, Luis Maas, Greg Meyer, and Bruce Schreiber, members of the DirectTrust

More information

MHC CAR USER GUIDE

MHC CAR USER GUIDE One Connection for a Healthier Missouri MHC CAREMAIL USER GUIDE Email address: helpdesk@missourihealthconnection.org Phone: 1-866-350-4778 www.missourihealthconnection.org 1 P a g e Contents About Direct

More information

Vocera Secure Texting 2.1 FAQ

Vocera Secure Texting 2.1 FAQ General Description Q. What is Vocera Secure Texting? A. Vocera Secure Texting (VST) combines convenience with privacy by providing a secure, easy to use, HIPAA-compliant alternative to SMS as well as

More information

California State Updates. Presenter: David A. Minch, President & COO, HealthShare Bay Area

California State Updates. Presenter: David A. Minch, President & COO, HealthShare Bay Area California State Updates Presenter: David A. Minch, President & COO, HealthShare Bay Area 1 Trust is the Foundation for Health Data Exchange Patients must trust the Providers to hold their data securely,

More information

Sevocity v.12 Provider-Patient Data Exchange (PPDX) User Reference Guide

Sevocity v.12 Provider-Patient Data Exchange (PPDX) User Reference Guide Sevocity v.12 User Reference Guide 1 877 877-2298 support@sevocity.com Table of Contents Product Support Services...2 About Sevocity v.12...2 Terms and Definitions...3 Icons Used in this Guide...3 What

More information

DRAFT FOR DISCUSSION ONLY REVISED OPTION FOR DRAFT PRELIMINARY RECOMMENDATION 1

DRAFT FOR DISCUSSION ONLY REVISED OPTION FOR DRAFT PRELIMINARY RECOMMENDATION 1 HIE Task Force REVISED OPTION FOR DRAFT PRELIMINARY RECOMMENDATION 1 Please note: This document reflects the research and activities completed as follow-up to questions and discussion draft preliminary

More information

ICD-10 Customer Testing Guidelines and Scenarios

ICD-10 Customer Testing Guidelines and Scenarios ICD-10 Customer Testing Guidelines and Scenarios Revision 2.0 Updated July 21, 2015 This document includes pre-release information and user interface designs that are in development for upcoming enhancements

More information

Use Cases for Argonaut Project -- DRAFT Page

Use Cases for Argonaut Project -- DRAFT Page Use Cases for Argonaut Project -- DRAFT Page 1 Use Cases for Argonaut Project DRAFT V0.3 March 03, 2015 Use Cases for Argonaut Project -- DRAFT Page 2 Introduction The Argonaut Project seeks to rapidly

More information

Testing for Reliable and Dependable Health Information Exchange

Testing for Reliable and Dependable Health Information Exchange Testing for Reliable and Dependable Health Information Exchange Presented by Didi Davis, Testing Programs Director 1 Copyright 2016 The Sequoia Project. All rights reserved. Discussion Topics 1. ehealth

More information

A Pilot Implementation of DIRECT Messaging and Provider Directory Services in the Palomar Health District

A Pilot Implementation of DIRECT Messaging and Provider Directory Services in the Palomar Health District A Pilot Implementation of DIRECT Messaging and Provider Directory Services in the Palomar Health District Project Overview and Plan Sujansky & Associates, LLC 1. Project Objectives Figure 1. High-level

More information

An Introduction to DirectTrust

An Introduction to DirectTrust An Introduction to DirectTrust David C. Kibbe, MD MBA President and CEO, DirectTrust Senior Advisor, American Academy of Family Physicians Prepared HIMSS October 16, 2013 Goals for this brief presentation

More information

Connecting Small Provider Organizations to the Massachusetts State HIE

Connecting Small Provider Organizations to the Massachusetts State HIE Connecting Small Provider Organizations to the Massachusetts State HIE MHDC CIO Forum - March 29 th, 2012 Larry Garber, MD Medical Director for Informatics Reliant Medical Group (AKA Fallon Clinic) 0 Overview

More information

Send and Receive Exchange Use Case Test Methods

Send and Receive Exchange Use Case Test Methods Send and Receive Exchange Use Case Test Methods Release 1 Version 1.0 October 1, 2017 Send and Receive Exchange Test Methods Release 1 Version 1.0 Technology Sponsor [Name] [Email] [Telephone] Signature

More information

Data Use and Reciprocal Support Agreement (DURSA) Overview

Data Use and Reciprocal Support Agreement (DURSA) Overview Data Use and Reciprocal Support Agreement (DURSA) Overview 1 Steve Gravely, Troutman Sanders LLP Jennifer Rosas, ehealth Exchange Director January 12, 2017 Introduction Steve Gravely Partner and Healthcare

More information

Federal-State Connections: Opportunities for Coordination and Collaboration

Federal-State Connections: Opportunities for Coordination and Collaboration Federal-State Connections: Opportunities for Coordination and Collaboration State Health Information Exchange Program October 23, 2012 Chris Muir Program Manager 1 ONC Overview Vision A health system that

More information

Presentation to HL7 S&I Framework Data Segmentation for Privacy Initiative 9/25/2013

Presentation to HL7 S&I Framework Data Segmentation for Privacy Initiative 9/25/2013 Presentation to HL7 S&I Framework Data Segmentation for Privacy Initiative 9/25/2013 Johnathan Coleman, CISSP Initiative Coordinator, Data Segmentation for Privacy OCPO/ONC/HHS / (CTR) Tel: (843) 647-1556

More information

Advancing Care With the NHIN and CONNECT

Advancing Care With the NHIN and CONNECT Advancing Care With the NHIN and CONNECT Presentation to Internet2 Health Network Initiative Workshop San Antonio, TX October 8, 2009 Craig Miller CONNECT Chief Architect Federal Health Architecture Overview

More information

Discuss and finalize recommendations on Entity-Level Provider Directories (ELPDs):

Discuss and finalize recommendations on Entity-Level Provider Directories (ELPDs): Agenda Discuss and finalize recommendations on Entity-Level Provider Directories (ELPDs): Users Uses/Functionality Directory Content Operating Requirements/Business Models Terminology Two TF calls to complete

More information

ehealth Exchange Onboarding Overview

ehealth Exchange Onboarding Overview ehealth Exchange Onboarding Overview Jennifer Rosas, ehealth Exchange Director Kati Odom, ehealth Exchange Implementation Manager ehealth Exchange Core Values Lead in national-level exchange of health

More information

Medical Device Vulnerability Management

Medical Device Vulnerability Management Medical Device Vulnerability Management MDISS / NH-ISAC Process Draft Dale Nordenberg, MD June 2015 Market-based public health: collaborative acceleration Objectives Define a trusted and repeatable process

More information

ecw and Direct - Achieving MU for Transitions of Care (TOC)

ecw and Direct - Achieving MU for Transitions of Care (TOC) TIP SHEET Read this tip sheet if you are an ecw user and want to learn how to set up your EHR for using P2P and HISP Direct exchange; how to obtain your Direct address; and how to achieve the TOC measures

More information

Efficiently Sharing All of a Patient s Data With All their Providers Completing the Model

Efficiently Sharing All of a Patient s Data With All their Providers Completing the Model www.gdhealth.com Efficiently Sharing All of a Patient s Data With All their Providers Completing the Model Multi-Source Longitudinal Medical Record (MLMR) Thomas Pole and Robert Guajardo 6.13.2017 Our

More information

Disclaimer This webinar may be recorded. This webinar presents a sampling of best practices and overviews, generalities, and some laws.

Disclaimer This webinar may be recorded. This webinar presents a sampling of best practices and overviews, generalities, and some laws. Disclaimer This webinar may be recorded. This webinar presents a sampling of best practices and overviews, generalities, and some laws. This should not be used as legal advice. Itentive recognizes that

More information

RPMS Direct Messaging (Secure Messaging) Presented by Marilyn Freeman California Area HIM Consultant DRAFT

RPMS Direct Messaging (Secure Messaging) Presented by Marilyn Freeman California Area HIM Consultant DRAFT RPMS Direct Messaging (Secure Messaging) Presented by Marilyn Freeman California Area HIM Consultant 1 RPMS Direct Messaging Team Glenn Janzen, Chief Enterprise Architect - IHS Chris Lamer, Clinical Informatics

More information

Request for Information Technical Response White Paper for Joint Operational Medicine Information Systems (JOMIS)

Request for Information Technical Response White Paper for Joint Operational Medicine Information Systems (JOMIS) Request for Information Technical Response White Paper for Joint Operational Medicine Information Systems (JOMIS) Ensuring Continuity of Data 5 May 2017 Prepared by: Northrop Grumman Systems Corporation

More information

ICD-10 Testing: Testing Your EHR, Practice Management System and Internal Processes for ICD-10 Readiness

ICD-10 Testing: Testing Your EHR, Practice Management System and Internal Processes for ICD-10 Readiness : Testing Your EHR, Practice Management System and Internal Processes for ICD-10 Readiness Learning Objectives: Understand testing variables and procedures for addressing applications that store and use

More information

Meaningful Use Webcast

Meaningful Use Webcast MU Security Objectives Direct Messaging Questions MU Security Objective Security s Importance to Meaningful Use The Security Objective Satisfying the Objective Security Mechanisms in the EHR Software MU

More information

Direct Project Update. May 31, 2011

Direct Project Update. May 31, 2011 Direct Project Update May 31, 2011 Why Direct? When current methods of health informa2on exchange are inadequate: Communication of health information among providers and patients still mainly relies on

More information

The Potential for Blockchain to Transform Electronic Health Records ARTICLE TECHNOLOGY. by John D. Halamka, MD, Andrew Lippman and Ariel Ekblaw

The Potential for Blockchain to Transform Electronic Health Records ARTICLE TECHNOLOGY. by John D. Halamka, MD, Andrew Lippman and Ariel Ekblaw REPRINT H03I15 PUBLISHED ON HBR.ORG MARCH 03, 2017 ARTICLE TECHNOLOGY The Potential for Blockchain to Transform Electronic Health Records by John D. Halamka, MD, Andrew Lippman and Ariel Ekblaw This article

More information

Telehealth Workforce Offers Unique Competencies & Opportunities #245, February 23, 2017 Jay Weems, Vice-President, Operations, Avera ecare

Telehealth Workforce Offers Unique Competencies & Opportunities #245, February 23, 2017 Jay Weems, Vice-President, Operations, Avera ecare Telehealth Workforce Offers Unique Competencies & Opportunities #245, February 23, 2017 Jay Weems, Vice-President, Operations, Avera ecare 1 Speaker Introduction Jay Weems Vice-President, Operations Avera

More information

CNATRAINST A N6 3 Mar 16. Subj: CNATRA ELECTRONIC MAIL DIGITAL SIGNATURE AND ENCRYPTION POLICY

CNATRAINST A N6 3 Mar 16. Subj: CNATRA ELECTRONIC MAIL DIGITAL SIGNATURE AND ENCRYPTION POLICY DEPARTMENT OF THE NAVY CHIEF OF NAVAL AIR TRAINING 250 LEXINGTON BLVD SUITE 102 CORPUS CHRISTI TX 78419-5041 CNATRAINST 5230.7A N6 CNATRA INSTRUCTION 5230.7A Subj: CNATRA ELECTRONIC MAIL DIGITAL SIGNATURE

More information

a publication of the health care compliance association MARCH 2018

a publication of the health care compliance association MARCH 2018 hcca-info.org Compliance TODAY a publication of the health care compliance association MARCH 2018 On improv and improving communication an interview with Alan Alda This article, published in Compliance

More information

Response to CMS. WEDI Attachment Forum Questions. August 9th Attachment Standard

Response to CMS. WEDI Attachment Forum Questions. August 9th Attachment Standard Response to CMS WEDI Attachment Forum Questions August 9th 2016 Attachment Standard August 25, 2016 Cooperative Exchange National Association of Clearinghouses 28 Clearinghouse member companies Represent

More information

PATIENT ACCESS REQUEST FOR MEDICAL RECORDS

PATIENT ACCESS REQUEST FOR MEDICAL RECORDS PATIENT ACCESS REQUEST FOR MEDICAL RECORDS Patient s Legal Name: Telephone: ( ) Address: Date of Birth: As provided by the Health Insurance Portability and Accountability Act ( HIPAA ), I am requesting

More information

The HITECH Act. 5 things you can do Right Now to pave the road to compliance. 1. Secure PHI in motion.

The HITECH Act. 5 things you can do Right Now to pave the road to compliance. 1. Secure PHI in motion. The HITECH Act 5 things you can do Right Now to pave the road to compliance Beginning in 2011, HITECH Act financial incentives will create a $5,800,000 opportunity over four years for mid-size hospital

More information

Case Study. Medical Information Records, LLC. Medical Software Company Relies on Azure to Improve Scalability, Cut Costs & Ensure Compliance

Case Study. Medical Information Records, LLC. Medical Software Company Relies on Azure to Improve Scalability, Cut Costs & Ensure Compliance Case Study Medical Information Records, LLC Medical Information Records, LLC Medical Software Company Relies on Azure to Improve Scalability, Cut Costs & Ensure Compliance Overview Industry: Healthcare

More information

Health Information Exchange - A Critical Assessment: How Does it Work in the US and What Has Been Achieved?

Health Information Exchange - A Critical Assessment: How Does it Work in the US and What Has Been Achieved? Health Information Exchange - A Critical Assessment: How Does it Work in the US and What Has Been Achieved? Use cases, best practice and examples for successful implementations 1 Agenda Overview of The

More information

RESTful Health Exchange (RHEx)

RESTful Health Exchange (RHEx) RESTful Health Exchange (RHEx) TAT R C, M I T R E 6 September 2013 For internal MITRE use 2013 The MITRE Corporation. All rights reserved. Disclaimer 2 This project is being conducted by MITRE and TATRC

More information

Guide to Meaningful Use Stage 2

Guide to Meaningful Use Stage 2 February, 2014 Introduction This document describes the following Core Measure requirements that are needed to comply with Meaningful Use Stage 2. Meaningful Use Clinical Quality Measures for 2014 and

More information

DOD Medical Device Cybersecurity Considerations

DOD Medical Device Cybersecurity Considerations Enedina Guerrero, Acting Chief, Incident Mgmt. Section, Cyber Security Ops Branch 2015 Defense Health Information Technology Symposium DOD Medical Device Cybersecurity Considerations 1 DHA Vision A joint,

More information

CERT Symposium: Cyber Security Incident Management for Health Information Exchanges

CERT Symposium: Cyber Security Incident Management for Health Information Exchanges Pennsylvania ehealth Partnership Authority Pennsylvania s Journey for Health Information Exchange CERT Symposium: Cyber Security Incident Management for Health Information Exchanges June 26, 2013 Pittsburgh,

More information

Connected Health Principles

Connected Health Principles Version 2.1 Table of Contents 1 INTRODUCTION... 1 2 TERMINOLOGY... 1 3 CONNECTED HEALTH PRINCIPLES... 4 3.1 CONNECTED HEALTH FOUNDATION PRINCIPLES...5 3.2 CONNECTED HEALTH ARCHITECTURAL PRINCIPLES... 6

More information

Terms used, but not otherwise defined, in this Agreement shall have the same meaning as those terms in the HIPAA Privacy Rule.

Terms used, but not otherwise defined, in this Agreement shall have the same meaning as those terms in the HIPAA Privacy Rule. Medical Privacy Version 2018.03.26 Business Associate Agreement This Business Associate Agreement (the Agreement ) shall apply to the extent that the Lux Scientiae HIPAA Customer signee is a Covered Entity

More information

Onboarding Overview. December 3, 2013

Onboarding Overview. December 3, 2013 Onboarding Overview December 3, 2013 1 2 Overview ehealth Exchange Overview Onboarding and Testing Process Resources and Tools ehealth Exchange Health Bank or PHR Support Organization State and Local Gov

More information

ConCert FAQ s Last revised December 2017

ConCert FAQ s Last revised December 2017 ConCert FAQ s Last revised December 2017 What is ConCert by HIMSS? ConCert by HIMSS is a comprehensive interoperability testing and certification program governed by HIMSS and built on the work of the

More information

Technologies for Securing the Networked Supply Chain. Alex Deacon Advanced Products and Research Group VeriSign, Inc.

Technologies for Securing the Networked Supply Chain. Alex Deacon Advanced Products and Research Group VeriSign, Inc. Technologies for Securing the Networked Supply Chain Alex Deacon Advanced Products and Research Group VeriSign, Inc. Agenda Introduction Security challenges Security technologies in use today Applying

More information

HIPAA by the Numbers. Presented by: Mark L. Schuweiler Director of Global Information Assurance Services EDS Corporation

HIPAA by the Numbers. Presented by: Mark L. Schuweiler Director of Global Information Assurance Services EDS Corporation HIPAA by the Numbers Presented by: Mark L. Schuweiler Director of Global Information Assurance Services EDS Corporation Security vs Privacy Privacy right of a individual to control his/her personal information

More information

PROService REMOTE SERVICE APPLICATION. Frequently asked questions

PROService REMOTE SERVICE APPLICATION. Frequently asked questions PROService REMOTE SERVICE APPLICATION Frequently asked questions MORE WAYS TO INCREASE UPTIME AND IMPROVE PRODUCTIVITY GENERAL INFORMATION Q: What is PROService? A: PROService is Beckman Coulter s remote

More information

PORTAL USER. Jayme Pina Version GUIDE

PORTAL USER. Jayme Pina Version GUIDE PORTAL USER Jayme Pina Version 2.6.2018 GUIDE Contents User Access Roles... 3 How to Log-in... 3 Patient Look Up... 5 My Patients... 5 All Patients... 6 Patient Notification... 8 Opt-out / Opt-Back-In...

More information

Meaningful Use Webcast. Direct Messaging. Questions. November 7,2013

Meaningful Use Webcast. Direct Messaging. Questions. November 7,2013 November 7,2013 Meaningful Use Webcast Direct Messaging Questions Integration of Direct Messaging Review of Direct Messaging Review of CPSI Process Review of On-boarding Process for Direct Messaging Review

More information

Clinical Information Security Pre-Purchase Security Assessment Vendor Packet Instructions

Clinical Information Security Pre-Purchase Security Assessment Vendor Packet Instructions Clinical Information Security Pre-Purchase Security Assessment Vendor Packet Instructions Executive Summary Mayo Clinic s primary value is The needs of the patient come first. It is built into our daily

More information

NextGen Share Direct Messaging. End User Guide

NextGen Share Direct Messaging. End User Guide NextGen Share Direct Messaging End User Guide 1 Introduction This guide provides step-by-step instructions on how to send and receive referrals and summary of care records through NextGen Share. Structured

More information

WASHINGTON UNIVERSITY HIPAA Privacy Policy # 7. Appropriate Methods of Communicating Protected Health Information

WASHINGTON UNIVERSITY HIPAA Privacy Policy # 7. Appropriate Methods of Communicating Protected Health Information WASHINGTON UNIVERSITY HIPAA Privacy Policy # 7 Appropriate Methods of Communicating Protected Health Information Statement of Policy Washington University and its member organizations (collectively, Washington

More information

Outcomes and Lessons Learned From 5010 Testing Project Collaboration

Outcomes and Lessons Learned From 5010 Testing Project Collaboration Outcomes and Lessons Learned From 5010 Testing Project Collaboration Elliot Sloane, PhD, CCE Villanova University Co-Chair, IHE International Bob Bowman CORE Manager CAQH Paul Decrosta Manager, IPP Regulatory

More information

Auditing and Monitoring for HIPAA Compliance. HCCA COMPLIANCE INSTITUTE 2003 April, Presented by: Suzie Draper Sheryl Vacca, CHC

Auditing and Monitoring for HIPAA Compliance. HCCA COMPLIANCE INSTITUTE 2003 April, Presented by: Suzie Draper Sheryl Vacca, CHC Auditing and Monitoring for HIPAA Compliance HCCA COMPLIANCE INSTITUTE 2003 April, 2003 Presented by: Suzie Draper Sheryl Vacca, CHC 1 The Elements of Corporate Compliance Program There are seven key elements

More information

Is your privacy secure? HIPAA Compliance Workshop September Presented by: Andrés Castañeda, Senior Manager Steve Nouss, Partner

Is your privacy secure? HIPAA Compliance Workshop September Presented by: Andrés Castañeda, Senior Manager Steve Nouss, Partner Is your privacy secure? HIPAA Compliance Workshop September 2008 Presented by: Andrés Castañeda, Senior Manager Steve Nouss, Partner Agenda Have you secured your key operational, competitive and financial

More information

MyHealthRecord. Patient User Guide. Top of Page Table of Contents

MyHealthRecord. Patient User Guide. Top of Page Table of Contents MyHealthRecord Patient User Guide 1 P a g e Information Technology Department MyHealthRecord Patient User Guide Copyright 2014 Family Health Centers of San Diego, Inc. 823 Gateway Center Way San Diego,

More information

ehealth NSW Dr John F. Lambert Chief Clinical Information

ehealth NSW Dr John F. Lambert Chief Clinical Information ehealth NSW Dr John F. Lambert Chief Clinical Information Officer @DrJaffleOz Introduction Site Experience Why are we here? Lessons Learnt Rural ehealth Questions @DrJaffleOz Patient centred systems Building

More information

Data Backup and Contingency Planning Procedure

Data Backup and Contingency Planning Procedure HIPAA Security Procedure HIPAA made Easy Data Backup and Contingency Planning Procedure Please fill in date implemented and updates for your facility: Goal: This document will serve as our back-up storage

More information

Open Source EHR Agent:

Open Source EHR Agent: Open Source EHR Agent: An Engine of Rapid Innovation Looking at the Future Seong K. Mun, Ph.D. President and CEO OSEHRA Arlington, Virginia munsk@osehra.org 202-320-4613 1 Custodial Agent Facilitate rapid

More information

Prior Authorization and Clinician Burden: Updates from ONC

Prior Authorization and Clinician Burden: Updates from ONC Prior Authorization and Clinician Burden: Updates from ONC Thomas A. Mason, MD, FACP Chief Medical Officer Office of the National Coordinator for Health Information Technology (ONC) U.S. Department of

More information

Cloud Communications for Healthcare

Cloud Communications for Healthcare Cloud Communications for Healthcare Today, many powerful business communication challenges face everyone in the healthcare chain including clinics, hospitals, insurance providers and any other organization

More information

Existing Healthcare Standards

Existing Healthcare Standards Existing Healthcare Standards Category Context (Information Model) Information Interchange Standard & Specific Elements ASN.1 Abstract Syntax Notation.1 ASTM E2369-05 Standard Specification for Continuity

More information

Health Information Exchange: Can There Be ONE National Model?

Health Information Exchange: Can There Be ONE National Model? Health Information Exchange: Can There Be ONE National Model? Session 56, February 20, 2017 John P. Kansky, President & CEO, Indiana Health Information Exchange Keith W. Kelley, Vice President of Solution

More information

Frequently Asked Questions. My life. My healthcare. MyChart.

Frequently Asked Questions. My life. My healthcare. MyChart. Frequently Asked Questions My life. My healthcare. MyChart. My life. My healthcare. MyChart. What is MyChart? MyChart offers patients personalized and secure online access to portions of their medical

More information

OncoEMR Certified Workflows Meaningful Use Core Measure 15: Summary of Care

OncoEMR Certified Workflows Meaningful Use Core Measure 15: Summary of Care In an effort to support oncology practices striving to achieve CMS s Meaningful Use Stage 2, Altos would like to share the following support information with you. The CMS website is the ultimate source

More information

Security and Privacy Breach Notification

Security and Privacy Breach Notification Security and Privacy Breach Notification Version Approval Date Owner 1.1 May 17, 2017 Privacy Officer 1. Purpose To ensure that the HealthShare Exchange of Southeastern Pennsylvania, Inc. (HSX) maintains

More information

Monarch General Capabilities Overview EMPOWERING ENABLING CONNECTING

Monarch General Capabilities Overview EMPOWERING ENABLING CONNECTING Monarch General Capabilities Overview EMPOWERING ENABLING CONNECTING Executive Summary Monarch is a data translation, interface engine and routing solution for enterprise and system owners. Whether your

More information

Bluestone Bridge Family User Guide Desktop-Version 2.0

Bluestone Bridge Family User Guide Desktop-Version 2.0 The Bluestone Bridge is a secure online communication tool that allows members of a patient s care team (family, nursing staff, provider team, home health or hospice agency, etc.) to exchange medically

More information

MEDICITY NETWORK ONC CERTIFICATION COST AND LIMITATIONS

MEDICITY NETWORK ONC CERTIFICATION COST AND LIMITATIONS MEDICITY NETWORK ONC CERTIFICATION COST AND LIMITATIONS Medicity is proud to offer health IT solutions that are certified under the Office of the National Coordinator for Health Information Technology.

More information

IT Security in a Meaningful Use Era C&SO HIMSS Meeting

IT Security in a Meaningful Use Era C&SO HIMSS Meeting CSOHIMSS 2011 Slide 1 October 21, 2011 October 21, 2011 IT Security in a Meaningful Use Era C&SO HIMSS Meeting Presented by: Mac McMillan CEO CynergisTek, Inc. Chair, HIMSS Privacy & Security Task Force

More information

HIPAA Compliance. with O365 Manager Plus.

HIPAA Compliance. with O365 Manager Plus. HIPAA Compliance with O365 Manager Plus www.o365managerplus.com About HIPAA HIPAA, the Health Insurance Portability and Accountability Act, sets the standard for protecting sensitive patient data. Any

More information

Clinician Administrator RAAPS 2.1 P4Clogin.com

Clinician Administrator RAAPS 2.1 P4Clogin.com RAAPS 2.1 P4Clogin.com Password Reset Access the system by going to www.p4clogin.org Accessing the System A P4C team member or your administrator will set up an account for you with an assigned user name

More information

Quick Start User Guide. Version 3.0

Quick Start User Guide. Version 3.0 Quick Start User Guide Version 3.0 1 Contents 1. Introduction: RSNA Image Share Network 2. The Edge Server Web UI 2.1 Normal Use 3. Retrieve Content and Research Sending Applications 3.1 Using the CTP

More information

Inside the OCR Investigation/Audit Process 2018 PBI HEALTH LAW INSTITUTE TUESDAY, MARCH 13, 2017 GREGORY M. FLISZAR, J.D., PH.D.

Inside the OCR Investigation/Audit Process 2018 PBI HEALTH LAW INSTITUTE TUESDAY, MARCH 13, 2017 GREGORY M. FLISZAR, J.D., PH.D. Inside the OCR Investigation/Audit Process 2018 PBI HEALTH LAW INSTITUTE TUESDAY, MARCH 13, 2017 GREGORY M. FLISZAR, J.D., PH.D. HIPAA GENERAL RULE PHI may not be disclosed without patient authorization

More information

Health Information Exchange (Summary of Care) Meaningful Use 2016 Job Aid

Health Information Exchange (Summary of Care) Meaningful Use 2016 Job Aid Health Information Exchange (Summary of Care) Meaningful Use 2016 Job Aid Health Information Exchange (Summary of Care/Transition of Care) This document outlines the workflow for meeting this measure in

More information

Data Compromise Notice Procedure Summary and Guide

Data Compromise Notice Procedure Summary and Guide Data Compromise Notice Procedure Summary and Guide Various federal and state laws require notification of the breach of security or compromise of personally identifiable data. No single federal law or

More information

EXAMPLE 2-JOINT PRIVACY AND SECURITY CHECKLIST

EXAMPLE 2-JOINT PRIVACY AND SECURITY CHECKLIST Purpose: The purpose of this Checklist is to evaluate your proposal to use or disclose Protected Health Information ( PHI ) for the purpose indicated below and allow the University Privacy Office and Office

More information

Setup of Direct Messaging Address and Referring Provider

Setup of Direct Messaging Address and Referring Provider Meaningful Use Related Modified Stage 2 Objective: Health Information Exchange (Summary of Care): The EP who transitions their patient to another setting of care or provider of care or refers their patient

More information

Jan 30,2018. PULSE: HIE Connectivity for Disaster Response Patient Unified Lookup System for Emergencies

Jan 30,2018. PULSE: HIE Connectivity for Disaster Response Patient Unified Lookup System for Emergencies Jan 30,2018 PULSE: HIE Connectivity for Disaster Response Patient Unified Lookup System for Emergencies PULSE Background History 2013: California Emergency Medical Services Authority (EMSA) holds its first

More information

HIPAA Federal Security Rule H I P A A

HIPAA Federal Security Rule H I P A A H I P A A HIPAA Federal Security Rule nsurance ortability ccountability ct of 1996 HIPAA Introduction - What is HIPAA? HIPAA = The Health Insurance Portability and Accountability Act A Federal Law Created

More information

Health Data & Blockchain: The New Sharing Frontier. Michael Dillhyon, CCO, Graftworx

Health Data & Blockchain: The New Sharing Frontier. Michael Dillhyon, CCO, Graftworx Health Data & Blockchain: The New Sharing Frontier Michael Dillhyon, CCO, Graftworx Twitter: @SwissGator Overview Who? Background Why? Enterprise & Consumer Benefit What? (Blockchain of course) Value Prop

More information

Disruptive Innovation for Pragmatic Interoperability March 1, 2016

Disruptive Innovation for Pragmatic Interoperability March 1, 2016 Disruptive Innovation for Pragmatic Interoperability March 1, 2016 David Waltman Chief Information Strategy Officer, VHA Conflict of Interest David Waltman Has no real or apparent conflicts of interest

More information

Redwood MedNet Established 2005

Redwood MedNet Established 2005 Redwood MedNet Established 2005 Health information exchange (HIE) services for healthcare facilities in Northern California 40 Outpatient Practices 5 Hospitals 1 Outpatient Surgery Center 5 Independent

More information

Health Information Technology - Supporting Joint Readiness

Health Information Technology - Supporting Joint Readiness Health Information Technology - Supporting Joint Readiness Session # 104, March 7, 2018 Mr. T. Pat Flanders, DADIO/J-6, CIO Kevin P. Seeley, Deputy CIO, Colonel, USAF, MSC 1 Speaker Introduction Pat Flanders

More information

Certificate Enrollment for the Atlas Platform

Certificate Enrollment for the Atlas Platform Certificate Enrollment for the Atlas Platform Certificate Distribution Challenges Digital certificates can provide a secure second factor for authenticating connections from MAP-wrapped enterprise apps

More information

Site Administrator ACT - SH 2.1 P4Clogin.com

Site Administrator ACT - SH 2.1 P4Clogin.com Site Administrator ACT - SH 2.1 P4Clogin.com Password Reset Access the system by going to www.p4clogin.org Accessing the System A P4C team member or your administrator will set up an account for you with

More information

ITaaS Portal vchs SaaS Private Public Hybrid

ITaaS Portal vchs SaaS Private Public Hybrid Your Cloud Be the broker of IT (cloud) services Own your cloud ITaaS Portal Messaging Application Development Mail Server Web Server DB Server File Server Cloud Server Web Server DB Server vchs Private

More information

Consolidated Health Informatics CHI. HIPAA Summit March 9, 2004

Consolidated Health Informatics CHI. HIPAA Summit March 9, 2004 Consolidated Health Informatics CHI HIPAA Summit March 9, 2004 1 Topics to discuss today Overview of Consolidated Health Informatics CHI history and strategy CHI in the Electronic Health Care Data Environment

More information

Veterans Affairs MOU Proxy User Guide

Veterans Affairs MOU Proxy User Guide 1 VETERANS AFFAIRS MOU FORM SUBMISSION PROCESS 1. The VA MOU application will send you an email notification confirming that task(s) are pending in your MOU work queue. 2. If you are outside of the Emory

More information

HIPAA/HITECH Act Update HCCA South Central Regional Annual Conference December 2, Looking Back at 2011

HIPAA/HITECH Act Update HCCA South Central Regional Annual Conference December 2, Looking Back at 2011 HIPAA/HITECH Act Update HCCA South Central Regional Annual Conference December 2, 2012 Phyllis F. Granade The Granade Law Firm Atlanta, GA (678) 705 2507 pgranade@granadelaw.com www.granadelaw.com Looking

More information

WEB-202: Building End-to-end Security for XML Web Services Applied Techniques, Patterns and Best Practices

WEB-202: Building End-to-end Security for XML Web Services Applied Techniques, Patterns and Best Practices WEB-202: Building End-to-end Security for XML Web Services Applied Techniques, Patterns and Best Practices Chris Steel, Ramesh Nagappan, Ray Lai www.coresecuritypatterns.com February 16, 2005 15:25 16:35

More information

The New England Approach to HIPAA. John D. Halamka MD Chairman, New England Health EDI Network CIO, CareGroup Healthcare System

The New England Approach to HIPAA. John D. Halamka MD Chairman, New England Health EDI Network CIO, CareGroup Healthcare System The New England Approach to HIPAA John D. Halamka MD Chairman, New England Health EDI Network CIO, CareGroup Healthcare System Three part approach Administrative Simplification Security/Confidentiality

More information

Veterans Affairs MOU Faculty User Guide

Veterans Affairs MOU Faculty User Guide 1 VETERANS AFFAIRS MOU FORM SUBMISSION PROCESS 1. You can start the MOU submission process by clicking on the following link: (https://bpm.emory.edu/processportal/login.jsp). If you are outside of the

More information