SlideShare una empresa de Scribd logo
1 de 14
DirectTrust.org
Building the Trust Framework for Directed

                Exchange


         David C. Kibbe, MD MBA
      NeHC University, February 8, 2012
          kibbedavid@mac.com
Today’s talk
• About DirectTrust.org
• Our mission and goals
• Brief overview of Directed exchange
 • Why e-mail? Why ‘push’ ?
• The importance of security and trust
• Components of the Trust Framework
 • It’s all about identity!
About DirectTrust.org
• DirectTrust.org is being organized as an
  independent, non-profit, and
  competitively neutral entity created by
  and for Direct community participants.
• Our goal is to develop, promote and, as
  necessary, help enforce the rules and
  best practices necessary to maintain
  trust within the Direct exchange
  community, and to foster widespread
  public confidence in the Direct
  exchange of health information.
• Our web presence:
      About DirectTrust.org
  www.directtrust.wikispaces.com
• ~80 members of the wiki, representing
  HISPs, HIEs, EHR technology vendors,
  Certificate Authorities, Identity Providers,
  state officials, patient advocacy
  organizations, providers, consultants,
  others.
• Please join if you wish to contribute to the
  effort!
About DirectTrust.org
• Two active workgroups:  Security and Trust
  Compliance; Certificate Policy and
  Practices
• Organizational Committee Members
 • AAFP, Arcadia Solutions, Cerner, DigiCert,
    Gorge Health Connect, Relay Health,
    Rhode Island Quality Institute, SAFE-
    BioPharma, Surescripts
The Direct Project
 Created a set of protocols,
 specifications, and standards, that,
 with a policy and trust framework,
 enables simple, secure transport
 over the Internet, to be used for
 exchange between known
 participants in support of
 meaningful use.
Meaningful Use, Quality Care
   Direct Project facilitates the communication of many different kinds of content
   necessary to fulfill meaningful use requirements.
                                                              Examples of Meaningful Use

                                                      Other Providers/Authorized Entities:
                                                         Clinical information for care coordination
                                                         Labs – test results
                                         DIRECT          Referrals – summary of care record
                                         EXCH ANGE
                                                      Patients:
                                                         Health information
                                                         Discharge instructions
                                                         Clinical summaries
    b.wells@direct.aclinic.org                           Reminders

1 Get a Direct Address ( e-mail-like) and a
 )
    security certificate                              Public Health:
2) Send mail securely using most e-mail                  Immunization registries
    clients OR contract with a HIO or HISP               Syndromic surveillance
    that performs authentication, encryption
    and trust verification on your behalf                Laboratory Reporting
Specific HISP duties:
- provide subscribers with account and Direct addresses
     - provide web portal or EHR/PHR integration
 - arrange for identity verification - org and individual
 - arrange for digital certificate issuance, management
  - maintain integrity of trust and security framework
   - stay current with federal policies and regulations
Security and Trust
      are Essential!
• We trust our doctors and nurses with our
  health information.
• We will need to be able to trust HISPs
  with our health information.
• Without a high level of trust accompanied
  by the requisite levels of security and
  privacy protection, health data exchange of
  any type or technology will likely fail.
Desirable HISP attributes:
         - strong, validated security practices
           - a track record in data exchange
   - working relationship with one or more RA/CA
- able and willing to interoperably exchange with other
                          HISPs
             - robust subscriber directory
Why Digital Certificates are So
        Important to Directed Exchange

• Digital certificates “stand in” for the
  individual/organizational identity in cyberspace
• They are issued by an RA/CA only after identity
  verification proves you are who you say you are
• They are used to sign, validate, and encrypt Direct
  exchange messages and attachments
• Any breach of trust with respect to certificate
  issuance or use threatens the integrity of exchange
Direct Identity, Trust, and Address Provisioning

                                                              Certificate Authority (CA)
                                                                Identity/Trust                 Certificate
                                                                 Verification              Validation Service

                                                             Certificate Signing                Revocation
                                                                  Services                       Services


                                                                                                                                    The CA and RA enforce the
                                                           6. Certificate Signing          7. Direct Organization                     policies specified in the
                                                              Request                         Certificate
                                                                                                                                     DirectTrust.org and FBCA
                                    2. Request Direct                                                                                Certificate Policies (CPs).
                                       Organization
 Assume has
Digital Identity
                                       Certificate
                                                            Registration Authority (RA)
  Certificate
                                    3. Credentials and
                                       Documentation             Compile/Validate Identity and Trust
                       HCO                                                Documentation
                                      Representative
                   Representative      FBCA Credentials
                                      Representative
    Healthcare                         Authorization
Organization (HCO)                    Legal Entity
                                       Documents
                                                          4. Direct
                                                                                    5. Public      8. Direct Organization
                                                             Organization
                                      Membership/Trust      Domain                    Key            Certificate
                                       Agreement
                                      HIPAA status
                                                                                                                                         Domain Name System
                                                                                                                                                (DNS)
                                    1. Enroll with HISP                                                             9. Direct Address/
                                                                Health Information Service                             Org Certificate

                                                                     Provider (HISP)                                                     LDAP Name System



                                                                                                       Source: DirectTrust.org February, 2012
Issues Remaining to be Resolved with
Respect to the Direct Exchange Trust
             Framework

• Who will be acceptable (ie. trustworthy) as
  Certificate Authorities?
• What level(s) of identity verification is
  required for groups; professionals;
  patients?
• What will be decided at a federal policy
  level, and what at an industry level?
Questions, Comments

• David C. Kibbe, MD MBA
• kibbedavid@mac.com
• 913 205 7968

Más contenido relacionado

Similar a DirectTrust.org: Building the Trust Framework for Directed Exchange

Identity Proofing to provision accurately
Identity Proofing to provision accuratelyIdentity Proofing to provision accurately
Identity Proofing to provision accuratelyDavid Kelts, CIPT
 
"NSTIC Pilots on the trust network" Webinar Slides 10-12-2012
"NSTIC Pilots on the trust network" Webinar Slides 10-12-2012"NSTIC Pilots on the trust network" Webinar Slides 10-12-2012
"NSTIC Pilots on the trust network" Webinar Slides 10-12-2012Collaborative Health Consortium
 
HIMSS GSA e-Authentication whitepaper June 2007
HIMSS GSA e-Authentication whitepaper June 2007HIMSS GSA e-Authentication whitepaper June 2007
HIMSS GSA e-Authentication whitepaper June 2007Richard Moore
 
Updates on the Western States Consortium
Updates on the Western States ConsortiumUpdates on the Western States Consortium
Updates on the Western States ConsortiumCHeQ-IPHI
 
Ecm sales training sample day 1
Ecm sales training sample  day 1Ecm sales training sample  day 1
Ecm sales training sample day 1DataVault
 
EHR Certification HIMSS Presentation
EHR Certification HIMSS PresentationEHR Certification HIMSS Presentation
EHR Certification HIMSS PresentationBrian Ahier
 
Hitpc.20090716.Certification Workgroup
Hitpc.20090716.Certification WorkgroupHitpc.20090716.Certification Workgroup
Hitpc.20090716.Certification Workgroupsdaviss
 
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...apidays
 
Can Blockchain Enable Identity Management?
Can Blockchain Enable Identity Management?Can Blockchain Enable Identity Management?
Can Blockchain Enable Identity Management?Priyanka Aash
 
Lc 08-2011-reg requirements
Lc 08-2011-reg requirementsLc 08-2011-reg requirements
Lc 08-2011-reg requirementseyepacs
 
November 2008 E Newsletter
November 2008 E NewsletterNovember 2008 E Newsletter
November 2008 E NewsletterJudson P. Bruno
 
Managing PIV Card Lifecycle and Converging Physical & Logical Access Control
Managing PIV Card Lifecycle and Converging Physical & Logical Access ControlManaging PIV Card Lifecycle and Converging Physical & Logical Access Control
Managing PIV Card Lifecycle and Converging Physical & Logical Access ControlRamesh Nagappan
 
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...Richard Moore
 
Security patterns with wso2 esb
Security patterns with wso2 esbSecurity patterns with wso2 esb
Security patterns with wso2 esbHasiniG
 
Security Patterns with the WSO2 ESB
Security Patterns with the WSO2 ESBSecurity Patterns with the WSO2 ESB
Security Patterns with the WSO2 ESBWSO2
 
21 CFR part 11- ELECTRONIC RECORDS; ELECTRONIC SIGNATURES
21 CFR part 11-ELECTRONIC RECORDS;ELECTRONIC SIGNATURES21 CFR part 11-ELECTRONIC RECORDS;ELECTRONIC SIGNATURES
21 CFR part 11- ELECTRONIC RECORDS; ELECTRONIC SIGNATURESMayur Patil
 
M12S18 - Records and Information Management: What Healthcare Should be Learni...
M12S18 - Records and Information Management: What Healthcare Should be Learni...M12S18 - Records and Information Management: What Healthcare Should be Learni...
M12S18 - Records and Information Management: What Healthcare Should be Learni...MER Conference
 
Electronic credential authentication_standard
Electronic credential authentication_standardElectronic credential authentication_standard
Electronic credential authentication_standardHai Nguyen
 

Similar a DirectTrust.org: Building the Trust Framework for Directed Exchange (20)

Identity Proofing to provision accurately
Identity Proofing to provision accuratelyIdentity Proofing to provision accurately
Identity Proofing to provision accurately
 
"NSTIC Pilots on the trust network" Webinar Slides 10-12-2012
"NSTIC Pilots on the trust network" Webinar Slides 10-12-2012"NSTIC Pilots on the trust network" Webinar Slides 10-12-2012
"NSTIC Pilots on the trust network" Webinar Slides 10-12-2012
 
HIE 101
HIE 101HIE 101
HIE 101
 
HIMSS GSA e-Authentication whitepaper June 2007
HIMSS GSA e-Authentication whitepaper June 2007HIMSS GSA e-Authentication whitepaper June 2007
HIMSS GSA e-Authentication whitepaper June 2007
 
Updates on the Western States Consortium
Updates on the Western States ConsortiumUpdates on the Western States Consortium
Updates on the Western States Consortium
 
Ecm sales training sample day 1
Ecm sales training sample  day 1Ecm sales training sample  day 1
Ecm sales training sample day 1
 
Issa fi xs briefing
Issa fi xs briefingIssa fi xs briefing
Issa fi xs briefing
 
EHR Certification HIMSS Presentation
EHR Certification HIMSS PresentationEHR Certification HIMSS Presentation
EHR Certification HIMSS Presentation
 
Hitpc.20090716.Certification Workgroup
Hitpc.20090716.Certification WorkgroupHitpc.20090716.Certification Workgroup
Hitpc.20090716.Certification Workgroup
 
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
 
Can Blockchain Enable Identity Management?
Can Blockchain Enable Identity Management?Can Blockchain Enable Identity Management?
Can Blockchain Enable Identity Management?
 
Lc 08-2011-reg requirements
Lc 08-2011-reg requirementsLc 08-2011-reg requirements
Lc 08-2011-reg requirements
 
November 2008 E Newsletter
November 2008 E NewsletterNovember 2008 E Newsletter
November 2008 E Newsletter
 
Managing PIV Card Lifecycle and Converging Physical & Logical Access Control
Managing PIV Card Lifecycle and Converging Physical & Logical Access ControlManaging PIV Card Lifecycle and Converging Physical & Logical Access Control
Managing PIV Card Lifecycle and Converging Physical & Logical Access Control
 
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
Healthcare Identity Management and Role-Based Access in a Federated NHIN - Th...
 
Security patterns with wso2 esb
Security patterns with wso2 esbSecurity patterns with wso2 esb
Security patterns with wso2 esb
 
Security Patterns with the WSO2 ESB
Security Patterns with the WSO2 ESBSecurity Patterns with the WSO2 ESB
Security Patterns with the WSO2 ESB
 
21 CFR part 11- ELECTRONIC RECORDS; ELECTRONIC SIGNATURES
21 CFR part 11-ELECTRONIC RECORDS;ELECTRONIC SIGNATURES21 CFR part 11-ELECTRONIC RECORDS;ELECTRONIC SIGNATURES
21 CFR part 11- ELECTRONIC RECORDS; ELECTRONIC SIGNATURES
 
M12S18 - Records and Information Management: What Healthcare Should be Learni...
M12S18 - Records and Information Management: What Healthcare Should be Learni...M12S18 - Records and Information Management: What Healthcare Should be Learni...
M12S18 - Records and Information Management: What Healthcare Should be Learni...
 
Electronic credential authentication_standard
Electronic credential authentication_standardElectronic credential authentication_standard
Electronic credential authentication_standard
 

Más de Collaborative Health Consortium

John Freedman - All-payer claims databases - CHC Pilots & Collaborations
John Freedman - All-payer claims databases - CHC Pilots & CollaborationsJohn Freedman - All-payer claims databases - CHC Pilots & Collaborations
John Freedman - All-payer claims databases - CHC Pilots & CollaborationsCollaborative Health Consortium
 
Himss e collaboration forum closing session (kuraitis, shah) final
Himss e collaboration forum closing session (kuraitis, shah) finalHimss e collaboration forum closing session (kuraitis, shah) final
Himss e collaboration forum closing session (kuraitis, shah) finalCollaborative Health Consortium
 
Dave Whitlinger - NYeHC - eCollaborationForum 2012 - 02/23/12
Dave Whitlinger - NYeHC - eCollaborationForum 2012 - 02/23/12Dave Whitlinger - NYeHC - eCollaborationForum 2012 - 02/23/12
Dave Whitlinger - NYeHC - eCollaborationForum 2012 - 02/23/12Collaborative Health Consortium
 

Más de Collaborative Health Consortium (14)

John Freedman - All-payer claims databases - CHC Pilots & Collaborations
John Freedman - All-payer claims databases - CHC Pilots & CollaborationsJohn Freedman - All-payer claims databases - CHC Pilots & Collaborations
John Freedman - All-payer claims databases - CHC Pilots & Collaborations
 
Dave Chase, Avado CEO, presents to CHC
Dave Chase, Avado CEO, presents to CHCDave Chase, Avado CEO, presents to CHC
Dave Chase, Avado CEO, presents to CHC
 
E-Innovations to Support Primary Care
E-Innovations to Support Primary CareE-Innovations to Support Primary Care
E-Innovations to Support Primary Care
 
From Silo's to Legos
From Silo's to LegosFrom Silo's to Legos
From Silo's to Legos
 
Ahier himss 2012 - direct project overview presentation
Ahier   himss 2012 - direct project overview presentationAhier   himss 2012 - direct project overview presentation
Ahier himss 2012 - direct project overview presentation
 
Salesforce ecollab himss2 copy
Salesforce ecollab himss2 copySalesforce ecollab himss2 copy
Salesforce ecollab himss2 copy
 
Nobel payer panel e collaborationforum 2.23.12
Nobel payer panel e collaborationforum 2.23.12Nobel payer panel e collaborationforum 2.23.12
Nobel payer panel e collaborationforum 2.23.12
 
E collaborationforumjoemiller (jmiller v1)
E collaborationforumjoemiller (jmiller v1)E collaborationforumjoemiller (jmiller v1)
E collaborationforumjoemiller (jmiller v1)
 
120223 e collaborationforum ppt_migliori
120223 e collaborationforum ppt_migliori120223 e collaborationforum ppt_migliori
120223 e collaborationforum ppt_migliori
 
Kolodner2 e collaborationforum
Kolodner2 e collaborationforumKolodner2 e collaborationforum
Kolodner2 e collaborationforum
 
E collaborationforum ppt_jmandel
E collaborationforum ppt_jmandelE collaborationforum ppt_jmandel
E collaborationforum ppt_jmandel
 
Blatt e collaborative himss 2012 final
Blatt   e collaborative himss 2012 finalBlatt   e collaborative himss 2012 final
Blatt e collaborative himss 2012 final
 
Himss e collaboration forum closing session (kuraitis, shah) final
Himss e collaboration forum closing session (kuraitis, shah) finalHimss e collaboration forum closing session (kuraitis, shah) final
Himss e collaboration forum closing session (kuraitis, shah) final
 
Dave Whitlinger - NYeHC - eCollaborationForum 2012 - 02/23/12
Dave Whitlinger - NYeHC - eCollaborationForum 2012 - 02/23/12Dave Whitlinger - NYeHC - eCollaborationForum 2012 - 02/23/12
Dave Whitlinger - NYeHC - eCollaborationForum 2012 - 02/23/12
 

Último

Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?Antenna Manufacturer Coco
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 

Último (20)

Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 

DirectTrust.org: Building the Trust Framework for Directed Exchange

  • 1. DirectTrust.org Building the Trust Framework for Directed Exchange David C. Kibbe, MD MBA NeHC University, February 8, 2012 kibbedavid@mac.com
  • 2. Today’s talk • About DirectTrust.org • Our mission and goals • Brief overview of Directed exchange • Why e-mail? Why ‘push’ ? • The importance of security and trust • Components of the Trust Framework • It’s all about identity!
  • 3. About DirectTrust.org • DirectTrust.org is being organized as an independent, non-profit, and competitively neutral entity created by and for Direct community participants. • Our goal is to develop, promote and, as necessary, help enforce the rules and best practices necessary to maintain trust within the Direct exchange community, and to foster widespread public confidence in the Direct exchange of health information.
  • 4. • Our web presence: About DirectTrust.org www.directtrust.wikispaces.com • ~80 members of the wiki, representing HISPs, HIEs, EHR technology vendors, Certificate Authorities, Identity Providers, state officials, patient advocacy organizations, providers, consultants, others. • Please join if you wish to contribute to the effort!
  • 5. About DirectTrust.org • Two active workgroups: Security and Trust Compliance; Certificate Policy and Practices • Organizational Committee Members • AAFP, Arcadia Solutions, Cerner, DigiCert, Gorge Health Connect, Relay Health, Rhode Island Quality Institute, SAFE- BioPharma, Surescripts
  • 6. The Direct Project  Created a set of protocols, specifications, and standards, that, with a policy and trust framework, enables simple, secure transport over the Internet, to be used for exchange between known participants in support of meaningful use.
  • 7. Meaningful Use, Quality Care Direct Project facilitates the communication of many different kinds of content necessary to fulfill meaningful use requirements. Examples of Meaningful Use  Other Providers/Authorized Entities:  Clinical information for care coordination  Labs – test results DIRECT  Referrals – summary of care record EXCH ANGE  Patients:  Health information  Discharge instructions  Clinical summaries b.wells@direct.aclinic.org  Reminders 1 Get a Direct Address ( e-mail-like) and a ) security certificate  Public Health: 2) Send mail securely using most e-mail  Immunization registries clients OR contract with a HIO or HISP  Syndromic surveillance that performs authentication, encryption and trust verification on your behalf  Laboratory Reporting
  • 8. Specific HISP duties: - provide subscribers with account and Direct addresses - provide web portal or EHR/PHR integration - arrange for identity verification - org and individual - arrange for digital certificate issuance, management - maintain integrity of trust and security framework - stay current with federal policies and regulations
  • 9. Security and Trust are Essential! • We trust our doctors and nurses with our health information. • We will need to be able to trust HISPs with our health information. • Without a high level of trust accompanied by the requisite levels of security and privacy protection, health data exchange of any type or technology will likely fail.
  • 10. Desirable HISP attributes: - strong, validated security practices - a track record in data exchange - working relationship with one or more RA/CA - able and willing to interoperably exchange with other HISPs - robust subscriber directory
  • 11. Why Digital Certificates are So Important to Directed Exchange • Digital certificates “stand in” for the individual/organizational identity in cyberspace • They are issued by an RA/CA only after identity verification proves you are who you say you are • They are used to sign, validate, and encrypt Direct exchange messages and attachments • Any breach of trust with respect to certificate issuance or use threatens the integrity of exchange
  • 12. Direct Identity, Trust, and Address Provisioning Certificate Authority (CA) Identity/Trust Certificate Verification Validation Service Certificate Signing Revocation Services Services The CA and RA enforce the 6. Certificate Signing 7. Direct Organization policies specified in the Request Certificate DirectTrust.org and FBCA 2. Request Direct Certificate Policies (CPs). Organization Assume has Digital Identity Certificate Registration Authority (RA) Certificate 3. Credentials and Documentation Compile/Validate Identity and Trust HCO Documentation  Representative Representative FBCA Credentials  Representative Healthcare Authorization Organization (HCO)  Legal Entity Documents 4. Direct 5. Public 8. Direct Organization Organization  Membership/Trust Domain Key Certificate Agreement  HIPAA status Domain Name System (DNS) 1. Enroll with HISP 9. Direct Address/ Health Information Service Org Certificate Provider (HISP) LDAP Name System Source: DirectTrust.org February, 2012
  • 13. Issues Remaining to be Resolved with Respect to the Direct Exchange Trust Framework • Who will be acceptable (ie. trustworthy) as Certificate Authorities? • What level(s) of identity verification is required for groups; professionals; patients? • What will be decided at a federal policy level, and what at an industry level?
  • 14. Questions, Comments • David C. Kibbe, MD MBA • kibbedavid@mac.com • 913 205 7968