Keith
Dear Stakeholders:
Announced this week, the HIT Policy Committee's Privacy and Security Tiger Team is seeking public comment on issues of authentication "trust" rules for information exchange between provider-entities. The Tiger Team will be evaluating trust rules at the organizational level in consideration of policy recommendations that will be presented to the HIT Policy Committee and the Office of the National Coordinator for Health IT (ONC). It is important that you make your voice heard in order to inform the deliberations of this workgroup and its recommendations. In the announcement below are a series of questions that the Tiger Team has asked the public to consider. Please take a moment to share your opinions on the answers to these questions and submit them to the ONC FACA Blog no later than next Friday, October 29. Instructions for direct comment submission are included below, or you can just reply to this email and NeHC will submit your responses to ONC on your behalf.
We appreciate your attention to this important aspect in the development of a safe and secure nationwide health information system.
ONC FACA Blog
Tuesday, October 19th, 2010 | Posted by: Deven McGraw and Paul Egerman | Category: FACA
The Privacy and Security Tiger Team is currently considering policy recommendations to ensure that authentication "trust" rules are in place for information exchange between provider-entities (or organizations). We are currently evaluating these trust rules at the organizational level, and as such, our scope here does not include authentication of individual users of electronic health record (EHR) systems. For purposes of this discussion, authentication is the verification that a provider entity (such as a hospital or physician practice) seeking access to electronic protected health information is the one claimed, and the level of assurance is the degree of confidence in the results of an authentication attempt.
We hope that we can have a robust discussion on this blog that provides valuable input on this topic. All comments are welcome, but we particularly encourage you to consider the following questions:
- What strength of provider-entity authentication (level of assurance) might be recommended to ensure trust in health information exchange (regardless of what technology may be used to meet the strength requirement)?
- Which provider-entities can receive digital credentials, and what are the requirements to receive those credentials?
- What is the process for issuing digital credentials (e.g., certificates), including evaluating whether initial conditions are met and re-evaluation on a periodic basis?
- Who has the authority to issue digital credentials?
- Should ONC select an established technology standard for digital credentials and should EHR certification include criteria that tests capabilities to communicate using that standard for entity-level credentials?
- What type of transactions must be authenticated, and is it expected that all transactions will have a common level of assurance?
Please comment by October 29, 2010, and identify which question(s) you are responding to.
Thank you,
Deven McGraw and Paul Egerman
Privacy and Security Tiger Team Co-Chairs

It should be about Service instead of Technology
More than two decades ago I worked in the Information Services department of a small marketing and publishing company. Simillarly named departments existed elsewhere in the industry. Over the years the name of that department has almost universally switched over to become first Information Systems, and finally Information Technology.
At the same time, my attention shifted from the technology, to the systems to the actual services being provided.
In healthcare the focus has changed from the Hospital Information System (or HIS) to the Electronic Medical Record (EMR) or Electronic Health Record (EHR). But again, thought leadership has been shifting from Information Systems and patient or practice medical records to the health services that the technology is providing (e.g., Health Information Exchange, lab result reporting, et cetera).
The name change does seem a little backwards, doesn't it?
At the same time, my attention shifted from the technology, to the systems to the actual services being provided.
In healthcare the focus has changed from the Hospital Information System (or HIS) to the Electronic Medical Record (EMR) or Electronic Health Record (EHR). But again, thought leadership has been shifting from Information Systems and patient or practice medical records to the health services that the technology is providing (e.g., Health Information Exchange, lab result reporting, et cetera).
The name change does seem a little backwards, doesn't it?

Friday, October 22, 2010
Crossing the HITECH Meaningful Divide
First up was Dr. Karen Bell, Chair of the Certification Commission on Health Information Technology.
She had some interesting things to say, and some things that people in the room needed to hear. One of her key points was that it's not enough to have certified technology, you have to be able to use it in order to get the incentive payments. That is pretty clearly stated in the regulations, but she was pushing in a slightly different direction. One of Karen's main themes was that it isn't enough to have a certified suite of modules, but that they all have to work together. For that she was pitching the CCHIT branded certification, because that was one of its differentiators.
She (and CCHIT in general) still has a number of questions about the security critieria (I know John Moehrke has been wrestling with may of the same issues). While CCHIT is working with ONC on getting clarifications, they are still trying to address all the issues around security's role in modular certification.
Karen also talked about how they are working with hospitals seeking certification of in-house developed EHR systems. CCHIT has a 3-step education program that is designed to help hospitals understand the certification process.
She finished her talk on this very important note. Patient care is not just about diagnosis and treatment. It is about caring for patients. It is very clear that Karen is very passionate about what she and CCHIT are doing, and it was a pleasure to hear from her.
One of the interesting follow-up questions which was asked by a healthcare provider was on the topic of certification and FDA involvement. Neither Karen nor I have a crystal ball to see where that is heading, and there doesn't seem to be much coming out of ONC and FDA on this topic. But it was good to see the concerns being raised.
Following Karen's talk was a panel presentation titled "How C-Suite it is". "Buddy" Gillespie led this panel and there were some interesting responses to some of the questions he posed to the panel. On the ROI of meaningful use, one panelist pointed out that Incentive payments aren't ROI, but the process change that the resulting changes have on your business should result in ROI if you do it right. He later points out that the penalties going into effect in 2016 are REAL MONEY, not quite like the incentives.
Another question on the cloud was asked, and one panelist made some daring predictions. In the next five years, he said, we will see heavier use of the cloud and SaaS models and lest creation of hospital data cetners. In 10 years, the model will be very much ASP based and the clincial apps will run in the cloud. Hospitals will focus on their core business models.
Now, HITECH/Meaningful Use isn't the only problem that providers face. ICD-10, 5010, and others are headed their way. What meaningful use does though, according to another panelist, is provide a proving ground for a governance process that can be reused for each of these different implementation projects.
My follow-up question on the cloud discussion had to do with provider readiness to accept the cloud, and the perceived risks. In response to my question, one panelist talked about how their organizational policy with respect to the cloud makes it OK to deal with de-identified data in the cloud, but not personally identifiable, because the perceived risks of accidental disclosure are too great. Another provider pointed out that for many, cloud = internet, and that SaaS may be made available through a secure link (e.g., VPN) rather than just over the web. The value of that was because privacy from a provider or practice perspective was also important. It was important for one hospital to ensure that their SaaS model included a neutral third party because practices were concerned about how access to usage information might now work in their favor.
Some of the issues he addressed were the importance of cross-border communication. Valley Forge where the conference was being held is in the "Delaware Valley", which is a tri-state area within about 30-60 minutes of 3 major cities in three different states (Philadelphia, Trenton, and Wilmington). There is a hospital in PA connected today to one of the New York RHIOs.
Another challenge for PHIX is the need to address the needs of providers who aren't being supported by meaningful use. So, they are providing a portal for LTC and other providers who aren't covered under meaningful use regulations.
PA has a pretty aggressive plan, and expects about 90% of hospitals to be fully connected to the HIE in five years. Their RFP for a HIE provider was issued on April 1, and was recently awarded through the State department of general services to Medicity.
Of course, while tweeting all of this, John Moore at Chilmark Research (@john_chilmark) responded through twitter pointing out that the laws make it difficult. I posed John's point to Phil and he had a great response. We ensure that we follow our State laws when we send the information, and it is up to the receiver to ensure that they follow theirs when making it available on the other end. I thought that was a really good way to handle the situation. I of course tweeted back the response...
Now, with regard to those policies, PA will be an opt-out state with restrictions for exchange of certain kinds of information that is more highly protected (e.g., drug and alcohol abuse treatment). Some of the challenges are with the lawyers: "If you have 20 lawyers in the room you get 27 opinions".
To wrap up the sessions, one of the presenters showed a picture of the World's oldest written medical records dated around 1800 BC. He noted that some providers are not much further along.
I had to find that picture for the HL7 CDA Ambassador presentation. The point to make is that you want a record that can last as long as necessary.

Thursday, October 21, 2010
IHE PCC Planning Meeting Results
This week about 20 people met in Oakbrook, Illinois for the IHE PCC planning meeting. The purpose of this meeting was to select the profile proposals that we would send to the technical committee for further review.
We moved forward two different profile proposals, which are described in somewhat more detail below:
We moved forward two different profile proposals, which are described in somewhat more detail below:
- Reconciliation
This proposal morphed from a Nursing Admission Assessment Reconciliation profile designed to support reconciliation of nursing diagnosis into a framework for reconciliation that would eventually support reconciliation of problems, medications, allergies, family and social history, immunizations, et cetera. We will focus only on problems in the first year, but the framework will be laid to support more complex requirements in subsequent years. - Interfacility Transport
This is a proposal to develop a profile to support the requirements for transport of a patient from one facility to another (e.g., from a hospital to a tertiary care facility). There are certainly overlaps with the ETC profile, and it is not clear how much of this proposal is workflow rather than content oriented.
There are two other work items that we will also take on this year: Completion of the Postpartum Visit Profile, and a change to the Patient Plan of Care Profile to add some vocabulary constraints in support of nursing diagnoses.
Other discussions we had jointly with QRPH involved how we establish governance and processes for the creation of templates, specialization of them, and refactoring of them, and to develop requirements around the infrastructure that we need to manage them. I encouraged the committees to bring this discussion up to the Domain Coordination Committee. I also pointed out that HL7 has a templates registry pilot that I'm woefully behind on (the book takes precedence right now), and the ONC S&I framework also has funded Stanley to develop tools that include a repository (and registry) of standards, and that we should try to collaborate on these efforts.
I also encourage IHE to consider how we might take advantage of the work Dave Carleson has done on CDA Tools
It was a very productive two days, and I now return to my old stomping grounds in Pennsylvania for a two day conference on meaningful use. I'll actually be speaking on Friday morning instead of Thursday so I had to rearrange a few things because I had the dates mixed up. I'm looking forward to being home this weekend so that I can finish painting my daughters bedroom and spend some time writing the CDA Book. I've got about ten days before I have to have the draft to the publisher.

Wednesday, October 20, 2010
Customer Service, a Hello, Upcoming Events and IHE Planning
SK wants to know:
Do we have any other (CDA based) templates other than CCD , which will enable us to provide discharge summary etc in cda format itself. As per your article, these kind of standards are in discussion and i would be thankful if you can advise me if there are any approved standards..
IHE Patient Care Coordination developed a discharge summary quite a number of years ago. In fact, it was the first profiles developed by that committee, placing it in the 2005-06 season. This post lists about 46 different CDA document implementation guides from four different sources
MO wants to know:
The NIST Test Procedure for §170.302 (v) Encryption when exchanging electronic health information and the Test Procedure for §170.302 (u) General Encryption require the tester to demonstrate that the encrypted data is unreadable. If using a third party mechanism, say a VPN, I don't think the data is accessible. How would NIST want this demonstrated?
I punted this one to John Moehrke, you'll have to read his answer here.
Liz, LF said to say hi. Hi!
Upcoming Events
Tomorrow I'll be heading back to near where I grew up, in Valley Forge, PA to speak at the "Crossing the Infrastructure & HITECH Meaningful Divide Symposium" being held at the Raddison Hotel in the Valley Forge Convention Center Complex. I'll be speaking on EHR and the Meaningful Evolution of Standards on Thursday morning.
IHE Planning Week at RSNA
Tomorrow ends the IHE PCC planning meetings to discuss our upcoming profiles. We've heard from four different proposal teams on:
Do we have any other (CDA based) templates other than CCD , which will enable us to provide discharge summary etc in cda format itself. As per your article, these kind of standards are in discussion and i would be thankful if you can advise me if there are any approved standards..
IHE Patient Care Coordination developed a discharge summary quite a number of years ago. In fact, it was the first profiles developed by that committee, placing it in the 2005-06 season. This post lists about 46 different CDA document implementation guides from four different sources
MO wants to know:
The NIST Test Procedure for §170.302 (v) Encryption when exchanging electronic health information and the Test Procedure for §170.302 (u) General Encryption require the tester to demonstrate that the encrypted data is unreadable. If using a third party mechanism, say a VPN, I don't think the data is accessible. How would NIST want this demonstrated?
I punted this one to John Moehrke, you'll have to read his answer here.
Liz, LF said to say hi. Hi!
Upcoming Events
Tomorrow I'll be heading back to near where I grew up, in Valley Forge, PA to speak at the "Crossing the Infrastructure & HITECH Meaningful Divide Symposium" being held at the Raddison Hotel in the Valley Forge Convention Center Complex. I'll be speaking on EHR and the Meaningful Evolution of Standards on Thursday morning.
IHE Planning Week at RSNA
Tomorrow ends the IHE PCC planning meetings to discuss our upcoming profiles. We've heard from four different proposal teams on:
- Nursing Admission Problem Reconciliation
- Nursing Vocabulary Value Sets
- Transport Workflow
- Completion of Perinatal Profiles
We've had some great discussions, and will come to consensus tomorrow on what to move forward with to the technical committee meeting in November. Some of my thoughts: We may expand the reconciliation profile to problems in general, although there's some discussion about how this is an interoperability profile. The evolution of transport workflow will likely depend on the data requirements, it could merge into ETC or stand on its own or both could be derived from a common data set. I believe we will have some concrete requests for what to bring to the technical committee for discussion.
The teams did a great job with value statements, resourcing of the efforts, and talking about market participation that I mentioned yesterday.
We also reviewed several change proposals, including one from Andrew at NIST that I've been behind on getting done for more than a year. Somehow I thought I'd managed to fob that off on someone else but it's back in my court. That was, as I recall, approved to move forward so now I have to write up the changes.
My hope is that we can also review a revision of the Functional Status Assessment profile as well, and bring it in line with current HL7 Patient Care work on assessments.
Ok, back to the CDA book. Ten days and counting...

Tuesday, October 19, 2010
IHE Planning Week
This week three different IHE domains are meeting in Oakbrook, Illinois to select profiles for the the next year (ITI, PCC and QRPH). We will hear four or five different proposals in the IHE PCC Domain over the next day and a half. As the planning co-chair, it's one of my responsibilities to help us focus the work.
I have three criteria we will be using to evaluate proposals as a committee:
I have three criteria we will be using to evaluate proposals as a committee:
- Available Resources
If we don't have the appropriately skilled resources to do the work, it simply won't get done well. - A Clear Value Statement
If the proposal doesn't have a clear value statement, then it will be hard to promote and get people interested in it. It becomes an academic exercise at that point, which may be interesting, but doesn't meet our goals. - Market Participation
It must be work that includes participation from all stakeholders, implementers of all sides of the transaction as well as healthcare providers willing to use it. If there are no participants interested in implementing the profile, it won't be adopted, and if there are no participants willing to use it, it won't have value to implementors.
My hope is that this will introduce focus and provide a reasonable scope of work. If we find we have more bandwidth than work, we'll simply keep some of it in reserve to be able to accept proposals later in the year.

Hallmarks
Yesterday I was furniture shopping with my youngest daughter. She is eight years old and we were shopping for a chest of drawers for her bedroom. The old dresser she had literally had fallen apart. We purchased it more than a decade ago, and it's had quite a bit of rough use since then. As we looked at new furniture, I inspected the drawers to see how they were constructed. I explained to my daughter that dovetailed joints were one of the hallmarks of good construction.
Thereafter, every piece of furniture she inspected was quickly accepted or rejected based on two criteria: Could she see inside the top drawer, and did it have "dove". She understood that these joints were a sign of good construction, but she didn't understand why. Later we examined a piece that had "dove" but was not nearly as well constructed because glue was everywhere, the joints were loose, and well, simply of poor quality. It went on my "no" list but her "yes" list because she'd learned to recognize the hallmark without understanding what it stood for.
I see the same thing in standards development. There are some who advocate an agile process who don't really know what agile is. They recognize one of the hallmarks though: iteration. Others look for services oriented enterprise architectures, without any real understanding of any single component of the term, but they recognize the hallmarks (its got services in it). And if I were to ask those that understood only the hallmarks of these things, but not the reasons behind them, what they were looking for, they wouldn't be able to describe it very well. There descriptions are remarkably like that of Justice Potter Stewart who said "I know it when I see it". Their understanding of the engineering behind what they are seeing is lacking. So, they will buy furniture with poorly fitted, machine made dovetail joints, not understanding why it doesn't hold up after a few years.
So, don't buy into the first thing you see with the hallmarks of what you've been told are good. Hallmarks can be counterfeited. Instead, understand the process that went into making it, and then, only then, if you really need to, should you look for the signs of that process. It is after all, the purpose of those processes and not the marks they leave behind that is really what we are after.
Thereafter, every piece of furniture she inspected was quickly accepted or rejected based on two criteria: Could she see inside the top drawer, and did it have "dove". She understood that these joints were a sign of good construction, but she didn't understand why. Later we examined a piece that had "dove" but was not nearly as well constructed because glue was everywhere, the joints were loose, and well, simply of poor quality. It went on my "no" list but her "yes" list because she'd learned to recognize the hallmark without understanding what it stood for.
I see the same thing in standards development. There are some who advocate an agile process who don't really know what agile is. They recognize one of the hallmarks though: iteration. Others look for services oriented enterprise architectures, without any real understanding of any single component of the term, but they recognize the hallmarks (its got services in it). And if I were to ask those that understood only the hallmarks of these things, but not the reasons behind them, what they were looking for, they wouldn't be able to describe it very well. There descriptions are remarkably like that of Justice Potter Stewart who said "I know it when I see it". Their understanding of the engineering behind what they are seeing is lacking. So, they will buy furniture with poorly fitted, machine made dovetail joints, not understanding why it doesn't hold up after a few years.
So, don't buy into the first thing you see with the hallmarks of what you've been told are good. Hallmarks can be counterfeited. Instead, understand the process that went into making it, and then, only then, if you really need to, should you look for the signs of that process. It is after all, the purpose of those processes and not the marks they leave behind that is really what we are after.

Subscribe to:
Posts (Atom)