This wiki has undergone a migration to Confluence found Here
<meta name="googlebot" content="noindex">

Difference between revisions of "February 20, 2018 Security Conference Call"

From HL7Wiki
Jump to navigation Jump to search
 
Line 89: Line 89:
 
# more detailed Security comments
 
# more detailed Security comments
  
'''TF4
+
'''TF4FA'''
 
* PSAF call this AM
 
* PSAF call this AM
 
* discussed the information model updates; have diagram/information from 22600 elaborated on some of the policy classes, particularly on the basic policy classes; distinguished
 
* discussed the information model updates; have diagram/information from 22600 elaborated on some of the policy classes, particularly on the basic policy classes; distinguished
Line 102: Line 102:
 
* Mike suspects that there will be drafts coming out soon from our discussions.
 
* Mike suspects that there will be drafts coming out soon from our discussions.
  
FHIR security call  
+
'''FHIR security call '''
 
* meeting this afternoon
 
* meeting this afternoon
 
* will work though other CPs this afternoon
 
* will work though other CPs this afternoon
  
Updates for harmonization
+
'''Updates for harmonization'''
 
* Rikki Merrick O&O
 
* Rikki Merrick O&O
 
** works with Kathleen on Michigan HIM
 
** works with Kathleen on Michigan HIM
  
Discussion
+
''Discussion''
 
* Sensitivity proposal - V3 addition to PHI, deprecating ETH code(updated to SUD)
 
* Sensitivity proposal - V3 addition to PHI, deprecating ETH code(updated to SUD)
 
* new table, importing code from different terms - Security labeling handling instructions
 
* new table, importing code from different terms - Security labeling handling instructions

Latest revision as of 21:13, 20 February 2018

Back to Security Main Page

Attendees

x Member Name x Member Name x Member Name x Member Name
x John Moehrke Security Co-chair x Kathleen Connor Security Co-chair . Alexander Mense Security Co-chair . Trish Williams Security Co-chair
x Christopher Shawn Security Co-chair x Suzanne Gonzales-Webb x Mike Davis x David Staggs
. Mohammed Jafari . Beth Pumo . Ioana Singureanu . Rob Horn
x Diana Proud-Madruga . Serafina Versaggi x Joe Lamy . Greg Linden
. Paul Knapp . Grahame Grieve . Johnathan Coleman . Aaron Seib
. Ken Salyards x Jim Kretz . Gary Dickinson x Dave Silver
. Oliver Lawless . Joyce] . David Tao . Nathan Botts
x Francisco Jauregui . Bo Dagnall . [1] . Theresa Connor

Back to Security Main Page

Agenda

  1. (2 min) Roll Call, Agenda Approval
  2. (5 min) Review and Approval of Feb.13, 2018 minutes and New Orleans Jan 2018 WGM Minutes - Thank you Princess Trish! We've had a week to review. Time to approve
  3. (5 min) Review of Final HL7 TEFCA Comments and TEFCA Security Appendix - Kathleen Connor.
  4. (5 min) TF4FA Updates from PSAF call - Mike Davis
  5. (5 min) FHIR Security Block Vote Call is scheduled today. John
  6. (30 min) Review March Harmonization initial proposals to add HCS Security Classification/Confidentiality codes, Category/Sensitivity codes, and Security Control/Purpose of Use, Obligation, and Refrain policy codes to HL7 Version 2

Meeting Materials

  1. March Harmonization Schedule
  • Initial Proposal Submission Deadline - Feb. 28th
  • Technical Review by March 6th
  • Final Proposal Submission Deadline - March 16th
  • Harmonization Meeting - March 20 - 21
  1. "Is Privacy Obsolete" Study Group Page"
  2. FHIR Security WG Call
  3. FHIR Consumer Centered Data Exchange (CCDE) Connectathon


Meeting Minutes DRAFT

Role taken / Agenda accepted (motion: Kathleen/David S)

Meeting Minutes: February 13 - Meeting minutes approval (motion: Suzanne/Mike D) objections: none, Abstentions: none, approved: 9

new Orleans WGM - Meeting minutes approval (ChrisS / Suzanne) objections: none, Abstentions: none, meeting minutes approved: 9

TEFCA Comments Two documents

  1. overarching HL7 comments
  2. more detailed Security comments

TF4FA

  • PSAF call this AM
  • discussed the information model updates; have diagram/information from 22600 elaborated on some of the policy classes, particularly on the basic policy classes; distinguished
  • looked also looked beyond the trust establishment, definitions-what it means to have policy within a contextual framework.
  • basic assumptions; in a federator domain initiators have ability t request
  • on track for presenting the document for May 2018 (normative); previously informative
    • resolution of comments from previous ballots are what we have been working on
    • NIB is being finalized
    • not planning to ballot the Behavioral model at this point--there have been several changes on Chapter 2, volume 1--we will not have time to complete before May
    • compressed down to 22600, focusing on basic policies for this update
  • WG has an outstanding project to work on an IM, balloting the 2014 model which is known to be incorrect anyway--to correct the trust framework information
  • Mike suspects that there will be drafts coming out soon from our discussions.

FHIR security call

  • meeting this afternoon
  • will work though other CPs this afternoon

Updates for harmonization

  • Rikki Merrick O&O
    • works with Kathleen on Michigan HIM

Discussion

  • Sensitivity proposal - V3 addition to PHI, deprecating ETH code(updated to SUD)
  • new table, importing code from different terms - Security labeling handling instructions

Purpose of Use table; codes for new table v2 tables are flat and do not support the higher level uses (Rikki will ask if we should include--not sure 'how they will be used' because they abstract codes in v3)

  • due February 28
  • would like to finish delegation/authorization policy so that we can get into this harmonization schedule (otherwise we need to wait until July)
  • we're moving Care management moving to coordination of care - because 42CFRPart2, it differentiation from HIPAA authorization a different set of activities--it carves out the activity (coordination of care) which if focused on BH clients, but it could be any patient. the idea is what is required to get a patient into treatment to make the treatment successful. its not the same as signing up for insurance. they carved that piece out. under Michigan health act they've made it so that Treatment, Payment and coordination of care does not require authorization as it did previously... if you want to use the information for other activities, population health, quality management, etc. (health plan type activities) under HIPAA ... that kind of activity does require an authorization.


Meeting adjourned at 1404 Arizona Time