This wiki has undergone a migration to Confluence found Here
<meta name="googlebot" content="noindex">

October 22, 2018 GDPR whitepaper on FHIR call

From HL7Wiki
Jump to navigation Jump to search

Back to Security GDPR Page

Attendees

x Member Name x Member Name x Member Name x Member Name
. John Moehrke Security Co-chair . Kathleen Connor Security Co-chair . Alexander Mense Security Co-chair . Trish Williams Security Co-chair
. Christopher Shawn Security Co-chair . David Pyke . Giorgio Cangioli . Joe Lamy
. [mailto: ] . [mailto: ] . [mailto: ] . [mailto: ]

Back to Security GDPR Page

Agenda

  1. (5 min) Roll Call, Agenda Approval
  2. (10 min) Need for / granularity use cases (care plan, IPS)
  3. (5 min) Issues from WGM:

Are update events to be reported in a transparency report? Depth of Provenance

Operations: Grahams to define an erasure operation that takes a Patient or Person. It returns rejected. Success. Or partial success.... Is there a need for it to report what it deleted? Or what it didn't? It does need to report external recipients Is it necessary tp report what was deleted? Operation for transparency: search on AuditEvents?

Do we need a CapabilityStatement like resource that describes server data retention rules. Possibly useful for client too to state the client need.

We might need to address Break-Glass as a healthcare safety mechanism.

  1. (20 min) Discussion on GDPR Purpose of use codes (Kathleen)

https://gforge.hl7.org/gf/project/security/docman/Harmonization/Nov%202018%20Harmonization/2018JulyHARM%20Initial%20PROPOSAL%20SECURITY%20v3%20and%20v2%20Table%200717%20Privacy%20Law%20and%20Consent%20Directive%20codes%20v2%20GDPR.doc

https://gdpr-info.eu/art-6-gdpr/

https://gdpr-info.eu/art-9-gdpr/


Link to Confluence page: http://confluence.hl7.org/display/SEC/FHIR+-+GDPR

Meeting Minutes (DRAFT)