HL7 FHIR Security 2016-3-29
Weekly: Tuesday at 05:00 EST (2 PM PST)
Conference Audio: 770-657-9270,' Access: 845692
Join online meeting: https://meet.RTC.VA.GOV/suzanne.gonzales-webb/67LLFDYV
If you are having difficulty joining, please try:
Please be aware that teleconference meetings are recorded to assist with creating the meeting minutes
|Member Name||Member Name||Member Name|
|.||John Moehrke Security Co-Chair||x||Kathleen Connor Security Co-Chair||x||Suzanne Gonzales-Webb CBCC Co-Chair|
|.||Gary Dickinson EHR Co-Chair||.||Johnathan ColemanCBCC Co-Chair||.||Mike Davis|
|.||Reed Gelzer RM-ES Lead||x||Glen Marshal||.||Galen Mulrooney|
|.||Dave Silver||.||Rob Horn||x||Judy Fincher|
|x||Diana Proud-Madruga||.||Beth Pumo||x||Oliver Lawless|
- Roll; approval of agenda and the March 15, 2016 minutes and March 22, 2016 minutes
- Review John's interaction diagrams for Provenance and AuditEvent showing how these may be generated by both the user system and the recipient server.
- Review deferred Security PC 9407 Align AuditEvent and Provenance action/activity element definition Continue work on activity definitions in spreadsheet
Other CPs for Review
- 7568 2015May core #859 - How are agent and activity linked? (Kathleen Connor) None
- 9407 Align AuditEvent and Provenance action/activity element. Recommend "Provenance.activity". (Kathleen Connor) None
- 9150 Provenance TODO section cleanup (John Moehrke) None
- 9151 AuditEvent has TODO section to be removed (John Moehrke) None
- 9166 Break-Glass method defined doesn't include AuditEvent effect. (John Moehrke) None
- 9167 AuditEvent needs to make more obvious how to record a break-glass event (John Moehrke) None
- 9176 Security-Labels page for _confidentialiy points at all "Confidentiality" codes, not just _confidentiality. (John Moehrke) None
- 9563 Add onBehalfOf to Signature datatype (Kathleen Connor) None
- 9564 Should FHIR AuditEvent resource include DICOM extension of ATNA Audit log message ? (Madhusudana B Shivalinge Gowda) None
- Kathleen chaired. Agenda and Minutes approved.
- John was not available to discuss interaction diagram topic, so deferred until he indicates he's ready.
- Kathleen showed updates to the cross FHIR P&S activity element harmonization spreadsheet.
- AuditEvent action, type, and subtype discussion from last week was documented.
- Discussed Provenance.activity "period" datatype. Oliver argued that "period' is the wrong datatype, and that it should be changed to "instant".
- Discussed whether the EHR Lifecycle concepts are the same as similarly named concepts in AuditEvent. Oliver and Glen suggested that they are the same or that they should be clearly differentiated.
- Given that those interested in these discussion were not in attendance, Kathleen proposed that these issues be discussed with the Vocabulary Alignment project before going back to both CBCC and the FHIR Provenance sponsor, the Security WG.
- Bob Dieterle expressed a strong interest in attending these discussions, so they will be deferred until the Tuesday, April 12 CBCC/Security calls.
Meeting adjourned at 6PM ET.