This wiki has undergone a migration to Confluence found Here
<meta name="googlebot" content="noindex">

Difference between revisions of "HL7 FHIR Security 2018-06-12"

From HL7Wiki
Jump to navigation Jump to search
(Created page with "==Call Logistics== Weekly: '''Tuesday at 02:00 pm EST''' Web conference desktop and VOIP https://www.freeconferencecall.com/join/security36 Online Meeting ID: security36 ...")
 
 
(3 intermediate revisions by the same user not shown)
Line 19: Line 19:
 
|-
 
|-
 
||  x||[mailto:suzanne.webb@engilitycorp.com Suzanne Gonzales-Webb] CBCC Co-Chair   
 
||  x||[mailto:suzanne.webb@engilitycorp.com Suzanne Gonzales-Webb] CBCC Co-Chair   
||||x||[mailto:jc@securityrs.com Johnathan Coleman] CBCC co-chair
+
||||.||[mailto:jc@securityrs.com Johnathan Coleman] CBCC co-chair
 
||||.||[mailto:christopher.shawn2@va.gov Chris Shawn] Security co-chair
 
||||.||[mailto:christopher.shawn2@va.gov Chris Shawn] Security co-chair
 
|-
 
|-
Line 26: Line 26:
 
||||.||[mailto:nathanbotts@westat.com Nathan Botts] Mobile co-chair
 
||||.||[mailto:nathanbotts@westat.com Nathan Botts] Mobile co-chair
 
|-
 
|-
||  x||[mailto:Diana.Proud-Madruga@engilitycorp.com Diana Proud-Madruga]
+
||  .||[mailto:Diana.Proud-Madruga@engilitycorp.com Diana Proud-Madruga]
 
||||x||[mailto:joe.lamy@aegis.net Joe Lamy] AEGIS
 
||||x||[mailto:joe.lamy@aegis.net Joe Lamy] AEGIS
 
||||.||[mailto:Beth.Pumo@kp.org Beth Pumo]
 
||||.||[mailto:Beth.Pumo@kp.org Beth Pumo]
Line 38: Line 38:
 
||||.||Kevin Shekleton (Cerner, CDS Hooks)
 
||||.||Kevin Shekleton (Cerner, CDS Hooks)
 
|-
 
|-
||  x||[mailto:lcmaas@emrdirect.com Luis Maas EMR Direct]
+
||  .||[mailto:lcmaas@emrdirect.com Luis Maas EMR Direct]
||||x||[mailto:dave.silver@electrosoft-inc.com Dave Silver]
+
||||.||[mailto:dave.silver@electrosoft-inc.com Dave Silver]
||||x||[mailto:fjauregui@electrosoft-inc.com Francisco Jauregui]
+
||||.||[mailto:fjauregui@electrosoft-inc.com Francisco Jauregui]
 +
|-
 +
||  .||[mailto:gary.dickinson@edhr-standards.com Gary Dickinson]
 +
||||.||[mailto:blah@example.com Foo Bar]
 +
||||.||[mailto:blah@example.com Foo Bar]
 
|-
 
|-
 
|}
 
|}
Line 47: Line 51:
 
*Roll;  
 
*Roll;  
 
* approval of agenda  
 
* approval of agenda  
* approval of [[HL7 FHIR Security 2018-05-29]] Minutes
+
* approval of [[HL7 FHIR Security 2018-06-05]] Minutes
 
* Announcements
 
* Announcements
 
** [[GDPR (General Data Protection Regulation)]] whitepaper
 
** [[GDPR (General Data Protection Regulation)]] whitepaper
Line 105: Line 109:
 
*[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=17300 17300] Break-Glass+description+needs+clarifications (John Moehrke) None
 
*[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=17300 17300] Break-Glass+description+needs+clarifications (John Moehrke) None
 
*[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=14027 14027] enhance+current+disclosure+AuditEvent+so+that+it+explains+what+is+being+recorded+and+why (John Moehrke) Not Related
 
*[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=14027 14027] enhance+current+disclosure+AuditEvent+so+that+it+explains+what+is+being+recorded+and+why (John Moehrke) Not Related
 
  
 
==Minutes==
 
==Minutes==
 
* John Chaired
 
* John Chaired
 +
* Agenda was reviewed
 +
* Meeting next week is canceled due to conflict with FHIR Dev Days
 +
* Johnathan seems to be out-of-office, so we can not make progress on those items
 +
* John has not progressed his assignments
 +
* Other CR assignments are not present
 +
* Therefore no agenda to cover
 +
* Previous minutes were not reviewed
 +
* Gary -- Question
 +
** What is the status of progressing the testing for AuditEvent and Provenance
 +
** John, although it is a very good idea to do it and it is required of FMM, there is little resources available at this time to further this
 +
** GDPR - GDPR will drive more use of AuditEvent and Provenance, but it is unclear that will make resources available to develop test tooling
 +
* Adjourned 15 minutes

Latest revision as of 18:19, 12 June 2018

Call Logistics

Weekly: Tuesday at 02:00 pm EST

Web conference desktop and VOIP https://www.freeconferencecall.com/join/security36 
Online Meeting ID: security36
Phone: +1 515-604-9567, Participant Code: 880898
 Please be aware that teleconference meetings are recorded to assist with creating the meeting minutes 

Back to HL7 FHIR security topics

Attendees

Member Name Member Name Member Name
x John Moehrke Security Co-Chair . Kathleen Connor Security Co-Chair . Alexander Mense Security Co-chair
x Suzanne Gonzales-Webb CBCC Co-Chair . Johnathan Coleman CBCC co-chair . Chris Shawn Security co-chair
x Jim Kretz . Kenneth Salyards . Nathan Botts Mobile co-chair
. Diana Proud-Madruga x Joe Lamy AEGIS . Beth Pumo
. Irina Connelly . Matt Blackman Sequoia . Mark Underwood NIST
. Peter Bachman . Grahame Greve FHIR Program Director . Kevin Shekleton (Cerner, CDS Hooks)
. Luis Maas EMR Direct . Dave Silver . Francisco Jauregui
. Gary Dickinson . Foo Bar . Foo Bar

Agenda

ACTIONS

references

Current Open issues in gForge

  • 9167 AuditEvent+needs+to+make+more+obvious+how+to+record+a+break-glass+event (John Moehrke) Considered for Future Use
  • 10343 Three+additional+Signature.type+codes (Kathleen Connor) Considered for Future Use
  • 11071 Improve+security+label+guidance+-+2016-09+core+%2390 (Kathleen Connor) None
  • 12660 HCS+use+clarification (John Moehrke) None
  • 14678 Implementation+guide+for+signatures+-+2018-Jan+Core+%231 (Brian Pech) None
  • 15659 Provenance+still+has+both+identifier+and+reference+elements (Simone Heckmann) None
  • 16171 Observation.category+needs+test%2Fdemo%2Fcalibration+codes+to+distinguish+%27fake%27+data (Brian Reinhold) None
  • 16345 Link+to+obsoleted+version+of+HTTP+specification (Luis Maas) None
  • 16527 Access+Controls+-+Identity+Proofing (John Moehrke) None
  • 16530 Access+Controls+-+Protect+authenticators (John Moehrke) None
  • 16532 Access+Control+-+Authentication (John Moehrke) None
  • 16534 Access+Controls+-+Authorization (John Moehrke) None
  • 17192 Verification+of+given+resource+without+changing+the+content (Thomas Johansen) None
  • 17242 Recommend+that+IETF+BCP+195+be+used+when+TLS+is+used (John Moehrke) None
  • 17299 enhance+current+disclosure+AuditEvent+so+that+it+explains+what+is+being+recorded+and+why (John Moehrke) None
  • 17300 Break-Glass+description+needs+clarifications (John Moehrke) None
  • 14027 enhance+current+disclosure+AuditEvent+so+that+it+explains+what+is+being+recorded+and+why (John Moehrke) Not Related

Minutes

  • John Chaired
  • Agenda was reviewed
  • Meeting next week is canceled due to conflict with FHIR Dev Days
  • Johnathan seems to be out-of-office, so we can not make progress on those items
  • John has not progressed his assignments
  • Other CR assignments are not present
  • Therefore no agenda to cover
  • Previous minutes were not reviewed
  • Gary -- Question
    • What is the status of progressing the testing for AuditEvent and Provenance
    • John, although it is a very good idea to do it and it is required of FMM, there is little resources available at this time to further this
    • GDPR - GDPR will drive more use of AuditEvent and Provenance, but it is unclear that will make resources available to develop test tooling
  • Adjourned 15 minutes