This wiki has undergone a migration to Confluence found Here
<meta name="googlebot" content="noindex">

Difference between revisions of "HL7 FHIR Security 2016-6-21"

From HL7Wiki
Jump to navigation Jump to search
 
(2 intermediate revisions by 2 users not shown)
Line 17: Line 17:
 
||  x||[mailto:john.moehrke@ge.med.com John Moehrke] Security Co-Chair
 
||  x||[mailto:john.moehrke@ge.med.com John Moehrke] Security Co-Chair
 
||||x||[mailto:Kathleen_Connor@comcast.net Kathleen Connor] Security Co-Chair
 
||||x||[mailto:Kathleen_Connor@comcast.net Kathleen Connor] Security Co-Chair
||||.||[mailto:suzanne.webb@engilitycorp.com Suzanne Gonzales-Webb] CBCC Co-Chair   
+
||||x||[mailto:suzanne.webb@engilitycorp.com Suzanne Gonzales-Webb] CBCC Co-Chair   
 
|-
 
|-
 
||  .||[mailto:gary.dickinson@ehr-standards.com Gary Dickinson] EHR Co-Chair
 
||  .||[mailto:gary.dickinson@ehr-standards.com Gary Dickinson] EHR Co-Chair
Line 24: Line 24:
 
|-
 
|-
 
||  .||[mailto:rgelzer@provider-resources.com Reed Gelzer] RM-ES Lead
 
||  .||[mailto:rgelzer@provider-resources.com Reed Gelzer] RM-ES Lead
||||x||[mailto:gfm@securityrs.com Glen Marshal]
+
||||.||[mailto:gfm@securityrs.com Glen Marshal]
 
||||.||[mailto:Galen.Mulrooney@JPSys.com Galen Mulrooney]
 
||||.||[mailto:Galen.Mulrooney@JPSys.com Galen Mulrooney]
 
|-
 
|-
||  .||[mailto:dsilver@electrosoft-inc.com Dave Silver]
+
||  x||[mailto:dsilver@electrosoft-inc.com Dave Silver]
 
||||x||[mailto:robert.horn@agfa.com Rob Horn]  
 
||||x||[mailto:robert.horn@agfa.com Rob Horn]  
 
||||.||[mailto:Judith.Fincher@va.gov Judy Fincher]
 
||||.||[mailto:Judith.Fincher@va.gov Judy Fincher]
 
|-
 
|-
 
||  x|| [mailto:Diana.Proud-Madruga@engilitycorp.com Diana Proud-Madruga]
 
||  x|| [mailto:Diana.Proud-Madruga@engilitycorp.com Diana Proud-Madruga]
||||.|| [mailto:Beth.Pumo@kp.org Beth Pumo]
+
||||x|| [mailto:Beth.Pumo@kp.org Beth Pumo]
 
||||.|| [mailto:oliver@lawless.co Oliver Lawless]
 
||||.|| [mailto:oliver@lawless.co Oliver Lawless]
 
|-  
 
|-  
 
||  .|| [mailto:rdieterle@enablecare.us Bob Dieterle]
 
||  .|| [mailto:rdieterle@enablecare.us Bob Dieterle]
||||.|| [mailto:mario.hyland@aegis.net Mario Hyland]
+
||||x|| [mailto:mario.hyland@aegis.net Mario Hyland]
 
||||.|| [mailto:joe.lamy@aegis.net Joe Lamy]
 
||||.|| [mailto:joe.lamy@aegis.net Joe Lamy]
 
|-  
 
|-  
||  x|| [mailto:Rick Grow]
+
||  .|| [mailto:richard.grow@va.gov Rick Grow]
||||.|| [mailto:Richard Etterma]
+
||||.|| [mailto: Richard Etterma]
||||.|| [mailto:Wayne Kubic]
+
||||.|| [mailto: Wayne Kubic]
 
|-
 
|-
 
|}
 
|}
Line 80: Line 80:
  
 
==Minutes==
 
==Minutes==
 +
* John Moehrke chair
 +
* approval of agenda - Glen/Rob : unanimous
 +
* approval of the [http://wiki.hl7.org/index.php?title=HL7_FHIR_Security_2016-6-14 June 14, 2016 minutes] - Glen/Rob : unanimous
 +
* FHIR spec was updated from last weeks approved CPs, so please review for mistakes.
 +
* Update on action items
 +
* Discussion around _confidentiality code vocabulary.
 +
**[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=9176 9176] Security-Labels page for _confidentialiy points at all "Confidentiality" codes, not just _confidentiality. (John Moehrke) None
 +
** This is fixed now.  http://hl7-fhir.github.io/v3/ConfidentialityClassification/vs.html -- Need to find prior notes where we agreed this needed to be fixed, and close it based on that meeting. Else we can vote in future block vote.
 +
** Temporary fix, Grahame owns the longer term and wider problem with Vocabulary wg
 +
*9563 -- assigned to Kathleen, to work with Rob -- Following the discussion in the CP
 +
**[http://gforge.hl7.org/gf/project/fhir/tracker/?action=TrackerItemEdit&tracker_item_id=9563 9563] Add onBehalfOf to Signature datatype ()
 +
** Edited on the call the Signature datatype to be submitted as 'pre-applied' in preparation for future vote.
 +
** updated CP also with text Rob provided.
 +
* Discussion with Mario on testing
 +
** Kathleen would like to focus on the Financial use-case
 +
*** Mario is concerned that the financial use-case might be not mature enough, and no have the broadest representation. Indicating that the percentage of connectathon participants is small compared to others
 +
*** John I am concerned this is too focused of a set of people. Meaning we don't get new players. I do think that Financial should include use of Provenance. So might we focus Provenamce on Financial?
 +
** John would like to focus on Lab use-case
 +
*** John - I want a significant use-case (so not Patient) that stands on its own. Meaning people want to test to that use-case alone (Financial also meets these two criteria).
 +
** We agree that the addition of AuditEvent testing would be an additional layer, not a mandatory part of the fundamental use-case. (Seems someone has indicated that we wanted it to be mandatory, and Grahame has pushed back. We don't want to be mandatory (yet))

Latest revision as of 12:58, 22 June 2016

Call Logistics

Weekly: Tuesday at 05:00 EST (2 PM PST)

Conference Audio: 770-657-9270,' Access: 845692
Join online meeting: https://meet.RTC.VA.GOV/suzanne.gonzales-webb/67LLFDYV
If you are having difficulty joining, please try: 
https://global.gotomeeting.com/join/520841173  
 Please be aware that teleconference meetings are recorded to assist with creating the meeting minutes 

Back to HL7 FHIR security topics

Attendees

Member Name Member Name Member Name
x John Moehrke Security Co-Chair x Kathleen Connor Security Co-Chair x Suzanne Gonzales-Webb CBCC Co-Chair
. Gary Dickinson EHR Co-Chair . Johnathan ColemanCBCC Co-Chair . Mike Davis
. Reed Gelzer RM-ES Lead . Glen Marshal . Galen Mulrooney
x Dave Silver x Rob Horn . Judy Fincher
x Diana Proud-Madruga x Beth Pumo . Oliver Lawless
. Bob Dieterle x Mario Hyland . Joe Lamy
. Rick Grow . [mailto: Richard Etterma] . [mailto: Wayne Kubic]

Agenda

  • Roll;
  • approval of agenda
  • approval of the June 14, 2016 minutes
  • FHIR spec was updated from last weeks approved CPs, so please review for mistakes.
  • Update on action items
  • Discussion around _confidentiality code vocabulary.
  • 9563 -- assigned to Kathleen, to work with Rob -- Following the discussion in the CP
    • 9563 Add onBehalfOf to Signature datatype ()
  • 9564 -- assigned to John -- following the discussion in the CP
    • 9564 Should FHIR AuditEvent resource include DICOM extension of ATNA Audit log message ? ()
  • 7568 -- assigned to Kathleen, seems this should be satisfid by 9840? -- following the discussion in the CP
    • 7568 2015May core #859 - How are agent and activity linked? ()
  • 3318 -- assigned to Rick to work with Mike -- following the discussion in the CP
    • 3318 Clarify how to use RBAC and ABAC using FHIR ()
  • 9042, 9043, 9052 -- assigned to Kathleen, she has the XML almost ready to go
    • 9042 Add RBAC as value set for AuditEvent.participant.role ()
    • 9043 Add ABAC as alternative value set for AuditEvent.participant.role ()
    • 9052 Add SNOMED Stuctural Roles as value set for AuditEvent.participant.role ()
  • 9167 -- assigned to John, only creating an example AuditEvent -- following the discussion in the CP
    • 9167 AuditEvent needs to make more obvious how to record a break-glass event ()
  • 9996 -- assigned to Glen -- following the discussion in the CP
    • 9996 Using Provenance resource to annotate content derived from non-FHIR sources ()
  • FMM evaluation vs desire - We picked 4 last week -- We might want to re-evaluate to level 3. As level 4 means we would need to work hard to get "complete" testing tools and procedures at 100% of functionality. I think we should only target getting some testing ready.
  • Discussion with Mario on getting prepared for next connectathon
    • What use-case should we focus on? (Lab vs Financial vs Patient)
  • Discussion around Record Lifecycle events (6303)? Are we going to support this? Are the vocabulary done yet? (Gary will join)
    • 6303 Add Record Lifecycle Events to AuditEventObjectLifecycle Set (Gary Dickinson) None
  • Prepare for a block vote for next week --

Minutes

  • John Moehrke chair
  • approval of agenda - Glen/Rob : unanimous
  • approval of the June 14, 2016 minutes - Glen/Rob : unanimous
  • FHIR spec was updated from last weeks approved CPs, so please review for mistakes.
  • Update on action items
  • Discussion around _confidentiality code vocabulary.
    • 9176 Security-Labels page for _confidentialiy points at all "Confidentiality" codes, not just _confidentiality. (John Moehrke) None
    • This is fixed now. http://hl7-fhir.github.io/v3/ConfidentialityClassification/vs.html -- Need to find prior notes where we agreed this needed to be fixed, and close it based on that meeting. Else we can vote in future block vote.
    • Temporary fix, Grahame owns the longer term and wider problem with Vocabulary wg
  • 9563 -- assigned to Kathleen, to work with Rob -- Following the discussion in the CP
    • 9563 Add onBehalfOf to Signature datatype ()
    • Edited on the call the Signature datatype to be submitted as 'pre-applied' in preparation for future vote.
    • updated CP also with text Rob provided.
  • Discussion with Mario on testing
    • Kathleen would like to focus on the Financial use-case
      • Mario is concerned that the financial use-case might be not mature enough, and no have the broadest representation. Indicating that the percentage of connectathon participants is small compared to others
      • John I am concerned this is too focused of a set of people. Meaning we don't get new players. I do think that Financial should include use of Provenance. So might we focus Provenamce on Financial?
    • John would like to focus on Lab use-case
      • John - I want a significant use-case (so not Patient) that stands on its own. Meaning people want to test to that use-case alone (Financial also meets these two criteria).
    • We agree that the addition of AuditEvent testing would be an additional layer, not a mandatory part of the fundamental use-case. (Seems someone has indicated that we wanted it to be mandatory, and Grahame has pushed back. We don't want to be mandatory (yet))