This wiki has undergone a migration to Confluence found Here
<meta name="googlebot" content="noindex">

Difference between revisions of "Security"

From HL7Wiki
Jump to navigation Jump to search
 
(59 intermediate revisions by 3 users not shown)
Line 1: Line 1:
 +
<div style="background-color: white; border: 1px solid red; margin: 4px; padding: 2px; font-weight: bold; text-align: center;">
 +
Current Content related to this page can be found on Confluence [https://confluence.hl7.org/display/SEC/Security+Work+Group Here]</div>
 +
 
{| {{table}}
 
{| {{table}}
 
{| border="10"
 
{| border="10"
| align="center" width="230pt" style="background:#f0f0f0;"|'''Leadership'''
+
| align="center" width="200pt" style="background:#f0f0f0;"|'''Leadership'''
| align="center" width="230pt" style="background:#f0f0f0;"|'''Governance'''
+
| align="center" width="200pt" style="background:#f0f0f0;"|'''Governance'''
| align="center" width="230pt" style="background:#f0f0f0;"|'''Weekly_Meeting_Information'''
+
| align="center" width="200pt" style="background:#f0f0f0;"|'''Weekly_Meeting_Information'''
 
|-
 
|-
 
|-valign="top"
 
|-valign="top"
Line 18: Line 21:
  
 
||
 
||
[http://gforge.hl7.org/gf/project/security/docman/HL7%20Security%20WG%20Administrative%20Documents/May%202017%20Madrid%20Admin/Security%20HL7%20WG%20DMP%20V6.0%202017.docx Security Decision Making Processes]
+
[http://gforge.hl7.org/gf/project/security/docman/HL7%20Security%20WG%20Administrative%20Documents/Security%20WG%20Mission%20and%20Charter/2017%20HL7%20Security%20WG%20Mission%20and%20Charter%20v4.doc Security Mission & Charter 2017]
  
[http://gforge.hl7.org/gf/project/security/docman/HL7%20Security%20WG%20Administrative%20Documents/Security%20WG%20Mission%20and%20Charter/2017%20HL7%20Security%20WG%20Mission%20and%20Charter%20v4.doc Security Mission & Charter 2017]
+
[http://gforge.hl7.org/gf/project/security/docman/HL7%20Security%20WG%20Administrative%20Documents/May%202017%20Madrid%20Admin/Security%20HL7%20WG%20DMP%20V6.0%202017.docx Security Decision Making Processes 2017]
  
 
[http://www.hl7.org/documentcenter/public/wg/secure/HL7%20Security%20SWOT%20Sep%202016.doc SWOT Sep 2016]
 
[http://www.hl7.org/documentcenter/public/wg/secure/HL7%20Security%20SWOT%20Sep%202016.doc SWOT Sep 2016]
  
 
[[Security 3-Year Plan]]  
 
[[Security 3-Year Plan]]  
 +
 +
[http://www.hl7tsc.org/wiki/index.php?title=Foundation_%26_Technology_Steering_Division_Home Infrastructure Steering Division Home]
 +
 +
[[Relevant HL7 Policies and Procedures]]
 +
 +
[https://confluence.hl7.org/display/SEC/Security+Work+Group Security Confluence]
 
||
 
||
  
 
Weekly, '''Tuesday at 3 pm EST''' (12 pm PST)  
 
Weekly, '''Tuesday at 3 pm EST''' (12 pm PST)  
 
Beginning March 28 -    [https://join.freeconferencecall.com/security36 Security WG FreeConference web meeting]
 
Beginning March 28 -    [https://join.freeconferencecall.com/security36 Security WG FreeConference web meeting]
* Online Meeting ID: security36
+
* [https://www.freeconferencecall.com/join/security36 Online Meeting Link]
 
* Dial-in Number: (515) 604-9567 Access Code: 880898  
 
* Dial-in Number: (515) 604-9567 Access Code: 880898  
  
Line 42: Line 51:
  
 
==Security WGM Calendar and Minutes==
 
==Security WGM Calendar and Minutes==
===Upcoming WGM Agenda & Minutes===
+
===January 2019 WGM San Antonio===
*[[HL7 WGM January 2018 - New Orleans US AGENDA]] - Jan 28, 2018 to Feb 2, 2018
+
* Confluence [https://confluence.hl7.org/pages/viewpage.action?pageId=39159947&src=contextnavpagetreemode January 2019 Security WGM Agenda/Minutes/Attendance] - DRAFT
*[[HL7 January 2018 - New Orleans US MINUTES]]
+
* Wiki [[January 2019 Security Working Group Meeting Agenda - San Antonio]] - DRAFT
 +
 
 +
====Previous WGM Links:====
 +
 
 +
*[http://www.hl7.org/documentcenter/public_temp_F0279555-1C23-BA17-0C0C093F748E646F/schedules/balloting_schedule/January%202019%20Balloting%20Schedule.pdf January 2019 Balloting Schedule]
 +
*[[September 2018 Security Working Group Meeting Agenda - Baltimore]]
 +
*[[September 2018 Security Working Group Meeting Agenda- Baltimore (DRAFT)]]
 +
*[http://wiki.hl7.org/index.php?title=HL7_September_2018_WGM_MINUTES HL7 September 2018 WGM MINUTES - Baltimore final]
  
===[[Recent Past WGM Agenda & Minutes]]===
 
*[[HL7 WGM Sept 2017 - San Diego US AGENDA]] - Sept 9, 2017 to Sept 15, 2017
 
*[[HL7 WGM Sept 2017 - San Diego US MINUTES]]
 
 
===[[Security FHIR Connectathons]]===
 
===[[Security FHIR Connectathons]]===
  
 
==Security WG Weekly Meeting Minutes and Agenda==
 
==Security WG Weekly Meeting Minutes and Agenda==
*[[April 24, 2018 Security Conference Call]]
+
 
*[[April 17, 2018 Security Conference Call]]
+
* [https://confluence.hl7.org/display/SEC/2019-01-08+Security+Meeting+Conference+Call+Agenda Security Conference Call, January 8, 2019] Meeting Agenda and Minutes are now located on Confluence!! 
*[[April 10, 2018 Security Conference Call]]
+
** Please do not forget to sign-up for a Confluence Account!!
*[[April 3, 2018 Security Conference Call]]
+
** Link to request an account for Jira/Confluence, https://confluence.hl7.org/#space-menu-link-content  If you have an account for other Work Groups, you do not need to request a new account.
===2018 Q2 ===
+
 
*[[March 27, 2018 Security Conference Call]]
+
* Calls cancelled for holidays until January 8, 2019
*[[March 20, 2018 Security Conference Call]] - No meeting, agenda pushed to 3/27/2018
+
* [[December 11, 2018 Security Conference Call]]
*[[March 13, 2018 Security Conference Call]]
+
* [[December 4, 2018 Security Conference Call]]
*[[March 6, 2018 Security Conference Call]]
+
* [[November 27, 2018 Security Conference Call]]
* [[February 27, 2018 Security Conference Call]]
+
* [[November 20, 2018 Security Conference Call]]
* [[February 20, 2018 Security Conference Call]]
+
* [[November 13, 2018 Security Conference Call]]
* [[February 13, 2018 Security Conference Call]] - Interim Begins
+
* [[November 6, 2018 Security Conference Call]]
* [[February 6, 2018 Security Conference Call]] - Cancelled for WGM
+
* [[October 30, 2018 Security Conference Call]]
* [[January 30, 2018 Security Conference Call]] - Cancelled for WGM
+
* [[October 23, 2018 Security Conference Call]]
* [[January 23, 2018 Security Conference Call]]
+
* [[October 16, 2018 Security Conference Call]]
* [[January 16, 2018 Security Conference Call]]
+
* Calls cancelled to prepare for, attend, and do follow up to September Baltimore WGM Sept 28 - October 5
* [[January 9, 2018 Security Conference Call]]
+
* [[September 18, 2018 Security Conference Call]]
* [[January 2, 2018 Security Conference Call]] - Cancelled for Holidays
+
* [[September 11, 2018 Security Conference Call]]
* [[December 26, 2017 Security Conference Call]] - Cancelled for Holidays
+
* [[September 4, 2018 Security Conference Call]]
* [[December 19, 2017 Security Conference Call]]
+
* [[August 28, 2018 Security Conference Call]]
 +
* [[August 21, 2018 Security Conference Call]]
 +
* [[August 14, 2018 Security Conference Call]]
 +
* [[August 07, 2018 Security Conference Call]]
 +
 
  
 
*[[Security WG Meeting Minutes Template]]
 
*[[Security WG Meeting Minutes Template]]
  
 
==[[Archive - Security WG WGM and Weekly Meeting Minutes and Agenda]]==
 
==[[Archive - Security WG WGM and Weekly Meeting Minutes and Agenda]]==
 +
===[http://wiki.hl7.org/index.php?title=HL7_FHIR_security_topics HL7 FHIR Security Calls]===
  
 
=Security Project Space=
 
=Security Project Space=
 
=='''HL7 Security Review and Comment Topics'''==
 
=='''HL7 Security Review and Comment Topics'''==
 +
===[[GDPR (General Data Protection Regulation)]]===
 
===''[["Is Privacy Obsolete" Study Group Page"]]''===
 
===''[["Is Privacy Obsolete" Study Group Page"]]''===
 
===[[HL7 Kantara and OASIS X-Paradigm Research by Mohammad Jafari]]===
 
===[[HL7 Kantara and OASIS X-Paradigm Research by Mohammad Jafari]]===
 
Features papers and blogs were developed to encourage collaborative development across several standards supporting emerging healthcare privacy and security use cases.
 
Features papers and blogs were developed to encourage collaborative development across several standards supporting emerging healthcare privacy and security use cases.
 
 
===''[[ONC Interoperability Standards Advisory 2018 Review and Comment Page]]''===
 
===''[[ONC Interoperability Standards Advisory 2018 Review and Comment Page]]''===
 
===''[[ONC Trusted Exchange Common Agreement Framework Comments Page]]''===
 
===''[[ONC Trusted Exchange Common Agreement Framework Comments Page]]''===
Line 92: Line 110:
 
===[[FHIR Bulk Data Transfer Privacy and Security Concerns]]===
 
===[[FHIR Bulk Data Transfer Privacy and Security Concerns]]===
 
===[[FHIR Consumer Centered Data Exchange (CCDE) Connectathon]]===
 
===[[FHIR Consumer Centered Data Exchange (CCDE) Connectathon]]===
 +
*[http://wiki.hl7.org/index.php?title=September_2018_Baltimore_CCDE_Connectathon_Track_4 201809 Integrated Care Plan, Clinical Decision Support and Consumer Mediated Exchange tracks]
 +
*[http://wiki.hl7.org/index.php?title=June_2018_MiHIN_Consumer_Mediated_Exchange_(CME)_Connectathon_Track_3 MIHIN June 2018 Consumer Mediated Exchange Connectathon Track 3]
 
*[[January 2018 New Orleans CCDE Connectathon Track 2]]
 
*[[January 2018 New Orleans CCDE Connectathon Track 2]]
 
*[[September 2017 San Diego CCDE Connectathon Track 1]]
 
*[[September 2017 San Diego CCDE Connectathon Track 1]]
 +
 
===[[HL7 Version 2 Privacy and Security]]===
 
===[[HL7 Version 2 Privacy and Security]]===
  
 
=='''[[Archive of HL7 Security Review and Comment Topics]]'''==
 
=='''[[Archive of HL7 Security Review and Comment Topics]]'''==
 
=='''Approved Security WG Projects'''==
 
=='''Approved Security WG Projects'''==
===[[Privacy and Security Framework Architecture (PSAF)]]===
+
==[http://wiki.hl7.org/index.php?title=Privacy_and_Security_Framework_Architecture_(PSAF) Privacy and Security Framework Architecture (PSAF), ''' ''TF4FA Ballot Reconciliation''' '']==
===[[HL7 FHIR security topics]]===
+
* latest [https://gforge.hl7.org/gf/project/security/docman/HL7%20Security%20SOA/PSAF/PSAF%20TF4FA%20May%202018/PSAF%20TF4FA%20May%202018%20Reconciliation/ballotcomments_V3_PSAF_R1_N1_2018MAY%20amalgamated.xls Ballot Reconciliation Sheet]
 +
* <<add link>> Ballot Document
 +
==[[PASS Healthcare Audit Services]] Project==
 +
* [<<add link>> Ballot Reconciliation Sheet]
 +
* <<add link>> Ballot Document
 +
 
 +
===[http://wiki.hl7.org/index.php?title=HL7_FHIR_security_topics HL7 FHIR Security Topics (wiki page)]]===
 
===[[HL7 Patient Friendly Consent Directive Project]]===  
 
===[[HL7 Patient Friendly Consent Directive Project]]===  
 
===[[Trust Label]]===
 
===[[Trust Label]]===
Line 110: Line 137:
 
**[http://healthlevelseven.projectinsight.net/Content/Folders/FolderDisplay.aspx?Id=167add16c33a41968e70be6e22d8d807&ReturnUrl=/Content/Folders/FolderDisplay.aspx%3FId%3Dddbc44e93a52422089595248f65bc993%26ReturnUrl%3D%252fContent%252fFolders%252fFolderDisplay.aspx%253fId%253dddbc44e93a52422089595248f65bc993%2526ReturnUrl%253d%25252fContent%25252fFolders%25252fFolderDisplay.aspx%25253fId%25253dddbc44e93a52422089595248f65bc993%252526ReturnUrl%25253d%2525252fContent%2525252fFolders%2525252fFolderDisplay.aspx%252526_sx%25253d0%252526_sy%25253d0%2526_sx%253d0%2526_sy%253d0%26_sx%3D0%26_sy%3D0 Project Insight - Project Plan]
 
**[http://healthlevelseven.projectinsight.net/Content/Folders/FolderDisplay.aspx?Id=167add16c33a41968e70be6e22d8d807&ReturnUrl=/Content/Folders/FolderDisplay.aspx%3FId%3Dddbc44e93a52422089595248f65bc993%26ReturnUrl%3D%252fContent%252fFolders%252fFolderDisplay.aspx%253fId%253dddbc44e93a52422089595248f65bc993%2526ReturnUrl%253d%25252fContent%25252fFolders%25252fFolderDisplay.aspx%25253fId%25253dddbc44e93a52422089595248f65bc993%252526ReturnUrl%25253d%2525252fContent%2525252fFolders%2525252fFolderDisplay.aspx%252526_sx%25253d0%252526_sy%25253d0%2526_sx%253d0%2526_sy%253d0%26_sx%3D0%26_sy%3D0 Project Insight - Project Plan]
 
* [http://gforge.hl7.org/gf/project/cbcc/scmsvn/?action=browse&path=%2Ftrunk%2FCDA%2520Implementation%2520Guide%2Fdocs%2FCDAR2_CD_IG%2520_D2_2010MAY.pdf&view=log CDA R2 Implementation Guide for Privacy Consent Directives May 2010] joint with [[Community-Based Collaborative Care]]
 
* [http://gforge.hl7.org/gf/project/cbcc/scmsvn/?action=browse&path=%2Ftrunk%2FCDA%2520Implementation%2520Guide%2Fdocs%2FCDAR2_CD_IG%2520_D2_2010MAY.pdf&view=log CDA R2 Implementation Guide for Privacy Consent Directives May 2010] joint with [[Community-Based Collaborative Care]]
===[[PASS Healthcare Audit Services]] Project===
+
 
  
 
===Joint Vocabulary Alignment Project===
 
===Joint Vocabulary Alignment Project===
Line 117: Line 144:
  
 
==='''Joint Projects with ONC and Others'''===
 
==='''Joint Projects with ONC and Others'''===
 +
 
==Updates to the FHIR Security Pages per ONC Precision Medicine Initiative and API Privacy and Security Considerations==
 
==Updates to the FHIR Security Pages per ONC Precision Medicine Initiative and API Privacy and Security Considerations==
 
*[https://www.healthit.gov/sites/default/files/privacy-security-api.pdf KEY PRIVACY AND SECURITY CONSIDERATIONS FOR HEALTHCARE APPLICATION PROGRAMMING INTERFACES (APIS)]
 
*[https://www.healthit.gov/sites/default/files/privacy-security-api.pdf KEY PRIVACY AND SECURITY CONSIDERATIONS FOR HEALTHCARE APPLICATION PROGRAMMING INTERFACES (APIS)]
Line 131: Line 159:
  
 
==Security Harmonization Information==
 
==Security Harmonization Information==
*[[July 2014 Harmonization Proposals]]
+
*[[July 2018 Harmonization Cycle]]
*[[March 2013 Harmonization Proposal]]
+
*[[Security Harmonization Archive]]
*[[November 2013 Harmonization Proposals]]
+
 
*[[July 2013 Harmonization Proposals]]
 
 
=='''[[HL7 Security Video Library]]'''==
 
=='''[[HL7 Security Video Library]]'''==
 
[[File:PoF_Icon.png|400px|thumb|right|Privacy on FHIR]]
 
[[File:PoF_Icon.png|400px|thumb|right|Privacy on FHIR]]

Latest revision as of 18:49, 26 April 2019

Current Content related to this page can be found on Confluence Here
Leadership Governance Weekly_Meeting_Information

Alexander Mense - Program Director Information Management und IT-Security University of Applied Sciences Technikum Wien

Kathleen Connor - VHA Security Architecture – Framework Engineering (Book Zurman Inc.)

John Moehrke - By-Light Professional IT Services, Inc

Trish Williams PhD - Flinders University

Christopher Shawn - VHA Security Architecture

Security Mission & Charter 2017

Security Decision Making Processes 2017

SWOT Sep 2016

Security 3-Year Plan

Infrastructure Steering Division Home

Relevant HL7 Policies and Procedures

Security Confluence

Weekly, Tuesday at 3 pm EST (12 pm PST) Beginning March 28 - Security WG FreeConference web meeting

Call Weekly Call Agenda Links below on this home page. Please be aware that teleconference meetings are recorded to assist with creating the meeting minutes

Foundation and Technology Steering Division Home Page

Contents

Security WGM Calendar and Minutes

January 2019 WGM San Antonio

Previous WGM Links:

Security FHIR Connectathons

Security WG Weekly Meeting Minutes and Agenda


Archive - Security WG WGM and Weekly Meeting Minutes and Agenda

HL7 FHIR Security Calls

Security Project Space

HL7 Security Review and Comment Topics

GDPR (General Data Protection Regulation)

"Is Privacy Obsolete" Study Group Page"

HL7 Kantara and OASIS X-Paradigm Research by Mohammad Jafari

Features papers and blogs were developed to encourage collaborative development across several standards supporting emerging healthcare privacy and security use cases.

ONC Interoperability Standards Advisory 2018 Review and Comment Page

ONC Trusted Exchange Common Agreement Framework Comments Page

FHIR Bulk Data Transfer Privacy and Security Concerns

FHIR Consumer Centered Data Exchange (CCDE) Connectathon

HL7 Version 2 Privacy and Security

Archive of HL7 Security Review and Comment Topics

Approved Security WG Projects

Privacy and Security Framework Architecture (PSAF), TF4FA Ballot Reconciliation

PASS Healthcare Audit Services Project

  • [<<add link>> Ballot Reconciliation Sheet]
  • <<add link>> Ballot Document

HL7 FHIR Security Topics (wiki page)]

HL7 Patient Friendly Consent Directive Project

Trust Label

Security Labeling Service Project Wiki

Healthcare Privacy and Security Classification System

Security and Privacy Ontology Project Wiki

HL7 DS4P CBCC-Security WG Joint Project


Joint Vocabulary Alignment Project

Joint Projects with ONC and Others

Updates to the FHIR Security Pages per ONC Precision Medicine Initiative and API Privacy and Security Considerations

Consent on FHIR

Security WG members collaborating on ONC Patient Choice Project Mike Davis, Duane Decouteau, Mohammad Jafari, and Tony Mallia participated in the ONC Patient Choice Basic Consent Pilots at the HL7 Connectathon. Presentations, demonstration, and other material available on this page.

HIMSS 2017 Patient Choice

Featuring FHIR Consent and Consent2Share with UMA and Smart on FHIR Authorization Servers, ONC Patient Choice pilots VA and MiHIN join SAMHSA to demonstrate how emerging technologies can protect sensitive patient health information in implementer friendly ways. See this page for HIMSS collateral, vignette, and demonstration links.

HIMSS 2017 Patient Choice on FHIR

Security Ballot Information

Security Harmonization Information

HL7 Security Video Library

Privacy on FHIR

HL7 Security Document Library

Security WG Reference Model Code

Action Item List

Tracking List