Difference between revisions of "March 15, 2016 Security Conference Call"
Line 15: | Line 15: | ||
||||.|| [mailto:aaron.seib@2311.net Aaron Seib] | ||||.|| [mailto:aaron.seib@2311.net Aaron Seib] | ||
|- | |- | ||
− | || | + | || X|| [mailto:mense@fhtw.onmicrosoft.com Alexander Mense] Security Co-chair |
||||.|| [mailto:ken.salyards@samhsa.hhs.gov Ken Salyards] | ||||.|| [mailto:ken.salyards@samhsa.hhs.gov Ken Salyards] | ||
||||.|| [mailto:cbrown@socialcare.com Christopher D Brown] TX | ||||.|| [mailto:cbrown@socialcare.com Christopher D Brown] TX | ||
Line 30: | Line 30: | ||
|- | |- | ||
− | || || [mailto:Suzanne.Webb@engilitycorp.com Suzanne Gonzales-Webb] | + | || |x| [mailto:Suzanne.Webb@engilitycorp.com Suzanne Gonzales-Webb] |
− | |||||| [mailto:mailto:robert.horn@agfa.com Rob Horn] | + | |||||x| [mailto:mailto:robert.horn@agfa.com Rob Horn] |
||||.|| [mailto:Galen.Mulrooney@JPSys.com Galen Mulrooney] | ||||.|| [mailto:Galen.Mulrooney@JPSys.com Galen Mulrooney] | ||
Line 42: | Line 42: | ||
|| .|| [mailto:rgrow@technatomy.com Rick Grow] | || .|| [mailto:rgrow@technatomy.com Rick Grow] | ||
||||.|| [mailto:pknapp@pknapp.com Paul Knapp] | ||||.|| [mailto:pknapp@pknapp.com Paul Knapp] | ||
− | |||| | + | ||||x|| [mailto:Mayada.Abdulmannan@va.gov Mayada Abdulmannan] |
|- | |- | ||
− | || | + | || x|| [mailto:gfm@securityrs.com Glen Marshall], SRS |
||||.|| [mailto:akleinebe@gmail.com Bill Kleinebecker ] | ||||.|| [mailto:akleinebe@gmail.com Bill Kleinebecker ] | ||
||||.|| [mailto:Christopher.Shawn2@va.gov Christopher Shawn] | ||||.|| [mailto:Christopher.Shawn2@va.gov Christopher Shawn] | ||
Line 53: | Line 53: | ||
||||.|| [mailto:serafina.versaggi@gmail.com Serafina Versaggi ] | ||||.|| [mailto:serafina.versaggi@gmail.com Serafina Versaggi ] | ||
|- | |- | ||
− | || | + | || x|| [mailto:Beth.Pumo@kp.org Beth Pumo] |
||||.|| [mailto:russell.mcdonell@c-cost.com Russell McDonell] | ||||.|| [mailto:russell.mcdonell@c-cost.com Russell McDonell] | ||
||||.|| [mailto:paul.petronelli@gmail.com Paul Petronelli ], Mobile Health | ||||.|| [mailto:paul.petronelli@gmail.com Paul Petronelli ], Mobile Health | ||
|- | |- | ||
|| .|| [mailto:cdoss@ncat.edu Christopher Doss] | || .|| [mailto:cdoss@ncat.edu Christopher Doss] | ||
− | |||| | + | ||||x|| [mailto:kamalinivaidya@systemsmadesimple.com Kamalini Vaidya] |
||||.|| [mailto: TBD ] | ||||.|| [mailto: TBD ] | ||
|- | |- |
Revision as of 16:22, 22 March 2016
Back to Security Work Group Main Page
Attendees
x | Member Name | x | Member Name | x | Member Name | |||
---|---|---|---|---|---|---|---|---|
x | Kathleen ConnorSecurity Co-chair | . | Duane DeCouteau | . | Chris Clark | |||
x | John MoehrkeSecurity Co-chair | . | Johnathan Coleman | . | Aaron Seib | |||
X | Alexander Mense Security Co-chair | . | Ken Salyards | . | Christopher D Brown TX | |||
. | Trish WilliamsSecurity Co-chair | . | Gary Dickinson | . | Dave Silver | |||
x | Mike Davis | . | Ioana Singureanu | . | Mohammed Jafari | |||
|x| Suzanne Gonzales-Webb | Rob Horn | . | Galen Mulrooney | |||||
x | Diana Proud-Madruga | . | Ken Rubin | . | William Kinsley | |||
. | Rick Grow | . | Paul Knapp | x | Mayada Abdulmannan | |||
x | Glen Marshall, SRS | . | Bill Kleinebecker | . | Christopher Shawn | |||
. | Oliver Lawless | . | ... | . | Serafina Versaggi | |||
x | Beth Pumo | . | Russell McDonell | . | Paul Petronelli , Mobile Health | |||
. | Christopher Doss | x | Kamalini Vaidya | . | [mailto: TBD ] |
Agenda DRAFT
- ( 5 min) Roll Call, Agenda Approval
- ( 5 min) Approve Security WG March 8 Conference Call Minutes
- (10 min) Discuss any comments on Draft ISO 21089 Health informatics — Trusted
end-to-end information flows for submission by 215 National Member Bodies. Appendices include FHIR Record Lifecycle Event Implementation Guide from FHIR DSTU-2
- (10 min) Review HL7 2017 ONC Interoperability Standards Advisory Cover Letter and HL7 2017 ONC Interoperability Standards Advisory draft recommendations
- ( 5 min) PASS Access Control Services Conceptual Model - Diana
- ( 5 min) Joint Vocabulary Alignment Update - Diana
- ( 5 min) PASS Audit Conceptual Model – Diana
- ( 5 min) FHIR Security report out - John
- Any changes expecting to be tested at the next FHIR Connectathon need to be submitted into the build by March 27th.
Note that there will be a FHIR Security call at 2pm PT/5pm ET See agenda at FHIR Security Agenda
Minutes
Approve Security WG March 15 Minutes- Approved
Review
- Discuss any comments on Draft ISO 21089 Health informatics — Trusted (Mike)
end-to-end information flows for submission by 215 National Member Bodies. Appendices include FHIR Record Lifecycle Event Implementation Guide from FHIR DSTU-2
- Discussion on EHR WKGP/FHIR Record cycle events
- Comments were accepted by EHR WKG
- Based on FHIR second edition
(Document was shared on screen)
- Review of Appendix A (Healthcare Interoperability Examples)
- Comments, Mike:
1) No copy right notices regarding HL7 Material 2) Appendix B Life Cycle Mta Data Capture; Rick and Mike reviewed and found the table to be confusing The W5 is highlighted
- the coding is not clear
- We were not clear on the action performers are recording Record Author User, or Record by Author User?
Is this an action performer, needs further clarity by Gary. 3) Question if Audit Event is a Column heading or description, the layout is not clear Note: Gary is creator of the table confirmed by Diana) difficulty understanding the table for W5 3) Appendix B, Questions on coding 4) to Change Record to Record life cycle event
- Note: The appendicitis were copied from the FHIR implementation guide
Issues/Concerns, Mike:
- Draft has been presented to TC215 Group
- From the U.S Tag TC215 there are 2 member
- Gary informed it has been submitted and HL7 does not have the right to comment but can see parts of the appendices
- Hl7 is an ISO specification, HL7 should be able to participate (Rick)
- Diana is waiting to hear from TC215 Secretary to obtain details on how Hl7 can participate
- According to Gary the appendicitis are copied from the FHIR implementation guide, part of DSTU- Diana
- initial ballot is in May, and Official Ballet is in July
- Remedy is to remove material
- Content issue can be addressed with tag
Action Item: (Kathleen, )
- Bring up to FHIR Management Governance board with HL7
- Provide them highlights of concerns
- Have them reviewed and make a motion
Motion (s) : 2 approve/ 1 abstain
1)As a group to speak to notify Karen Vann voicing Governance Concerns
and provide recommendations and comments
2) Security Co-Chairs to notify Johnathan regarding the tables and obtain recommendation
Next Steps:
- HL7 chairs would let him know we would appreciate more input (Mike)
- Security work group has a item to review the tags
- harmonization action to improve the existing lifecycle vocab
- if that was done the FHIR can then take that Lifecycle vocab
Note: The life cycle audit event that has a lifecycle element is Diacom
- Review HL7 2017 ONC Interoperability Standards Advisory Cover Letter and HL7 2017 ONC Interoperability Standards Advisory draft recommendations
- no new update, no new issues (John)
- Health Care Privacy Security by Design -
- deferred until further discussion
- invite to be sent to group
- Joint Vocabulary Alignment Update - Diana
- meetings will resume next week
- PASS Audit Conceptual Model – Diana
- waiting to hear back from Alex on the withdrawal of the negative vote, will reach out to Alex
- Functional Model is available
- New material: We have detailed requirements on high level audit requirements surrounding the service
- FHIR Security report out - John
- Approvals of CP's
- Approved CPS are updates
- Signature is now in discussion