Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Blog
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Events
  • HIMSS JobMine
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » Privacy and Security
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Tiger team proposes authentication policies for data exchange

November 18, 2010 | Mary Mosquera, Contributing Editor

Related Resources

  • Focus on Patient Care without Worrying about Underlying Technology
  • Securing Electronic Health Records to Achieve "Meaningful Use" Compliance, Prevent Data Theft and Fraud
  • Intel Drives National Discussion on IT Infrastructure for ACOs
  • Reimagining the U.S. Healthcare System: Investing in Innovative Health IT to Support the 21st Century Personal Health Model
  • Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management

WASHINGTON – A Department of Health and Human Services advisory group has proposed broad steps that healthcare organizations should take in order to establish their corporate identities for the simple exchanges of patient information that will be required under the first stage of meaningful use.

All organizations involved in health data exchange should have digital credentials, such as electronic certificates, to assure they are who they say they are, according to the privacy and security tiger team, which works under HHS's Health IT Policy Committee.

The team proposed authentication policies for the direct electronic exchange of health records between providers, where sender and receiver are most likely known to each other. Authentication, one of the guardrails of privacy and security, is critical when transactions involve any patient risk or the potential exposure personal health information, according to tiger team members.

The Office of the National Coordinator wants to build the public's confidence in simple organization-to-organization electronic health record exchanges using its NHIN Direct project, a streamlined version of nationwide health information network specifications.

The goal of authentication is to assure that computer systems link to the correct organization's gateway in such transactions, said Deven McGraw, chair of the tiger team and director of the health privacy project at the Center for Democracy and Technology.

"For the lightweight set of recommendations for stage one, there is an assumption that the organizations are more likely to know one another even if their computers don't know one another" said McGraw.

"That is likely to change in stages two and three," she said at a Nov. 12 meeting of the tiger team to finalize recommendations that it plans to submit to the policy committee Nov. 19.

Looking for balance

The group has tried to find a balance between an appropriate level of confidence in an identity and the cost and business burden to establish authentication of organizations. It has concentrated on steps for authenticating organizations only. The tiger team may consider authentication of individuals when it wrestles with more privacy and security issues next year, McGraw said.

"Electronic health records should be able to accommodate any authentication policies that organizations mandate," McGraw said, adding "we have a lever in certification to make sure the systems have the capability to be authenticated and digitally credentialed."

Eventually, EHRs will have to support two-factor authentication as health information exchange becomes more complex.

To obtain digital certificates, organizations will have to demonstrate they are a legitimate business, using a business license or financial account, and that they participate in healthcare transactions required for meaningful use.

Multiple categories of organizations, such as vendors and state agencies, will need to issue digital credentials in order to meet the demand for secure health information exchange, McGraw said.

Groups that perform credentialing should build on existing criteria or processes. "Issuers of digital certificates should bootstrap onto existing processes as much as possible, and the national provider identifier would be one of them," McGraw  said.
 
For example, the National Plan and Provider Enumeration System collects identifying information on healthcare providers and assigns each a unique identifier under the Health Insurance Portability and Accountability Act.

Mary Mosquera
Senior Editor for Government Health IT
Follow Mary on Twitter @GovHITreporter
Related Topics:
  • Department of Health and Human Services
  • Deven McGraw
  • Mary Mosquera
  • Washington
  • Privacy and Security

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • 6 things patients want from social media
  • FCC gives green light to wireless medical devices
  • Tablet adoption by docs soars
  • Lawsuit seeks Allscripts CEO's removal
  • Web First: Q&A with Allscripts CEO Glen Tullman
  • 6 reasons physicians need to be on social media
  • Oregon to implement new statewide HIE
  • Tablet adoption by docs soars
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • WHITE PAPERS
    The Scarborough Hospital: Establishing a Document Management Strategy for EHRs
  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
More Resources
Syndicate content

HIMSS JOBMINE

  • Clinical Informatics Physician - Epic - Verona, WI
  • Regional Senior Quality Analyst - Memorial Medical Center - Modesto, CA
  • Network Engineer II - Carilion Clinic - Roanoke, VA
  • EMR Implementation - Project Manager Rothman Specialty Hospital - Rothman Specialty Hospital - Bensalem, PA
  • Director of Information Systems - Mission Regional Medical Center - Mission, Texas
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy