Slide 1

Slide 1 text

Health Level Seven® Privacy and Security Standards

Slide 2

Slide 2 text

● ● ● ● ● ● Outline

Slide 3

Slide 3 text

Introduction

Slide 4

Slide 4 text

● ● ● EHR Definition

Slide 5

Slide 5 text

EHR,Patient Receives Care Across Care Providers & Settings

Slide 6

Slide 6 text

EHR,Clinician systems “put” relevant data for sharing into interoperable EHR

Slide 7

Slide 7 text

EHR,Clinician systems “list” and “get” desired data from interoperable EHR for display and use

Slide 8

Slide 8 text

EHR,Patient Receives Care Across Care Providers & Settings

Slide 9

Slide 9 text

Data Segmentation for Privacy (DS4P)

Slide 10

Slide 10 text

● ● ● What is Data Segmentation for Privacy?

Slide 11

Slide 11 text

● ● ● What is Data Segmentation for Privacy? Think about some of the key features to access Personal Health Information

Slide 12

Slide 12 text

Potential System Components of a Data Segmentation for Privacy Solution locally in a provider system - privacy consents - organizational policies - jurisdictional policies stored in a centralized database As jurisdictional and organizational policies are always subject to change: What it would be preferable for organizational/jurisdictional policies to be expressed in a centralized or a locally way?

Slide 13

Slide 13 text

Potential System Components of a Data Segmentation for Privacy Solution rules engine

Slide 14

Slide 14 text

Potential Data Components Jurisdictional Privacy Policies: ● ●

Slide 15

Slide 15 text

Potential Data Components a standardized way for EHRs to tag where the data was created change would only have to be made at the policy decision point rules engine

Slide 16

Slide 16 text

Potential Data Components Privacy Consent: are patient preferences about sharing information.These consents overcome default organizational/jurisdictional sharing policies (share/don’t share) ● Using the policy decision point/rules engine to segment data based on privacy consents ● Using “privacy metadata” to help the policy decision point/rules engine adjudicate privacy consents

Slide 17

Slide 17 text

Potential Data Components ● ● ●

Slide 18

Slide 18 text

Review final, consented Use Case Document: http://wiki.siframework.org/Data+Segmentation+for+Privacy+Use+Cases Review the latest version of the Data Segmentation for Privacy Implementation Guidance (IG): http://wiki.siframework.org/Data+Segmentation+for+Privacy+Standards+and+Harmonization View the paper written by Scott Weinstein & Ioana Singureanu: http://wiki.siframework.org/Data+Segmentation+for+Privacy+Paper References

Slide 19

Slide 19 text

● ● ● Items for discussion

Slide 20

Slide 20 text

What it would be preferable for organizational/jurisdictional policies to be expressed in a centralized or a locally way? It may be preferable for organizational/jurisdictional policies to be expressed in a centralized way (either on a website or in a database), so that when policies change the local systems do not have to correct every policy for every patient in their system.

Slide 21

Slide 21 text

… … … … Key Features, To access Personal Health Information

Slide 22

Slide 22 text

DS4P which brought together stakeholders, from providers to health IT standards experts, health IT vendors… to discuss technological solutions that would allow for this behavioural health information to be sent with metadata or data that explain the protections that must be afford and particularly the importance of not redisclosing this information beyond that sharing that take place in accordance with the patient wishes. How Does DSP4S it protect against redisclosure of confidential patient information?

Slide 23

Slide 23 text

● ● ● ● ● ● ● ● EHR Key Clinical & Business Req