490 likes | 625 Views
Discussion on the Western States Consortium and Inter-State Exchange. Robert Cothren, California Health eQuality Institute for Population Health Improvement. Who we are…. Focus…. Investigating the policies, procedures, and technologies that allow interstate exchange of health information.
E N D
Discussion on the Western States Consortium andInter-State Exchange Robert Cothren, California Health eQualityInstitute for Population Health Improvement
Focus… Investigating the policies, procedures, and technologies that allow interstate exchange of health information.
Use Case Using Direct to exchange clinical information between providers across state lines for treatment purposes. • Includes investigation of policies, procedures, and technologies. • “Using Direct” concentrates on a simple use case being implemented today. • “Across state lines” is a more complex version of “with unaffiliated providers”. • “Between providers” and “for treatment purposes” places focus on interstate exchange rather than patient privacy issues.
Use Case Using Direct to exchange clinical information between providers across state lines for treatment purposes. Really about scalable trust. Two important components… • Establishing a Trust Community. • Discovering how to communicate with others.
Use Case – the Future Using Direct to exchange clinical information between providers across state lines for treatment purposes. Focus on this use case for now, but we want to prepare for the future… • Use cases beyond Direct. • Use cases within state lines but between unaffiliated organizations. • Use cases beyond between providers. • Use cases beyond treatment purposes.
Pilot Scenarios Using Direct to exchange clinical information between providers across state lines for treatment purposes. Scenario 1 The sender knows the Direct address of the recipient. • Defines a Trust Community of HISPs that conform to Eligibility Criteria. (governance task) • Creates a Trust Bundle as the identities of Qualified Entities. (technology task) • Currently underway.
Creating a Trust Community Moving from today’s world of point to point trust agreements…. … to tomorrow’s world of scalable trust.
Creating a Trust Community • Policies for sharing of information between HISPs. • Eligibility criteria that look a little like accreditation. • A process for managing and distributing trust anchors.
So on to the meat… Using Direct to exchange clinical information between providers across state lines for treatment purposes. Scenario 1 The sender knows the Direct address of the recipient. Not today’s topic.
Question We are looking for input, so will be asking questions today. A little practice… • What is your favorite color? My favorite color is blue. I don’t like blue all that much.
Context • Many states are focused on implementing Direct. • Direct doesn’t require provider directories, but directories can facilitate use cases where the sender doesn’t know in advance recipients’ addresses and other desired information. • Many solutions include address books or some other level of provider directory to serve their participants internally. • However – the ability for participants to query directories outside of their HISP/HIE will be needed to continue to advance today’s exchange objectives and facilitate tomorrow’s.
Pilot Scenarios Using Direct to exchange clinical information between providers across state lines for treatment purposes. Scenario 1 The sender knows the Direct address of the recipient. Scenario 2a The sender does not know the Direct address of the recipient.
The picture… • What is Dr. Smith’s Direct address? query HISP (directory) HISP (directory) response NCHIN, an HIO operating a HISP with a directory in California. CareAccord, operating the statewide HISPwith a directoryin Oregon.
The purpose… • Test an emerging standard for Directory Services query. • Drive out additional requirements as a result of user feedback. • Address these issues without complications of federation.
Who are we talking about? • For the WSC, and for right now, there is a one-to-one correspondence between HISPs and directories. • This may not always be the case: • A HISP may use a third party directory provider. • A state may implement a statewide directory for multiple HISPs. • A HISP may have multiple directories to serve multiple geographies.
Pilot Scenarios Using Direct to exchange clinical information between providers across state lines for treatment purposes. Scenario 1 The sender knows the Direct address of the recipient.. Scenario 2a The sender does not know the Direct address of the recipient. • Requires that a HISP use a searchable provider directory containing provider demographics. (operations task) • Defines a standard for Directory Services to query a provider directory for a Direct address. (technology task) • Currently underway.
Concept of Operations Trivial Case – Message to a local recipient. • For most HISPs, this is functionality that exists today. • Requires that there be a provider directory populated with appropriate demographic information to perform a search. NCHIN DirectoryOperated by NCHIN HISP Fills out query form. Retrieves Direct address. Ensures recipient address is appropriate. Sends message. Audit Log Directory Authorized User Searches local directory. Locates matching entry. Presents match to user.
Concept of Operations Scenario 2a – Queryanother HISP. Oregon LDSOperated by CareAccord HISP LDS = local directory service, e.g. operated by a HISP Audit Log Directory Logs received query. Searches local directory. Locates matching entry. Sends response to NCHIN; logs sent response. Fills out query form. Retrieves Direct address. Ensures the recipient address is appropriate. Sends message. NCHIN LDSOperated by NCHIN HISP Audit Log Directory Authorized User Recognizes recipient not in local directory. Sends query to CareAccord LDS; logs sent query. Logs received response. Presents match to user.
The standards… SOAP: Robust web services standard widely accepted for health information exchange. HPD: Emerging IHE (LDAP) standard for Healthcare Provider Directory data model. HPDPlus: Emerging EHR | HIE Interop Workgroup recommendation that adds more robust organizational elements to HPD. DSML: OASIS standard for querying an LDAP directory. S&I: Guidance on query for individual.
The standards… SOAP: Robust web services standard widely accepted for health information exchange. HPD: Investigating an update to incorporate HPDPlus functionality. HPDPlus: Commitment of many industry partners, plans to adopt / align with IHE adjustments to HPD. DSML: OASIS standard for querying an LDAP directory. S&I: Looking for experience of states implementing provider directories.
Question There is a concern over protection of PII. • Should directory query be authenticated? Yes, I want to know who is asking the question. No, we should keep this simple. It is public information.
Question There is a concern over protection of PII. • Should directory query be authenticated? • This is a technology question implementing a policy decision. • Currently, WSC approach is to include authentication between directory systems using TLS. • Note that individuals are NOT authenticated. • There is an assumption of system/organizational trust, part of “scalable trust”.
Question We have said that we will log a query. • What information should be logged? Nothing. Date and time, querying org, the query. Date and time, querying org, the query, the response.
Question We have said that we will log a query. • What information should be logged? • While the technology may be “complicated”, this is really a policy question. • Currently, WSC response is to log all queries and responses, but reconsidering responses since they include PII. • Question for thought: What would you do with log information?
Pilot Scenarios Using Direct to exchange clinical information between providers across state lines for treatment purposes. Scenario 1 The sender knows the Direct address of the recipient. Scenario 2a The sender does not know the Direct address of the recipient. Scenario 2b The sender does not know the Direct address or the HISP of the recipient.
The picture… • What is Dr. Smith’s Direct address? query State State IPHI, acting on behalf of California. CareAccord, acting on behalf of Oregon. response response query NCHIN, an HIO operating a HISP with a directory in California. HISP
The need for Scenario 2a… Scenario 2a… • Requires knowledge of each HISP in Trust Community. • Requires knowledge about geography or customers served by each HISP. • Is not scalable; requires coordinating updates to every HISP every time… … a new HISP is added, or … a HISP changes the customers it serves. Scenario 2aleads back to…
The big picture… Where we are headed… California Statewide Provider Directory OregonSDS SDS = state directory service CaliforniaSDS NevadaSDS Hides complexity of federation. NCHINLDS AlaskaSDS HawaiiSDS SD BeaconLDS RWMNLDS SCHIELDS IEHINLDS LDS = local directory service
The big picture… Where we are headed… Western States California Statewide Provider Directory OregonSDS SDS = state directory service CaliforniaSDS NevadaSDS Hides complexity of federation. NCHINLDS AlaskaSDS HawaiiSDS SD BeaconLDS RWMNLDS SCHIELDS IEHINLDS LDS = local directory service
The big picture… Where we are headed… California OregonSDS California Statewide Provider Directory SDS = state directory service SDS = state directory service CaliforniaSDS NevadaSDS Hides complexity of federation. Hides complexity of federation. NCHINLDS AlaskaSDS HawaiiSDS SD BeaconLDS RWMNLDS SCHIELDS IEHINLDS LDS = local directory service LDS = local directory service
The purpose… • Continue to test an emerging standard for Directory Services query. • Drive out additional requirements as a result of user feedback. • Address federation!
Who are we talking about? • For the WSC, and for right now, California is implementing a federated directory service. • There are almost 30 HIOs operating in California, with 5 separate HISPs. • This complexity should be hidden from the provider. • The California state node stores no data; all directory information is managed by local directories.
Pilot Scenarios Using Direct to exchange clinical information between providers across state lines for treatment purposes. Scenario 1 The sender knows the Direct address of the recipient. Scenario 2a The sender does not know the Direct address of the recipient. Scenario 2b The sender does not know the Direct address or the HISP of the recipient. • Builds on Scenario 2a. • Addresses scalability by adding state Directory Service and federation.
Concept of Operations Scenario 2b – Query a state’s Directory Service. SDS = state directory service Acts as an SDS and hides federation. California SDSOperated by IPHI/CHeQ Oregon SDSOperated by CareAccord HISP Audit Log Audit Log Directory Logs received query. Recognizes recipient not in California. Sends query to Oregon; logs sent query. Logs received response. Forwards response to NCHIN. Logs received query. Searches statewide directory. Locates matching entry. Sends response to California; logs sent response. NCHIN LDSOperated by NCHIN HISP Fills out query form. Retrieves Direct address. Ensures recipient address is appropriate. Sends message. Audit Log Directory Authorized User Recognizes recipient not in local directory. Sends query to California SDS; logs sent query. Logs received response. Presents match to user.
Concept of Operations Scenario 2b – Query a state’s Directory Service. SDS = state directory service Acts as both an SDS and an LDS. California SDSOperated by IPHI/CHeQ Oregon LDSOperated by CareAccord HISP Audit Log Audit Log Directory Logs received query. Forwards query to LDS(es); logs sent queries. Logs received response(s). Aggregates response(s). Forwards response(s) to Oregon. Recognizes recipient not in Oregon Sends query to California; logs sent query. Logs received response. Presents matches to user. NCHIN LDSOperated by NCHIN HISP Fills out query form. Retrieves Direct address. Ensures recipient address is appropriate. Sends message. Audit Log Directory Authorized User Logs received query. Searches local directory. Locates matching entry. Sends response to California SDS; logs sent response.
The standards… SOAP: Robust web services standard widely accepted for health information exchange. HPD: Investigating an update to incorporate HPDPlus functionality. HPDPlus: Addresses the need for complex organizational descriptions within the data model; not yet accepted or implemented. DSML: Not designed to address federation; one query to one directory. S&I: Looking for experience of states implementing provider directories.
Question Federation allows for centralized or distributed policy decisions. • Should the decision to respond be centralized or local? Leave the decision with those responsible for the data. Users have an expectation, so policy should be uniform.
Question Federation allows for centralized or distributed policy decisions. • Should the decision to respond be centralized or local? • For now, WSC is adopting an approach of local autonomy. Each state and directory operator should be empowered to decide on whether to respond to a query.
Question We said we should log information about the query. DSML does not support federation. • What do you need to know about “who”? I need to know the name of the individual. I need to know the name of the organization (i.e., the HISP). I need to know the name of the state.
Question We said we should log information about the query. DSML does not support federation. • What do you need to know about “who”? • For now, WSC is passing only the identity of the last organization in a query. • Oregon knows the query came from California. • California knows the query came from NCHIN. • NCHIN knows the query came from Dr. Jones.
Question DSML does not support federation. You can only have one response to a query. • What do you do if someone errors? Pass on all the matches there were. Sometimes the Internet fails. Pass on the matches, but report an error. I don’t know.
Question DSML does not support federation. You can only have one response to a query. • What do you do if someone errors? • This is a technical issue with user experience implications. • WSC is trying to think of the user. • What would the user do with the information? • Should errors be only an administrator’s issue? • If a user didn’t get the information they expected,would they just ask again? • DSML doesn’t support the answer we like.
Question DSML and HPDPlus support querying for members of an organization. Directory operators are concerned about protecting directory information. • Should directory queries allow browsing? No, you need to know enough to get a single response. Yes, users are expecting to be able to browse a directory.
Question DSML and HPDPlus support querying for members of an organization. Directory operators are concerned about protecting directory information. • Should directory queries allow browsing? • Must be controlled by policy. • WSC decided that browsing should not be allowed. • The first time a query was placed, the user asked “but why can’t I get a list of the members”? • Our users have an expectation. • If we meet that expectation, we open the door to fishing. • This is what pilots are for!
Question DSML allows for a rich set of query capabilities. Directory operators are concerned about protecting directory information. • Is there a minimum standard for wildcards? No, we decided that should be left to the directory operators. Yes, so the users know what to expect.
Question DSML allows for a rich set of query capabilities. Directory operators are concerned about protecting directory information. • Is there a minimum standard for wildcards? • This is really a policy decision. • For now, WSC has not established any requirements for minimum data in the query.
Question HPD and HPDPlus are complex. They may not be uniformly populated. End users need to be able to decide whether they can use the address. • Is there a minimum standard for data that must be included in a response? No, any information is useful and the user is smart enough. Yes, directory operators to create good directories.
Question HPD and HPDPlus are complex. They may not be uniformly populated. End users need to be able to decide whether they can use the address. • Is there a minimum standard for data that must be included in a response? • This is really a policy decision. • For now, WSC has not established any requirements for minimum data in the response.