210 likes | 440 Views
HL7 Security WG November 2012 Harmonization Proposals. Kathleen Connor VA (ESC) Oct. 23, 2012. Nov 2012 Proposals. Change CEL Sensitivity Code to VIP Change PRD Sensitivity Code to PDS General POU Technical Correction Security Observation Vocabulary. Change CEL Sensitivity Code to VIP.
E N D
HL7 Security WG November 2012Harmonization Proposals Kathleen Connor VA (ESC) Oct. 23, 2012
Nov 2012 Proposals • Change CEL Sensitivity Code to VIP • Change PRD Sensitivity Code to PDS • General POU Technical Correction • Security Observation Vocabulary
Change CEL Sensitivity Code to VIP Proposal: • Change CEL Code to VIP, as VIP is considered by the Security WG to be the conventional code for this concept, and therefore, more user-friendly • No change to print name or definition
Change PRD Sensitivity Code to PDS Proposal: • Change PRD Code to PDS is more user-friendly • No change to print name or definition
General POU Technical Correction • Technical Correction to July 2012 Harmonization Proposal “2012Jul_HARM_Approved_FINALPROPOSAL_VOCAB_SECURE_kathleen_connor_Final PurposeOfUse_20120701160914” • Need to add COVERAGE and ETREAT in GeneralPurposeOfUse value set as approved in previous cycle.
Security Observation Vocabulary • Enables association of Security Metadata with HL7 Acts and Roles, e.g., • Confidentiality Codes • Sensitivity and Privacy Law Codes • Obligation and Refrain Codes • Integrity Codes • Integrity Status – e.g., legally authenticated • Integrity Confidence – e.g., reliable, not reliable • Provenance – e.g., reported by clinician, asserted by patient • Data Integrity – e.g., ensured by digital signature • Data Alteration – e.g., masked, anonymized
Integrity Status Definition • Conveys the completion status or workflow state of a Resource • (data, information, objects or system capabilities, which may be targets of access control decisions) • May be used to determine a user’s (Initiator’s) entitlement to operate on a Resource based on its completion status, e.g., legally authenticated or in progress • Binds to HL7 DocumentCompletionCode System • Defined as: Identifies the current completion state of a clinical document.
Integrity Confidence Definition • Conveys the perceived or policy-based attribution of likely veracity or trustworthiness of a Resource for the purpose of use for which it is being acted upon. • The user should consider IntegrityConfidence when making decisions based on that resource. • For example, a Resource created by a clinician and used for treatment may be perceived or assigned a higher level of IntegrityConfidence than a Resource created by a patient.
Provenance Definition • Conveys metadata about the originating source of the Resource especially when reported second-hand by another author. Examples of vocabulary include: • Clinician, Healthcare Professional, Patient, Payer, Device reported • Clinician, Healthcare Professional, Patient, Payer, Device asserted
Use of Security Observation Vocabulary • Supports • Resource Security Labels • Requester Security Clearance • Enables labeling of CDA Entries with codes for • Confidentiality • Sensitivity • Obligation • Refrain • Integrity
Resource Security Classification Label S& DAM Resource attributes convey key Security Classification Labels: + categoryType + confidentiality + sensitivity + compartment + integrityStatus + integrityConfidence + provenance + dataIntegrity + dataAlteration Resource “compartment” may be populated with information from component classes such as Policy/Program
Initiator Security Clearance Label S& DAM Initiator attributes convey key Security Clearance Label Fields: + resourceCategoryType + POU + confidentiality + sensitivity + compartment + integrityStatus + x509SubjectName + LoA Initiator “compartment” may be populated with information from Hierarchical and Functional Group