Chair: @Kathleen Connor
Scribe: @Suzanne Gonzales-Webb
Weekly calls Tuesdays 3PM ET
https://us02web.zoom.us/j/89559883576?pwd=ckd0N2V1L1FybXhhbHhVdElQekg2QT09
Meeting ID: 895 5988 3576
Passcode: 258923
Find your local number: https://us02web.zoom.us/u/kc8xHnbexU
ATTENDEES - PLEASE TYPE YOUR NAME IN THE CHAT OR IF YOU ARE ON THE CONFLUENCE SITE, PLEASE SCROLL DOWN TO THE BOTTOM AND CHECK YOURSELF IN TO BE COUNTED FOR ATTENDANCE - THANK YOU!
Agenda Topics
Agenda Overview |
| |
Minutes Approval | Approve Meeting Minutes: | Motion to Approve Meeting minutes as written Moved/Second: Beth / Mohammad Vote - Approve/Abstain/Oppose : (7) approved by consensus |
FHIR Security |
Note that we approved Security WG continued co-sponsorship of PSS to revise SMART | |
PSAF Provenance Errata | Review and approve Errata Letter for CTO Consideration QA of final ANSI publication submittal missed that Volume 3 Provenance DAM did not include the Contributor Table. We are requesting an errata version. May not be possible because ANSI has already approved it. Mike's alternative: wants to claim an author name on HL7 formal letterhead (not to add as an ANSI change) | |
Harmonization | https://jira.hl7.org/browse/UP-129 https://jira.hl7.org/browse/UP-128 https://jira.hl7.org/browse/UP-127 https://jira.hl7.org/browse/UP-121 Security WG members who want to vote on these UTG proposals need to sign up to vote. See: Vocabulary Maintenance at HL7 UTG Consensus Review Anyone wishing to participate in the Consensus Review of proposals in flight is welcome to participate. No tooling is required to participate - if you want to be a reviewer/voter on vocabulary change proposals and you are not one already, click this link below: | 11/10 Mohammad already rebased this, and pushed new commit to Bitbucket repo. Should be a timely way to do this - needs to be reviewed and approved by harmonization process so that we don't have to continually redo. Also, Security members who have asked to be reviewers have not been responded to. We will ask that someone from UTG join Security to help us progress our proposals. |
Privacy & Security Logical Data Model | Review and approve P&S Logical Model draft NIB submitted without suffix "Cross-Paradigm" after TSC review. 2020-11-11 Privacy and Security Logical Data Model meeting did not meet quorum.Please review and send Mike comments on V3 Logical Model Draft 1116.docx
Meeting scheduled for document and model review HL7 Privacy and Security Information Model PSS Information model update: The new information model will consolidate and harmonize security models across HL7 standards (Access Control, Audit, TF4FA etc.) and (incomplete) updates from FHIM (Consolidated unresolved models). Also included are direct mappings to Access Control, Audit and Authentication (e.g. Class models) mapped to Access Control services. TSC PSS approval before August 23, 2020 | |
DPROV CDA IG | Update on CBCP transitioning sponsorship to Security. Next steps: STU extension request listing emerging use cases, and possible sponsors for preparing DPROV CDA IG http://www.hl7.org/implement/standards/product_brief.cfm?product_id=420 for normative ballot | |
SOA Consent Management Service | This project is co-sponsored by Security and CBCP. The project's model has progressed and is impressive. However, some of the underlying analysis of policy and consent differ to some extent with Security foundational standards. See PolicyVsConsent.docx MIke reviewed and commented - see attached. | SOA invites Security to join 7 pm ET call Nov 5 Join Zoom Meeting https://hl7-org.zoom.us/j/93128162118?pwd=dnZlSzNVOThpeWdpb2hWOHFMU29aQT09 Phone Number: +1 770-657-9270 |
FHIR DS4P IG | <ADD MOTION> made by Jeff: Security labeling reduces information blocking when used properly. Data holder can share more information by accurately labeling information that should not be shared. This allows for less sensitive information to be shared according to is associated security labeling. The net result is more information shared, along with the ability to defend why sensitive information is not being shared. BLOCK: 1-24 Motion to approve as presented (Suzanne / Mike ) VOTE: abstain/opposed Motion passes (6) Moving comments from spreadsheet into JIRA Tickets - View comments at this link. Postponed early January ballot until regular January ballot cycle. Review and approve FHIR DS4P IG Out-of-cycle ballot request for 10/20 opening date. Carmela A. Couderc block - continue review Review Reconciliation Spreadsheets and JIRA Ballot Recon Missed approval of Reconciliation prior to July 5th Sept NIB due date Security WG Admin Ballot results: Quorum met - 107 voters, FHIR DS4P IG Ballot Passed
Negatives - missing definitions, which is the result of tooling errors we need to fix, and a general misunderstanding that the FHIR DS4P IG is the basis for profiles for policy specific security label IGs much like the CDA DS4P IG is. Only the profiles are implementable. https://www.hl7.org/documentcenter/public/wg/tsc/HL7%20May%202020%20Ballot%20Results.zip Upcoming deadlines:
If you have any questions about these dates or the process, you can check out the FHIR IG Process Flow on Confluence (https://confluence.hl7.org/display/FHIR/B+-+Content+Development+and+Submission) | RE "Data tagging is not always sufficient; in some instances data should not be sent at all." We agree that data tagging is not sufficient if the governing policy requires that certain tagged data not be disclosed. However, data tagging is necessary for filtering on data, which is not disclosed fully as how security labels are used by Access Control Systems is somewhat out of scope. As is, the use cases do not adequately describe that access control will still need to be performed on specific requests even where the requester's capability statement indicate that the requester can consume, persist, and enforce labels. We will discuss how security labels are used in Access Control Systems briefly in the Use Cases http://hl7.org/fhir/uv/security-label-ds4p/2020May/background.html#use-cases and reference other HL7 standards that are more focused on this aspect of data segmentation. That said, this IG is policy agnostic and conceptual. Requirements for the policy specific use cases listed in this comment could be profiled for various policy specific use cases. ===== WG discussed need to continue to emphasize that security labeling enables maximum sharing to avoid information blocking. |
Cross-Paradigm US Regulatory Security Labeling IG | Postponed early January ballot until regular January ballot cycle. Previously approved NIB already submitted. JIRA tickets filed for acceptance of new UTG values/data; motion next week when we bring information forward on the value sets. New CUI Notice 2020-06 RE CUI Marking Waivers with e.g., splash screens, seems to be limited to internal CUI use. FHIR US Regulatory Security Labels Continuous Build - No update in the build GitHub repo for the source material:https://github.com/HL7/us-security-label-regs John and Mohammad are committers. US Regulatory Security Label Example Sandbox US Regulatory Security Label examples were included in the FHIR DS4P IG. These will be the starter set for the FHIR US Regulatory Security Label IG | |
Share with Protections White Paper Project | Worked on ballot recon with Beth for KP comments. Ready for review. | |
Infrastructure SD | Progress on ISD approval of Project for Reaffirmation of Normative Healthcare (Security and Privacy) Access Control Catalog, Release 3 Kathleen moved for Security. Need a second, 3 days of discussion, and then the vote. Reaffirm HL7 Version 3 Standard: Healthcare (Security and Privacy) Access Control Catalog, Release 3 | |
Ballot Management | With the move of the WGM schedule dates to start virtually on January 25, the ballot cycle and content deadline dates have also changed. Nov 8: Next Sunday is the Notification of Intent to Ballot (NIB) deadline – Now November 8th (Ballot minus 6 weeks) Nov 17: FHIR Connectathon proposals due– (The Connectathon dates did NOT change) Nov 29: Reconciliation deadline for ballot items having previously balloted – (Ballot -3 weeks) Dec 13: Final content deadline Dec 18: Ballot opens Dec 27: Deadline for TSC approval of PSS for 2021MAY cycle The on-line Notification of Intent to Ballot form (off of the TSC Utilities page) is available at: http://www.hl7.org/special/committees/tsc/ballotmanagement/index.cfm. All Calendars for this cycle are available on the new Confluence Calendars page at: | |
ONC | Final HL7 ISA and SVAP lettersFinal 2020-2025 Federal Health IT Strategic Plan Now AvailableRead the Plan → Webinar Recording | |
ONC FAST | Next Steps report out. | |
OCR News | ||
Notes from CHAT | Requesting review provide comment / recommend participants review the information (links below) Consent - https://chat.fhir.org/#narrow/stream/179247-Security-and.20Privacy/topic/Consent.20IG.3F Scopes for data access - https://chat.fhir.org/login/#narrow/stream/179175-argonaut/topic/Scopes.20for.20data.20access DS4P IG - https://chat.fhir.org/#narrow/stream/179247-Security-and.20Privacy/topic/DS4P.20IG Fine-grained Security Policies OCR ruling related to Cost for Right of Access Grahame Provenance agent.type vs agent.role value sets and element semantics | |
Useful Links | Confluence and JIRA Tutorials https://confluence.hl7.org/display/HDH#c4472ec9-1ffa-4734-835d-ea12286e013e-31686915 | |
Meeting Adjournment | No additional agenda items brought forward Meeting adjourned at 1350 Arizona time | Meeting recording: <link> |
Attendees
@Adam Wong adam.wong@hhs.gov | HHS | |
ONC | ||
Alexander MenseCo-Chair | HL7 Austria | |
Kaiser | ||
Amol Vyas amol.vyas@cambiahealth.com | Cambia Health | |
Wave One | ||
Aegis | ||
Celine Lefebvre Celine.Lefebvre@ama-assn.org | AMA | |
Clara Y. Ren clara.y.ren.ctr@mail.mil | Federal Electronic Health Records Modernization (FEHRM) Office | |
Chris Shawn, Co-Chair | VA | |
Dave Silver | Electrosoft | |
Ready Computing | ||
@David Staggs drs@securityrs.com | SRS | |
Sequoia | ||
@Heather McComas heather.mccomas@ama-assn.org | AMA | |
EPIC | ||
AEGIS for SSA | ||
Jim Kamper | Altarum | |
Federal Electronic Health Records Modernization (FEHRM) Office | ||
SRS | ||
John Davis (Mike) | VA | |
John Moehrke Co-Chair | By-Light | |
Aegis | ||
Julie Chan jchan@cwglobalconsult.com | CWGlobal | |
Kathleen Connor Co-Chair | VA (Book Zurman) | |
Laura Bright laurabright4@gmail.com | ||
Laura Hoffman laura.hoffman@ama-assn.org | AMA | |
EMR Direct | ||
Sequoia | ||
Matthew Reid matt.reid@ama-assn.org | AMA | |
VA (Book Zurman) | ||
Patient Centric Solutions | ||
PJM Consulting | ||
Phillips | ||
Trustworthy EHR | ||
@Ricky Sahu, @1up.health | 1up Health | |
Rob McClure | rmcclure@mdpartners.com | |
Robert Dieterle rdieterle@enablecare.us | Enablecare | |
Deloitte | ||
Saul Kravitz saul@mitre.org | MITRE | |
Scott Fradkin | sfradkin@flexion.us | |
Jopari | ||
Serafina Versaggi | ||
Stephen MacVicar smacvicar@mitre.org | MITRE | |
VA (Book Zurman) | ||
Terrence Cunningham 'Terry' | AMA | |
Tom Hicke | ||
Patricia A.H. Williams aka Trish | Flinders University | |
Vicki Giatzikis vig9034@nyp.org | NYP |