future of privacy in health it · today’s privacy control systems are very limited – limited...

21
© 2011 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited. Future of Privacy in Health IT ISPAB Briefing, May 30, 2012 Gerald Beuchelt Approved for Public Release. Distribu3on Unlimited.

Upload: others

Post on 05-Aug-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

© 2011 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited.

Future of Privacy inHealth IT ISPAB Briefing, May 30, 2012 Gerald Beuchelt

Approved for Public Release. Distribu3on Unlimited.

Page 2: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

Mission Statement

As a public interest company, MITRE works inpartnership with the government, applying systemsengineering and advanced technology to addressissues of critical national importance.

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

2

Page 3: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

     

   

MITRE’s Focus on Health IT

■ Through this work, MITRE manages the critical tradeoffs between agile cybersecurity and timely data sharing and analysis. Examples include: – hData Standards for Electronic Health Information – Kairon Patient Consent Management – popHealth Population Health Monitoring

■ Demonstrate simple, secure, and standards-based health information exchange – Apply proven web technologies to health domain for

secure and private exchange – Apply hData using Patient Data Server (PDS) – Inform possible new standards

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

3

Page 4: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

   

     

     

Patient-Centric Privacy

■ Basic access control available today through limitedprivacy controls

– Individual Clinical Documents can be marked as sensitive – Coarse granularity

■ Web Based Privacy and Access Management – Looking at web-centric authentication and authorization protocols – Focus on developing PII and HIPAA compliant profile

■ Future requirements – Minimally: individual entry-level granularity – Ideally: XML node based access control

Page 4 © 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 5: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

Data Sharing Aspects: Patient Centric

■ Resource-orientation enables application of user-centric identitymanagement to theclinical domain – Patient can allow

advanced EHR systemsinto a personal health data federation

– Patient-managed withprivacy-preserving policydefaults

■ Enables patient-moderated cross-organizational datasharing

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 6: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

Future Patient-Centric Scenario

Patient

Patient registers with Discovery

and Authorization Service

Discovery and Authorization

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 7: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

PCP Visit

Patient sees PCP during regular visit Patient Everything is ok

Discovery and Authorization

Patient authorizes PCP

system to federate with PCP patient discovery service

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 8: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

Emergency: Sports Accident

Sees emergency room surgeon after

sports accident. ER Surgeon Patient

Surgeon EHR system is authorized;

discovers existing systems from patient service Discovery and Authorization

PCP

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 9: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

Data Retrieval and Subscription

Sees emergency room after

a sports accident. ER Surgeon Patient

Gets the relevant data from the

PCP EHR system. Also subscribes

to PCP EHR system. Discovery and Authorization

PCP

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 10: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

Data Retrieval and Subscription

Performs procedure and

prescribes new medication ER Surgeon Patient

Updates local records with new data

Discovery and Authorization

PCP

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 11: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

Discovery Service Check

ER Surgeon Patient

Discovery and Authorization

Discovers new system from

surgeon and updates subscription PCP

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 12: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

PCP System Update

ER Surgeon Patient

Subscribes to data for

patient from new system

and updates records Discovery and Authorization

PCP

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 13: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

Follow Up Visit

Sees PCP for follow up;

PCP prescribes new

ER Surgeon Patient medication

Discovery and Authorization

PCP

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 14: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

Near Real Time Update

ER Surgeon Patient

Updates data via subscription;

obtains new medications

Discovery and Authorization

PCP

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 15: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

Near Real Time Notification

ER Surgeon Patient

Warns patient and PCP about

potential problems with medication

Discovery and Authorization

PCP

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 16: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

Patient-Centric Provider Change

ER Surgeon Patient

Patient decides to change

surgeon; updates authorization

service to deny future access Discovery and Authorization

PCP

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 17: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

Subscription Access Revoked

ER Surgeon Patient

Access tokens are revoked;

surgeon system cannot get more data

Discovery and Authorization

PCP

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 18: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

Interoperability with Patient Consent

Request Server (e.g., hData) Browser

Record Holder Server

EHR

Policy Enforcer

Consent Server

Consent DB

Policy Reasoner

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

18

Page 19: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

   

Example for Privacy and Consent Problems ■ Patient wants to hide his mental health condition from his

dentist – Dentist should not be able to infer from clinical data that patient

has mental health problem ■ Dentist wants to prescribe pain killer

– Drug-drug interaction between Lithium and Ibuprofen that requires close monitoring of blood Lithium levels

■ If dentist knows about Lithium, he knows about mentalhealth problems

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 20: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

       

   

   

Conclusions

■ Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control decision – Limited or no patient-facilitated privacy controls

■ Future systems will be capable of – Enable patient access control and consent for inter-

organizational data sharing

– Fully automated identity-based discovery of EHR services – Semantically consistent application of patient preferences

Page 20 © 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited

Page 21: Future of Privacy in Health IT · Today’s privacy control systems are very limited – Limited automatic cross-organizational data sharing – Fallback to human-managed access control

More Information

■ MITRE Center for Transforming Health

http://www.mitre.org/work/health/

Public Release Approvals: 09-2805, 09-4511,09-4513, 09-4557, 09-5212, 10-0100, 12-2251

Page 21

© 2012 The MITRE Corporation. All rights Reserved. Approved for Public Release. Distribution Unlimited