Friday, October 7, 2011

As the discussion of the functionality to be included in a Nationwide Health Information Network (NwHIN) continues, there are 3 different secure transports being evaluated:

Exchange:  “NHIN Messaging Platform Specification”, which uses SOAP for transport and WS-I Basic Security Profile for security (TLS + XML signature + WSDL + AES + X.509 + SAML)

Direct:  “Applicability Statement for Secure Health Transport”, which uses SMTP for transport and S/MIME for security (AES + X.509)

Secured REST:  specification to be done, but will use HTTP for transport; candidates for security include TLS, X.509, and OAuth.

Each has different characteristics and different strengths.   The barrier to RESTful implementation is lack of a consistent implementation guide.

The folks at MITRE have implemented project hData  noting that "Current electronic health data standards are complex, hard to implement, and difficult to manage”.

hData separates transport and packaging from content – something the HIT Standards Committee has supported.   This FAQ provides more details.  Clearly hData is still in development and not yet adopted, but I do think they are pursing an appropriately simple approach to transport.

The hData content format has been balloted by HL7 and a Draft Standard for Trial Use (DTSU) is expected this month.  The hData transport format (RESTBinding) is in the Open Management Group comment resolution phase.

A RESTful implementation guide for healthcare that separates content and transport, providing easy to implement,  secure transport.    That's cool.

Related Posts:

  • Hospital Disaster PlanningIn my role as CIO and a Professor of Medicine, I'm asked many questions about the policies, processes, and procedures of healthcare.   Here's one I was recently asked about Hospital Disaster planning. Meg Femino, BIDMC D… Read More
  • The BIDMC Laptop Encryption ProgramI've been writing about the Bring Your Own Device (BYOD)/Consumer IT challenge for the past several months.  Today, an action plan goes into effect.   Here's the message we sent to employees:"Information Systems wil… Read More
  • Separating Professional and Hospital RecordsAs Patient Centered Medical Homes and Accountable Care Organizations form, the lines between professional and hospital practice become increasingly murky.CMS has long required that hospital and professional records be separab… Read More
  • Our Cancer Journey Week 30Today Kathy visited her oncologist to discuss a 5 year course of anti-estrogen (tamoxifen) therapy.    I've said before that Cancer is chronic disease and although the first phase of our journey ends on July 31 afte… Read More
  • The July HIT Standards Committee MeetingThe July HIT Standards Committee focused on a discussion of maturity and adoptability criteria for standards, a review of recent testimony regarding best practices for electronic identity authentication of providers, an updat… Read More

0 comments:

Post a Comment

Powered by Blogger.

Popular Posts

Blog Archive