Wednesday, February 1, 2012

As Massachusetts prepares a Request for Response (RFR)  to procure healthcare information exchange infrastructure and applications,  many stakeholders have been hard at work documenting requirements.

The Provider Directory and Public Key infrastructure are some of the hardest specifications to write since they have not yet been widely deployed for healthcare information exchange anywhere in the country.

The leaders of the Massachusetts HIE effort have held 3 major vendor and user forums over the past month and have been told that no vendor has a standards-based provider directory in production at any customer site.

Here's our best thinking about Provider Directory and Public Key infrastructure services.

Provider Directory
The Directory will have a schema within a relational database that enables lookup of entities, which could include a person (John Halamka),  an organization (BIDMC), a department (The BIDMC Department of Emergency Medicine), a state entity (Massachusetts Department of Public Health),   a payer (Blue Cross Blue Shield of Massachusetts), a vendor (The Massachusetts eHealth Collaborative Quality Data Center), or a PHR infrastructure trusted by the HIE (Microsoft Healthvault).     There will be two ways to query this database - Lightweight Directory Access Protocol (LDAP) for  use within the Massachusetts state government firewall and SOAP-based web service APIs for all users external to the firewall.   The response to a query will include the node name for communication to the entity i.e. John Halamka will not have a node, but the BIDMC Department of Emergency Medicine or BIDMC could.   Digital certificates are not stored in the Provider Directory.

Public Key Infrastructure
Certificates will be issued by a single Certificate Authority and will be stored in one of many Domain Naming System (DNS) services capable of supporting certificate queries such as BIND or Microsoft's special implementation of DNS created for the Direct Project (http://directproject.org/).    For example, BIDMC could offer a DNS service called Direct.bidmc.org which hosts the public keys for all our nodes.

Here's how it would be used.  An EHR would look up an entity in the Provider Directory and then use DNS services to retrieve the certificate for the entity's node.

We're also considering an alternative approach using the open source tools available in the Direct Project's Reference Implementation.   These tools include administrative tools to store and manage certificates and an adapter that links the directory store to a DNS responder.    Participants could upload their certificates to this centralized data store.  For example:

DNS Responder <--DNS Web Services--> Direct Reference Implementation Web Services <--BIDMC adaptor--> BIDMC datastore

The vendor community has told us that they want a single simple directory and public key infrastructure specification they can implement one time for an entire state.   We'll give that to them and I'll write about their responses in future posts.

Related Posts:

  • The April HIT Standards Committee The April HIT Standards Committee focused on refining the work plan for 2013, ensuring that standards work is appropriately divided among SDOs, S&I initiatives, and HITSC committee workgroups.Doug Fridsma presented ONC's … Read More
  • Supporting the LivingMy father died a month ago and I flew to Los Angeles this weekend to help my mother during the grieving process.She's doing very well.The death of a spouse (or father) can be traumatic to everyone involved.  The tasks th… Read More
  • Reflections on the Tragedy in BostonNow that schedules are returning to normal, it's appropriate to review the events of last week and reflect on the lessons learned with the benefit of hindsight.1.  Risk planning is forever alteredTo me, risk is the likel… Read More
  • An IT Perspective on the Bombings in Boston Many reporters have contacted me today for an IT perspective on the April 15 bombings in Boston.  Within moments of the event, social media became the preferred mechanism for communication and coordination.   I was … Read More
  • Optimizing Electronic Medication Administration Records In June, BIDMC goes live with Electronic Medication Records (EMAR) on one ward to be followed by 3 other wards, ensuring we meet our 10% Meaningful Use Stage 2 target by the reporting period October 1-December 31, 2013.We bui… Read More

0 comments:

Post a Comment

Powered by Blogger.

Popular Posts

Blog Archive