Example: bankruptcy

Frequently Asked Questions (FAQ) - Health IT

Frequently Asked Questions (FAQ) Federal Health Architecture Directed Health Exchange Security Sub-Work Group May 2015 Federal Health Architecture Program Management Office | Office of the National Coordinator for Health IT | Department of Health and Human Services Capital View Office Building Website: General Email: 425 3rd Street SW, Washington, DC 20004 MAY 2015 Frequently Asked Questions (FAQ) ABSTRACT This document is the work product of the Federal Health Architecture (FHA) Directed Exchange Working Group (FHA DEWG).

MAY 2015 Frequently Asked Questions (FAQ) ABSTRACT. This document is the work product of the Federal Health Architecture (FHA) …

Tags:

  Health, Question, Frequently, Asked, Frequently asked questions, Health it

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Frequently Asked Questions (FAQ) - Health IT

1 Frequently Asked Questions (FAQ) Federal Health Architecture Directed Health Exchange Security Sub-Work Group May 2015 Federal Health Architecture Program Management Office | Office of the National Coordinator for Health IT | Department of Health and Human Services Capital View Office Building Website: General Email: 425 3rd Street SW, Washington, DC 20004 MAY 2015 Frequently Asked Questions (FAQ) ABSTRACT This document is the work product of the Federal Health Architecture (FHA) Directed Exchange Working Group (FHA DEWG).

2 It contains Frequently Asked Questions that Working Group members determined relevant to examining federal participation in Direct. It provides interpretations and understanding of technology and policy matters pertaining exclusively to federal agencies. Every effort has been made to provide the best and most authoritative answers through consultation with knowledgeable experts; however, caution should be taken when extending use beyond its intent purely as a Working Group guideline. As such the viewpoints expressed may not be applicable to all readers. Note: Reminder this is a FAQ document. For Guidance details, please see the FHA Directed Exchange Guidelines document located at in the resource box on the right.

3 MAY 2015 Frequently Asked Questions (FAQ) TABLE OF CONTENTS 1. 4 Must all Direct Exchange Certificates be Cross-Certified with the Federal Bridge 4 . in Order for Federal Agencies to Fully Participate in Direct?.. Can Direct Certificates held by a HISP have the Non-Repudiation bit set?.. 4 Is it true that the non-repudiation (NR) bit in certificates used by HISPs must .be turned off?.. 4 What kind of certificates must be used to support BB+? .. 4 What are the Direct requirements for Certificate Verification?

4 5 Is the subject of the Direct address bound certificate ever in possession 5 . (as defined by NIST) of the private key? If yes, then when? .. What are the Pros and Cons of Address/Domain-bound Certificates? .. 5 How can Direct Endpoint Users (Senders and Receivers) be known to each other at a 6 . prescribed Federal NIST level of assurance? .. Do patients entities/individuals have the same identity proofing requirements as an 7 . enterprise representative/individual? .. How is the identity of representatives of organizations being issued certificates and 7 . individuals using HISP services established?

5 What are HIPAA s general requirements for verifying the individual s identity when the individual requests that the Health care provider furnish an electronic 8 . copy of the individual s Blue Button Health information? .. What are the Use cases for transmitting Blue Button Health information?.. 8 2. Direct Messaging, HIPAA and the 9 Are all providers who use Direct covered entities under HIPAA privacy rule?.. 9 Is direct exchange information sent by a covered entity (CE) to a patient s HealthV ault account using the patient s direct email account considered PHI once it is received and loaded into the patient's PHR under the following 2 scenarios?

6 When HealthVault is a Business Associate of the Covered Entity? ..9 Does a Business Associate of a HIPAA entity need to sign an MOU or Business Associate Agreement to participate in Direct? .. 10 Does an entity that is not a HIPAA covered entity need to sign an MOU/contract with HISPs?.. 10 Are patient actions in Direct with regards to their own healthcare information covered under HIPAA?.. 10 MAY 2015 Frequently Asked Questions (FAQ) Is transmitting PHI on behalf of a patient using Direct a covered electronic transaction under the HIPAA regulation?

7 10 3. What is the architecture approach taken by the federal agencies participating in the FHA Directed Exchange activity?.. 11 What is the purpose of the FHA Directed Exchange Workgroup Risk Assessment? .. 11 What is a Security and Trust Agent (STA) vs. a Health Information Service Provider (HISP) and how are they distinguished?.. 11 HealthVault and Direct 12 Are there any restrictions on to whom a patient may send Direct messages? .. 12 Per the Applicability Statement, Can a Direct user apply a digital signature to a document transported by Direct? .. 13 What is a Trust Framework and how does it apply to Direct Messaging?

8 14 What are the Consequences to a Covered Entity for Direct Messages Sent on Behalf of a Patient?.. 14 MAY 2015 Frequently Asked Questions (FAQ) 1. Certificates Must all Direct Exchange Certificates be Cross-Certified with the Federal Bridge in Order for Federal Agencies to Fully Participate in Direct? Entities wanting to exchange direct messages with federal agencies must use federal bridge certificates until a commercial equivalent is available that provides that same level of assurance as the federal bridge certificate policy.

9 Please see Guideline one of the FHA Directed Exchange Guidelines PowerPoint located at in the resource box on the right Can Direct Certificates held by a HISP have the Non-Repudiation bit set? There is no reason stated in the Direct applicability statement (see link below) or known technical reason why a HISP could not set the bit and stand by it. How the messages are handled at the receiver would imply whether somebody can use that promise meaningfully for messages they ve received. For more information about non repudiation please see the white paper titled: Certificate Issuance and Assurance in Direct, page 11, A Note on Non-Repudiation located at +Statement+for+Secure+ Health +Transport+W orki ng+Version Is it true that the non-repudiation (NR) bit in certificates used by HISPs must be turned off?

10 The source of this statement (urban myth) is not known; however, see: 2011consensus at the time was that the NR bit is fundamentally a statement that the certificate holder intends a signature from this certificate to be binding on them. See Item , Specifically the Certificate Issuance and Assurance in Direct white paper, page 11, A Note on Non-Repudiation located at What kind of certificates must be used to support BB+? BB+ discussion regarding certificates can be found at: #certificates 4 MAY 2015 Frequently Asked Questions (FAQ) What are the Direct requirements for Certificate Verification?


Related search queries