Nationwide Health Information Network Exchange and the SSA Patient Authorization June 18, 2012 SSA Background • Over 3 million initial disability applications a year • Over 15 million requests for medical evidence each year (3-4 medical records per case) • 500,000 sources: doctors, hospitals, etc • SSA is not a HIPAA covered entity • Require a patient’s authorization to obtain medical records • Initial Federal Agency on the Nationwide Health Information Network (NwHIN) Exchange 2 Authorized Release of Information to a Trusted Entity Use Case • Use Case Scenario – Social Security Administration requests medical documentation from a healthcare provider with the patient’s authorization Patient Authorization Patient Authorization File Disability Claim Claimant Request Evidence SSA/DDS Claim Determination Providers Medical Evidence 3 SSA – 827 (Patient Authorization) • • • • • • Requestor Responder Purpose Effective Date Effective Timeframe Type of Information Requested • Signed 4 NwHIN Specifications & Standards • Content Structure • Consent Structure – – – – HL7 CDA Release 2 CCD – IHE Basic Patient Privacy Consents HITSP C32 • Transport and Security HITSP C62 Unstructured Documents (pdf, – Messaging Platform txt, doc, tif, jpg, gif, png) – Authorization Framework • Vocabulary & Code Sets – Patient Discovery – ICD-9-CM – Query for Documents – Systematized Nomenclature of – Retrieve Documents Medicine--Clinical Terms – Access Consent Policy (SNOMED-CT) – Logistical Observation Identifiers names and Codes (LOINC) 5 NwHIN Exchange Transaction Flow Health IT Partner (NHIE) SSA 1. Patient Discovery Request 2. Access Control Decision 3. Query for Documents Request (Access Consent) 4. Query for Document Response (Access Consent) Patient Authorization 5. Retrieve Document Request (Access Consent) 6. Retrieve Document Response (Access Consent) 7. Access Control Decision 8. Patient Discovery Response 9. Query for Documents Request (Clinical Document) 10. Query for Document Response (Clinical Document) 11. Retrieve Document Request (Clinical Document) 12. Retrieve Document Response (Clinical Document) Clinical Documents 6 Security Assertion • Subject ID - MEGAHIT • Subject Organization - Social Security Administration • Subject Organization ID 2.16.840.1.113883.3.184 • Subject Role - SNOMED-CT (106328005) – Social Worker • Purpose of Use - Coverage • Patient Identifier – encoded per the NwHIN Authorization Framework specification 7 Authorization Decision Statement • NwHIN Exchange uses a Authorization Decision Statement to allow an entity to assert the requester should be permitted to execute the transaction based on a specific security policy • Access Consent Policy and Authorization Framework specifications define the format of the policy 8 Access Consent Policy XDS Metadata XDS Metadata Value availabilityStatus urn:oasis:names:tc:ebxml-regrep:StatusType:Approved classCode 57016-8 (LOINC) classCode DisplayName Privacy Policy Acknowledgement confidentialityCode N (Normal) formatCode urn:ihe:iti:bppc-sd:2007 formatCode codeSystem 1.3.6.1.4.1.19376.1.2.3 healthcareFacilityTypeCode 385432009 (SNOMED CT code for Not Applicable) mimeType text/xml practiceSettingCode 385432009 (SNOMED CT code for Not Applicable) serviceStartTime Effective start date of privacy policy (authorization) serviceStopTime Effective end date of privacy policy (authorization) Title AUTHORIZATION TO DISCLOSE INFORMATION TO THE SOCIAL SECURITY ADMINISTRATION 9 Questions 10 For Further Information • Contact - Marty Prahl at martin.prahl@ssa.gov - Bob Hastings at bob.hastings@ssa.gov 11 Reference Materials • • • • • • NwHIN Exchange Technical Specifications (all of the specifications can be found at http://www.nationalehealth.org/technical-specifications Patient Discovery (requestor only) http://www.nationalehealth.org/ckfinder/userfiles/files/Technical%20Specs/Patient_Discove ry_Production_Specification_v2_0.pdf Query for Documents (requestor only) http://www.nationalehealth.org/ckfinder/userfiles/files/Technical%20Specs/QueryforDocum entsProductionSpecification_v3_0.pdf Retrieve Documents (requestor only) http://www.nationalehealth.org/ckfinder/userfiles/files/Technical%20Specs/Retrieve_Docum ents_Production_Specification_v3_0.pdf Access Consent Policy (responder only) http://www.nationalehealth.org/ckfinder/userfiles/files/Technical%20Specs/AccessConsentP oliciesProductionSpecification_v1_0.pdf Core Capabilities that support the above transactions Messaging Platform http://www.nationalehealth.org/ckfinder/userfiles/files/Technical%20Specs/MessagingPlatfo rmProductionSpecification_v3_0.pdf Authorization Framework http://www.nationalehealth.org/ckfinder/userfiles/files/Technical%20Specs/AuthorizationFra 12 meworkProductionSpecification_v3_0.pdf