Patient Authorization

advertisement
Nationwide Health Information Network
Exchange and the
SSA Patient Authorization
June 18, 2012
SSA Background
• Over 3 million initial disability applications a year
• Over 15 million requests for medical evidence each
year (3-4 medical records per case)
• 500,000 sources: doctors, hospitals, etc
• SSA is not a HIPAA covered entity
• Require a patient’s authorization to obtain medical
records
• Initial Federal Agency on the Nationwide Health
Information Network (NwHIN) Exchange
2
Authorized Release of Information
to a Trusted Entity Use Case
• Use Case Scenario
– Social Security Administration requests medical
documentation from a healthcare provider with
the patient’s authorization
Patient Authorization
Patient Authorization
File Disability Claim
Claimant
Request Evidence
SSA/DDS
Claim Determination
Providers
Medical Evidence
3
SSA – 827 (Patient Authorization)
•
•
•
•
•
•
Requestor
Responder
Purpose
Effective Date
Effective Timeframe
Type of Information
Requested
• Signed
4
NwHIN Specifications & Standards
• Content Structure
• Consent Structure
–
–
–
–
HL7 CDA Release 2 CCD
– IHE Basic Patient Privacy
Consents
HITSP C32
• Transport and Security
HITSP C62
Unstructured Documents (pdf,
– Messaging Platform
txt, doc, tif, jpg, gif, png)
– Authorization Framework
• Vocabulary & Code Sets
– Patient Discovery
– ICD-9-CM
– Query for Documents
– Systematized Nomenclature of
– Retrieve Documents
Medicine--Clinical Terms
– Access Consent Policy
(SNOMED-CT)
– Logistical Observation
Identifiers names and Codes
(LOINC)
5
NwHIN Exchange Transaction Flow
Health IT Partner
(NHIE)
SSA
1. Patient Discovery Request
2. Access
Control
Decision
3. Query for Documents Request (Access Consent)
4. Query for Document Response (Access Consent)
Patient
Authorization
5. Retrieve Document Request (Access Consent)
6. Retrieve Document Response (Access Consent)
7. Access
Control
Decision
8. Patient Discovery Response
9. Query for Documents Request (Clinical Document)
10. Query for Document Response (Clinical Document)
11. Retrieve Document Request (Clinical Document)
12. Retrieve Document Response (Clinical Document)
Clinical
Documents
6
Security Assertion
• Subject ID - MEGAHIT
• Subject Organization - Social Security
Administration
• Subject Organization ID 2.16.840.1.113883.3.184
• Subject Role - SNOMED-CT (106328005) – Social
Worker
• Purpose of Use - Coverage
• Patient Identifier – encoded per the NwHIN
Authorization Framework specification
7
Authorization Decision Statement
• NwHIN Exchange uses a Authorization
Decision Statement to allow an entity to
assert the requester should be permitted to
execute the transaction based on a specific
security policy
• Access Consent Policy and Authorization
Framework specifications define the format of
the policy
8
Access Consent Policy
XDS Metadata
XDS Metadata
Value
availabilityStatus
urn:oasis:names:tc:ebxml-regrep:StatusType:Approved
classCode
57016-8 (LOINC)
classCode DisplayName
Privacy Policy Acknowledgement
confidentialityCode
N (Normal)
formatCode
urn:ihe:iti:bppc-sd:2007
formatCode codeSystem
1.3.6.1.4.1.19376.1.2.3
healthcareFacilityTypeCode
385432009 (SNOMED CT code for Not Applicable)
mimeType
text/xml
practiceSettingCode
385432009 (SNOMED CT code for Not Applicable)
serviceStartTime
Effective start date of privacy policy (authorization)
serviceStopTime
Effective end date of privacy policy (authorization)
Title
AUTHORIZATION TO DISCLOSE INFORMATION TO THE SOCIAL
SECURITY ADMINISTRATION
9
Questions
10
For Further Information
• Contact
- Marty Prahl at martin.prahl@ssa.gov
- Bob Hastings at bob.hastings@ssa.gov
11
Reference Materials
•
•
•
•
•
•
NwHIN Exchange Technical Specifications (all of the specifications can be found at
http://www.nationalehealth.org/technical-specifications
Patient Discovery (requestor only) http://www.nationalehealth.org/ckfinder/userfiles/files/Technical%20Specs/Patient_Discove
ry_Production_Specification_v2_0.pdf
Query for Documents (requestor only) http://www.nationalehealth.org/ckfinder/userfiles/files/Technical%20Specs/QueryforDocum
entsProductionSpecification_v3_0.pdf
Retrieve Documents (requestor only) http://www.nationalehealth.org/ckfinder/userfiles/files/Technical%20Specs/Retrieve_Docum
ents_Production_Specification_v3_0.pdf
Access Consent Policy (responder only) http://www.nationalehealth.org/ckfinder/userfiles/files/Technical%20Specs/AccessConsentP
oliciesProductionSpecification_v1_0.pdf
Core Capabilities that support the above transactions
Messaging Platform http://www.nationalehealth.org/ckfinder/userfiles/files/Technical%20Specs/MessagingPlatfo
rmProductionSpecification_v3_0.pdf
Authorization Framework http://www.nationalehealth.org/ckfinder/userfiles/files/Technical%20Specs/AuthorizationFra
12
meworkProductionSpecification_v3_0.pdf
Download