![]() |
Health Care PKI Project
for Internet Security Presentation
to the CHIA Technology Symposium |
What is the Goal of a Health Information Network
Why The Internet
- Support information exchange that is accurate, authentic, private, and available when and where needed
Why The Internet
- Links together a large array of computer and information systems
- Truly a worldwide computer network supporting public access
- Standards that drive interoperability and cost-efficiencies
- Target of massive research and development
The Internet Security Challenge
- Democratizes the information access environment
- Makes each party responsible for their own domain
- Much simpler on the user
- Commonplace across industries
- Being adopted as the universal network for information exchange
- Concerted effort to develop electronic commerce applications
Will the Health Care Industry Accept Public Network Security
- FedEx
- Charles Swab
- McKesson
- Department of Defense
- Automotive Industry
5 Point Security Model
- Education and awareness
- Technology developments and diffusion
- Business issues and application support
- Collaboration; common expectations
- User acceptance and participation
Identity and Authentication
- Authentication
- Non-repudiation
- Authorization
- Encryption
- Integrity
Short Tutorial Public Key Encryption
- On the Internet No one knows if you’re a dog !
- Authenications becomes a critical component of Internet security
Health Care PKI Project
- Digital Certificates
- Certificate Authority
- Directories
- Navigation Assistance
- Education and Training
Feedback from Providers
- Single identification procedure
- Eliminates multiple separate pins and passwords
- Enables secure email and other data exchange
- Exploits the interest of others who will distribute information via the Internet
Feedback From Information Providers
- Immediate benefits to provider organizations
- CMA has agreed to be active partner
- Providers want to see health plan participation and commitments for specific types of data
- Provider systems with physician organizations are starting to get interested
- Biggest hurdle
- developing an understanding of the concepts
- a strategy for how to introduce electronic communications existing business processes.
A Healthcare PKI Supports Secure Information
- Support move to Internet due to low cost structure and elimination of user hardware/software support
- Some are piloting Internet websites with user passwords and pins, but are wary of support for certificates. Issuing digital certificates to staff is not economical on single resource basis
- Most will not provide sensitive patient or business information without appropriate Internet security provisions
- Certificates are not well understood
- Will increase their efforts to deploy more web-based resources when they see physician buy-in
- Physician participation and acceptance of certificates will unlock web deployment
- Each party connects, as appropriate, to the Internet
- Each party obtains a healthcare certificate for use as electronic identity & authentication
- Providers are responsible for their staff certificates
- Each information provider accepts the healthcare certificate as proof of identity to make authorization assignments
- Authentication and authorization replace need to issue different passwords and pins
- Secure, low cost communications and information distribution solutions encourage increased web deployment
- Content attracts users; users attract content
| Tunitas Group is a Moraga, CA based consulting firm that assists its clients to plan and implement their electronic business and communications initiatives. We analyze policy, evaluate market trends, assess new technology and forecast their implications for the health care industry. We offer expertise in public key infrastructure, directory services, electronic messaging and EDI. The Health Care PKI Project is offered as an industry program to help health care organizations coordinate electronic commerce with their business partners. We can be reached at 925.631.1244 or by eMail to tunitas@earthlink.net |