July 8, 2009

Version 1.3

HITSP Security and Privacy Technical Note

HITSP/TN900   Click here to download the PDF version of this document

Healthcare Information Technology Standards Panel (HITSP) logo

Submitted to:

Healthcare Information Technology Standards Panel

Submitted by:

Security, Privacy and Infrastructure Domain Technical Committee

(Formerly Security and Privacy Technical Committee)

Document Change History

Version Number

Description of Change

Name of Author

Date Published

1.0

Review Copy

Security and Privacy Technical Committee

July 20, 2007

1.0.1

Review Copy

Security and Privacy Technical Committee

October 5, 2007

1.1

Released for Implementation

Security and Privacy Technical Committee

October 15, 2007

1.1.1

Review Copy

Security, Privacy and Infrastructure Domain Technical Committee

August 20, 2008

1.2

Released for Implementation

Security, Privacy and Infrastructure Domain Technical Committee

August 27, 2008

1.2.1

Review Copy

Security, Privacy and Infrastructure Domain Technical Committee

June 30, 2009

1.3

Released for Implementation

Security, Privacy and Infrastructure Domain Technical Committee

July 8, 2009

Table of Contents

1.0 Introduction. 6

1.1 Overview. 6

1.1.1 HITSP Security and Privacy Policy. 6

1.1.2 HITSP Security and Privacy Management Overview. 7

1.2 Security and Privacy Relationship to Use Cases. 7

1.3 Copyright Permissions. 7

1.4 Terminology. 7

1.5 HITSP References. 7

2.0 Security and Privacy Scope. 9

2.1 Security and Privacy Principles. 9

2.2 Policy Groups. 11

2.3 Guidance Standards. 12

2.4 Relationship of Constructs to Security and Privacy Policies. 12

2.5 Focus of Construct Development on Interoperability. 13

3.0 Roadmap and Gaps of the HITSP Security and Privacy Constructs. 15

3.1 Selection of Security and Privacy Constructs. 15

3.2 Roadmap for Security and Privacy Constructs. 16

3.3 Limitations from Use Cases/Value Cases/Harmonization Requests. 16

3.4 Requirements Outside the Current Scope. 16

3.4.1 Gaps and Resolution Recommendations Specific to Security and Privacy Constructs. 18

4.0 Security and Privacy Constructs. 20

4.1 HITSP Security and Privacy Construct Overview. 20

4.2 Relationship Between Security and Privacy Principles and Constructs. 20

4.3 Overview of Construct Characteristics. 22

4.4 Conceptual Relationship Between Constructs. 30

4.4.1 Management of Consent directives and Access Control 30

4.4.2 Nonrepudiation of origin, and document integrity. 31

4.4.3 Emergency Access. 31

4.5 Description of Security and Privacy Constructs. 32

4.5.1 HITSP/T17 Secured Communication Channel 32

4.5.2 HITSP/T15 Collect and Communicate Security Audit Trail 33

4.5.3 HITSP/SC109 Security Audit 33

4.5.4 hitsp/tp20 Access Control 34

4.5.5 HITSP/SC108 Access Control 34

4.5.6 HITSP/TP13 Manage Sharing of Documents (with Document Integrity Option) 35

4.5.7 HITSP/C19 - Entity Identity Assertion. 35

4.5.8 HITSP/C26 - Nonrepudiation of Origin. 36

4.5.9 HITSP/T16 - Consistent Time. 37

4.5.10 HITSP/TP30 - Manage Consent Directives. 37

4.5.11 HITSP/C25 Anonymize. 38

4.5.12 HITSP/T24 Pseudonymize. 39

4.5.13 HITSP/C44 - Secure Web Connection. 39

5.0 Security and Privacy Management Background. 40

5.1 Privacy Background. 40

5.2 Risk Management 42

5.2.1 Defining and Managing Risk. 42

5.2.2 Developing a Risk Management Framework. 43

5.3 Risk Assessment 43

5.3.1 Organizational (Strategic) vs. System (Tactical) Risk Assessments. 43

5.4 Security Management 44

6.0 Glossary. 45

7.0 Appendix. 46

7.1 Information Policy Management 46

8.0 Change History. 50

8.1 October 5, 2007. 50

8.2 October 15, 2007. 50

8.3 August 20, 2008. 50

8.4 August 27, 2008. 50

8.5 JUNE 30, 2009. 50

8.6 July 8, 2009. 51

Figures and Tables

Figure 4-1 Dynamic Security and Privacy Constructs. 31

Figure 7-1 Policy Concepts. 47

Table 1-1 HITSP Reference Documents. 8

Table 2-1 Guidance Standards. 12

Table 3-1 HITSP Security and Privacy Constructs. 15

Table 3-2 Out-of-Scope Requirements Assessment 17

Table 3-3 Construct Standards Gaps. 18

Table 4-1 Relationship of Privacy Principles and HITSP Security and Privacy Constructs. 21

Table 4-2 Relationship of Security Principles and HITSP Security and Privacy Constructs. 22

Table 4-3 Security and Privacy Construct Summary. 23

Table 4-4 Reference Documents. 30