HIMSIG20080418
SIG-HIM
Conference Call
April 18th 2008
ACTION: Have this call same time next Friday (on April 25) – let’s look at the CCHIT use cases and work to make a response for input.
Greetings
John opened the call, greeted the participants and gave an overview of the planned agenda:
Dan Combs - Overview of the health care system and Federation today.
Asa Hardcastle – Overview of Openliberty activities
Overview of the health care system and federation today, Dan Combs
EXAMPLE: Medical professionals and identity
How can you tell who people are in the healthcare emergency field? Various other examples of how people can use the internet to hurt people. One example was a person posted some visuals on an epilepsy board that would cause a seizure to occur.
One Simple use case is to allow a hospital to act as an IdP.
There’s also a situation where you might want to check credentials of posters who ‘give’ medical advice on line. It seems most of it would be bogus. One way to deal with this would be to moderate the board/list.
The group continued to discuss issues that present barriers to adoption of new specifications / tools / systems for Identity Based services in health care. This discussion moved in to the Openliberty overview where some possible solutions and actions were discussed.
Overview of Openliberty activities, Brett McDowell and Eric Tiffany
SUGGESTION: Brett suggests we discuss the Interoperable profile for SAML and Brett will talk about Open liberty.
Openliberty is an independent open source initiative. It’s an independent community of developers implementing liberty standards. Identity Governance Framework is a Liberty specification set taking advantage of HIGGINS project open source code.
There’s also some question if Shibboleth has what’s needed. It’s difficult to make a decision on what’s out there in the open world.
QUESTION: IHE has had success with HIMSS open IOP conferences. Is there some way we can work with them? We’ve been in their IOP demo’s at HIMSS. We also run our own cert program which goes beyond HIMSS. Yes we can do more activities in this line.
The Openliberty code is based on the same tooling used in shibboleth and what he’s developing would most likely easily deploy over Shibboleth. 2 of the 5 or so options out there share the same library and that’s Openliberty and Shibboleth
SUGGESTION: Work toward creating an environment where we can recommend what people would use. Make the choices easier to make for the health care industry.
QUESTION: How we could ‘package up’ the tools, guidelines, etc to make it easier for others to digest? XUA profile from OHF…. Perhaps Liberty can work directly with OHF.
QUESTION: Perhaps OHF is a ‘base tool kit’ and then we could build other pieces on top? Perhaps keep them cleanly separated but there would be packages on the open liberty site that were packaged up to use. And we should position it as an XUA profile.
Liberty did give XUA some guidance but it didn’t get very far along.
Brett suggests that it would be an activity for this group (HIM SIG) to help to make IHE a fully compliant implementation and perhaps write recommendations on what to do to help IHE make decisions.
SUGGESTED OUTPUT: Recommendation(s) to IHE regarding compliant implementation
The potential 'hospital to act as an IdP' use case was also mentioned again in this discussion.
SUGGESTION: CCHIT – We should take advantage of any opportunity we can to work with CCHIT
ACTION: Have this call same time next Friday – let’s look at the CCHIT use cases and work to make a response for input.
Adjourned

