ONC names 17 members of the privacy and security workgroup

The Office of National Coordinator for Health IT named 17 members of the newly formed privacy and security workgroup of the HIT Policy Committee.  According to Government Health IT:

The work group will be co-chaired by Deven McGraw, director of the Health Privacy Project at the Center for Democracy and Technology, and Rachel Block, executive director of the New York eHealth Collaborative and deputy commissioner for health IT transformation at the New York State Department of Health.

Their team will advise the Policy Committee on such matters as how safeguards for the exchange of health information should fit into the “meaningful use” test for health IT incentives that ONC has been working on.

The ONC has previously announced the establishment of a separate workgroup devoted to creation of a national health information network, which, of course, will have to deal with its own set of privacy and security concerns.  There is also a privacy and security workgroup under the HIT Standards Committee.

Government Health IT provides a list of the other members of the workgroup:

Some of the privacy and security work group members named today already sit on its parent Policy Committee. They are: are Dixie Baker, SAIC; Paul Egerman, consultant; Judy Faulkner, Epic Inc.; Gayle Harrell, a consumer representative with the state of Florida; Dr. Mike Klag, Johns Hopkins University School of Public Health; Latanya Sweeney, Carnegie Mellon University; and Paul Tang, Palo Alto Medical Foundation and Policy Committee vice chairman.

New members who are not current members of the Policy Committee are: Dr. Peter Basch; a healthcare practitioner, Dr. A. John Blair, a practitioner; Marianna Bledsoe, the National Institutes for Health; Joyce DuBow, AARP; Justine Handelman, Blue Cross Blue Shield; John Houston, University of Pittsburgh Medical Center; Terri Shaw, Children’s Partnership; and Paul Uhrig, SureScripts. Jodi Daniel and Sarah Wattenberg will represent the Office of the National Coordinator for Health IT on the workgroup.

"ONC names privacy, security workgroup members," Government Health IT (December 8, 2009).

HIT Standards Committee endorses privacy and security standards

On September 15, 2009, the HIT Standards Committee endorsed a set of privacy and security standards for electronic health record systems. 
These standards will be recommended to Dr. David Blumenthal, the National Coordinator for Health Information Technology, as a basis for establishing the privacy and security criteria for, inter alia, "certified EHR technology" as defined under the HITECH Act.  Eligible healthcare providers must meet the criteria for "meaningful use" of "certified EHR technology" in order to qualify for significant incentives available under the HITECH Act.

The committee’s Privacy and Security Workgroup included access control, authentication, authorization and transmission of health data among the requirements that electronic health record systems must include by 2011 in order to meet the definition of "certified EHR technology."   Specifically for 2011, the Standards Committee approved the Workgroup's recommendation to require certified products to provide the capabilities necessary to support the HIPAA and ARRA security and privacy requirements and best practices for “meaningful use.”  The endorsed privacy and security standards will become more rigorous in 2013 and 2015.

You can find the spreadsheet of endorsed privacy and security standards here.

You can also view the presentation from the Workgroup here.

"Federal panel okays EHR security, privacy standards," Government Health IT (September 15, 2009).