trust and governance in health and social care

35
Trust and Governance in Health and Social Care Prof William J Buchanan Twitter: @billatnapier Web: http://asecuritysite.com http://thecyberacademy.org

Upload: napier-university

Post on 22-Jan-2018

276 views

Category:

Healthcare


2 download

TRANSCRIPT

Page 1: Trust and Governance in Health and Social Care

Trust and Governance in Health and Social CareProf William J BuchananTwitter: @billatnapierWeb: http://asecuritysite.comhttp://thecyberacademy.org

Page 2: Trust and Governance in Health and Social Care

Changing face of health care

2

Page 3: Trust and Governance in Health and Social Care

Barriers to Information Sharing

Records are

often static

Different

systems/

formatting

used for data

Limited/

difficult access

methods …

lack of trust

Lack of

integration

between health

and social

care

Lack of

integration with

carers, trusted

people and

families

Requirements

for 24/7 support

with real-time

response

Data often

aggregated

and context is

often lost

Strong demand

to consume

health/social

care data

Lack of

information

sharing across the

public sector

Poor access

control to data

Societal

Technical

Page 4: Trust and Governance in Health and Social Care

Information Sharing

Page 5: Trust and Governance in Health and Social Care

Risk Assessors

Health Care

Data

Social Care

Data

Education

Data

Police

Data

Child at

Risk

Records:

Child’s Action Plan

Risk Assessors:

Posted Concerns

Attendance Records

Health Problems

Crime Trace

Named Person

Trust Access to Action Plan

for the Required Time Limit

Health Care

Data

Social Care

Data

Education

Data

Police

Data

Strong Governance

Infrastructure

Health/

Social Care

Records:

Personal Health Record

Risk Assessors:

Frailty Index

Early Warning Score

Appointments Missed

Named Person (GP)

Possible Trust Access to parts of

the Electronic Health Record

Rights granted

Page 6: Trust and Governance in Health and Social Care

Information Sharing

Human

TrustDigital

Trust

Identity

Rights Health/Social

Services

Strong

Governance

Education

Health Care

Police/Law

Enforcement

Social Care

Translation of rights

Translation of identities

Strong Governance Policy

Infinite

possiblities

Primary

Health Care

(role-based)

Secondary

Health Care

(role-based)

Assisted Living (Circle of

Trust)

Family might ask: Who are the

people responsible the action plan?

GP might ask: How often does the team

meet to discuss the child?

Social Care might ask: When is the

next formal review of the case?

Page 7: Trust and Governance in Health and Social Care

Trust Model

Data source 1

Data source 2

Data source 3

Trusted Platform

Page 8: Trust and Governance in Health and Social Care

Symphonic TrustProf William J BuchananTwitter: @billatnapierWeb: http://asecuritysite.comhttp://thecyberacademy.org

Page 9: Trust and Governance in Health and Social Care

Translation Gateway

Governance PolicyHealth and Social Care

Domain

Governance

Policy

Translation

Gateway

Domain Ontology,

Roles, and Well-

managed Services

Exposed

Data elements

Law Enforcement

Domain

Domain

Ontology, Roles,

and Services

Exposed

Data elements

Human Readable Policy

defined for access

(based on role,

relationship and identity)

Roles

Federated Identity Attribute,

and Relationship

Management

[Unit]

[Dept]

Domain Ontology

Page 10: Trust and Governance in Health and Social Care

Governance and Trust

Police/Law

EnforcementSocial Care

Governance Policy

Translation

Gateway

Page 11: Trust and Governance in Health and Social Care

Governance and Trust

Police/Law

EnforcementSocial Care

Governance Policy

Translation

Gateway

Governance

model

Translator of roles,

services, and rights

Governance Policy

Translation

Gateway

Automated generation

Information

Sharing Policy

Document

Real-time

implementation

Page 12: Trust and Governance in Health and Social Care

ENU e-Health Cloud Architecture

12

Page 13: Trust and Governance in Health and Social Care

Service Claims

Page 14: Trust and Governance in Health and Social Care

Policy Syntax

14

Page 15: Trust and Governance in Health and Social Care

London Data SharingProf William J BuchananTwitter: @billatnapierWeb: http://asecuritysite.comhttp://thecyberacademy.org

Page 16: Trust and Governance in Health and Social Care

London Digital Programme

• London Digital Programme – As part of Healthy London initiative, the Health and Social Care ecosystem in London is piloting new ways to provide a data sharing environment to allow the 7,000 diverse organisation involved in patient care to access patient records. Symphonic Software is delivering the key governance layer to this important programme to ensure that any data access meets with data controller agreements, which codify the inter-organisational rules for patient data access, and also allowing citizens to express their own data sharing preferences.

Page 17: Trust and Governance in Health and Social Care

Scope

Ref: London Data Sharing Partnership, Mike Park

Page 18: Trust and Governance in Health and Social Care

Dimensions of Integrated Care

Ref: London Data Sharing Partnership, Mike Park

Page 19: Trust and Governance in Health and Social Care

Activated Citizen

Ref: London Data Sharing Partnership, Mike Park

Page 20: Trust and Governance in Health and Social Care

Digital enabled care

Ref: London Data Sharing Partnership, Mike Park

Page 21: Trust and Governance in Health and Social Care

London Data Sharing

London Digital Program

Ref: London Data Sharing Partnership, Mike Park

Page 22: Trust and Governance in Health and Social Care

Sharing AgreementsProf William J BuchananTwitter: @billatnapierWeb: http://asecuritysite.comhttp://thecyberacademy.org

Page 23: Trust and Governance in Health and Social Care

Background

• Five years academic research motivated by CaldicottReport

• Software to improve patient care through trusted data sharing:

• Across organisation & application boundaries

• Using trust-based access models

• Protecting patient information

• With built-in information governance

• Patient consent and preference

• Aligning IT and service delivery in data security

Page 24: Trust and Governance in Health and Social Care

Common Authorisation Layer

Symphonic Trust:• Interoperability• Accelerated Service

Delivery• Holistic view• Dynamic Access

Management

Page 25: Trust and Governance in Health and Social Care

Implementing Data Sharing

• Capture landscape• Who – “users” of the ecosystem• What – to-be-shared data and resources• Policies – Data Sharing Agreements

• Define Policies & Data Ownership• Organisation• Patient Consent

• Management Reporting• Rights• Usage• Policy Change

Page 26: Trust and Governance in Health and Social Care

Define who has access

• Different domains• Different organisational structures• Capture End points and synchronisation

Page 27: Trust and Governance in Health and Social Care

Define data and services

• Different domains• Different technologies• Define endpoints and access methods

Page 28: Trust and Governance in Health and Social Care

Attribute as a service

• Resolve rules “on-the-fly”

Page 29: Trust and Governance in Health and Social Care

Define identity providers

• Different identity providers• Define “trust”• Different provisioning policies

Page 30: Trust and Governance in Health and Social Care

Define policy documents

• Relate IT access methods to business policy• Data Sharing Agreements

Page 31: Trust and Governance in Health and Social Care

Store policies

• Centralise policy management

Page 32: Trust and Governance in Health and Social Care

Define basic policy

• Business User driven (Data Controller)• API suite for policy management by user apps

Page 33: Trust and Governance in Health and Social Care

Define advanced policy

• Capture advanced policy requirements• Time, Geo, device type, IP Address etc

Page 34: Trust and Governance in Health and Social Care

Management Reporting

• Full set of management reports• User Entitlements

• Access reporting• Permits

• Denies

• Policy Changes

• Information “obligations” on access; SMS, email, etc

• Meets compliance and regulatory needs

• Aligned to Data Sharing Agreements

Page 35: Trust and Governance in Health and Social Care

Trust and Governance in Health and Social CareProf William J BuchananTwitter: @billatnapierWeb: http://asecuritysite.comhttp://thecyberacademy.org