01.12.2014 Views

IHE Patient Care Coordination Technical Framework Vol I

IHE Patient Care Coordination Technical Framework Vol I

IHE Patient Care Coordination Technical Framework Vol I

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

PCC <strong>Technical</strong> <strong>Framework</strong> V3.0, vol. 1<br />

________________________________________________________________________<br />

1195<br />

1200<br />

information which the patient believes may indicate that the patient has genetic,<br />

substance use, HIV-AIDs, mental health or other conditions, which the patient wishes to<br />

mask. Another use for sensitivity markers is for victims of abuse who wish to mask all<br />

records containing their demographic information.<br />

3.3.2 Privacy Access Policies (Informative)<br />

One possible implementation may have a collection of policies and sensitivity markers<br />

form an access control matrix. A simple access control matrix is shown in the table<br />

below.<br />

Sensitivity<br />

Functional Role<br />

Billing Information<br />

Administrative<br />

Information<br />

Dietary Restrictions<br />

General Clinical<br />

Information<br />

Sensitive Clinical<br />

Information<br />

Research<br />

Information<br />

Mediated by<br />

Direct <strong>Care</strong> Provider<br />

Administrative Staff X X<br />

Dietary Staff X X<br />

General <strong>Care</strong> Provider X X X<br />

Direct <strong>Care</strong> Provider X X X X X<br />

Emergency <strong>Care</strong> Provider X X X X X<br />

Researcher<br />

X<br />

<strong>Patient</strong> or Legal Representative X X X X X<br />

1205<br />

Table 3.3-1 Sample Access Control Policies<br />

The matrix can be sliced vertically. By slicing the matrix vertically (by sensitivity<br />

marker), a single patient consent policy (aka. sensitivity marker) vocabulary can be<br />

established. This vocabulary must then be configured in the XDS Affinity Domain.<br />

Using the example above, the privacy consent policies would be.<br />

Privacy Consent<br />

Policy<br />

Description<br />

Billing Information<br />

Administrative<br />

Information<br />

May be accessed by administrative staff and the patient or their legal representative.<br />

May be accessed by administrative or dietary staff or general, direct or emergency care<br />

providers, the patient or their legal representative.<br />

_____________________________________________________________________<br />

43<br />

Revision 3.0 Public Comment — June 25, 2007<br />

Copyright © 1997-2007: ACC/HIMSS/RSNA

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!