<html><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8"></head><body ><div>I might ask a question that may eliminate one of the options.</div><div><br></div><div>Is there any case where Alice can share with Dr. Bob where the EMR used by Dr. Bob for his relationship with Alice isn't that isn't a chained delegation? </div><div><br></div><div>Even in the case of a single user for a given EMR instance does any known EMR constrain the displaying of data to the user whonhas the patient-provider relationship? Even in the small specialty practices you usually have a case where other members of the practice cover for one another when one is on vacation. </div><div><br></div><div>Does anyone offer an EMR that manages access in the way they would need to in order to support the Direct model? How would a consumer know one from the other?</div><div><br></div><div><br></div><div><br></div><div><br></div><div><div style="font-size:10px;color:#575757">Sent from my Verizon Wireless 4G LTE smartphone</div></div><br><br><div>-------- Original message --------</div><div>From: Eve Maler <eve.maler@forgerock.com> </div><div>Date:08/23/2015 12:22 PM (GMT-05:00) </div><div>To: Debbie Bucci <debbucci@gmail.com> </div><div>Cc: openid-specs-heart@lists.openid.net </div><div>Subject: Re: [Openid-specs-heart] HEART AGENDA 2015-08-24 </div><div><br></div><div dir="ltr">Some commentary on these that may help us decide...<div><div style="font-size:12.8000001907349px"><a href="https://docs.google.com/document/d/1V3e_fDH63fNDsV-WOGKcyg0ebuW165DOpjY_RcuMk4U/edit" target="_blank"><br>https://docs.google.com/document/d/1V3e_fDH63fNDsV-WOGKcyg0ebuW165DOpjY_RcuMk4U/edit</a><br></div><div style="font-size:12.8000001907349px"><br></div><div style="font-size:12.8000001907349px"><a href="https://docs.google.com/document/d/1biUqGwvOinf9Sj6eyh3hiiDzoccSEaz3ewOTa7WcwoY/edit" target="_blank">https://docs.google.com/document/d/1biUqGwvOinf9Sj6eyh3hiiDzoccSEaz3ewOTa7WcwoY/edit</a><br></div><div style="font-size:12.8000001907349px"><br></div><div style="font-size:12.8000001907349px"><a href="https://docs.google.com/document/d/17-C7nyI-ZiL4_LsFNrXXrM2MSPx4sCqXSEui2pwhVe8/edit" target="_blank">https://docs.google.com/document/d/17-C7nyI-ZiL4_LsFNrXXrM2MSPx4sCqXSEui2pwhVe8/edit</a><span><font color="#888888"><br></font></span></div><span style="font-size:12.8000001907349px"><font color="#888888"></font></span><div><br></div><div>The "Only 4 Ways to Share Data" are four design patterns/proto-use cases that are not mutually exclusive. They can perhaps help us identify which scenarios are of most interest or are most useful in the near term. Here's how I'd summarize:</div><div><ul><li>Alice-to-Alice N: The OAuth model is “pairwise” between each service and client app. UMA, by contrast, allows Alice to aggregate the records of all of her consents.</li><li>Alice-to-Custodian: This is about the ability to delegate to the custodian for further sharing -- what my company has been referring to as chained delegation.</li><li>Alice-to-Bob Directed: This is sharing with Dr. Bob, party-to-party.</li><li>Alice-to-Bob HIE: This involves an extra layer of discoverability of Alice's resources.</li></ul><div>Some observations:</div><div><br></div><div>Alice-to-Alice N would probably be a very straightforward exploration of a key value of UMA. It would be important to get specific about the use case details.</div><div><br></div><div>Alice-to-Bob Directed would be a very interesting contrast to the use case we've already done. It sounds like it would be similar, but it might differ in a lot of ways depending on which ways we want to take it: a) the sharing might be directly to "Dr. Bob" rather than to "the PCP's EHR system" (or that might even involve chained delegation), b) it might happen through proactive policy or through an attempted access that results in an access approval rather than a run-time consent experience, and c) there might be other subtleties that show up in UX or in back-end flows. That could be a heavy lift for a first time out.</div><div><br></div><div>Elderly Mom with Family Caregiver is a mix of both Alice-to-Alice N and Alice-to-Custodian. A bit complex, but easier to take on if Alice-to-Alice N were already in the bag.<br></div></div><div><br></div><div>ROI Perspective: I don't detect much enthusiasm in this one, despite the usefulness of the annotated ROI form for other purposes. :-)</div></div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature"><div dir="ltr"><div><div dir="ltr">
<p><b>Eve Maler<br></b>ForgeRock Office of the CTO | VP Innovation & Emerging Technology<br>Cell +1 425.345.6756 | Skype: xmlgrrl | Twitter: @xmlgrrl<br>Join our <a href="http://forgerock.org/openuma/" target="_blank">ForgeRock.org OpenUMA</a> community!</p></div></div></div></div></div>
<br><div class="gmail_quote">On Sun, Aug 23, 2015 at 8:36 AM, Debbie Bucci <span dir="ltr"><<a href="mailto:debbucci@gmail.com" target="_blank">debbucci@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><strong><font face="Times">When: 1 PM PST/4 PM EST</font></strong><p class="MsoNormal" style="font-size:13px"><b><span style="font-family:Times;font-size:10pt">Where: Gotomeeting – </span></b><span style="font-family:Times;font-size:10pt"><a href="https://global.gotomeeting.com/join/785234357" target="_blank"><span style="color:blue">https://global.gotomeeting.com/join/785234357</span></a></span></p><p class="MsoNormal" style="font-size:13px"><span style="font-family:Times;font-size:10pt"><b>US phone number</b>: <a href="tel:%2B1%20%28619%29%20550-0003" value="+16195500003" target="_blank"><font color="#0066cc">+1 (619) 550-0003</font></a>. Access Code 785-234-357</span></p><p class="MsoNormal" style="font-size:13px"><b> </b><br></p><p class="MsoNormal" style="font-size:13px"><b><br></b></p><p class="MsoNormal" style="font-size:13px"><b>Agenda :</b></p><ul style="font-size:13px"><li style="margin-left:15px">semantic profile development - how will use cases inform?</li><li style="margin-left:15px"><div>Choose next Use case - as posted by Adrian:</div></li><ul><ul><li><div><a href="https://docs.google.com/document/d/1V3e_fDH63fNDsV-WOGKcyg0ebuW165DOpjY_RcuMk4U/edit" target="_blank">Elderly Mom with Family Caregiver </a></div></li><ul><li><div>A heartwarming true story of love and devotion. It's all about Alice!</div></li></ul><li><div><a href="https://docs.google.com/document/d/1biUqGwvOinf9Sj6eyh3hiiDzoccSEaz3ewOTa7WcwoY/edit#" target="_blank">ROI Perspective on health information sharing</a></div></li><ul><li><div>A true story based on paving the current cow path. It's all about the institution.</div></li></ul><li><div><a href="http:///" target="_blank">Only 4 Ways to Share Data</a></div></li><ul><li><div>From Alice's perspective. Not a full use-case but a useful way to understand why UMA</div></li></ul></ul></ul></ul><ul style="font-size:13px"><li style="margin-left:15px">AOB</li></ul></div>
<br>_______________________________________________<br>
Openid-specs-heart mailing list<br>
<a href="mailto:Openid-specs-heart@lists.openid.net">Openid-specs-heart@lists.openid.net</a><br>
<a href="http://lists.openid.net/mailman/listinfo/openid-specs-heart" rel="noreferrer" target="_blank">http://lists.openid.net/mailman/listinfo/openid-specs-heart</a><br>
<br></blockquote></div><br></div>
</body>