Privacy eSuite (PeS)
Privacy eSuite is the web-based ‘consent engine’ at the heart of our ability to manage and enforce consumer, organizational and jurisdictional privacy policies in a diverse EHR ecosystem. Our software is deployed in healthcare organizations, health information exchanges and regions both large and small.
Privacy eSuite consists of the following web services:
- Consent Management Service – the CMS enables privacy policies to be administered and processed into computable access rules
- Consent Validation Service – the CVS determines if a user’s access to a patient’s personal, protected health information (PHI) is appropriate based on the rules of the existing privacy policies
- Universal Audit Repository – the UAR is the IHE ATNA-compliant central audit repository that tracks audit events related to updates, queries and access/attempted access to PHI.
Privacy eSuite supports ‘break-the-glass’ (override) access to PHI.
The software enables granular, standards-based privacy policies applicable to:
- purpose of use – e.g. treatment, research, marketing
- information type – e.g. laboratory results, radiology exam, medication
- specific user(s) – e.g. roles, groups of users, facility
- PHI identifiers – e.g. category codes, classification codes
- Java-based n-tier application
- LDAP
- Java Message Service (JMS)
- High availability
- Monitoring
- Registry support: standards-based, non standards-based
- Web application servers: Apache Tomcat, JBoss, WebSphere
- Operating system: Linux (Redhat), MS Windows
- Databases: IBM, Microsoft, Oracle
- Standards supported:
-
HL7 FHIR R4B (4.3)
-
ISO/TS 17975
-
OAuth 2.0, Open ID Connect
-
IHE ATNA / XDS.b
-
OASIS XACML v3.0
-
OASIS XSPA v1.0
-
