<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=BB%2B_Direct_PULL</id>
	<title>BB+ Direct PULL - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=BB%2B_Direct_PULL"/>
	<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=BB%2B_Direct_PULL&amp;action=history"/>
	<updated>2026-05-09T07:15:15Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.38.4</generator>
	<entry>
		<id>https://wiki.idesg.org/index.php?title=BB%2B_Direct_PULL&amp;diff=565&amp;oldid=prev</id>
		<title>Omaerz: 36 revisions imported: Initial Upload of old pages from IDESG Wiki</title>
		<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=BB%2B_Direct_PULL&amp;diff=565&amp;oldid=prev"/>
		<updated>2018-06-28T03:00:51Z</updated>

		<summary type="html">&lt;p&gt;36 revisions imported: Initial Upload of old pages from IDESG Wiki&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Blue Button + Pull&amp;#039;&amp;#039;&amp;#039;: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Use Case Description&amp;#039;&amp;#039;&amp;#039;: A patient directs an electronic health data holder to allow a designated third party to access to his/her personal health information using an existing trusted credential held by the patient  (mobile, email acct etc) via the internet.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Use Case Category&amp;#039;&amp;#039;&amp;#039;: Authentication, Authorization, Consent&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Contributor&amp;#039;&amp;#039;&amp;#039;: IDESG Health Care Committee&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Use Case Details ===&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Actors&amp;#039;&amp;#039;&amp;#039;: &lt;br /&gt;
* Data Provider (EHR Portal) &lt;br /&gt;
* Identity Provider&lt;br /&gt;
* Relying Party (3rd Party application and/or Delegated Patient Proxy)&lt;br /&gt;
* Patient&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Goals&amp;#039;&amp;#039;&amp;#039;: Permit patients to delegate access to their own personal health information.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Assumptions&amp;#039;&amp;#039;&amp;#039;: &lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;3rd Party application has registered Blue Button Root CA with Blue Button Plus&amp;#039;&amp;#039;&amp;#039; NEEDS  MORE WORK&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Requirements&amp;#039;&amp;#039;&amp;#039;: &lt;br /&gt;
* There is a existing record or data in a data holder store&lt;br /&gt;
* The patient has an existing trusted credential&lt;br /&gt;
* The data holder has a legal, defined agreement to share data under HIPAA, its extensions or other formal agreements.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Process Flow&amp;#039;&amp;#039;&amp;#039;: &lt;br /&gt;
*Patient authenticates to an EHR or other data holder and request that EHR send patient information to a 3rd Party Application (3PA) by providing a unique URI - Direct address&lt;br /&gt;
*EHR/data holder uses address to locate 3PA public certificate and reconcile that certificate with the legal defined agreement &lt;br /&gt;
     &amp;#039;&amp;#039;*EHR wraps up CCDA using the Direct Message protocol to transport for delivery &lt;br /&gt;
     &amp;#039;&amp;#039;*3PA unwraps Direct Message and notifies the patient to confirm delivered information&lt;br /&gt;
     &amp;#039;&amp;#039;*3PA registers with EHR Authorization server and generates a shared secret&lt;br /&gt;
     &amp;#039;&amp;#039;*Patient authenticates to 3PA application, verifies information.&lt;br /&gt;
     &amp;#039;&amp;#039;*3PA prompts user to confirm if they would like set up periodic updates&lt;br /&gt;
     &amp;#039;&amp;#039;*If yes -3PA redirects patient to authenticate EHR to generate token necessary for future access behind.&amp;#039;&amp;#039;&lt;br /&gt;
     &amp;#039;&amp;#039;LINES IN ITALICS ABOVE NEED MORE WORK&amp;#039;&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Success Scenario&amp;#039;&amp;#039;&amp;#039;: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Error Conditions&amp;#039;&amp;#039;&amp;#039;: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Relationships ===&lt;br /&gt;
* Extended by:&lt;br /&gt;
** &lt;br /&gt;
**&lt;br /&gt;
* Extension of: &lt;br /&gt;
* Remote electronic identity proofing&lt;br /&gt;
* Authenticate Person Use case&lt;br /&gt;
* Delegated Authentication of User Managed access&lt;br /&gt;
&lt;br /&gt;
=== References and Citations ===&lt;br /&gt;
* NIST SP 800-63&lt;br /&gt;
* HIPAA&lt;br /&gt;
* Meaningful Use Stage 2 45 CFR 170.314(b)(2) Federal Register /Vol. 77, No.171 September 4, 2012 54163  at 54288 &lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Authentication Use Cases]]&lt;br /&gt;
[[Category:Use Cases]]&lt;/div&gt;</summary>
		<author><name>Omaerz</name></author>
	</entry>
</feed>