Healthcare OpenID
Full Title
The OpenID Foundation has a working group, HEART, which is creating specifications for the use of OpenID and related specifications within the US Healthcare ecosystem.
Context
The following Implementer’s Drafts of Four HEART Specifications have been approved as of March 12, 2019. The four specifications that were approved are:
- [ http://openid.net/specs/openid-heart-oauth2-1_0.htmlHealth Relationship Trust Profile for OAuth 2.0]
- Health Relationship Trust Profile for Fast Healthcare Interoperability Resources (FHIR) OAuth 2.0 Scopes
- Health Relationship Trust Profile for User-Managed Access 2.0 Health Relationship Trust Profile for User-Managed Access 2.0
- Health Relationship Trust Profile for Fast Healthcare Interoperability Resources (FHIR) UMA 2 Resources
A complete list of HEART specifications produced (including previous Implementer’s Drafts) can be found in the group’s BitBucket repository.
Problems
- The documents are written in the language of OpenID rather than in the terms of the US Healthcare ecosystem.
- The paradigm for the existing specifications is the documents from the corresponding standards committees rather than the need of the Healthcare ecosystem.
- Bit Bucket has entered end-of-life and is not viable for future development.
Solutions
- Adopt a paradigm shift to documents that are problem oriented rather than solution oriented. For example the FAPI specifications of the OpenID foundation is oriented to solutions for financial payments from users.
- Focus only on new specification that feature the goals of the Cares Act, such as giving Patient Choice in how their information is accessed,
- Bring up a GitHub repository and deprecate the bitbucket repository.