certification and verification of OpenEHR

this, of course, raises the issue of the certification of the
certifiers... i.e., where does the meta-certification-buck stop? In my
opinion, certification (that an application, record structure, message,
data elements, archetypes, etc. conform to a particular version of
"registered" standard) should be undertaken ONLY by the SDO who
maintains the standard, or by an agent that is directly certified by the
SDO to perform this function in its place.

What certification business models have been contemplated by this group?

Incidentally, I see "certification services" being a principle revenue
stream for the SDO or "maintenance authority", along with license fees
to use and advertise conformance to the standard. Has the group
considered specific business plans for the development and maintenance
of these EHR standards products?

Christopher J. Feahr, O.D.
Optiserv Consulting (Vision Industry)
Office: (707) 579-4984
Cell: (707) 529-2268
http://Optiserv.com
http://VisionDataStandard.org

Christopher Feahr wrote:

this, of course, raises the issue of the certification of the
certifiers... i.e., where does the meta-certification-buck stop? In my
opinion, certification (that an application, record structure, message,
data elements, archetypes, etc. conform to a particular version of
"registered" standard) should be undertaken ONLY by the SDO who
maintains the standard, or by an agent that is directly certified by the
SDO to perform this function in its place.

What certification business models have been contemplated by this group?

Incidentally, I see "certification services" being a principle revenue
stream for the SDO or "maintenance authority", along with license fees
to use and advertise conformance to the standard. Has the group
considered specific business plans for the development and maintenance
of these EHR standards products?

Christopher J. Feahr, O.D.
Optiserv Consulting (Vision Industry)
Office: (707) 579-4984
Cell: (707) 529-2268
http //Optiserv.com
http //VisionDataStandard.org
From: <lakewood@copper.net>
To: "Patrick Lefebvre" <patrick.lefebvre@psl.ap-hop-paris.fr>
Cc: <openehr-technical@openehr.org>
Sent: Thursday, August 14, 2003 11:14 AM
Subject: Re: certification and verification of OpenEHR

Patrick Lefebvre wrote:

Hi All,

--- (...)
Been off looking at some operational considerations associated
with supporting, maintaining and updating global EHRs.
The following types of users were considered:
1)CREATORS
2)REVIEWERS
3)ADMINISTRATORS
4)CERTIFIERS
       

This idea of certification is not only good for EHRs.

Self-proclaimed openEHR-conformant software sould also be tested by
general,
public certification tests, including EHRs & archetypes examples.

Independent organisms should also deliver their stamps, in a scheme
     

like:

"Veritas has controlled this software to be openEHR-compliant with
     

the

specifications issued by... (openEHR, CEN, ISO, HL7 ?) ".

-- Patrick Lefebvre
  "Ce que j'écris n'engage que moi, et ce jusqu'à ma prochaine
     

idée."

-
If you have any questions about using this list,
please send a message to d.lloyd@openehr.org

Hi All,

Certification should be identified as well. This should include
information such as:
station, date, time, source, results, requestor. With this information
tracking
can be performed so that actual/potential problems can be isolated.

-Thomas Clark

-
If you have any questions about using this list,
please send a message to d.lloyd@openehr.org
   

Hi All,

certification, and verification, can be performed by appropriate software packages.
Hence, different jurisdictions can require more/less in the package, which fits
nicely into the model permitting different jurisdictions developing their own
versions of record-based systems, including their own archetypes.

Localization is important; localized certification is therefore important. Problem
solved if a set of basic goals/objectives/results are defined/developed/tested.
A "maintenance authority" in this case may be a "big chunk" or work especially
if within a single facility a group of records may be certified multiple times, e.g.,
-incoming
-emergency care
-radiology
-surgery
-admitting
-in-patient care
-discharge
At each stage this is a change someone will 'modify' the records. At each stage
there can be justification for certifying the records, e.g., 'I don't want to deal
with the problems someone created in the records!'.

Finally, one should insure that upon discharge the records at 'incoming' are in the
final result along with the one that 'should' be there from the facility and providers.

It appears to be a good application for a set of basic tools (language translators
optionally or provided by the Client) that is modified for the end-user. On a regional,
national, internation scale I don't think a standards body should be this far into it.
License fees are a much better source of revenue.

-Thomas Clark

Christopher Feahr wrote:

this, of course, raises the issue of the certification of the
certifiers... i.e., where does the meta-certification-buck stop? In my
opinion, certification (that an application, record structure, message,
data elements, archetypes, etc. conform to a particular version of
"registered" standard) should be undertaken ONLY by the SDO who
maintains the standard, or by an agent that is directly certified by the
SDO to perform this function in its place.

What certification business models have been contemplated by this group?

Incidentally, I see "certification services" being a principle revenue
stream for the SDO or "maintenance authority", along with license fees
to use and advertise conformance to the standard. Has the group
considered specific business plans for the development and maintenance
of these EHR standards products?

this is the openEHR model - everything is free to use (of course;-) but openEHR would need to change something for certification of a claimed openEHR vX.X compliant component - essentially for the right to be able to use the conformance mark "openEHR xxx compliant". The testing will be conducted by a group whcih acts independently, and will be based on published test specifications. A licence fee structure has not been determined, apart from the basic principle of "dual-licencing" (free for non-commercial use under open source licence, else under a normal commercial licence). Some interesting models have been suggested, including runtime "licencing" called a "penny a patient per annum".

- thomas beale

Hi all,
Concerning certification, the model developed in Europe (through CEN and
eEurope Smart Card) for electronic signature apply very well to the openEHR
environment.
Norbert Lipszyc
----- Message d'origine -----

Hi all,

Christopher Feahr wrote:

this, of course, raises the issue of the certification of the
certifiers... i.e., where does the meta-certification-buck stop? In my
opinion, certification (that an application, record structure, message,
data elements, archetypes, etc. conform to a particular version of
"registered" standard) should be undertaken ONLY by the SDO who
maintains the standard, or by an agent that is directly certified by the
SDO to perform this function in its place.

What certification business models have been contemplated by this group?

Incidentally, I see "certification services" being a principle revenue
stream for the SDO or "maintenance authority", along with license fees
to use and advertise conformance to the standard. Has the group
considered specific business plans for the development and maintenance
of these EHR standards products?

this is the openEHR model - everything is free to use (of course;-) but openEHR would need to change something for certification of a claimed openEHR vX.X compliant component - essentially for the right to be able to use the conformance mark "openEHR xxx compliant". The testing will be conducted by a group whcih acts independently, and will be based on published test specifications. A licence fee structure has not been determined, apart from the basic principle of "dual-licencing" (free for non-commercial use under open source licence, else under a normal commercial licence). Some interesting models have been suggested, including runtime "licencing" called a "penny a patient per annum".

- thomas beale

About certification mechanisms... a few remarks.

(1) openEHR (eventually CEN) has to publish a list of "standard tests". I think of conformant messages in different syntaxes (XML, Corba, etc). These messages may be part of the openEHR &/or EHRcom specification.

(1bis) Anyone could do so. People will adopt the good work ;-))

(2) National organisations, Universities, CEN, openEHR, other... independent or not, profit and non-profit organisations may certificate "openEHR compliant". Compliant with what ? Only the public, published specs should be a serious test.

(2bis) As for benchmarks, anyone should be able to verify that the certification results were serious. So anyone has to get the tests.

(3) People (Hospitals, Health Care Organisations, etc ) will pay for a product, but will not accept paying an undefinite fee. Product may be "certified by Veritas" or "Certified by TNO": the stamp value is/will be the certifier's reputation.

(4) Such schemes are widely in use in Quality Insurance (ISO 9000 for example). The test is published and well-known; The tester/certifier is independent from the vendor/buyer;

-- Patrick Lefebvre ------------- ( plefebv@wanadoo.fr )

Patrick Lefebvre wrote:

Hi all,

About certification mechanisms... a few remarks.

(1) openEHR (eventually CEN) has to publish a list of "standard tests". I think of conformant messages in different syntaxes (XML, Corba, etc). These messages may be part of the openEHR &/or EHRcom specification.

agree

(1bis) Anyone could do so. People will adopt the good work ;-))

agree

(2) National organisations, Universities, CEN, openEHR, other... independent or not, profit and non-profit organisations may certificate "openEHR compliant". Compliant with what ? Only the public, published specs should be a serious test.

correct. But any certification has to be managed by openEHR - other there is no point of trust for the whole process.

(2bis) As for benchmarks, anyone should be able to verify that the certification results were serious. So anyone has to get the tests.

well, they're needed anyway, for any vendor or developer who wants to get certified - obviously they need the "exam questions" to know how to practice;-)

(3) People (Hospitals, Health Care Organisations, etc ) will pay for a product, but will not accept paying an undefinite fee. Product may be "certified by Veritas" or "Certified by TNO": the stamp value is/will be the certifier's reputation.

no doubt. Clearly openEHR has to make sure these certification processes are not uneconomic for those getting certified. On the other hand, commercial vendors should expect to pay something - openEHR saves them millions by giving away free specifications...

(4) Such schemes are widely in use in Quality Insurance (ISO 9000 for example). The test is published and well-known; The tester/certifier is independent from the vendor/buyer;

yep.

- thomas

Hi All,

Be sure to include certification boundaries, e.g., certify records available in a single facility. Records may be resident in multiple remote facilities with the Providers attempting to deal quickly with the Patient in their facility, e.g., traveling salesman (has a known homebase).

If the remote records are not accessible for some reason, e.g., the latest security issue, then the local Providers may be able to certify the records (incoming/outgoing) at that facility and proceed. Reconciling distributed records can be treated as a separate issue. The current Patient/Provider requirements may be superior.

These type certification issues are spread between the Provider and the IT fields, the IT field flush with examples. What is important here is whether the Providers can live with certification of locally available records perhaps with the knowledge that others exists but are currently unavailable. Some decision process is needed.

If not, then I would appreciate knowing what issues need to be resolved. If the Patient can wait and the occupied resources could be put to no better use, then let the Patient wait. However, that doesn't seem to be the 'usual' situation.

-Thomas Clark

Thomas Beale wrote: