Significance and Use

American National Standards Institute Inc.

The policy defined by this practice is written from the perspective of healthcare relying parties. It defines a set of requirements to ensure that certificates, used for authentication, authorization, confidentiality, integrity, and nonrepudiation of health information by healthcare organizations and persons, have a minimally sufficient assurance level.

This policy defines a healthcare public key infrastructure that can be used to implement other ASTM standards including Specification E2084 and Guide E2086.

CA that implement procedures satisfying each requirement of the policy should reference the policy’s OID in the appropriate fields within its certificates. Relying parties can recognize the inclusion of the policy’s OID as an indication that the issuing CA has conformed to the requirements of the policy and that the certificates referencing the policy’s OID may be used for healthcare purposes.

CA that do not comply with all provisions of the policy must not assert the policy’s OID in its certificates. A CA that complies with all but a limited number of provisions may reference the policy in its own policy, provided that it clearly states the specific deviations. For example, a healthcare organization might operate an internal CA that complies with all of the provisions of the basic individual certificate class except that it uses a noncomplying cryptographic module for the CA signer keys. The organization might want to use the policy as the basis for establishing trust with external relying parties. While it may not directly assert this policy using the OID, it may reference the policy in a document that includes statements explaining measures it has taken to protect the integrity of the CA signing key. Relying parties or CA wishing to facilitate cross-trust relationships must then make their own risk analysis to determine if the modified policy is adequate for the proposed usage. This assessment, while not as easy as that based upon full compliance, should be significantly facilitated by treating the policy as a reference standard from which to judge the modifications.

Certificates and the certificate issuance process can vary in at least three distinct ways. The most frequently cited variation is about assurance. Assurance levels vary depending upon the degree of diligence applied in the registration, key generation, certificate issuance, certificate revocation, and private key protection. The required assurance level depends on the risks associated with a potential compromise. The federal PKI, among others, divides assurance into three classes. Rudimentary assurance involves very little control of either the registration process or key security. The federal PKI does not consider rudimentary assurance appropriate for healthcare use. Medium assurance involves a higher degree of diligence in the registration process and requires a number controls over CA keys. Medium assurance is designed for moderate risk applications. High assurance adds additional controls on the CA and subscriber keys as well as careful division of roles in the issuance process. These additions make high assurance certificates more appropriate for higher risk applications. Certificates may also vary depending upon the type of entity whose identity is bound to the certificate. Finally, certificates are often described in terms of appropriate and inappropriate uses.

The policy does not define certificates in terms of assurance levels. Instead, it defines three classes of certificates (entity, basic individual, and clinical individual) that differ in terms of their primary intended use or purpose and in terms of their intended subscriber type. The three certificate classes are ordered so that the clinical individual certificate must meet all the requirements of the basic individual certificate and the basic individual certificate must meet all the requirements of the entity certificate.

It is anticipated that the policy will be used to facilitate cross-licensing between healthcare CA. The policy is intended to provide a common reference point for establishing compatibility of purposes, representations, and practices among a number of autonomous healthcare CA.

Scope

1.1 This practice covers a policy (“the policy”) for digital certificates that support the authentication, authorization, confidentiality, integrity, and nonrepudiation requirements of persons and organizations that electronically create, disclose, receive, or otherwise transact health information.

1.2 This practice defines a policy for three classes of certificates: (1) entity certificates issued to computing components such as servers, devices, applications, processes, or accounts reflecting role assignment; (2) basic individual certificates issued to natural persons involved in the exchange of health information used for healthcare provisioning; and (3) clinical individual certificates issued to natural persons and used for authentication of prescriptive orders relating to the clinical treatment of patients.

1.3 The policy defined by this practice covers: (1) definition of healthcare certificates, healthcare certification authorities, healthcare subscribers, and healthcare relying parties; (2) appropriate use of healthcare certificates; (3) general conditions for the issuance of healthcare certificates; (4) healthcare certificate formats and profile; and (5) requirements for the protection of key material.

1.4 The policy establishes minimum responsibilities for healthcare certification authorities, relying parties, and certificate subscribers.

Go to ASTM E2212 at ASTM.org

Add your thoughts about the standard.

1375 - Demolition Materials (549) 1377 - Cartridge and Propellant Actuated Devices and Components (524) 4720 - Hose and Flexible Tubing (552) 4730 - Hose, Pipe, Tube, Lubrication, and Railing Fittings (1823) 5120 - Hand Tools, Nonedged, Nonpowered (1124) 5305 - Screws (781) 5306 - Bolts (996) 5310 - Nuts and Washers (864) 5330 - Packing and Gasket Materials (583) 5340 - Hardware, Commercial (953) 5905 - Resistor (753) 5910 - Capacitors (783) 5930 - Switches (1012) 5935 - Connectors, Electrical (4357) 5940 - Lugs, Terminals, and Terminal Strips (564) 5945 - Relays and Solenoids (733) 5950 - Coils and Transformers (856) 5960 - Electron Tubes and Associated Hardware (1630) 5961 - Semiconductor Devices and Associated Hardware (707) 6145 - Wire and Cable, Electrical (1629) 6240 - Electric Lamps (662) 6505 - Drugs and Biologicals (1343) 6515 - Medical and Surgical Instruments, Equipment, and Supplies (1907) 6520 - Dental Instruments, Equipment, and Supplies (790) 6530 - Hospital Furniture, Equipment, Utensils, and Supplies (745) 6610 - Flight Instruments (540) 6625 - Electrical and Electronic Properties Measuring and Testing Instruments (1241) 6640 - Laboratory Equipment and Supplies (1187) 6810 - Chemicals (1114) 8010 - Paints, Dopes, Varnishes, and Related Products (2046) 8030 - Preservative and Sealing Compounds (554) 8140 - Ammunition and Nuclear Ordnance Boxes, Packages and Special Containers (797) 8305 - Textile Fabrics (910) 8415 - Clothing, Special Purpose (660) 8455 - Badges and Insignia (3093) 8915 - Fruits and Vegetables (531) 9330 - Plastics Fabricated Materials (759) FACR (1647) ISDA (1776) ISDD (786) ISDF (1827) ISDN (581) MISC (1045) PACK (539) SESS (581)
Aerospace Material (225) Aircraft Air Conditioning, Heating, and Pressurizing Equipment (334) Aircraft Hydraulic, Vacuum, and De-icing System Components (263) Ammunition, 75mm through 125mm (192) Ammunition, over 30mm up to 75mm (208) Ammunition, through 30mm (349) Analytical Chemistry (180) Bombs (192) Building (414) Bulk Explosives (261) Cartridge and Propellant Actuated Devices and Components (524) Consumer Product Evaluation (267) Copper (192) Demolition Materials (549) Electrical and Magnetic Conductor (162) Electronics (153) Environmental Toxicology (187) Fire Control Computing Sights and Devices (338) Fire Control Radar Equipment, except Airborne (197) Fuzes and Primers (454) Geotechnical Engineering (217) GUN (640) Land Mines (276) Medical Device and Implant (427) Military Chemical Agents (156) Miscellaneous Aircraft Accessories and Components (231) Miscellaneous Fire Control Equipment (216) Nondestructive Testing (246) Nonferrous Metal and Nonferrous Alloy (367) Nuclear Technology (274) Optical Sighting and Ranging Equipment (451) Paint and Related Coating (456) Parachutes; Aerial Pick Up, Delivery, Recovery Systems; and Cargo Tie Down Equipment (324) Petroleum (378) Plastic Pipe (248) Pyrotechnics (175) Road and Paving (177) Rockets, Rocket Ammunition and Rocket Components (368) Rubber (166) Security System Pedestrian and Walkway Safety (157) Specialized Test and Handling Equipment, Nuclear Ordnance (150) Sports and Recreation (316) Steel (908) Torpedos and Components, Inert (258) (621)