Construction and Data Sharing
From DOC
Introduction
This section of the Implementation Guide explains the basic constructs of the Tolven account mechanisms. Account structures and boundaries are the basic premise behind the installation of the Tolven solution.
An account can be described as a secure collection of administrative and clinical data that can only be accessed by users who have access to the account. The basic account types are the electronic Personal Health Record (ePHR) and electronic Clinician Health Record (eCHR).
Accounts can have one or more members authorized to access them. For example an electronic Personal Health Record account may have one member (i.e., the person who created the account) or multiple members if other family members are granted access. The security features associated with the Tolven platform (see www.tolven.org for architectural briefs) ensure that data within an account can only be accessed by members of that account.
Implementation
The structure of accounts used in a deployment of the Tolven solution is extremely flexible. Therefore, consideration must be given to the level of privacy and confidentiality required for certain types of data, as well as the impact that creating numerous accounts will have on the usability of the solution.
The figure below indicates the way in which a single deployment of the Tolven solutions can contain multiple secure accounts. The data within each account is only accessible by the members of the account. Members can be granted access to multiple accounts (e.g., physicians may have access to a practice account and their own personal health record account).
In the example in Figure 1, only one user (i.e., User C) has access to data that resides in multiple accounts. Authorized account members, however, can share patient information and data among accounts; in this way a patient’s data in Account 2 can be shared with Account 1 and viewed by User A. All actions associated with viewing, adding and sharing data among accounts and users are fully audited.
3.1 Implementation Decision When implementing Tolven, a decision needs to be made regarding the following: 3.1.1 Enable Users to Create New Accounts This profile defines whether users of the system can create new accounts or whether they can only access accounts created by the system administrator. 3.1.2 Type of Accounts This defines the types of accounts that are available to the end user (e.g., eCHR or ePHR). 3.1.3 Account Invitation Enabling account invitations means that users must be invited to join a specific account by the account administrator. Users will require a specific code to access the account for the first time.
3.1.4 Account Administrators This identifies the account administrators on an account.
3.1.5 Provider Preferences Enables a specified account to be visible by name by other accounts for data sharing purposes.
3.1.6 Number of Discrete Accounts This identifies the number of discrete accounts.
3.1.7 Account Names This is the name by which an account is to be identified (e.g., Valley Hospital), which should be unique.

