Project Update
The HIMSA IAM Committee, well represented for all of HIMSA's partner companies, has made very good process since the initial project kick off meeting in February 2019. The currently understood project work is almost done, below is a list of highlights:
- A completed set of user stories that the committee members are pleased with. The user stories cover uses cases from both the perspective of the manufacturer developing applications as well as uses cases representing how Hearing Care Professionals (HCB) will make use of and enjoy the identity features. The last meeting meeting took place at the end of June 2019
- HIMSA is currently creating a sample application and test environment that enable the committee members and HIMSA product management to further model and test the user stories. We may find that some minor adjustments to the users stories are needed.
More details can be found in the "Financing and Next Steps" section below.
How it Works
A brief high level summary of the features and selling points for the HIMSA Identity Service.
Authentication
With Noah ES, HIMSA has implemented a HIMSA Identity Service that makes use of IT industry standards and best practices to ensure that the HCP is in fact, for example, Brian Jones (bjones@email.com). Once authenticated Brian is able to make use of the Noah ES features. At this point, Brian's HIMSA's Identity is available for other approved applications to make use of.
Q: Does the business that Brian works for need to subscribe to and use Noah ES in order to make use of the Identity Service?
A: As implemented today yes, but HIMSA can easily make smaller adjustments so that it is possible for the Identity Services to be available without requiring that Noah ES be purchased. HIMSA has assumed that it offering this service at no charge to the HCB would be beneficial to the hearing health care industry as a whole and also provide for some helpful sales exposure for also using Noah ES.
Easy Identification
During the day Brian may have need to make use of a web site application provided by manufacturer A. Manufacturer A is a HIMSA member company and is a trusted integrator with HIMSA Identity Service. In this example Brian is wishing to make use of an order system.
When Brian arrives at the web site he will have the ability to gain access to protected functionality without needing to enter in a user name and password.
Q: Does the HIMSA Identity at all influence what Brian can do in the system (e.g. how much product can he order)? Are the feature offering controlled by HIMSA in anyway?
A: Not at all, the HIMSA identity proves that Brian is bjones@email.com but the manufacturers application decides the functionality and level of access.
Seamless Movement Between Different Systems
Manufacturer A may also have additional separate systems (e.g. a remote fitting/care Telemedicine solution). Even though the systems may be separate Brian still does not need to login again but can rather use his HIMSA Identity. Brian's business also works with another manufacturer and can enjoy the same friendly workflow experience.
Q: Will the HIMSA Identity service make it easier for a manufacturer to create different applications such as order systems or remote care solutions?
A: Not directly. Although it is entirely feasible to solely rely on the HIMSA Identity service HIMSA assumes that most manufacturers will still wish to provide individual identity systems and offer HIMSA's as a very nice option.
For Brian, the HIMSA Identity Service can provide for a better overall user experience, for example:
- Brian does not need to enter in his password each time he visits another system, he does not need a separate password for each system.
- If Brian forgets his password he will work his Noah ES administrator or potentially HIMSA to get logged back in.
Directory Features
The identity service will provide for the storage of basic information about the business such as location name, address and other contact information. It will also be possible for different employees to be recorded and assigned to different office locations.
User types, such as Business Decision Makers (i.e. can sign agreements with HIMSA) and Administrators are also defined.
Manufacturers Benefit
Location and User Information is available to manufacture applications to assist in on-boarding a business as easily as possible. Manufacturers will also be able to determine when HIMSA Identity accounts have been disabled, signaling that the individual is most likely no longer employed, the manufacturer make take any action within their applications if they wish.
Advanced Systems
Hospitals, large chains/groups, businesses with special security needs or advanced setups (e.g. use of a physical PIV card) have already have most of their software systems setup to use products such as Microsoft Active Directory or Azure Active Directory.
These businesses really dislike using separate identity systems as each separate system represents a level of complexity for the administration of their business. These businesses will most likely not accept to abandon their chosen solution for HIMSA products as well as other online based systems.
To accommodate this situation HIMSA’s Identity service is implemented and ready to integrate with other approved systems so that HIMSA can still deliver a high quality identity for uses with Noah ES and associated applications.
Manufacturers Benefit
This type of integration will be taken care so that manufacturers do not need to worry about them. As far as a manufacturer is concerned it is just working with the HIMSA Identity Service. For example, if Brian's company has decided to using Azure Active Directory this change will not no impact for manufacturer created applications.
Future Proofing
Identity and authentication for software application is a fast changing field and will most likely change quickly during the next few years. For example, the next large change is assumed to come with moving away from the use of passwords and replacing them with authentication App and easy to use hardware devices. Microsoft and other companies are working very hard on addressing this topic. Rather then forcing users to deal with the ever increasing number of password changes and complexity other methods are sure to become the standard in the future.
Manufacturers and HIMSA's Benefit
As this field changes HIMSA will be able to make adjustments to the Identity Management Systems to make sue of new standards, without causing direct impact on the development of Noah ES or applications that integrate with Noah ES or the Identity Services.
In other words, HIMSA can perform the work once and all companies may then enjoy the benefit of this work.
Financing and Next Steps
Q: Who pays for the HIMSA Identity Services?
A: HCB's that will have Noah ES accounts will help fund the feature as part of their Noah ES subscription payments. For HCB's that may use just the Identity Services.
Arild, not really sure what to write here - not sure if there is a budget etc. we can talk about it or you can of course enter text etc.