 
              OASIS Electronic Trial Master File Standard Technical Committee April 13, 2015 9:00 – 10:30 AM PDT
Agenda Topic Presenter 9:00 - 9:05 Call to Order Chair 9:05 - 9:10 Roll Call (secretary: Cathy ) Cathy 9:10 – 9:12 Mar 16 2015 minute approval All 9:12 – 9:22 OASIS eTMF Tech Workgroup – update Zack 9:22 – 9:30 New Business All 9:30 – 9:40 Discussion period All 9:40 – 9:50 Agenda – next meeting All 2
Roll Call Name Company Status Jenny Huang AT&T Observer Jennifer Alpert Palchak CareLex Member Aliaa Badr CareLex Member Oleksiy (Alex) Palinkash CareLex Member Beau Grignon Forte Research Systems Member Troy Jacobson Forte Research Systems Member Junichi Ishida Fujitsu Limited Member Mead Walker Health Level 7 (HL7) Member Sharon Elcombe Mayo Clinic Member Robert Gehrke Mayo Clinic Member Rich Lustig Oracle Member Lorie McClain Oracle Member Michael Agard Paragon Solutions Member Karen McCarthy Schau Paragon Solutions Member Chris McSpiritt Paragon Solutions Member Jamie O'Keefe Paragon Solutions Member Fran Ross Paragon Solutions Member Peter Alterman SAFE-BioPharma Association Member Catherine Schmidt SterlingBio Member Lou Chappuie SureClinical Chris Ibell SureClinical Member Ayrat Sadreev SureClinical Member Zack Schmidt, Chair SureClinical Member Trish Whetzel SureClinical Member Jill Malayang University of Michigan Member
eTMF Spec Workgroup Update Items in Progress - From eTMF Spec Workgroup’s Mar 16 2015 meeting: – Spec: • Rich Lustig, Oracle: Presented enhanced audit trail • Discussed format – TBD: Finalize format – Additional work completed • Finalization of outstanding ‘discussion items from comment resolutions’ • List of new eTMF terms prepared for submission to National Cancer Institute Thesaurus DB – To be done: • Submit terms to NCI thesaurus, get controlled vocab term assignment – THEN: » Add new metadata to RDF/XML code (from public comments) » Add new TMF RM artifacts to RDF/XML code (from public comments)
Audit Trail Definition An audit trail (also called audit log) is a security-relevant chronological record, set of records, and/or destination and source of records that provide documentary evidence of the sequence of activities that have affected at any time a specific operation, procedure, or event.
eTMF Interoperability and Audit Logs • Documents, files, file content tree, document versions necessary but insufficient for the purposes of eTMF interoperability • Registry-type data e.g. users, persons, organizations as well as related content audit logs are required
ASTM E2147 – Audit Log American Society for Testing and Materials (now ASTM International) 7. Audit Log Content [for Meaningful Use] 7.1 Audit log content is determined by regulatory initiatives, accreditation standards, and principles and organizational needs. Information is needed to adequately understand and oversee access to patient identifiable data in health information systems in order to perform security oversight tasks responsibly. Logs must contain the following minimum data elements: 7.2 Date and Time of Event 7.3 Patient Identification 7.4 User Identification 7.5 Access Device (optional) 7.6 Type of Action (additions, deletions, changes, queries, print, copy) 7.7 Identification of the Patient Data that is Accessed(optional) 7.8 Source of Access (optional unless the log is combined from multiple systems or can be indisputably inferred) 7.9 Reason for Access (optional) 7.10 If capability exists, there should be recognition that both an electronic “copy” operation and a paper “print” operation are qualitatively different from other actions.
Audit Logs – Candidate Attributes Candidate attributes for consideration – Date/timestamp (Universal time) – User ID performing action – User machine IP address used for access – User device type (mobile, desktop, phone etc.) – Study ID – Document or file ID – User action description – User action type (additions, deletions, changes, queries, print, copy) – Study subject ID – Reason for access
OASIS eTMF Audit Log – Proposed Attributes • [Timestamp] - GMT +/- local offset • [Person Name] - First, Last name of person making change • [Username] - (system username )@ system issuer domain name • Ex: joesmith@instance.issuer.com • [system ID] - ID of system providing info (format?) • [Content Item UUID] - UUID using RFC 4122, 128 bit ID of content item • [Content Item name] - Name of item from referring system • [Content Item Major.minor vn] - Version of content item • [Type of change] - History of action on content item: Create, Modify, Delete • [MD Attribute Changed] - If item modified is metadata – list MD attribute name. • [prev MD value] – If MD change, list the previous MD value • [new value] - If MD change, list the new MD value • [Reason for change] - Description or reason for change. Applies to content item or MD value change (optional)
Example OASIS eTMF Audit Log Record (for discussion) Timestamp Person Name Username System ID Content Version Type MD Previous New Reason MD MD for Item Of Attribute Value Value change Name Change Changed 17:00:01+4GMT Joe Smith joesmith instance.company.com server@abc.com 1000-A342-FDA-1572 03.01 Modify MD=Gender Male Female Corrected For discussion Needed: IP Address? - Study ID ? System Name? --Study ID: Required MD attribute for content item. Domain name? Don’t include this in the audit log domain name+system name: -Study Subject ID? [Node.company.com server name] --Study Subject ID: Optionl MD attribute for content What if system/source is from File? item. Don’t include this in the audit log [if no system: text description]
New Business • New Business – Discussion
Next Meeting(s) Agenda / Close • General OASIS eTMF TC Meeting date: – May 4 2015 9am-10.00am PT • eTMF Spec Workgroup update • New business • eTMF Spec Workgroup: – April 30 2015 8am-9am Meeting close
Recommend
More recommend