gpcnetwork / gpc_va-linkage

This repo will host sharable resources on GPC advancing Datavant tokenization of the Veterans Administration (VA) and Department of Defense (DoD) electronic health records to support linkage across PCORnet and the corresponding Governance processes.
1 stars 1 forks source link

[UIOWA] Hash token submit to GPC CC #8

Closed vyshu1094 closed 1 year ago

vyshu1094 commented 1 year ago

Please request additional regulatory documents and approval locally

bgryzlak commented 1 year ago

UIowa IRB adjudicated this work to be not-HSR. The remaining step is to obtain external data sharing committee approval. Once that is done UIowa can submit data. Is there a date after which UIowa data cannot be used for this work?

vyshu1094 commented 1 year ago

@sxinger please answer @bgryzlak 's question

bgryzlak commented 1 year ago

@sxinger Also, some questions i need answers to for the external data review submission:

  1. Length of Engagement - # of months this data will be stored outside of the healthcare covered entity.
  2. Can you describe the data access controls of the system we are sharing data to? I looked but couldn't find anything in GitHub (may have missed it)
  3. Who will be able to see the data? (research team members at MU and Utah?)
  4. What is your data management plan? I looked but couldn't find anything in GitHub (may have missed it)
  5. What happens to data after engagement? - will the data ever be destroyed? or retained consistent with the GPC contract, etc?
  6. If intellectual property will be developed, who owns it? (consistent with whatever is in the GPC contract?)
bgryzlak commented 1 year ago

Hi @sxinger, just making sure you saw the above questions. Thanks!

bgryzlak commented 1 year ago

@vyshu1094 is Song OOO or maybe not receiving notifications?

sxinger commented 1 year ago

@bgryzlak my apologies for the late reply!

@sxinger Also, some questions i need answers to for the external data review submission:

  1. Length of Engagement - # of months this data will be stored outside of the healthcare covered entity.

12 months since data submission.

  1. Can you describe the data access controls of the system we are sharing data to? I looked but couldn't find anything in GitHub (may have missed it)

Approved personnel at GPC CC will aggregate the hash token tables and then transfer the aggregated hash token tables to VA team to complete an analysis of the number of overlapping patients. The approved personnel on VA linkage team will perform the linkage with VA data, and the approved personnel at analytic team will perform the overlap analysis who has with no access to GPC clinical data. This language has been incorporated in the corresponding DROC request per Carol's request.

  1. Who will be able to see the data? (research team members at MU and Utah?)

Only approved research team members at MU and Utah will be able to access the data (less than 4 people). We can provide a list of personnel if needed.

  1. What is your data management plan? I looked but couldn't find anything in GitHub (may have missed it)

We are following the CMS-approved data management plan, which we have developed for GROUSE following the NIST-800-53 controls. Would that be sufficient? Or additional material is needed.

  1. What happens to data after engagement? - will the data ever be destroyed? or retained consistent with the GPC contract, etc?

Data will be retained consistent with the GPC contract. But as discussed before, for new funded projects with more extensive data needs, we will submit a new DROC request with a new project-specific DV token.

  1. If intellectual property will be developed, who owns it? (consistent with whatever is in the GPC contract?)

Consistent with GPC master contract.

bgryzlak commented 1 year ago

Thank you for this @sxinger . I just submitted the request to the external data sharing review committee. It was adjudicated not HSR by the UIOWA IRB so this committee review is the last admin hurdle. -Brian

sxinger commented 1 year ago

Thank you for this @sxinger . I just submitted the request to the external data sharing review committee. It was adjudicated not HSR by the UIOWA IRB so this committee review is the last admin hurdle. -Brian

That's awesome news! let me know if anything else is needed from us. - Song

bgryzlak commented 1 year ago

Will do!

From: SongX @.> Sent: Monday, February 20, 2023 1:45 PM To: gpcnetwork/gpc-va-linkage @.> Cc: Gryzlak, Brian M @.>; Mention @.> Subject: [External] Re: [gpcnetwork/gpc-va-linkage] [UIOWA] Hash token submit to GPC CC (Issue #8)

Thank you for this @sxingerhttps://github.com/sxinger . I just submitted the request to the external data sharing review committee. It was adjudicated not HSR by the UIOWA IRB so this committee review is the last admin hurdle. -Brian

That's awesome news! let me know if anything else is needed from us. - Song

— Reply to this email directly, view it on GitHubhttps://github.com/gpcnetwork/gpc-va-linkage/issues/8#issuecomment-1437481781, or unsubscribehttps://github.com/notifications/unsubscribe-auth/AFDABA3TXG4ADXKO3I4OSZLWYPCTJANCNFSM6AAAAAAUB4QFKI. You are receiving this because you were mentioned.Message ID: @.**@.>>

bgryzlak commented 1 year ago

hi @sxinger ,

Data Gov committee at UIowa is asking the following - can you get me answers to these? Thanks!

  1. Who owns the Amazon S3 bucket where the data will be stored? It is unclear if this is a VA/FEDRAMP bucket, or an AWS bucket purchased by a PI at MU/Utah that is being used for the data consolidation (before comparison).
  2. What controls have been put in place on that environment?
sxinger commented 1 year ago
  1. Who owns the Amazon S3 bucket where the data will be stored? It is unclear if this is a VA/FEDRAMP bucket, or an AWS bucket purchased by a PI at MU/Utah that is being used for the data consolidation (before comparison).

University of Missouri owns the Amazon S3 bucket where the hash token file is stored. This S3 bucket is part of the approved environment where we also stored CMS data (but in a separate S3 bucket).

  1. What controls have been put in place on that environment?

The S3 bucket is completely private and can only be accessed by approved roles via TLS/SSL protocols (guarantee encryption at rest and in transit). Full s3 bucket security details can be found in this attached pdf document. Data_IO_Management.pdf

MU-NIUX commented 1 year ago

@bgryzlak Do you need any other information on this? Will @giyungryu have to upload the token? If he is OOO for March, we would want to have someone else get this done.

bgryzlak commented 1 year ago

@MU-NIUX no we don't need anything else. We have the data ready to share but are awaiting review/approval by the UIHC External Data Sharing Committee.

bgryzlak commented 1 year ago

@sxinger or @MU-NIUX , we have approval to share DaVINIC data. Do you know if I have access to the IOWA-specific bucket or if not, can someone grant my access to it?

sxinger commented 1 year ago

@bgryzlak we currently have 2 data uploaders from UIOWA, who should have access to the data upload bucket "gpc-uiowa-upload".

image

According to our protocol, we will only allow at most two data uploaders from each site, who would you like me to swap out the seat for you?

bgryzlak commented 1 year ago

OK thanks @sxinger. Can you please swap out Michael Wright for me? He's no longer at the UIOWA.

sxinger commented 1 year ago

@bgryzlak thanks for letting us know.

@aaronmbruce please completely delete the use account for Michael Wright and create a new user account with the following spec:

aaronmbruce commented 1 year ago

@bgryzlak I have set up a new account for you.

bgryzlak commented 1 year ago

Thanks. I’ve tried a few times to connect via WinSCP but keep getting an access denied error. The tokens for the GPC-UIowa-Data-Load role are still active/legit?

From: aaronmbruce @.> Sent: Tuesday, April 11, 2023 11:04 AM To: gpcnetwork/gpc-va-linkage @.> Cc: Gryzlak, Brian M @.>; Mention @.> Subject: [External] Re: [gpcnetwork/gpc-va-linkage] [UIOWA] Hash token submit to GPC CC (Issue #8)

@bgryzlakhttps://github.com/bgryzlak I have set up a new account for you.

— Reply to this email directly, view it on GitHubhttps://github.com/gpcnetwork/gpc-va-linkage/issues/8#issuecomment-1503679986, or unsubscribehttps://github.com/notifications/unsubscribe-auth/AFDABAY3YQN7PTXUW6Y4O3LXAV6F3ANCNFSM6AAAAAAUB4QFKI. You are receiving this because you were mentioned.Message ID: @.**@.>>

bgryzlak commented 1 year ago

Ignore that actually as I think I found how to upload our data.

From: aaronmbruce @.> Sent: Tuesday, April 11, 2023 11:04 AM To: gpcnetwork/gpc-va-linkage @.> Cc: Gryzlak, Brian M @.>; Mention @.> Subject: [External] Re: [gpcnetwork/gpc-va-linkage] [UIOWA] Hash token submit to GPC CC (Issue #8)

@bgryzlakhttps://github.com/bgryzlak I have set up a new account for you.

— Reply to this email directly, view it on GitHubhttps://github.com/gpcnetwork/gpc-va-linkage/issues/8#issuecomment-1503679986, or unsubscribehttps://github.com/notifications/unsubscribe-auth/AFDABAY3YQN7PTXUW6Y4O3LXAV6F3ANCNFSM6AAAAAAUB4QFKI. You are receiving this because you were mentioned.Message ID: @.**@.>>

bgryzlak commented 1 year ago

@aaronmbruce , @sxinger, is the target file upload destination:

s3://gpc-uiowa-upload/ OR s3://gpc-uiowa-upload/va-linkage-pilot/ OR something else?

bgryzlak commented 1 year ago

@aaronmbruce , @sxinger, is the target file upload destination:

s3://gpc-uiowa-upload/ OR s3://gpc-uiowa-upload/va-linkage-pilot/ OR something else?

@sxinger , @aaronmbruce can you please advise on this? Thanks!

sxinger commented 1 year ago

s3://gpc-uiowa-upload/

please just upload to the root bucket s3://gpc-uiowa-upload/ . Once we reviewed the upload, we will move it to the ./va-linkage-pilot folder on our end

bgryzlak commented 1 year ago

@sxinger - just uploaded. Can you please confirm receipt?

bgryzlak commented 1 year ago

@sxinger @spinkac can you please confirm receipt of the Iowa token data?

sxinger commented 1 year ago

@bgryzlak received and validated. Thank you so much for the effort!

bgryzlak commented 1 year ago

Thanks!

From: SongX @.> Sent: Tuesday, April 25, 2023 12:32 PM To: gpcnetwork/gpc-va-linkage @.> Cc: Gryzlak, Brian M @.>; Mention @.> Subject: [External] Re: [gpcnetwork/gpc-va-linkage] [UIOWA] Hash token submit to GPC CC (Issue #8)

@bgryzlakhttps://github.com/bgryzlak received and validated. Thank you so much for the effort!

— Reply to this email directly, view it on GitHubhttps://github.com/gpcnetwork/gpc-va-linkage/issues/8#issuecomment-1522162859, or unsubscribehttps://github.com/notifications/unsubscribe-auth/AFDABA3CYBJAW3KVL2NICRLXDADBXANCNFSM6AAAAAAUB4QFKI. You are receiving this because you were mentioned.Message ID: @.**@.>>