OASIS members have published a draft charter for a proposed "Cross-Enterprise Security and Privacy Authorization (XSPA) Technical Committee" healthcare enterprises. The XSPA profile would provide a mechanism to exchange privacy policies, consent directives and authorizations in an interoperable manner. The need for an XSPA profile has been identified by the security and privacy working group of the Healthcare Information Technology Standards Panel (HITSP).
The XSPA profile will require the participation of subject matter experts in several areas, including WS-Federation, SAML, and WS-Trust. Current TC proposers include representatives from Cisco, Redhat, Symlabs, and the U.S. Veterans Health Administration.
Comments on the proposed charter should be submitted by 23 June 2008.