Feedback on Privacy section - DTR #73

XMLWordPrintableJSON

    • Type: Change Request
    • Resolution: Persuasive
    • Priority: Medium
    • US Da Vinci DTR (FHIR)
    • STU3
    • Clinical Decision Support
    • (profiles) [deprecated]
    • Privacy, Safety and
    • Hide

      Existing Wording: Some SMART on FHIR applications are browser based, such as those conforming to the public app profile.

      …

      Other SMART on FHIR applications are server based, such as those conforming to the confidential app profile.

      Replace with:

      Data retrieved by the SMART app from the provider's FHIR server may or may not be shared with, kept by the payer. Depending upon the SMART app's architecture, patient information obtained by the SMART app may or may not leave the provider's network.

      Providers should carefully evaluate SMART apps conforming to the DTR IG to evaluate risk.

      Show
      Existing Wording: Some SMART on FHIR applications are browser based, such as those conforming to the public app profile. … Other SMART on FHIR applications are server based, such as those conforming to the confidential app profile. — Replace with: Data retrieved by the SMART app from the provider's FHIR server may or may not be shared with, kept by the payer. Depending upon the SMART app's architecture, patient information obtained by the SMART app may or may not leave the provider's network. Providers should carefully evaluate SMART apps conforming to the DTR IG to evaluate risk.
    • Bob Dieterle / Rachael Foerster: 7-0-1
    • Clarification
    • Non-substantive

      Existing Wording: Some SMART on FHIR applications are browser based, such as those conforming to the public app profile.

      …

      Other SMART on FHIR applications are server based, such as those conforming to the confidential app profile.

      Comment:

      This distinction between single-page javascript applications and server-based app and the correlation with public and confidential SMART app profiles only complicates the point that you're trying to make, which, I think, is: data retrieved by the SMART app from the provider's FHIR server may or may not be shared with, kept by the payer. Depending upon the SMART app's architecture, patient information obtained by the SMART app may or may not leave the provider's network.

      Providers should carefully evaluate SMART apps conforming to the DTR IG to evaluate risk.

      Summary:

      Feedback on Privacy section

            Assignee:
            Unassigned
            Reporter:
            Michael Clifton
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: