-
Type:
Change Request
-
Resolution: Not Persuasive
-
Priority:
Medium
-
US Da Vinci PAS (FHIR)
-
STU3
-
Financial Mgmt
-
(profiles) [deprecated]
-
Overall
-
-
Kathleen Connor / Robert Dieterle: 20-0-1
Comment:
The ballot should include a discussion of Privacy and Security issues. For example, the following issues should be discussed and addressed:
- Authorization details such as OAuth scopes for this type of transaction.
- Details of handling authorization in presence of intermediaries. Do intermediaries terminate OAuth authorization or do they relay the access token? What are the risks of exposing client access tokens to the intermediary and how does that affect accountability and audits?
- Any health information in the claims and other resources included in the request which is provided to the payer via the CDS or directly (via driect retrieval) should be marked with handling instructions and security labels to ensure this information is not used, redisclosed, or retained by the payer beyond the intended purpose ("share with prorection").
Summary:
The ballot should include a discussion of Privacy and Security issues.
- is voted on by
-
BALLOT-10855 Negative - Kenneth Rubin : 2019-Sep-FHIR IG PAS R1
- Balloted