[Openid-specs-heart] Resources vs Resource sets

Glen Marshall [SRS] gfm at securityrs.com
Wed Jul 27 20:03:26 UTC 2016


The boundary of existing regulatory mandates for privacy and security is a bright line.  It defines the minimum we in health IT must achieve.  Anything beyond that either anticipates regulatory change or states an objective or some sort.

In the case of covered entities’ objectives, we can assume they have performed HIPAA-required risk analysis and set risk management policies accordingly. I believe that OAuth and UMA operate most effectively in a such a businesslike risk-mitigation environment, where the semantics of the security and privacy metadata are unambiguous.

When we honor patient-specific privacy choices, we ignore covered entity risk assessment and in-common semantics.  Patients are under no obligation to perform a formal business risk analysis or articulate it in a commonly-understood way.  Their choices may be realistic or not, articulate or not.  We have no simple objective basis to assess, let alone enforce, them.

It is a philosophic ethical question as to how we honor patient privacy choices.  It is not clear to me that the health IT marketplace is ready to answer it.


Glen F. Marshall
Consultant
Security Risk Solutions, Inc.
698 Fishermans Bend
Mount Pleasant, SC 29464
Tel: (610) 644-2452
Mobile: (610) 613-3084
gfm at securityrs.com
www.SecurityRiskSolutions.com<http://www.securityrisksolutions.com/>

From: Openid-specs-heart [mailto:openid-specs-heart-bounces at lists.openid.net] On Behalf Of Aaron Seib
Sent: Wednesday, July 27, 2016 14:25
To: Adrian Gropper <agropper at healthurl.com>; Salyards, Kenneth (SAMHSA/OPPI) <Kenneth.Salyards at samhsa.hhs.gov>
Cc: HEART List <openid-specs-heart at lists.openid.net>
Subject: Re: [Openid-specs-heart] Resources vs Resource sets

I don't understand why we would even ask the consumer what their preference is if they can't change a default used by a Covered Entity?

That is the entire point.





Aaron Seib

The trick to establishing trust is to avoid all tricks.  Especially tricks on yourself.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-heart/attachments/20160727/73ea3816/attachment-0001.html>


More information about the Openid-specs-heart mailing list