[Openid-specs-heart] Health Relationship Trust Profile for Fast Healthcare Interoperability Resources (FHIR) OAuth 2.0 Scopes
Kinsley, William
BKinsley at nextgen.com
Mon Oct 5 21:31:44 UTC 2015
This document was presented quickly during the last few minutes of our call and I am not sure what the objective was. However, it did raise some questions that could not be addressed at the time, specifically paragraph 2.1 "Permission type" raised some questions which I broke out below:
1) The term "Patient" and "User" seem misleading and the purpose is not clear.
a. A patient can have access to multiple patient records. For example, a parent who has five children at the same pediatrician would be a patient that can access multiple patient records.
b. It also sounds like we are hardcoding two specific security roles, which would seem to contradict what we are trying to support in HEART (i.e. RBAC vs ABAC).
c. There can be resource that are not related to specific patient or patients in general such as "Organization", "HealthcareService", "Practitioner", etc.
Bill
[http://bridge.nextgen.com/Media/3140]
________________________________
William Kinsley , CISSP
Enterprise Architect, Ambulatory
NEXTGEN HEALTHCARE
Solutions for: Ambulatory, Inpatient and Community Connectivity
795 Horsham Road, Horsham, PA 19044
(215) 657-7010 x21128
BKinsley at nextgen.com [http://bridge.nextgen.com/Media/3181] <http://www.oneugm.com>
Be ready for MU and ICD-10 in 2015. Start your EHR version 5.8 and KBM version 8.3 upgrade today. Get the resources you need at www.nextgen.com/upgradecentral<http://www.nextgen.com/upgradecentral>
This message, and any documents attached hereto, may contain confidential or proprietary information intended only for the use of the addressee(s) named above or may contain information that is legally privileged. If you are not the intended addressee, or the person responsible for delivering it to the intended addressee, you are hereby notified that reading, disseminating, distributing or copying this message is strictly prohibited. If you have received this message by mistake, please immediately notify us by replying to the message and delete the original message and any copies immediately thereafter. Thank you for your cooperation.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-heart/attachments/20151005/963cad6f/attachment.html>
More information about the Openid-specs-heart
mailing list