> But if EHRs are to be moved about we need to be publish the security model
> in a form that consumers can comprehend and be sure who is going to have
> access to what parts of their EHR and under what circumstances.
>
> Just saying it is too hard will not suffice.

I believe that ultimately there will be no other way than the way gnumed
implements access regulation: arbitrary encryption at column level. The
patient or the doctor can decide at any time which fraction of information
shall be restricted in access. Algorithms have to be implemented as
plug-ins, as virtually all cryptographic algorithms have only limited "life
span".

Horst

Reply via email to