Horst Herb wrote: > > > It is scalable. Depends on teaching & sticking to security policies. Think > of it as a pyramid. > Your pyramid is roughly comparable to three groups of access: 1) Everyone in the org. 2) Clinicians 3) Small group of clinicians and patient. Each group shares a passphrase to encryption. Shared secrets demonstrably are hard to protect as the number of people sharing the secret increases. Once again, as the number of users in the system increases, the security of the shared passphrase moves from marginal for category 1) to marginal for category 2) and probably not worth the effort for category 1). Most large organizations don't even implement a category 3 system, but it is the only model where human behavior and technical protections can intersect to provide a reasonable assurance of privacy. But if the access control were implemented in a way not using encryption, the same argument would apply. Encryption is a workable means of getting the protection to follow the data. The adminstration of the ACL is not really worked out, i.e. who has the passphrase. T
- RE: Principles of health care system security. Dave Hamilton
- Re: Principles of health care system security. Horst Herb
- Re: Principles of health care system security. Thomas Beale
- Re: Principles of health care system securi... Horst Herb
- Re: Principles of health care system se... Dr. Ernst Molitor
- Re: Principles of health care syst... Tim Cook
- Re: Principles of health care ... Wayne Wilson
- Re: Principles of health care ... Horst Herb
- Re: Principles of health care system se... Wayne Wilson
- Re: Principles of health care syst... Horst Herb
- RE: Principles of health care ... Wayne Wilson
- RE: Principles of health care system securi... Gerard Freriks
- RE: Principles of health care system security. Gerard Freriks
- Re: Principles of health care system securi... Wayne Wilson
- RE: Principles of health care system se... Gerard Freriks
- Re: Principles of health care system se... Horst Herb
- Re: Principles of health care system security. Wayne Wilson
- Re: Principles of health care system security. Sam Heard
- Re: Principles of health care system security. Chris Fraser
- Re: Principles of health care system security. Wayne Wilson
- Re: Principles of health care system security. Chris Fraser
