blankev wrote on Monday, March 03, 2014:
My thought on this is as follows:
Any doctor can be hold responsible for his deeds if this doctor see some medical information. At least the doctor can be told that whenever he/she sees medical information it is supposed to be in the field of Hypocrates and is a secret.
If there is need to have an important change in Drug, Inventory, even other products and this is done by a non medical trained person, the medical information should be hidden for spying eyes. (This could lead to a breech, or something for conformation to HIPAA rules IMHO).
What I met in my discovery challenge towards better understanding GACL is that there are about 10 login options (Administration, Accountancy, Doctor, Physician, Nurse, Frontdesk, etc … ) fine-tuned for what they can see and what they can do. (Calendar, SuperBill, Patients, Drugs and Inventory, etc )
The SuperUser can DELETE, ADD, CHANGE…
All others are restricted in some way derived from modules. What I did not investigate, is what happens if some modules are “Allow” -ed and some modules are “Deny” -ed and so fine-tune a lay-person to get the correct Allow-s and Deny-s for medical information. Make a Child for a Child for a child in ACO and ARO. But if it is so easy, please guide me towards the correct place, since the explanation in the WIKI is from the 2.9.0 and 3.0 versions and some of the names of the mentioned files are changed or hidden in another Directory and not as shown in the WIKI about phpGACL.
(But having computers with terra- Harddisks, Cloud storage, intelligent control/use of the Add function of Drug and Inventory, there is hardly a need to DELETE. So my question might be more of theoretical interest and not of any practical use for the average OpenEMR addict)