1) If the electronic signature on a given request doesn't match the name of the patient, we make sure that the patients are who they say they are before moving on with gathering the medical records.
2) If one tries to sign up on behalf of another patient, we require a Power of Attorney (POA) document!
Hope this answers your question!
2) How do you know they're trying to do that if they don't tell you? Your scenario looks like a regular situation, not an attack..
I'm assuming there's something I missed there.
This Safe Harbor Framework?: https://techcrunch.com/2015/10/06/europes-top-court-strikes-...
There seems to be a couple options!
1) Once we gather your records, we will work on creating a shareable summary of your health history. In that case, the physician can look at that summary via our web portal.
2) In many cases, most EHRs support the upload of PDFs. So, the documents you share can be "integrated" to hospital's EHR. This already happens in large hospital networks when hospitals gather medical records on behalf of patients before their appointments! When hospitals receive the records via fax or mail, they scan the pages to the EHR. Obviously, in the future, easier ways to export data (via EHR integrations) could be extremely valuable to patients and physicians!
We can certainly work on making that clearer up front though—thanks for the feedback!
For example, Palo Alto Medical Foundation has hospitals spread across the Bay Area. Some of the hospitals don't offer all the services but if you walk into a new branch for a specialized treatment, your new doctor will simply look up your old record or order it internally if they are not yet on the network.
Haven't looked at that many immutable databases, but they seem interesting. Most of the time medical data does not require many writes (rarely are two doctors editing your record simultaneously), but the audit trail that datomic provides could be very useful as a built-in feature.
With that said, there are a number of startups that have struggled with similar ideas. How are you different from, say, PicnicHealth?
What we've optimized for is simplicity—while our process for getting medical records from hospital A may var from our process with hospital B, we abstract all of that away and make the ordering process the same for all U.S. hospitals.