How do you handle authentication and authorization? Suppose I have a nefarious enemy who attempts to use your service to obtain my medical records so he can poison me or embarrass me or something. How does he fail?
1) If the electronic signature on a given request doesn't match the name of the patient, we make sure that the patients are who they say they are before moving on with gathering the medical records.
2) If one tries to sign up on behalf of another patient, we require a Power of Attorney (POA) document!
Hope this answers your question!
2) How do you know they're trying to do that if they don't tell you? Your scenario looks like a regular situation, not an attack..
I'm assuming there's something I missed there.
This Safe Harbor Framework?: https://techcrunch.com/2015/10/06/europes-top-court-strikes-...