Worse, it is trivial to tamper with this and insert forged pager messages. A lot of harm could be done with this, possibly even leading to death of patients.
Worse, it is trivial to tamper with this and insert forged pager messages. A lot of harm could be done with this, possibly even leading to death of patients.
Extending the model beyond "Call this extension" starts to go awry. There are ways of maintaining privacy: just don't connect the personal info with an identity. Yes, I know stuff like this can be deanonymized, but you need a lot of data to do so. "Consult requested for patient 432432434" or "Check results for 34334343" or "Consult required in 4W-34"
> The data being broadcast includes the patients name, age, gender marker, diagnosis, their attending doctor and room number. Other broadcasts regarding medical tests such as x-rays are often associated with a patients last name or medical number, exposing their progression through hospital departments.
https://openprivacy.ca/blog/2019/09/09/open-privacy-discover...
If it's the organization's in-house medical number, that should be okay. It's literally a random identifier number. Or better yet, use a visit number, test number or result number to avoid linking them together.