RE: AS2 returning EDI

"Eric D. Williams" <[email protected]>
Newsgroups gmane.ietf.ediint
Organization Information Brokers, Inc.
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Jim;

The only previously stipulated mechanism for authentication that is 'definite' 
is the following:

"It is expected that companies following the GISB AS2 profile will protect
their web sites from unauthorized access through the use of basic
authentication (username/passwords), as defined in the HTTP specification.

GISB is not "requiring" the use of signed receipts; however, signed receipts
are allowed between consenting trading partners."

[http://www.ietf.org/internet-drafts/draft-ietf-ediint-as2-07.txt]

Now, there may be an allowable construct in the healthcare industry under the 
HIPPA where the provider should be obligated to establish a vetting process for 
individuals or entities requesting information.  with regard to the 
establishment of these procedures it would seem to me as an encumbrance on the 
provider to establish a mechanism (easily reached by the client/patient/service 
recipient and physician) which provides a lag for outside requests/denials 
["for disclosure or use for research purposes, an Internal Review Board (IRB) 
or Privacy Review Board must make several determinations about the need for the 
PHI and the ability of the researcher to protect the information."..."of health 
and non-health items and services, disclosure by sale, rental, or barter, 
disclosure to an employer for use in employment determinations, and use or 
disclosure for fundraising."] to access.

With regard to your specific query no other 'standard' for HTTP presentation is 
indicated that would augment the aforementioned - BTW, the use of PGP for 
additional security integrity (not authenticity) has been addressed.  Hope this 
helps.

Eric

Eric Williams, Pres.
Information Brokers, Inc.    Phone: +1 202.889.4395
http://www.infobro.com/        Fax: +1 202.889.4396
mailto:[email protected]      Pager: +1 301.303.8998
           For More Info: [email protected]
                    PGP Public Key
   http://new.infobro.com/KeyServ/EricDWilliams.asc
Finger Print: 1055 8AED 9783 2378 73EF  7B19 0544 A590 FF65 B789



On Monday, January 08, 2001 11:55 AM, Jim Hurd [SMTP:[email protected]] 
wrote:
> I would like a future AS2 to clarify how EDI should be returned in the http
> response. This is needed for healthcare transactions like eligibility checks.
> I assume that the generalized receipt mechanism could be used, but isn't this
> important enough to standardize? Are there already proposals to this effect
> that I am unaware of?
>
> Jim
>
>  << File: ATT00004.htm >>
-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.8

iQA/AwUBOlpMYAVEpZD/ZbeJEQImwACg1PZWaIBTQeLBtiEqtcMrsKKXPEAAn3YG
0i5pKiPonHyXnIVbt5d82yop
=0dmH
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.