RE: AS2 returning EDI
"Eric D. Williams" <[email protected]>
| Newsgroups | gmane.ietf.ediint |
|---|---|
| Organization | Information Brokers, Inc. |
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Jim; The only previously stipulated mechanism for authentication that is 'definite' is the following: "It is expected that companies following the GISB AS2 profile will protect their web sites from unauthorized access through the use of basic authentication (username/passwords), as defined in the HTTP specification. GISB is not "requiring" the use of signed receipts; however, signed receipts are allowed between consenting trading partners." [http://www.ietf.org/internet-drafts/draft-ietf-ediint-as2-07.txt] Now, there may be an allowable construct in the healthcare industry under the HIPPA where the provider should be obligated to establish a vetting process for individuals or entities requesting information. with regard to the establishment of these procedures it would seem to me as an encumbrance on the provider to establish a mechanism (easily reached by the client/patient/service recipient and physician) which provides a lag for outside requests/denials ["for disclosure or use for research purposes, an Internal Review Board (IRB) or Privacy Review Board must make several determinations about the need for the PHI and the ability of the researcher to protect the information."..."of health and non-health items and services, disclosure by sale, rental, or barter, disclosure to an employer for use in employment determinations, and use or disclosure for fundraising."] to access. With regard to your specific query no other 'standard' for HTTP presentation is indicated that would augment the aforementioned - BTW, the use of PGP for additional security integrity (not authenticity) has been addressed. Hope this helps. Eric Eric Williams, Pres. Information Brokers, Inc. Phone: +1 202.889.4395 http://www.infobro.com/ Fax: +1 202.889.4396 mailto:[email protected] Pager: +1 301.303.8998 For More Info: [email protected] PGP Public Key http://new.infobro.com/KeyServ/EricDWilliams.asc Finger Print: 1055 8AED 9783 2378 73EF 7B19 0544 A590 FF65 B789 On Monday, January 08, 2001 11:55 AM, Jim Hurd [SMTP:[email protected]] wrote: > I would like a future AS2 to clarify how EDI should be returned in the http > response. This is needed for healthcare transactions like eligibility checks. > I assume that the generalized receipt mechanism could be used, but isn't this > important enough to standardize? Are there already proposals to this effect > that I am unaware of? > > Jim > > << File: ATT00004.htm >> -----BEGIN PGP SIGNATURE----- Version: PGP 6.5.8 iQA/AwUBOlpMYAVEpZD/ZbeJEQImwACg1PZWaIBTQeLBtiEqtcMrsKKXPEAAn3YG 0i5pKiPonHyXnIVbt5d82yop =0dmH -----END PGP SIGNATURE-----