# Security of EHR, etc

**URL:** <https://forums.librehealth.io/t/security-of-ehr-etc/890>\
**Category:** Development\
**Created:** [June 23, 2017, 7:40pm UTC](https://forums.librehealth.io/t/security-of-ehr-etc/890 "2017-06-23T19:40:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tony](https://forums.librehealth.io/user_avatar/forums.librehealth.io/tony/32/42_2.png) [@tony](https://forums.librehealth.io/u/tony)\
**Post date:** [June 23, 2017, 7:40pm UTC](https://forums.librehealth.io/t/security-of-ehr-etc/890/1 "2017-06-23T19:40:04Z")

</div>

Security is always a topic worth discussing… Patient Portals are a big issue and we need to discuss models that are NOT browse directly into the data models …

This extract from: [Compromise Assessments & Penetration Testing in Healthcare | Healthcare IT Today](http://www.emrandhipaa.com/guest/2017/06/21/compromise-assessments-penetration-testing-in-healthcare/)

> True Health Diagnostics, a Frisco, TX-based healthcare services company recently became aware of a security flaw in their patient portal after an IT consultant logged in to view their test results and accessed other patient’s records by accident. Upon investigating the issue it was determined that because True Health uses sequential numbers on their patient record PDF files, users of the patient portal could easily alter a digit in the URL and therefore view the medical information of other patients (also known as Forceful Browsing).\_

We need to move forward with API (like FHIR) based solutions for access to patient data via apps, not portals.

---

<div class="post-metadata">

**Author:** ![rhoyt](https://forums.librehealth.io/user_avatar/forums.librehealth.io/rhoyt/32/93_2.png) [@rhoyt](https://forums.librehealth.io/u/rhoyt)\
**Post date:** [November 30, 2017, 9:36pm UTC](https://forums.librehealth.io/t/security-of-ehr-etc/890/2 "2017-11-30T21:36:51Z")

</div>

@tony

The vulnerability of OpenEMR made the [press](https://www.beckershospitalreview.com/cybersecurity/security-researchers-discover-vulnerability-in-openemr-that-potentially-compromises-90m-health-records.html) today. I have no idea if LibreHealth shares the same

---

<div class="post-metadata">

**Author:** ![aethelwulffe](https://forums.librehealth.io/user_avatar/forums.librehealth.io/aethelwulffe/32/63_2.png) [@aethelwulffe](https://forums.librehealth.io/u/aethelwulffe)\
**Post date:** [November 30, 2017, 10:01pm UTC](https://forums.librehealth.io/t/security-of-ehr-etc/890/3 "2017-11-30T22:01:05Z")

</div>

Yeah, that is a file you supposed to remove after setup.

Wouldn’t call this really “The Press” though…it’s someone’s mostly contextually irrelevant blog post. Where and how they would _possibly_ come up with a “90 million patients” number clues me into the fact that it is not exactly a…a peer-reviewable paper…

---

<div class="post-metadata">

**Author:** ![tony](https://forums.librehealth.io/user_avatar/forums.librehealth.io/tony/32/42_2.png) [@tony](https://forums.librehealth.io/u/tony)\
**Post date:** [December 1, 2017, 8:20pm UTC](https://forums.librehealth.io/t/security-of-ehr-etc/890/4 "2017-12-01T20:20:04Z")

</div>

Plus the “fix” is to simply delete the setup.php file after the setup is completed, as instructed.

We have a more elegant solution in the works, but it’s not a real vulnerability, its a security service using OpenEMR to advertise himself since he can’t do this kind of work on a proprietary product. The community typically benefits from this kind of transparency.

---

<div class="post-metadata">

**Author:** ![r0bby](https://forums.librehealth.io/user_avatar/forums.librehealth.io/r0bby/32/1781_2.png) [@r0bby](https://forums.librehealth.io/u/r0bby)\
**Post date:** [December 1, 2017, 11:34pm UTC](https://forums.librehealth.io/t/security-of-ehr-etc/890/5 "2017-12-01T23:34:08Z")

</div>

Removed the setup.php file.
