Uploaded image for project: 'i2b2 Core Software'
  1. i2b2 Core Software
  2. CORE-145

Users with LDS access can view de-identified data (i.e. reports)

    XMLWordPrintable

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • 1.7.02
    • 1.7.04
    • CRC Cell
    • None
    • Rank:
      0|i000db:
    • Timeline View
    • Roles Based Access
    • i2b2 Core
    • All databases
    • All Web Browsers
    • This can be reproduced in the i2b2 testing environment (release 1.7.02).
    • Hide
      Tested with build 1.7.04.0001 and the issue still exists.

      Tested with build 1.7.04.0002 and this issue appears to be working correctly.
      Show
      Tested with build 1.7.04.0001 and the issue still exists. Tested with build 1.7.04.0002 and this issue appears to be working correctly.

    Description

      Users with Limited data access are able to view de-identified data in the i2b2. Users with DATA_LDS should not be able to see any data that can be encrypted.

      Only those users with DATA_DEID (de-identified) access can view information that can be encrypted (i.e. text in the *_blob columns). If the data is encrypted the user will still need the decryption key to decrypt the data before viewing it.

      Attachments

        Activity

          People

            jmd86 Janice Donahoe
            jmd86 Janice Donahoe
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: