Hacker News new | ask | show | jobs
by htechenjoyer 871 days ago
That's simply not true. The user is not the only stakeholder. The example I gave opens up the hospital to fines from the government and in the worst case scenario a massive legal judgement from the patient who's data was breached by a physician leaving his workstation with a patient record opened and it was compromised by a malicious actor.

edit: in any case this is very likely a security configuration by the hospital infosec team, not the developer of the EMR.