Never auto-provision Patient Records into a tenant

OtherSecurityService
已装运
2026年8月27日 16:01 UTC
作者
Kamo
提交
4040498

Two of the three paths that would hand a clinical record system to orgs that never asked for one, now that ServiceType.EHR is COMPLETED and therefore available. FeatureController.list auto-enables every available non-core app with no OrgFeature row -- on an ordinary Settings page load, for every org. The same loop exists in OrganizationController's host lookup, which is PUBLIC and UNAUTHENTICATED. Both already called isPhiPermitted, and that is the trap rather than the fix: PhiTenantGuard returns true for EVERY module when a tenant is NOT_PHI, because it exists to keep a PHI tenant inside the compliance boundary, not to keep the boundary out of everyone else. It reads like the check that would stop this and it is the check that would wave it through. Third: resolveAppProvisioningPlan fell back to the applied model's default for any app the creator did not answer for. "Enabled by default" is a reasonable answer for a calendar and the wrong one for a record system, so the EHR now gets a row that is OFF instead -- discoverable and switchable, but never on because nobody said so. An explicit yes in the wizard still turns it on; the exclusion is about defaults, not about refusing.

所有更改

就像你看到的运输?

每一个都自动更新您工作空间的地盘。 开始自由,看它成长 一周又一周.

永远开始自由查看定价