|
|
Post #1 (permalink)
05-11-2005, 09:40 AM
|
HD Master
Join Date: Sep 2002
Location: Jungle
Posts: 411
Status:
|
I have a local design client who has asked me to find a reliable web host for them for a dedicated server. This client is a major hospital and they plan on maintaining some sensitive patient info on the server. So privacy is an obvious concern.
If the server is physically located in the US, their concern relates to any implications with The Patriot Act. They need to be assured that all info is private and will always remain so. Otherwise, I will need to source out a host who uses a Canadian datacenter.
Any wisdom you can share on this? Aside from your own thoughts, I would greatly appreciate any links to verifiable sources that actually address this issue.
Vito
__________________
DemoDemo.com-The pioneer in Flash tutorials for web hosts - since 2002
OnlineSupport.org- VERY targetted advertising venue for web hosts.
|
|
|
|
|
|
|
Post #2 (permalink)
05-11-2005, 09:58 AM
|
HD Wizard
Join Date: Jul 2003
Location: IA
Posts: 1,020
Status:
|
The hospital in question is in Canada?
Edit: If found this:
Quote:
|
However, Graham Hospital Association does comply with court orders requesting the release of information about access to our web site, log files, etc. In the event of an eminent threat, the Federal “Patriot Act” requires us to turn over all information to law enforcement officials even in the absence of a court order. The court orders and the Patriot Act could force a release of information. Some court orders are accompanied by a “gag” order that prevents us from notifying a customer that we have released his/her information to authorities.
|
From here:
http://www.grahamhospital.org/About/legal.htm
Last edited by Exon : 05-11-2005 at 10:01 AM.
|
|
|
|
|
|
|
Post #3 (permalink)
05-11-2005, 10:08 AM
|
HD Master
Join Date: Sep 2002
Location: Jungle
Posts: 411
Status:
|
Thanks, John. But that hospital is in the US, my client is in Canada. Sorry, I should have been more specific.
Vito
__________________
DemoDemo.com-The pioneer in Flash tutorials for web hosts - since 2002
OnlineSupport.org- VERY targetted advertising venue for web hosts.
|
|
|
|
|
|
|
Post #4 (permalink)
05-11-2005, 12:13 PM
|
HD Wizard
Join Date: Sep 2004
Location: Pennsylvania
Posts: 1,606
Status:
|
Vito, as far as I am aware, the hospital has no legal obligation to release any information whatsoever.
Under the Patriot Act, only US citizens are subject to it. In addition, the hosting provider does not have to grant access to any privacy sensitive materials, such as passwords, etc. This would be the only information the server provider would have.
The server provider is only obligated to release the information obtained on the client, such as address, name, phone number, and IP. Passwords, and usernames are not included under the Patriot Act. The client you're hosting, if in the US, would then be obligated to supply information on their clients/patience. However, as stated, since they are not located within the US, they are not governed by US law, and thus do not have to comply. They can of course comply upon their own wishes, but are certainly not obligated to do so.
We for example have to follow the Patriot Act, as does any business in the US now. However, the information we're obligated to provide is only the information we obtain on the client, not including username and password information.
Heads up however, regardless of country or if the username/password is supplied, the United States Government can and will retrieve the data if they want... (This is what I used to do in the Army as a Special Forces Operator.) If they feel the information is that much of a threat to National Security, they will ask for the information up front. The host however is not obligated to provide it. At that point they will enlist Ops/CIA/NSA to crack anything, do it silently, and obtain the information on their own. Unfortunately no computer is safe from that.
Damn nasty world we live in lol However, feel safe in knowing that they typically will not do the above unless they feel the information is of tremendous National Security importance.
__________________
Mark - Co-President/Lead Developer
• avidInteractive Software
• The ServeraSuite 2007 Award Winning Professional Server Monitoring Solution - Click here
|
|
|
|
|
|
|
Post #5 (permalink)
05-11-2005, 01:01 PM
|
HD Master
Join Date: Sep 2002
Location: Jungle
Posts: 411
Status:
|
Thanks for the explanation, Mark.
I guess what I'm having trouble finding is a reference to an authoritative source that I can send to my client. It's one thing to elaborate in an email about it. It's quite another to back it up with supportive references. And the latter is what my client will be looking for.
Vito
__________________
DemoDemo.com-The pioneer in Flash tutorials for web hosts - since 2002
OnlineSupport.org- VERY targetted advertising venue for web hosts.
|
|
|
|
|
|
|
Post #6 (permalink)
05-11-2005, 01:16 PM
|
HD Wizard
Join Date: Sep 2004
Location: Pennsylvania
Posts: 1,606
Status:
|
In that case, give me a few hours, and I'll have it for you 
__________________
Mark - Co-President/Lead Developer
• avidInteractive Software
• The ServeraSuite 2007 Award Winning Professional Server Monitoring Solution - Click here
|
|
|
|
|
|
|
Post #7 (permalink)
05-11-2005, 02:10 PM
|
HD Wizard
Join Date: Sep 2004
Location: Pennsylvania
Posts: 1,606
Status:
|
And here you go:
http://www.epic.org/privacy/terrorism/hr3162.html
Section 215, Amendmant 501
Also note, that by the end of this year they are adding a sunset provision to this article that says internet service providers may release information, voluntarily only. In other words, if the ISP notices something suspicious, they can determine on their own, to contact the FBI and release that information.
http://www.fbi.gov/page2/may05/hulon050905.htm
Until then, there have been provisions that state that the authorities must only request records within an ongoing investigation, in which the records are suspected of being linked to terrorist activity. They are not permitted any longer to simply "sneek a peek" they must show due cause now, and must provide documentation to the business (host).
SO there is some safety for you, with more to come by the end of the year.
__________________
Mark - Co-President/Lead Developer
• avidInteractive Software
• The ServeraSuite 2007 Award Winning Professional Server Monitoring Solution - Click here
|
|
|
|
|
|
|
Post #8 (permalink)
05-11-2005, 06:47 PM
|
HD Master
Join Date: Sep 2002
Location: Jungle
Posts: 411
Status:
|
Hey, thanks very much, Mark! I will take a look at the links tomorrow morning, and then pass the info on to my client.
Thanks again.
Vito
__________________
DemoDemo.com-The pioneer in Flash tutorials for web hosts - since 2002
OnlineSupport.org- VERY targetted advertising venue for web hosts.
|
|
|
|
|
|
|
Post #9 (permalink)
05-15-2005, 10:31 PM
|
HD Wizard
Join Date: Sep 2004
Location: Pennsylvania
Posts: 1,606
Status:
|
Vito, just wanted follow up and see how this worked out for you.
__________________
Mark - Co-President/Lead Developer
• avidInteractive Software
• The ServeraSuite 2007 Award Winning Professional Server Monitoring Solution - Click here
|
|
|
|
|
|
|
Post #10 (permalink)
05-16-2005, 08:07 AM
|
HD Master
Join Date: Sep 2002
Location: Jungle
Posts: 411
Status:
|
It's still all up in the air. It's a bit frustrating dealing with this customer, as there are so many people trying to give input on what the content should be, it changes every week. As it stands now, they no longer wish to have patient info on the site. Now it's just down to some Continuing Education stats and scores.
Who knows what it'll be next week?
Vito
__________________
DemoDemo.com-The pioneer in Flash tutorials for web hosts - since 2002
OnlineSupport.org- VERY targetted advertising venue for web hosts.
|
|
|
|
|
|
|
Post #12 (permalink)
07-05-2005, 10:10 PM
|
HD Master
Join Date: Sep 2002
Location: Jungle
Posts: 411
Status:
|
Thanks for the info, Reece.
The customer has secured hosting based here in Canada so we're good to go.
Vito
__________________
DemoDemo.com-The pioneer in Flash tutorials for web hosts - since 2002
OnlineSupport.org- VERY targetted advertising venue for web hosts.
|
|
|
|
|
|
|
Post #13 (permalink)
07-06-2005, 12:21 AM
|
HD Newbie
Join Date: Sep 2004
Posts: 8
Status:
|
Quote:
|
Originally Posted by vito
Thanks for the info, Reece.
The customer has secured hosting based here in Canada so we're good to go.
Vito
|
Thank goodness 
__________________
Reece Sellin
Net Logistics Pty. Ltd. - Empowering humanity's expression
|
|
|
|
|
New Post
Old Post
|
|
Posting Rules:
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|
|