CiviCRM Community Forums (archive)

*

News:

Have a question about CiviCRM?
Get it answered quickly at the new
CiviCRM Stack Exchange Q+A site

This forum was archived on 25 November 2017. Learn more.
How to get involved.
What to do if you think you've found a bug.



  • CiviCRM Community Forums (archive) »
  • Old sections (read-only, deprecated) »
  • Support »
  • Installing CiviCRM »
  • WordPress Installations (Moderators: Kurund Jalmi, Coleman Watts) »
  • WP web designer and HIPAA
Pages: [1]

Author Topic: WP web designer and HIPAA  (Read 541 times)

civieric

  • I post occasionally
  • **
  • Posts: 37
  • Karma: 1
  • CiviCRM version: 4.3.5
  • CMS version: WordPress
  • MySQL version: 5.5.32
  • PHP version: 5.4.17
WP web designer and HIPAA
July 28, 2014, 06:23:22 am
The question arose with a client whether it's possible to use an outside web-designer in a way that would not permit access to HIPAA protected health Information (ePHI) in CiviCRM. 

We're using the Capability Manager Enhanced plugin and I'm wondering if this set of capabilities would give the web designer necessary access while protecting the ePHI. If anyone who's expert on WP and Civi can help me evaluate this role creation, I'd appreciate it:

activate plugins
delete themes
edit theme options
install plugins
install themes
manage options
read
switch themes
update core
update plugins
update themes
level 0

Thanks.

Coleman Watts

  • Administrator
  • I’m (like) Lobo ;)
  • *****
  • Posts: 2346
  • Karma: 183
  • CiviCRM version: The Bleeding Edge
  • CMS version: Various
Re: WP web designer and HIPAA
July 28, 2014, 06:26:57 am
Well you could certainly have someone work on a copy of your website (there is a simple anonymize script you can run to scramble the civi data). Any code changes they make would be easy to copy over to the live site, and most db changes in Drupal could be managed by something like the features module.
So that's one approach.
Try asking your question on the new CiviCRM help site.

civieric

  • I post occasionally
  • **
  • Posts: 37
  • Karma: 1
  • CiviCRM version: 4.3.5
  • CMS version: WordPress
  • MySQL version: 5.5.32
  • PHP version: 5.4.17
Re: WP web designer and HIPAA
July 28, 2014, 07:05:49 am
That's a good option too. Thanks.
Another option would be to put Civi in a subdomain only available to staff and just use stock WP stuff, since this client may not need public access to any Civi functions--they'll basically be using a custom case type.

civieric

  • I post occasionally
  • **
  • Posts: 37
  • Karma: 1
  • CiviCRM version: 4.3.5
  • CMS version: WordPress
  • MySQL version: 5.5.32
  • PHP version: 5.4.17
Re: WP web designer and HIPAA
July 30, 2014, 03:49:01 am
Quote from: Coleman Watts on July 28, 2014, 06:26:57 am
(there is a simple anonymize script you can run to scramble the civi data).


Is that script available somewhere?

Thanks.

JohnFF

  • I post frequently
  • ***
  • Posts: 235
  • Karma: 6
  • CiviCRM version: 4.4.13
  • CMS version: Drupal 7.28
  • MySQL version: 5.5.31-1
  • PHP version: 5.3.27
Re: WP web designer and HIPAA
July 30, 2014, 05:23:17 am
I ended up working on a scrambled CiviCRM site, and the data was unusable. I.e. first names 30+ characters long.

I found it best to replace all individual names, emails, phone numbers with my own, delete the log and email activities, delete all uploaded files, delete smtp and mobile settings... the list goes on, and Future First has its own customised script for this.
If you like empowering charities in a free and open way, then you're going to love Civi.

Email Amender: https://civicrm.org/extensions/email-amender
UK Phone Validator: https://civicrm.org/extensions/uk-phone-number-validator
http://civifirst.com
https://twitter.com/civifirst

Hershel

  • Forum Godess / God
  • I’m (like) Lobo ;)
  • *****
  • Posts: 4640
  • Karma: 176
    • CiviHosting
  • CiviCRM version: Latest
  • CMS version: Mostly WordPress and Drupal
Re: WP web designer and HIPAA
July 30, 2014, 07:51:19 am
Another option is to copy the WordPress site and then install a fresh, empty CiviCRM onto it, then it has no data.

JohnFF, can you share your script? Or a generic version so that others could also use it?
CiviHosting and CiviOnline -- The CiviCRM hosting experts, since 2007

See here for the official: What to do if you think you've found a bug.

Pages: [1]
  • CiviCRM Community Forums (archive) »
  • Old sections (read-only, deprecated) »
  • Support »
  • Installing CiviCRM »
  • WordPress Installations (Moderators: Kurund Jalmi, Coleman Watts) »
  • WP web designer and HIPAA

This forum was archived on 2017-11-26.