
Health E-Docs provides object access controls via Access Control Lists that identify the user or group with access rights and the reader/writer/manager privileges and a private attribute for the object. These access controls are established for all Collections and their child collections and documents. Users who create objects have object access determined, by default, from the object access rights of the Collection where the object is created.
Additional privacy can be implemented for each collection or document by making specific assignments or restrictions to the Access Control List for the object. Health E-Docs manages every object access and the authorization of the ACL is always verified before users are given access to the object. Object access controls are robust and users will need to understand how to set access lists to provide the desired level of security.