Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Moesif and Moesif API Observability. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Moesif and Moesif API Observability or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

12. API Security and FHIR Recommendations

46:57
 
Share
 

Manage episode 302999731 series 2856900
Content provided by Moesif and Moesif API Observability. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Moesif and Moesif API Observability or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Alissa Knight, partner at Knight Inc Media, shares her insights into how to protect your APIs and what's in store with the latest version of FHIR. Specifically, we cover: • Avoid prison yellow and become an ethical hacker • Authentication doesn’t equal authorization • Protect against BOLA with scopes • Don’t use WAFs to protect your APIs • Know what traffic is going to your API • Shift left security. Shield right. • PHI is worth 1,000X credit card info • APIs are the weakest link in healthcare • APIs have multiple attack surfaces • Banning apps from jail-broken phones doesn’t help • Use MobSF to find API keys • APIs need to comply with FHIR • Implement FHIR correctly • Get FHIR certified • FHIR certification versus HIPAA compliance • There’s no one right solution for API security • Instrument your APIs
  continue reading

22 episodes

Artwork
iconShare
 
Manage episode 302999731 series 2856900
Content provided by Moesif and Moesif API Observability. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Moesif and Moesif API Observability or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Alissa Knight, partner at Knight Inc Media, shares her insights into how to protect your APIs and what's in store with the latest version of FHIR. Specifically, we cover: • Avoid prison yellow and become an ethical hacker • Authentication doesn’t equal authorization • Protect against BOLA with scopes • Don’t use WAFs to protect your APIs • Know what traffic is going to your API • Shift left security. Shield right. • PHI is worth 1,000X credit card info • APIs are the weakest link in healthcare • APIs have multiple attack surfaces • Banning apps from jail-broken phones doesn’t help • Use MobSF to find API keys • APIs need to comply with FHIR • Implement FHIR correctly • Get FHIR certified • FHIR certification versus HIPAA compliance • There’s no one right solution for API security • Instrument your APIs
  continue reading

22 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Listen to this show while you explore
Play