Skip to Main Content
Merative Ideas Portal

Shape the future of Merative!

We invite you to shape the future of Merative, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Post your ideas

Start by posting ideas and requests to enhance a product or service. Take a look at ideas others have posted and upvote them if they matter to you,

  1. Post an idea

  2. Upvote ideas that matter most to you

  3. Get feedback from the Merative team to refine your idea

Help Merative prioritize your ideas and requests

The Merative team may need your help to refine the ideas so they may ask for more information or feedback. The offering manager team will then decide if they can begin working on your idea. If they can start during the next development cycle, they will put the idea on the priority list. Each team at Merative works on a different schedule, where some ideas can be implemented right away, others may be placed on a different schedule.

Receive notification on the decision

Some ideas can be implemented at Merative, while others may not fit within the development plans for the product. In either case, the team will let you know as soon as possible. In some cases, we may be able to find alternatives for ideas which cannot be implemented in a reasonable time.


Merative External Privacy Statement: https://www.merative.com/privacy

Status Is a defect
Created by Guest
Created on Jul 21, 2016

FIPPA breaches when caseworkers open and edit Microsoft Word documents

Enhancement request to provide inline viewing of documents OOTB.

Hard Requirements: - No documents left on the system. - Includes whatever documents are opened from C�ram (e.g. doc and pdf)

Customer Problem description: Management on the project are concerned about possible FIPPA breaches when caseworkers open documents (doc and pdf) because such documents may be saved on the caseworkers local computer.

This is a major FIPPA/MFIPPA risk for several reasons:
�Not all workers in an office have access to SAMS or are allowed to access client data, however they all may access the shared machines. If they even see a client�s name, that puts us on a FIPPA breach situation immediately.
�Many offices have interview rooms to see their clients. Those offices may be shared between Social Assistance workers, clerks, Housing Workers, Child Care workers, etc. There MUST be assurance that only users authenticated through the system, via Go-Secure can view or access any client information.
�Letters stored on a local machine are accessible to many people (e.g. IT Help desks) � they have no authority to view or access any client information
�Many offices have an �open concept� approach, where clients have access to workers work spaces. If the information is not safeguarded via a proper means of authentication, there is nothing preventing anyone from viewing, copying, etc that information
�We have audit in the system to ensure that we can track anyone accessing a file or client�s information. When letters get downloaded we lose the ability to guarantee the information is secure. To demonstrate the features in question, we offer the following scenarios in the attached document

This was reproduced using chrome, after logout the downloads folder was not cleared. The client developers who tested this provided details that the cache settings should not be a contributing factor to the issue as C�ram is invoking download.

Customer Name Ontario - Ministry of Community and Social Services
  • Attach files
  • Guest
    Reply
    |
    Aug 5, 2016

    Hi,

    We acknowledge that this is a valid enhancement request. It will be considered for inclusion in a future release of the product. Thank you for your interest in the Cúram product.

    Thanks,
    Eloise O'Riordan, Cúram SPM Offering Management team