We are currently on Cloverleaf 6.1 on AIX 7.1. We have been asked to write ADT and orders messages to a vendor’s URL (https), which is not something we have done before. The only external connections we have done from Cloverleaf have been through VPN.
We have been able to make the connection and successfully send a test message, but we have concerns about potentially exposing our server to the outside world. We process several million messages monthly, most of which contain at least some level of PHI.
Are there steps we can take to minimize the risk? Are we worried unnecessarily? Any thoughts or suggestions are welcome.