Episode Synopsis "12. API Security and FHIR Recommendations"
Alissa Knight, partner at Knight Inc Media, shares her insights into how to protect your APIs and what's in store with the latest version of FHIR. Specifically, we cover: • Avoid prison yellow and become an ethical hacker • Authentication doesn’t equal authorization • Protect against BOLA with scopes • Don’t use WAFs to protect your APIs • Know what traffic is going to your API • Shift left security. Shield right. • PHI is worth 1,000X credit card info • APIs are the weakest link in healthcare • APIs have multiple attack surfaces • Banning apps from jail-broken phones doesn’t help • Use MobSF to find API keys • APIs need to comply with FHIR • Implement FHIR correctly • Get FHIR certified • FHIR certification versus HIPAA compliance • There’s no one right solution for API security • Instrument your APIs
Listen "12. API Security and FHIR Recommendations"
More episodes of the podcast APIs Over IPAs
- From Vision to Venture 03: Gregory Koberger - Founder of ReadMe
- From Vision to Venture E02: James Hirst - Co-Founder and COO at Tyk
- From Vision to Venture E01: Josh Twist - Co-Founder and CEO at Zuplo
- 14. APIs for the Right Business Case
- 13. Supporting 10 Million Developers
- 12. API Security and FHIR Recommendations
- 11. Launching API Programs in Non API-First Companies
- 10. Developer Marketing Essentials
- 9. Successful API Product Management in Large Enterprises
- 8. VC Perspective on Developer-First Companies
- 7. Architectural Best Practices with LoungeBuddy/AmEx
- 6. Nick Patrick, CEO at Radar
- 5. Charles Miller, Documentation Strategist
- 4. Mike Amundsen, Author and Speaker
- 3. Kin Lane, the API Evangelist
- 2. Developer Experience Best Practices with Okta
- 1. Product Management Best Practices with Jeremy Glassenberg