An Architect is collaborating with a healthcare company’s Enterprise data-governance team to review how company-sensitive data is protected in Snowflake. Physicians in the company network can query views. Two views exist: one displays mental-health information, and the other displays physical-health information:
create view mental_health_view as select * from patients where category = 'MentalHealth';
create view physical_health_view as select * from patients where category = 'PhysicalHealth';
Most physicians do not have direct access to the table. Instead, they are assigned one of two roles:
MentalHealth, which has privileges to read from mental_health_view; or
PhysicalHealth, which has privileges to read from physical_health_view.
A physician with the PhysicalHealth role wants to determine whether any mental-health patients exist in the table and runs the following query:
select * from physical_health_view where 1/iff(category = 'MentalHealth', 0, 1) = 1;
How will this query affect the sensitive data?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion