The requirement RB1 is implemented as a feature of the Web portal. When launching a VM, in fact, patients can select only part of their PHR data currently available within MyPHRMachines to be shared with a given care institution.
Finally, the requirement RB2 is forced by design because,as we discussed before, VMs do not have Internet access
and, therefore, the PHR data used by them cannot be pushed outside the domain of MyPHRMachines to pursue improper
use. Having VMs without Internet connection may represent a limitation of our prototype. This issue is discussed more
in depth in Section IV-A. It is however also an essential security strength: by cutting off internet access at the level
of the hypervisor, MyPHRMachines ensures that even when end-users or applications tamper with the firewall settings of
a VM, no harm can be done.