HL7 FHIR Implementation Guide: Data Access Policies
1.0.0-current - ci-build International flag

HL7 FHIR Implementation Guide: Data Access Policies, published by HL7 International / Security. This guide is not an authorized publication; it is the continuous build for version 1.0.0-current built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/data-access-policies/ and changes regularly. See the Directory of published versions

Example Permission: A Permission with all the Directory rules

Page standards status: Informative

Generated Narrative: Permission ex-permission-directory-all

status: Active

asserter: Organization nowhere

date: 2023-11-22

combining: Deny-unless-permit

rule

type: Permit

activity

action: Create, Read, Update, Delete, Execute

purpose: directory, health system administration

rule

type: Permit

activity

action: Read, Execute

purpose: treatment, healthcare payment, healthcare operations

rule

type: Permit

data

Expressions

-DescriptionLanguageExpression
*select all Practitioner resources where the Practitioner has a PractitionerRole with code of doctorapplication/x-fhir-queryPractitioner?_has:PractitionerRole:practitioner:role=http://terminology.hl7.org/CodeSystem/practitioner-role|doctor

activity

action: Read, Execute

purpose: patient requested