HL7 FHIR Implementation Guide: Data Access Policies
1.0.0-current - ci-build International flag

HL7 FHIR Implementation Guide: Data Access Policies, published by HL7 International / Security. This guide is not an authorized publication; it is the continuous build for version 1.0.0-current built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/data-access-policies/ and changes regularly. See the Directory of published versions

Example Permission: Permission expressing an overriding policy using RBAC with Resource first

Profile: Permission with support for rule on Resource-Type

Security Label: test health data (Details: ActReason code HTEST = 'test health data')

status: Active

asserter: Organization nowhere

date: 2023-12-22

combining: Permit-overrides

rule

type: Deny

rule

type: Permit

Data

-Extension
*

activity

Actors

-Reference
*PractitionerRole Doctor

action: create, read, update

purpose: treatment

activity

Actors

-Reference
*PractitionerRole Administration

action: delete, update

purpose: healthcare operations

Limits

-Control
*audit

rule

type: Permit

Data

-Extension
*

activity

Actors

-Reference
*PractitionerRole Doctor

action: create, read, update

purpose: treatment

activity

Actors

-Reference
*PractitionerRole Dietician

action: read

purpose: treatment, healthcare operations

activity

Actors

-Reference
*PractitionerRole Administration

action: delete, update

purpose: healthcare operations

Limits

-Control
*audit

rule

type: Permit

Data

-Extension
*

activity

Actors

-Reference
*PractitionerRole Doctor

action: create, read, update

purpose: treatment

activity

Actors

-Reference
*PractitionerRole Dietician

action: read

purpose: treatment, healthcare operations

activity

Actors

-Reference
*PractitionerRole Administration

action: delete, update

purpose: healthcare operations

Limits

-Control
*audit

rule

type: Permit

Data

-Extension
*

activity

Actors

-Reference
*PractitionerRole Doctor

action: read

purpose: treatment

activity

Actors

-Reference
*PractitionerRole Dietician

action: read

purpose: healthcare operations

activity

Actors

-Reference
*PractitionerRole Registration Clerk

action: read

purpose: healthcare operations

activity

Actors

-Reference
*PractitionerRole Administration

action: delete, update

purpose: healthcare operations

Limits

-Control
*audit

rule

type: Permit

Data

-Extension
*

activity

Actors

-Reference
*PractitionerRole Doctor

action: read

purpose: treatment

activity

Actors

-Reference
*PractitionerRole Dietician

action: read

purpose: healthcare operations

activity

Actors

-Reference
*PractitionerRole Registration Clerk

action: read

purpose: healthcare operations

activity

Actors

-Reference
*PractitionerRole Administration

action: delete, update

purpose: healthcare operations

Limits

-Control
*audit

rule

type: Permit

Data

-Extension
*

activity

Actors

-Reference
*PractitionerRole Doctor

action: read

purpose: treatment

activity

Actors

-Reference
*PractitionerRole Dietician

action: read

purpose: healthcare operations

activity

Actors

-Reference
*PractitionerRole Registration Clerk

action: read, update

purpose: healthcare operations

activity

Actors

-Reference
*PractitionerRole Administration

action: delete, update

purpose: healthcare operations

Limits

-Control
*audit

rule

type: Permit

Data

-Extension
*

activity

Actors

-Reference
*PractitionerRole Doctor

action: read

purpose: treatment

activity

Actors

-Reference
*PractitionerRole Dietician

action: read

purpose: healthcare operations

activity

Actors

-Reference
*PractitionerRole Registration Clerk

action: read, update, create

purpose: healthcare operations

activity

Actors

-Reference
*PractitionerRole Administration

action: delete, update

purpose: healthcare operations

Limits

-Control
*audit

rule

type: Permit

Data

-Extension
*

activity

Actors

-Reference
*PractitionerRole Doctor

action: read

purpose: treatment

activity

Actors

-Reference
*PractitionerRole Dietician

action: read

purpose: healthcare operations

activity

Actors

-Reference
*PractitionerRole Registration Clerk

action: read, update

purpose: healthcare operations

activity

Actors

-Reference
*PractitionerRole Administration

action: delete, update

purpose: healthcare operations

Limits

-Control
*audit

rule

type: Permit

Data

-Extension
*

activity

Actors

-Reference
*PractitionerRole Doctor

action: read

purpose: treatment

activity

Actors

-Reference
*PractitionerRole Dietician

action: read

purpose: healthcare operations

activity

Actors

-Reference
*PractitionerRole Registration Clerk

action: read

purpose: healthcare operations

activity

Actors

-Reference
*PractitionerRole Administration

action: delete, update

purpose: healthcare operations

Limits

-Control
*audit

rule

type: Permit

Data

-Extension
*

activity

Actors

-Reference
*PractitionerRole Doctor

action: read

purpose: treatment

activity

Actors

-Reference
*PractitionerRole Dietician

action: read

purpose: healthcare operations

activity

Actors

-Reference
*PractitionerRole Registration Clerk

action: read

purpose: healthcare operations

activity

Actors

-Reference
*PractitionerRole Administration

action: delete, update

purpose: healthcare operations

Limits

-Control
*audit