HL7 FHIR Implementation Guide: Data Access Policies
1.0.0-current - ci-build International flag

HL7 FHIR Implementation Guide: Data Access Policies, published by HL7 International / Security. This guide is not an authorized publication; it is the continuous build for version 1.0.0-current built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/data-access-policies/ and changes regularly. See the Directory of published versions

Example Permission: Permission expressing an overriding policy using RBAC with Role first

Profile: Permission with support for rule on Resource-Type

Security Label: test health data (Details: ActReason code HTEST = 'test health data')

status: Active

asserter: Organization nowhere

date: 2023-12-22

combining: Permit-overrides

rule

type: Deny

rule

type: Permit

data

Permission rule by Resource Type: Observation

data

Permission rule by Resource Type: AllergyIntolerance

data

Permission rule by Resource Type: Condition

activity

Actors

-Reference
*PractitionerRole Doctor

action: create, read, update

purpose: treatment

Limits

-Control
*audit

rule

type: Permit

data

Permission rule by Resource Type: Practitioner

data

Permission rule by Resource Type: PractitionerRole

data

Permission rule by Resource Type: Person

data

Permission rule by Resource Type: Patient

data

Permission rule by Resource Type: RelatedPerson

data

Permission rule by Resource Type: Organization

data

Permission rule by Resource Type: Location

activity

Actors

-Reference
*PractitionerRole Doctor

action: read

purpose: treatment

Limits

-Control
*audit

rule

type: Permit

data

Permission rule by Resource Type: AllergyIntolerance

data

Permission rule by Resource Type: Condition

data

Permission rule by Resource Type: Practitioner

data

Permission rule by Resource Type: PractitionerRole

data

Permission rule by Resource Type: Person

data

Permission rule by Resource Type: Patient

data

Permission rule by Resource Type: RelatedPerson

data

Permission rule by Resource Type: Organization

data

Permission rule by Resource Type: Location

activity

Actors

-Reference
*PractitionerRole Dietician

action: read

purpose: treatment, healthcare operations

Limits

-Control
*audit

rule

type: Permit

data

Permission rule by Resource Type: Person

data

Permission rule by Resource Type: Patient

data

Permission rule by Resource Type: RelatedPerson

activity

Actors

-Reference
*PractitionerRole Registration Clerk

action: create, read, update

purpose: healthcare operations

Limits

-Control
*audit

rule

type: Permit

data

Permission rule by Resource Type: Practitioner

data

Permission rule by Resource Type: PractitionerRole

data

Permission rule by Resource Type: Organization

data

Permission rule by Resource Type: Location

activity

Actors

-Reference
*PractitionerRole Registration Clerk

action: read

purpose: healthcare operations

Limits

-Control
*audit

rule

type: Permit

activity

Actors

-Reference
*PractitionerRole Administration

action: delete, update

purpose: healthcare operations

Limits

-Control
*audit