HL7 FHIR Implementation Guide: Data Access Policies
0.1.0 - ci-build Global (Whole world)

HL7 FHIR Implementation Guide: Data Access Policies, published by HL7 International / Security. This guide is not an authorized publication; it is the continuous build for version 0.1.0 built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/data-access-policies/ and changes regularly. See the Directory of published versions

Resource: Permission - Examples

Page standards status: Trial-use Maturity Level: 1

Examples for the Permission Resource.

Fine Grained Patient Access to Data
Permission expressing an overriding policy using ABAC
Permission expressing an overriding policy using RBAC with Resource first
Permission expressing an overriding policy using RBAC with Role first
Directory permission allowing HR and IT full access
A Permission with rules for only doctors
Permission allowing data to be used, but don't expose sensitive location elements
Permission allowing data authored by a practitioner
Permission allowing most sharing but NOT data authored by a practitioner
Permission require exposure to meet a given k-anonymity value
Permission allowing most use but NOT a given practitioner
Permission allowing data authored by a patient
A Permission with all the Patient Directory rules
Permission allowing data to be used, but with redisclosure condition
Permission allowing most use but expires in a year
A base permission example.
A composite permission example that imports another permission as one of the rules.
SANER permission example
VhDir permission example
Degenerate permission example