HL7 FHIR Implementation Guide: Data Access Policies
0.1.0 - ci-build Global (Whole world)

HL7 FHIR Implementation Guide: Data Access Policies, published by HL7 International / Security. This guide is not an authorized publication; it is the continuous build for version 0.1.0 built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/data-access-policies/ and changes regularly. See the Directory of published versions

Table of Contents

Page standards status: Informative
0 Table of Contents
1 Index
2 Non Patient
3 Consent
4 Residual
5 Overriding
6 Provider Directory Fine Grain
7 Fine Grain Patient Access
8 Patient Directory
9 About
10 Artifacts Summary
10.1 Permission
10.2 PermissionStatusSearchParam
10.3 PermissionIdentifierSearchParam
10.4 PermissionRuleActivityActorSearchParam
10.5 PermissionRuleDataResourceSearchParam
10.6 PermissionRuleDataPeriodSearchParam
10.7 PermissionRuleLimitElementSearchParam
10.8 A computable expression for what is controlled by the Permission.rule
10.9 Permission From Consent
10.10 Permission imposed K-Anonymity value
10.11 Permission imposed on a Bundle
10.12 Current Roles in MyOrg
10.13 ValueSet for Permission Rule Combining
10.14 ValueSet of Permission Status
10.15 MyOrg defined Roles CodeSystem
10.16 Permission Rule Combining
10.17 Permission Status
10.18 A base permission example.
10.19 A composite permission example that imports another permission as one of the rules.
10.20 A Permission with all the Patient Directory rules
10.21 A Permission with rules for only doctors
10.22 Bundle with permission external residual rules to apply
10.23 Consent Deny for Patient Directory
10.24 Consent for Patient Directory
10.25 Consent for Patient Directory by Clinican
10.26 Consent that uses Overriding Permission for base rules
10.27 Consent that uses Permission for rules
10.28 Degenerate permission example
10.29 Directory permission allowing HR and IT full access
10.30 Dummy MeasureReport example
10.31 Dummy Organization example
10.32 Dummy Patient example
10.33 Dummy Patient example with Religion
10.34 Dummy Practitioner de-sensitive example
10.35 Dummy Practitioner example
10.36 Dummy Practitioner sensitive example
10.37 Fine Grained Patient Access to Data
10.38 Permission allowing data authored by a patient
10.39 Permission allowing data authored by a practitioner
10.40 Permission allowing data to be used, but don't expose sensitive location elements
10.41 Permission allowing data to be used, but with redisclosure condition
10.42 Permission allowing most sharing but NOT data authored by a practitioner
10.43 Permission allowing most use but expires in a year
10.44 Permission allowing most use but NOT a given practitioner
10.45 Permission expressing an overriding policy using ABAC
10.46 Permission expressing an overriding policy using RBAC with Resource first
10.47 Permission expressing an overriding policy using RBAC with Role first
10.48 Permission require exposure to meet a given k-anonymity value
10.49 PractitionerRole defining those that are Admin
10.50 PractitionerRole defining those that are Dietician
10.51 PractitionerRole defining those that are Doctors
10.52 PractitionerRole defining those that are Janitor
10.53 PractitionerRole defining those that are Registration
10.54 SANER permission example
10.55 VhDir permission example