HL7 FHIR Implementation Guide: Data Access Policies
1.0.0-current - ci-build Global (Whole world)

HL7 FHIR Implementation Guide: Data Access Policies, published by HL7 International / Security. This guide is not an authorized publication; it is the continuous build for version 1.0.0-current built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/data-access-policies/ and changes regularly. See the Directory of published versions

Table of Contents

Page standards status: Informative
.. 0 Table of Contents
... 1 Index
... 2 Non Patient
... 3 Consent
... 4 Residual
... 5 Overriding
... 6 Provider Directory Fine Grain
... 7 Fine Grain Patient Access
... 8 Patient Directory
... 9 About
... 10 Artifacts Summary
.... 10.1 Permission
.... 10.2 PermissionStatusSearchParam
.... 10.3 PermissionIdentifierSearchParam
.... 10.4 PermissionRuleActivityActorSearchParam
.... 10.5 PermissionRuleDataResourceSearchParam
.... 10.6 PermissionRuleDataPeriodSearchParam
.... 10.7 PermissionRuleLimitElementSearchParam
.... 10.8 Permission From Consent
.... 10.9 Current Roles in MyOrg
.... 10.10 ValueSet for Permission Rule Combining
.... 10.11 ValueSet of Permission Status
.... 10.12 MyOrg defined Roles CodeSystem
.... 10.13 Permission Rule Combining
.... 10.14 Permission Status
.... 10.15 A base permission example.
.... 10.16 A composite permission example that imports another permission as one of the rules.
.... 10.17 A Permission with all the Directory rules
.... 10.18 A Permission with all the Patient Directory rules
.... 10.19 A Permission with all the Patient Directory rules
.... 10.20 Bundle with permission expressed residual rules to apply
.... 10.21 Consent Deny for Patient Directory
.... 10.22 Consent for Patient Directory
.... 10.23 Consent for Patient Directory by Clinican
.... 10.24 Consent that uses Overriding Permission for base rules
.... 10.25 Consent that uses Permission for rules
.... 10.26 Degenerate permission example
.... 10.27 Directory permission allowing HR and IT full access
.... 10.28 Directory permission with excluding sensitive elements
.... 10.29 Dummy MeasureReport example
.... 10.30 Dummy Organization example
.... 10.31 Dummy Patient example
.... 10.32 Dummy Patient example with Religion
.... 10.33 Dummy Practitioner de-sensitive example
.... 10.34 Dummy Practitioner example
.... 10.35 Dummy Practitioner sensitive example
.... 10.36 Fine Grained Patient Access to Data
.... 10.37 Permission allowing data authored by a practitioner
.... 10.38 Permission allowing data authored by a practitioner
.... 10.39 Permission allowing data to be used, but don't expose sensitive location elements
.... 10.40 Permission allowing data to be used, but with redisclosure condition
.... 10.41 Permission allowing most sharing but NOT data authored by a practitioner
.... 10.42 Permission allowing most use but expires in a year
.... 10.43 Permission allowing most use but NOT a given practitioner
.... 10.44 Permission expressing an overriding policy using ABAC
.... 10.45 Permission expressing an overriding policy using RBAC with Resource first
.... 10.46 Permission expressing an overriding policy using RBAC with Role first
.... 10.47 PractitionerRole defining those that are Admin
.... 10.48 PractitionerRole defining those that are Dietician
.... 10.49 PractitionerRole defining those that are Doctors
.... 10.50 PractitionerRole defining those that are Janitor
.... 10.51 PractitionerRole defining those that are Registration
.... 10.52 SANER permission example
.... 10.53 VhDir permission example
.... 10.54 Permission-examples
.... 10.55 Permission-operations