HL7 FHIR Implementation Guide: Data Access Policies
1.0.0-current - ci-build International flag

HL7 FHIR Implementation Guide: Data Access Policies, published by HL7 International / Security. This guide is not an authorized publication; it is the continuous build for version 1.0.0-current built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/data-access-policies/ and changes regularly. See the Directory of published versions

Non Patient

Page standards status: Informative

Read-Only access to SANER report is authorized for PurposeOfUse of Public-Health, from Organizations in List/P1. Access requests are denied shall be recorded using the profiled auditEvent S-audit-1. Access requests authorized shall be recorded using profiled auditEvent S-audit-2. No access is granted to previous historic revisions (only current report).

Analysis

Permission

  • status - active
  • intent - permit (how to get multiple vectors?)
  • asserter - organization holding the data
  • assertionDate - today
  • purpose - Public-Health
  • dataScope - this SANER report
  • accesses must be audit logged

Example Permission explicitly identifying this SANER report

Variations

Similar yet different

  • have a validity scope