Da Vinci Clinical Data Exchange (CDex), published by HL7 International / Payer/Provider Information Exchange Work Group. This guide is not an authorized publication; it is the continuous build for version 2.1.0 built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/davinci-ecdx/ and changes regularly. See the Directory of published versions
| Page standards status: Trial-use | Maturity Level: 2 |
<Requirements xmlns="http://hl7.org/fhir">
<id value="cdex-verifier"/>
<text>
<status value="generated"/>
<div xmlns="http://www.w3.org/1999/xhtml"><p class="res-header-id"><b>Generated Narrative: Requirements cdex-verifier</b></p><a name="cdex-verifier"> </a><a name="hccdex-verifier"> </a><table class="grid"><tr><td><b><a name="CONF-053"> </a></b>CONF-053</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>[To verify the identity of the entity signing the Bundle or QuestionnaireResponse] One of the certificate Subject Alternative Name (SAN)) <strong>SHALL</strong> match <code>Signature.who.identifier</code> to verify the identity of the entity signing</p>
</div><p>Links: </p><ul><li>References: <a href="signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse">signatures.html</a></li></ul></td></tr><tr><td><b><a name="CONF-054"> </a></b>CONF-054</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>[To verify the identity of the entity signing the Bundle or QuestionnaireResponse] The <code>"srCms"</code> Signer Commitments header ids <strong>SHALL</strong> match the <code>Signature.type.code</code> elements.</p>
</div><p>Links: </p><ul><li>References: <a href="signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse">signatures.html</a></li></ul></td></tr><tr><td><b><a name="CONF-055"> </a></b>CONF-055</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>[To verify the identity of the entity signing the Bundle or QuestionnaireResponse] The <code>"sigT"</code> header timestamp <strong>SHALL</strong> match <code>Signature.when</code></p>
</div><p>Links: </p><ul><li>References: <a href="signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse">signatures.html</a></li></ul></td></tr><tr><td><b><a name="CONF-050"> </a></b>CONF-050</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHOULD">SHOULD</a></td><td><div><p>[To verify the identity of the entity signing the Bundle or QuestionnaireResponse.] The certificate Issuer <strong>SHOULD</strong> be a trusted CA for the Consumer</p>
</div><p>Links: </p><ul><li>References: <a href="signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse">signatures.html</a></li></ul></td></tr><tr><td><b><a name="CONF-051"> </a></b>CONF-051</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHOULD">SHOULD</a></td><td><div><p>[To verify the identity of the entity signing the Bundle or QuestionnaireResponse] The certificate KeyUsage <strong>SHOULD</strong> include 'DigitalSignature'</p>
</div><p>Links: </p><ul><li>References: <a href="signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse">signatures.html</a></li></ul></td></tr><tr><td><b><a name="CONF-052"> </a></b>CONF-052</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHOULD">SHOULD</a></td><td><div><p>[To verify the identity of the entity signing the Bundle or QuestionnaireResponse] The certificate Validity Dates <strong>SHOULD</strong> be appropriate/long enough as determined by the business partners</p>
</div><p>Links: </p><ul><li>References: <a href="signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse">signatures.html</a></li></ul></td></tr></table></div>
</text>
<extension
url="http://hl7.org/fhir/StructureDefinition/structuredefinition-wg">
<valueCode value="claims"/>
</extension>
<extension
url="http://hl7.org/fhir/StructureDefinition/structuredefinition-fmm">
<valueInteger value="2">
<extension
url="http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom">
<valueCanonical
value="http://hl7.org/fhir/us/davinci-cdex/ImplementationGuide/hl7.fhir.us.davinci-cdex"/>
</extension>
</valueInteger>
</extension>
<extension
url="http://hl7.org/fhir/StructureDefinition/structuredefinition-standards-status">
<valueCode value="trial-use">
<extension
url="http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom">
<valueCanonical
value="http://hl7.org/fhir/us/davinci-cdex/ImplementationGuide/hl7.fhir.us.davinci-cdex"/>
</extension>
</valueCode>
</extension>
<url
value="http://hl7.org/fhir/us/davinci-cdex/Requirements/cdex-verifier"/>
<identifier>
<system value="urn:ietf:rfc:3986"/>
<value value="urn:oid:2.16.840.1.113883.4.642.40.21.36.5"/>
</identifier>
<version value="2.1.0"/>
<name value="CDexVerifierRequirements"/>
<title value="CDex Verifier Requirements"/>
<status value="draft"/>
<date value="2026-07-09T22:52:27+00:00"/>
<publisher
value="HL7 International / Payer/Provider Information Exchange Work Group"/>
<contact>
<name
value="HL7 International / Payer/Provider Information Exchange Work Group"/>
<telecom>
<system value="url"/>
<value value="http://www.hl7.org/Special/committees/claims"/>
</telecom>
<telecom>
<system value="email"/>
<value value="pie@lists.hl7.org"/>
</telecom>
</contact>
<description
value="This [Requirements](https://hl7.org/fhir/R5/requirements.html) resource lists all the CDex Verifier requirements defined in the narrative sections of this IG."/>
<jurisdiction>
<coding>
<system value="urn:iso:std:iso:3166"/>
<code value="US"/>
</coding>
</jurisdiction>
<copyright
value="Used by permission of HL7 International all rights reserved Creative Commons License"/>
<statement>
<key value="CONF-053"/>
<conformance value="SHALL"/>
<requirement
value="[To verify the identity of the entity signing the Bundle or QuestionnaireResponse] One of the certificate Subject Alternative Name (SAN)) **SHALL** match `Signature.who.identifier` to verify the identity of the entity signing"/>
<reference
value="signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"/>
</statement>
<statement>
<key value="CONF-054"/>
<conformance value="SHALL"/>
<requirement
value="[To verify the identity of the entity signing the Bundle or QuestionnaireResponse] The `"srCms"` Signer Commitments header ids **SHALL** match the `Signature.type.code` elements."/>
<reference
value="signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"/>
</statement>
<statement>
<key value="CONF-055"/>
<conformance value="SHALL"/>
<conditionality value="true"/>
<requirement
value="[To verify the identity of the entity signing the Bundle or QuestionnaireResponse] The `"sigT"` header timestamp **SHALL** match `Signature.when`"/>
<reference
value="signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"/>
</statement>
<statement>
<key value="CONF-050"/>
<conformance value="SHOULD"/>
<requirement
value="[To verify the identity of the entity signing the Bundle or QuestionnaireResponse.] The certificate Issuer **SHOULD** be a trusted CA for the Consumer"/>
<reference
value="signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"/>
</statement>
<statement>
<key value="CONF-051"/>
<conformance value="SHOULD"/>
<requirement
value="[To verify the identity of the entity signing the Bundle or QuestionnaireResponse] The certificate KeyUsage **SHOULD** include 'DigitalSignature'"/>
<reference
value="signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"/>
</statement>
<statement>
<key value="CONF-052"/>
<conformance value="SHOULD"/>
<requirement
value="[To verify the identity of the entity signing the Bundle or QuestionnaireResponse] The certificate Validity Dates **SHOULD** be appropriate/long enough as determined by the business partners"/>
<reference
value="signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"/>
</statement>
</Requirements>