Scalable Consent Management
1.0.0-preview - STU 1 PReview United States of America flag

Scalable Consent Management, published by HL7 International / Community Based Collaborative Care. This guide is not an authorized publication; it is the continuous build for version 1.0.0-preview built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/fhir-consent-management/ and changes regularly. See the Directory of published versions

Requirements: CapStmt Consent Server

Official URL: http://hl7.org/fhir/us/consent-management/Requirements/capstmt-consent-server Version: 1.0.0-preview
Standards status: Trial-use Maturity Level: 1 Computable Name: CapStmtConsentServer

CapStmt Requirements for Consent Server

Requirements Actor(s)

These requirements apply to the following actors:

  • Consent Server An application or product that implements the Consent Server.

Requirements Statement List

Specification: HL7 FAST Consent IG

Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/CapabilityStatement-ConsentAdministrativeServerCapabilities.json.html

Conformance: SHALL

Notes: - Plan is to have JSON and XML flavors of all tests, but explicitly tracing each of those back to these requirements is probably not necessary.

Specification: HL7 FAST Consent IG

Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/CapabilityStatement-ConsentAdministrativeServerCapabilities.json.html

Conformance: SHALL

Notes: - Plan is to have JSON and XML flavors of all tests, but explicitly tracing each of those back to these requirements is probably not necessary.

Specification: HL7 FAST Consent IG

Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/CapabilityStatement-ConsentAdministrativeServerCapabilities.json.html

Conformance: SHALL

Notes: For now, testing limited to the topic declared in the CapStmt

Specification: HL7 FHIR R4

Link to Text: https://hl7.org/fhir/R4/profiling.html

Conformance: SHALL

Related Requirement: 597: Requirements-structure-definitions-client-consent-server.html#requirement-597

Notes: Base FHIR requirement, applies because of declaring supportedProfile. Not marking as fully tested because I will continue to need to trace this to every transaction that applies.

Specification: HL7 FHIR R4

Link to Text: https://hl7.org/fhir/R4/profiling.html

Conformance: SHALL

Related Requirement: 477: Requirements-structure-definitions-client-consent-server.html#requirement-477

Notes: Base FHIR requirement, applies because of declaring supportedProfile. BUT, what if the server doesn't support searching on the resource at all? Since searching isn't required, leaving this untested for now.

Specification: HL7 FHIR R4

Link to Text: https://hl7.org/fhir/R4/profiling.html

Conformance: SHALL

Notes: Base FHIR requirement, applies because of declaring supportedProfile

Specification: HL7 FHIR R4

Link to Text: https://hl7.org/fhir/R4/profiling.html

Conformance: SHALL

Related Requirement: 597: Requirements-structure-definitions-client-consent-server.html#requirement-597

Notes: Base FHIR requirement, applies because of declaring supportedProfile

Specification: HL7 FHIR R4

Link to Text: https://hl7.org/fhir/R4/profiling.html

Conformance: SHALL

Related Requirement: 595: Requirements-structure-definitions-client-consent-server.html#requirement-595

Notes: Base FHIR requirement, applies because of declaring supportedProfile. BUT, what if the server doesn't support searching on the resource at all? Since searching isn't required, leaving this untested for now.

Specification: HL7 FHIR R4

Link to Text: https://hl7.org/fhir/R4/profiling.html

Conformance: SHALL

Related Requirement: 477: Requirements-structure-definitions-client-consent-server.html#requirement-477

Notes: Base FHIR requirement, applies because of declaring supportedProfile. Not marking as fully tested because I will continue to need to trace this to every transaction that applies.

Specification: HL7 FHIR R4

Link to Text: https://hl7.org/fhir/R4/profiling.html

Conformance: SHALL

Related Requirement: 595: Requirements-structure-definitions-client-consent-server.html#requirement-595

Notes: Base FHIR requirement, applies because of declaring supportedProfile. Not marking as fully tested because I will continue to need to trace this to every transaction that applies.

Specification: HL7 FHIR R4

Link to Text: https://hl7.org/fhir/R4/profiling.html

Conformance: SHALL

Notes: Base FHIR requirement, applies because of declaring supportedProfile. Not marking as fully tested because I will continue to need to trace this to every transaction that applies.

Specification: Subscriptions R5 Backport

Link to Text: https://hl7.org/fhir/uv/subscriptions-backport/STU1.1/CapabilityStatement-backport-subscription-server-r4.html

Conformance: SHALL

Specification: Subscriptions R5 Backport

Link to Text: https://hl7.org/fhir/uv/subscriptions-backport/STU1.1/CapabilityStatement-backport-subscription-server-r4.html

Conformance: SHALL

Specification: Subscriptions R5 Backport

Link to Text: https://hl7.org/fhir/uv/subscriptions-backport/STU1.1/CapabilityStatement-backport-subscription-server-r4.html

Conformance: SHOULD

Notes: - "After POSTing the subscription, the client parses the Location header and saves the new Subscription's logical id for use in subsequent operations." - implies server should always return Location

Specification: Subscriptions R5 Backport

Link to Text: https://hl7.org/fhir/uv/subscriptions-backport/STU1.1/CapabilityStatement-backport-subscription-server-r4.html

Conformance: SHOULD

Notes: The CapStmt and the rendered page disagree - the raw CS does not include patch and the page does. Not testing patch at this time.

Specification: Subscriptions R5 Backport

Link to Text: https://hl7.org/fhir/uv/subscriptions-backport/STU1.1/CapabilityStatement-backport-subscription-server-r4.html

Conformance: SHOULD

Specification: Subscriptions R5 Backport

Link to Text: https://hl7.org/fhir/uv/subscriptions-backport/STU1.1/CapabilityStatement-backport-subscription-server-r4.html

Conformance: SHOULD

Notes: Not testing search at this time, as the Consent IG doesn't require/use it.

Specification: Subscriptions R5 Backport

Link to Text: https://hl7.org/fhir/uv/subscriptions-backport/STU1.1/CapabilityStatement-backport-subscription-server-r4.json

Conformance: SHALL

Related Requirement: 595: Requirements-structure-definitions-client-consent-server.html#requirement-595

Notes: For now, only testing Subscriptions that conform to FASTSubscription, since it derives from BackportSubscription.

Specification: Subscriptions R5 Backport

Link to Text: https://hl7.org/fhir/uv/subscriptions-backport/STU1.1/CapabilityStatement-backport-subscription-server-r4.json

Conformance: SHALL

Notes: Not testing search at this time, as the Consent IG doesn't require/use it. Also, the raw CapStmt (linked) and the rendered page for the CapStmt disagree: the raw says SHALL, the page says SHOULD. See: https://hl7.org/fhir/uv/subscriptions-backport/CapabilityStatement-backport-subscription-server-r4.html#:~:text=Search%20Parameter%20Summary,uri

Specification: Subscriptions R5 Backport

Link to Text: https://hl7.org/fhir/uv/subscriptions-backport/STU1.1/CapabilityStatement-backport-subscription-server-r4.json

Conformance: SHOULD

Notes: Not testing search at this time, as the Consent IG doesn't require/use it.

Specification: Subscriptions R5 Backport

Link to Text: https://hl7.org/fhir/uv/subscriptions-backport/STU1.1/CapabilityStatement-backport-subscription-server-r4.json

Conformance: MAY

Notes: Not testing at this time

Specification: Subscriptions R5 Backport

Link to Text: https://hl7.org/fhir/uv/subscriptions-backport/STU1.1/CapabilityStatement-backport-subscription-server-r4.json

Conformance: MAY

Notes: Not testing at this time


Language: en

These requirements apply to the actor Consent Server

requirement-2SHALL

Consent Administration Service SHALL support JSON FHIR<br/><br/>- Plan is to have JSON and XML flavors of all tests, but explicitly tracing each of those back to these requirements is probably not necessary.

Links:

requirement-34SHALL

Consent Administration Service SHALL support XML FHIR<br/><br/>- Plan is to have JSON and XML flavors of all tests, but explicitly tracing each of those back to these requirements is probably not necessary.

Links:

requirement-397SHALL

Consent Administration Service SHALL support AuditEvent resource

Links:

requirement-398SHALL

Consent Administration Service SHALL support AuditEvent resources that conform to FASTConsentAuditEvent profile

Links:

requirement-1161SHALL

Consent Administration Service SHALL support AuditEvent create

Links:

requirement-406SHALL

Consent Administration Service SHALL support AuditEvent search

Links:

requirement-404SHALL

Consent Administration Service SHALL support AuditEvent read

Links:

requirement-412SHALL

Consent Administration Service SHALL support AuditEvent search by patient

Links:

requirement-43SHALL

Consent Administration Service SHALL support Consent resource

Links:

requirement-35SHALL

Consent Administration Service SHALL support Consent resources that conform to FASTConsent profile

Links:

requirement-37SHALL

Consent Administration Service SHALL support Consent search

Links:

requirement-36SHALL

Consent Administration Service SHALL support Consent read

Links:

requirement-199SHALL

Consent Administration Service SHALL support Consent search by FASTConsentController

Links:

requirement-72SHALL

Consent Administration Service SHALL support Consent search by date

Links:

requirement-200SHALL

Consent Administration Service SHALL support Consent search by FASTConsentManager

Links:

requirement-40SHALL

Consent Administration Service SHALL support Consent search by patient

Links:

requirement-42SHALL

Consent Administration Service SHALL support Consent search by scope

Links:

requirement-41SHALL

Consent Administration Service SHALL support Consent search by status

Links:

requirement-46SHALL

Consent Administration Service SHALL support $fileConsent operation against Consent resource

Links:

requirement-374SHALL

Consent Administration Service SHALL support $revokeConsent operation against Consent resource

Links:

requirement-377SHALL

Consent Administration Service SHALL support Consent subscriptions as defined by the FASTConsentSubscriptionTopic for FHIR R4 with Subscriptions Backport

Links:

requirement-661SHALL

Consent Administration Service SHALL support Subscription resource

Links:

requirement-959SHALL

Consent Administration Service SHALL support Subscription resources that conform to FASTSubscription profile

Links:

requirement-378SHALL

Consent Administration Service SHALL support Subscription create<br/><br/>For now, testing limited to the topic declared in the CapStmt

Links:

requirement-379SHALL

Consent Administration Service SHALL support Subscription update

Links:

requirement-380SHALL

Consent Administration Service SHALL support Subscription delete

Links:

requirement-331SHALL

Consent Administration Service SHALL mark with profile assertions Consent resources that conform to the FASTConsent profile<br/><br/>Base FHIR requirement, applies because of declaring supportedProfile. Not marking as fully tested because I will continue to need to trace this to every transaction that applies.

Links:

requirement-961SHALL

Consent Administration Service SHALL support searching by the _profile parameter for Subscription resources that conform to the FASTSubscription profile<br/><br/>Base FHIR requirement, applies because of declaring supportedProfile. BUT, what if the server doesn't support searching on the resource at all? Since searching isn't required, leaving this untested for now.

Links:

requirement-400SHALL

Consent Administration Service SHALL support searching by the _profile parameter for AuditEvent resources that conform to the FASTConsentAuditEvent profile<br/><br/>Base FHIR requirement, applies because of declaring supportedProfile

Links:

requirement-332SHALL

Consent Administration Service SHALL support searching by the _profile parameter for Consent resources that conform to the FASTConsent profile<br/><br/>Base FHIR requirement, applies because of declaring supportedProfile

Links:

requirement-515SHALL

Consent Administration Service SHALL support searching by the _profile parameter for Subscription resources that conform to the BackportSubscription profile<br/><br/>Base FHIR requirement, applies because of declaring supportedProfile. BUT, what if the server doesn't support searching on the resource at all? Since searching isn't required, leaving this untested for now.

Links:

requirement-960SHALL

Consent Administration Service SHALL mark with profile assertions Subscription resources that conform to the FASTSubscription profile<br/><br/>Base FHIR requirement, applies because of declaring supportedProfile. Not marking as fully tested because I will continue to need to trace this to every transaction that applies.

Links:

requirement-514SHALL

Consent Administration Service SHALL mark with profile assertions Subscription resources that conform to the BackportSubscription profile<br/><br/>Base FHIR requirement, applies because of declaring supportedProfile. Not marking as fully tested because I will continue to need to trace this to every transaction that applies.

Links:

requirement-399SHALL

Consent Administration Service SHALL mark with profile assertions AuditEvent resources that conform to the FASTConsentAuditEvent profile<br/><br/>Base FHIR requirement, applies because of declaring supportedProfile. Not marking as fully tested because I will continue to need to trace this to every transaction that applies.

Links:

requirement-508SHALL

Consent Administration Service SHALL support $status operation against Subscription resource

Links:

requirement-505SHALL

Consent Administration Service SHALL support Subscription read

Links:

requirement-503SHOULD

Consent Administration Service SHOULD support Subscription write via POST or PUT<br/><br/>- "After POSTing the subscription, the client parses the Location header and saves the new Subscription's logical id for use in subsequent operations." - implies server should always return Location

Links:

requirement-509SHOULD

Consent Administration Service SHOULD support Subscription update via PUT or PATCH<br/><br/>The CapStmt and the rendered page disagree - the raw CS does not include patch and the page does. Not testing patch at this time.

Links:

requirement-510SHOULD

Consent Administration Service SHOULD support Subscription delete

Links:

requirement-511SHOULD

Consent Administration Service SHOULD support Subscription search<br/><br/>Not testing search at this time, as the Consent IG doesn't require/use it.

Links:

requirement-517SHALL

Consent Administration Service SHALL support Subscription resources that conform to BackportSubscription profile<br/><br/>For now, only testing Subscriptions that conform to FASTSubscription, since it derives from BackportSubscription.

Links:

requirement-602SHALL

Consent Administration Service SHALL support Subscription search by url<br/><br/>Not testing search at this time, as the Consent IG doesn't require/use it. Also, the raw CapStmt (linked) and the rendered page for the CapStmt disagree: the raw says SHALL, the page says SHOULD. See: https://hl7.org/fhir/uv/subscriptions-backport/CapabilityStatement-backport-subscription-server-r4.html#:~:text=Search%20Parameter%20Summary,uri

Links:

requirement-604SHOULD

Consent Administration Service SHOULD support Subscription search by status<br/><br/>Not testing search at this time, as the Consent IG doesn't require/use it.

Links:

requirement-694MAY

Consent Administration Service MAY support $events operation against Subscription resource<br/><br/>Not testing at this time

Links:

requirement-695MAY

Consent Administration Service MAY support $get-ws-binding-token operation against Subscription resource<br/><br/>Not testing at this time

Links: