Scalable Consent Management, published by HL7 International / Community Based Collaborative Care. This guide is not an authorized publication; it is the continuous build for version 1.0.0-preview built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/fhir-consent-management/ and changes regularly. See the Directory of published versions
| Official URL: http://hl7.org/fhir/us/consent-management/Requirements/implementation-notes-client-consent-server | Version: 1.0.0-preview | ||||
| Standards status: Trial-use | Maturity Level: 1 | Computable Name: ImplementationNotesClientConsentServer | |||
Implementation Notes Requirements for Client Consent Server
These requirements apply to the following actors:
Specification: HL7 FAST Consent IG
Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html
Conformance: SHOULD
Notes: Can test by combining Consent and Security tests.
Specification: HL7 FAST Consent IG
Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html
Conformance: SHALL
Specification: HL7 FAST Consent IG
Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html
Conformance: SHALL
Specification: HL7 FAST Consent IG
Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html
Conformance: SHOULD
Specification: HL7 FAST Consent IG
Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html
Conformance: SHALL
Notes: No conformance verb, but this is the key guidance that can drive both black box tests (e.g. A shares with B, B uses access, A revokes, B rejected) as well as tests for specific mechanisms and fallbacks, conditional on systems' support for each technique.
Specification: HL7 FAST Consent IG
Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html
Conformance: SHALL
Specification: HL7 FAST Consent IG
Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html
Conformance: SHALL
Language: en
These requirements apply to the following actors:
| requirement-1185 | SHOULD | A consent administration service receiving a POST Subscription request SHOULD verify that the subscribing system is authorized to access the consents it is requesting to be notified about<br/><br/>Can test by combining Consent and Security tests. Links:
|
| requirement-1186 | SHALL | Access should be limited to consents where the requesting system is a named participant: for example, consents where the system's organization is identified as a controller, manager, or actor within a consent's provision Links:
|
| requirement-1187 | SHALL | Implementers of consent administration services should apply appropriate access control filters when processing search queries Links:
|
| requirement-1184 | SHOULD | A system that cannot maintain a subscription to the consent management source SHOULD fetch a fresh copy of the consent at the time of each authorization decision rather than rely on a cached copy Links:
|
| requirement-1183 | SHALL | When a copy of consent travels to a different system, before making decisions based on the consent, the enforcing system needs to ensure it is up to date<br/><br/>No conformance verb, but this is the key guidance that can drive both black box tests (e.g. A shares with B, B uses access, A revokes, B rejected) as well as tests for specific mechanisms and fallbacks, conditional on systems' support for each technique. Links:
|
| requirement-1181 | SHALL | When the Consent record is created on System A, System A's system identifier SHALL be recorded in the manager extension of the Consent instance Links:
|
| requirement-1182 | SHALL | Systems that ingest a Consent from another system SHALL preserve the manager extension value unchanged Links:
|