Scalable Consent Management
1.0.0-preview - STU 1 PReview United States of America flag

Scalable Consent Management, published by HL7 International / Community Based Collaborative Care. This guide is not an authorized publication; it is the continuous build for version 1.0.0-preview built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/fhir-consent-management/ and changes regularly. See the Directory of published versions

Requirements: Implementation Notes Client Consent Server

Official URL: http://hl7.org/fhir/us/consent-management/Requirements/implementation-notes-client-consent-server Version: 1.0.0-preview
Standards status: Trial-use Maturity Level: 1 Computable Name: ImplementationNotesClientConsentServer

Implementation Notes Requirements for Client Consent Server

Requirements Actor(s)

These requirements apply to the following actors:

  • Client An application or product that implements the Client.
  • Consent Server An application or product that implements the Consent Server.

Requirements Statement List

Specification: HL7 FAST Consent IG

Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html

Conformance: SHOULD

Notes: Can test by combining Consent and Security tests.

Specification: HL7 FAST Consent IG

Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html

Conformance: SHALL

Specification: HL7 FAST Consent IG

Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html

Conformance: SHALL

Specification: HL7 FAST Consent IG

Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html

Conformance: SHOULD

Specification: HL7 FAST Consent IG

Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html

Conformance: SHALL

Notes: No conformance verb, but this is the key guidance that can drive both black box tests (e.g. A shares with B, B uses access, A revokes, B rejected) as well as tests for specific mechanisms and fallbacks, conditional on systems' support for each technique.

Specification: HL7 FAST Consent IG

Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html

Conformance: SHALL

Specification: HL7 FAST Consent IG

Link to Text: https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html

Conformance: SHALL


Language: en

These requirements apply to the following actors:

requirement-1185SHOULD

A consent administration service receiving a POST Subscription request SHOULD verify that the subscribing system is authorized to access the consents it is requesting to be notified about<br/><br/>Can test by combining Consent and Security tests.

Links:

requirement-1186SHALL

Access should be limited to consents where the requesting system is a named participant: for example, consents where the system's organization is identified as a controller, manager, or actor within a consent's provision

Links:

requirement-1187SHALL

Implementers of consent administration services should apply appropriate access control filters when processing search queries

Links:

requirement-1184SHOULD

A system that cannot maintain a subscription to the consent management source SHOULD fetch a fresh copy of the consent at the time of each authorization decision rather than rely on a cached copy

Links:

requirement-1183SHALL

When a copy of consent travels to a different system, before making decisions based on the consent, the enforcing system needs to ensure it is up to date<br/><br/>No conformance verb, but this is the key guidance that can drive both black box tests (e.g. A shares with B, B uses access, A revokes, B rejected) as well as tests for specific mechanisms and fallbacks, conditional on systems' support for each technique.

Links:

requirement-1181SHALL

When the Consent record is created on System A, System A's system identifier SHALL be recorded in the manager extension of the Consent instance

Links:

requirement-1182SHALL

Systems that ingest a Consent from another system SHALL preserve the manager extension value unchanged

Links: