{
  "resourceType" : "Basic",
  "id" : "implementation-notes-client-consent-server",
  "language" : "en",
  "text" : {
    "status" : "generated",
    "div" : "<div xmlns=\"http://www.w3.org/1999/xhtml\"><p class=\"res-header-id\"><b>Generated Narrative: Requirements implementation-notes-client-consent-server</b></p><a name=\"implementation-notes-client-consent-server\"> </a><a name=\"hcimplementation-notes-client-consent-server\"> </a><p>These requirements apply to the following actors: </p><ul><li><a href=\"ActorDefinition-client.html\">Client</a></li><li><a href=\"ActorDefinition-consent-server.html\">Consent Server</a></li></ul><table class=\"grid\"><tr><td><b><a name=\"1185\"> </a></b>requirement-1185</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHOULD\">SHOULD</a></td><td><div><p>A consent administration service receiving a POST Subscription request SHOULD verify that the subscribing system is authorized to access the consents it is requesting to be notified about&lt;br/&gt;&lt;br/&gt;Can test by combining Consent and Security tests.</p>\n</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>References: <a href=\"https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=a%20consent%20administration%20service%20receiving%20a%20post%20subscription%20request%20should%20verify%20that%20the%20subscribing%20system%20is%20authorized%20to%20access%20the%20consents%20it%20is%20requesting%20to%20be%20notified%20about\">https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html</a></li></ul></td></tr><tr><td><b><a name=\"1186\"> </a></b>requirement-1186</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>Access should be limited to consents where the requesting system is a named participant: for example, consents where the system's organization is identified as a controller, manager, or actor within a consent's provision</p>\n</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>References: <a href=\"https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=access%20should%20be%20limited%20to%20consents%20where%20the%20requesting%20system%20is%20a%20named%20participant%3A%20for%20example%2C%20consents%20where%20the%20system%27s%20organization%20is%20identified%20as%20a%20controller%2C%20manager%2C%20or%20actor%20within%20a%20consent%27s%20provision\">https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html</a></li></ul></td></tr><tr><td><b><a name=\"1187\"> </a></b>requirement-1187</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>Implementers of consent administration services should apply appropriate access control filters when processing search queries</p>\n</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>References: <a href=\"https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=implementers%20of%20consent%20administration%20services%20should%20apply%20appropriate%20access%20control%20filters%20when%20processing%20search%20queries\">https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html</a></li></ul></td></tr><tr><td><b><a name=\"1184\"> </a></b>requirement-1184</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHOULD\">SHOULD</a></td><td><div><p>A system that cannot maintain a subscription to the consent management source SHOULD fetch a fresh copy of the consent at the time of each authorization decision rather than rely on a cached copy</p>\n</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>References: <a href=\"https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=a%20system%20that%20cannot%20maintain%20a%20subscription%20to%20the%20consent%20management%20source%20should%20fetch%20a%20fresh%20copy%20of%20the%20consent%20at%20the%20time%20of%20each%20authorization%20decision%20rather%20than%20rely%20on%20a%20cached%20copy\">https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html</a></li></ul></td></tr><tr><td><b><a name=\"1183\"> </a></b>requirement-1183</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>When a copy of consent travels to a different system, before making decisions based on the consent, the enforcing system needs to ensure it is up to date&lt;br/&gt;&lt;br/&gt;No conformance verb, but this is the key guidance that can drive both black box tests (e.g. A shares with B, B uses access, A revokes, B rejected) as well as tests for specific mechanisms and fallbacks, conditional on systems' support for each technique.</p>\n</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>References: <a href=\"https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=when%20a%20copy%20of%20consent%20travels%20to%20a%20different%20system%2C%20before%20making%20decisions%20based%20on%20the%20consent%2C%20the%20enforcing%20system%20needs%20to%20ensure%20it%20is%20up%20to%20date\">https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html</a></li></ul></td></tr><tr><td><b><a name=\"1181\"> </a></b>requirement-1181</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>When the Consent record is created on System A, System A's system identifier SHALL be recorded in the manager extension of the Consent instance</p>\n</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>References: <a href=\"https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=when%20the%20consent%20record%20is%20created%20on%20system%20a%2C%20system%20a%27s%20system%20identifier%20shall%20be%20recorded%20in%20the%20manager%20extension%20of%20the%20consent%20instance\">https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html</a></li></ul></td></tr><tr><td><b><a name=\"1182\"> </a></b>requirement-1182</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>Systems that ingest a Consent from another system SHALL preserve the manager extension value unchanged</p>\n</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>References: <a href=\"https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=systems%20that%20ingest%20a%20consent%20from%20another%20system%20shall%20preserve%20the%20manager%20extension%20value%20unchanged\">https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html</a></li></ul></td></tr></table></div>"
  },
  "extension" : [{
    "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-wg",
    "valueCode" : "cbcc"
  },
  {
    "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-fmm",
    "valueInteger" : 1,
    "_valueInteger" : {
      "extension" : [{
        "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom",
        "valueCanonical" : "http://hl7.org/fhir/us/consent-management/ImplementationGuide/hl7.fhir.us.consent-management"
      }]
    }
  },
  {
    "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-standards-status",
    "valueCode" : "trial-use",
    "_valueCode" : {
      "extension" : [{
        "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom",
        "valueCanonical" : "http://hl7.org/fhir/us/consent-management/ImplementationGuide/hl7.fhir.us.consent-management"
      }]
    }
  },
  {
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.url",
    "valueUri" : "http://hl7.org/fhir/us/consent-management/Requirements/implementation-notes-client-consent-server"
  },
  {
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.version",
    "valueString" : "1.0.0-preview"
  },
  {
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.name",
    "valueString" : "ImplementationNotesClientConsentServer"
  },
  {
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.title",
    "valueString" : "Implementation Notes Client Consent Server"
  },
  {
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.status",
    "valueCode" : "active"
  },
  {
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.experimental",
    "valueBoolean" : false
  },
  {
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.date",
    "valueDateTime" : "2026-09-02T22:40:54-04:00"
  },
  {
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.publisher",
    "valueString" : "HL7 International / Community Based Collaborative Care"
  },
  {
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.contact",
    "valueContactDetail" : {
      "name" : "HL7 International / Community Based Collaborative Care",
      "telecom" : [{
        "system" : "url",
        "value" : "http://www.hl7.org/Special/committees/homehealth"
      }]
    }
  },
  {
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.description",
    "valueMarkdown" : "Implementation Notes Requirements for Client Consent Server"
  },
  {
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.jurisdiction",
    "valueCodeableConcept" : {
      "coding" : [{
        "system" : "urn:iso:std:iso:3166",
        "code" : "US",
        "display" : "United States of America"
      }]
    }
  },
  {
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.actor",
    "valueCanonical" : "http://hl7.org/fhir/us/consent-management/ActorDefinition/client"
  },
  {
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.actor",
    "valueCanonical" : "http://hl7.org/fhir/us/consent-management/ActorDefinition/consent-server"
  },
  {
    "extension" : [{
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.key",
      "valueId" : "1185"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.label",
      "valueString" : "requirement-1185"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.conformance",
      "valueCode" : "SHOULD"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.requirement",
      "valueMarkdown" : "A consent administration service receiving a POST Subscription request SHOULD verify that the subscribing system is authorized to access the consents it is requesting to be notified about<br/><br/>Can test by combining Consent and Security tests."
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.derivedFrom",
      "valueString" : "HL7 FAST Consent IG"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.reference",
      "valueUrl" : "https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=a%20consent%20administration%20service%20receiving%20a%20post%20subscription%20request%20should%20verify%20that%20the%20subscribing%20system%20is%20authorized%20to%20access%20the%20consents%20it%20is%20requesting%20to%20be%20notified%20about"
    }],
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement"
  },
  {
    "extension" : [{
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.key",
      "valueId" : "1186"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.label",
      "valueString" : "requirement-1186"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.conformance",
      "valueCode" : "SHALL"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.requirement",
      "valueMarkdown" : "Access should be limited to consents where the requesting system is a named participant: for example, consents where the system's organization is identified as a controller, manager, or actor within a consent's provision"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.derivedFrom",
      "valueString" : "HL7 FAST Consent IG"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.reference",
      "valueUrl" : "https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=access%20should%20be%20limited%20to%20consents%20where%20the%20requesting%20system%20is%20a%20named%20participant%3A%20for%20example%2C%20consents%20where%20the%20system%27s%20organization%20is%20identified%20as%20a%20controller%2C%20manager%2C%20or%20actor%20within%20a%20consent%27s%20provision"
    }],
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement"
  },
  {
    "extension" : [{
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.key",
      "valueId" : "1187"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.label",
      "valueString" : "requirement-1187"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.conformance",
      "valueCode" : "SHALL"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.requirement",
      "valueMarkdown" : "Implementers of consent administration services should apply appropriate access control filters when processing search queries"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.derivedFrom",
      "valueString" : "HL7 FAST Consent IG"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.reference",
      "valueUrl" : "https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=implementers%20of%20consent%20administration%20services%20should%20apply%20appropriate%20access%20control%20filters%20when%20processing%20search%20queries"
    }],
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement"
  },
  {
    "extension" : [{
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.key",
      "valueId" : "1184"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.label",
      "valueString" : "requirement-1184"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.conformance",
      "valueCode" : "SHOULD"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.requirement",
      "valueMarkdown" : "A system that cannot maintain a subscription to the consent management source SHOULD fetch a fresh copy of the consent at the time of each authorization decision rather than rely on a cached copy"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.derivedFrom",
      "valueString" : "HL7 FAST Consent IG"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.reference",
      "valueUrl" : "https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=a%20system%20that%20cannot%20maintain%20a%20subscription%20to%20the%20consent%20management%20source%20should%20fetch%20a%20fresh%20copy%20of%20the%20consent%20at%20the%20time%20of%20each%20authorization%20decision%20rather%20than%20rely%20on%20a%20cached%20copy"
    }],
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement"
  },
  {
    "extension" : [{
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.key",
      "valueId" : "1183"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.label",
      "valueString" : "requirement-1183"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.conformance",
      "valueCode" : "SHALL"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.requirement",
      "valueMarkdown" : "When a copy of consent travels to a different system, before making decisions based on the consent, the enforcing system needs to ensure it is up to date<br/><br/>No conformance verb, but this is the key guidance that can drive both black box tests (e.g. A shares with B, B uses access, A revokes, B rejected) as well as tests for specific mechanisms and fallbacks, conditional on systems' support for each technique."
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.derivedFrom",
      "valueString" : "HL7 FAST Consent IG"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.reference",
      "valueUrl" : "https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=when%20a%20copy%20of%20consent%20travels%20to%20a%20different%20system%2C%20before%20making%20decisions%20based%20on%20the%20consent%2C%20the%20enforcing%20system%20needs%20to%20ensure%20it%20is%20up%20to%20date"
    }],
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement"
  },
  {
    "extension" : [{
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.key",
      "valueId" : "1181"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.label",
      "valueString" : "requirement-1181"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.conformance",
      "valueCode" : "SHALL"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.requirement",
      "valueMarkdown" : "When the Consent record is created on System A, System A's system identifier SHALL be recorded in the manager extension of the Consent instance"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.derivedFrom",
      "valueString" : "HL7 FAST Consent IG"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.reference",
      "valueUrl" : "https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=when%20the%20consent%20record%20is%20created%20on%20system%20a%2C%20system%20a%27s%20system%20identifier%20shall%20be%20recorded%20in%20the%20manager%20extension%20of%20the%20consent%20instance"
    }],
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement"
  },
  {
    "extension" : [{
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.key",
      "valueId" : "1182"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.label",
      "valueString" : "requirement-1182"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.conformance",
      "valueCode" : "SHALL"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.requirement",
      "valueMarkdown" : "Systems that ingest a Consent from another system SHALL preserve the manager extension value unchanged"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.derivedFrom",
      "valueString" : "HL7 FAST Consent IG"
    },
    {
      "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement.reference",
      "valueUrl" : "https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=systems%20that%20ingest%20a%20consent%20from%20another%20system%20shall%20preserve%20the%20manager%20extension%20value%20unchanged"
    }],
    "url" : "http://hl7.org/fhir/5.0/StructureDefinition/extension-Requirements.statement"
  }],
  "code" : {
    "coding" : [{
      "system" : "http://hl7.org/fhir/fhir-types",
      "code" : "Requirements"
    }]
  }
}