Scalable Consent Management
1.0.0-preview - STU 1 PReview United States of America flag

Scalable Consent Management, published by HL7 International / Community Based Collaborative Care. This guide is not an authorized publication; it is the continuous build for version 1.0.0-preview built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/fhir-consent-management/ and changes regularly. See the Directory of published versions

: Implementation Notes Client Consent Server

Page standards status: Trial-use Maturity Level: 1

Raw xml | Download


<Requirements xmlns="http://hl7.org/fhir">
  <id value="implementation-notes-client-consent-server"/>
  <text>
    <status value="generated"/>
    <div xmlns="http://www.w3.org/1999/xhtml"><p class="res-header-id"><b>Generated Narrative: Requirements implementation-notes-client-consent-server</b></p><a name="implementation-notes-client-consent-server"> </a><a name="hcimplementation-notes-client-consent-server"> </a><p>These requirements apply to the following actors: </p><ul><li><a href="ActorDefinition-client.html">Client</a></li><li><a href="ActorDefinition-consent-server.html">Consent Server</a></li></ul><table class="grid"><tr><td><b><a name="1185"> </a></b>requirement-1185</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHOULD">SHOULD</a></td><td><div><p>A consent administration service receiving a POST Subscription request SHOULD verify that the subscribing system is authorized to access the consents it is requesting to be notified about&lt;br/&gt;&lt;br/&gt;Can test by combining Consent and Security tests.</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>References: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=a%20consent%20administration%20service%20receiving%20a%20post%20subscription%20request%20should%20verify%20that%20the%20subscribing%20system%20is%20authorized%20to%20access%20the%20consents%20it%20is%20requesting%20to%20be%20notified%20about">https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html</a></li></ul></td></tr><tr><td><b><a name="1186"> </a></b>requirement-1186</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Access should be limited to consents where the requesting system is a named participant: for example, consents where the system's organization is identified as a controller, manager, or actor within a consent's provision</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>References: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=access%20should%20be%20limited%20to%20consents%20where%20the%20requesting%20system%20is%20a%20named%20participant%3A%20for%20example%2C%20consents%20where%20the%20system%27s%20organization%20is%20identified%20as%20a%20controller%2C%20manager%2C%20or%20actor%20within%20a%20consent%27s%20provision">https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html</a></li></ul></td></tr><tr><td><b><a name="1187"> </a></b>requirement-1187</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Implementers of consent administration services should apply appropriate access control filters when processing search queries</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>References: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=implementers%20of%20consent%20administration%20services%20should%20apply%20appropriate%20access%20control%20filters%20when%20processing%20search%20queries">https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html</a></li></ul></td></tr><tr><td><b><a name="1184"> </a></b>requirement-1184</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHOULD">SHOULD</a></td><td><div><p>A system that cannot maintain a subscription to the consent management source SHOULD fetch a fresh copy of the consent at the time of each authorization decision rather than rely on a cached copy</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>References: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=a%20system%20that%20cannot%20maintain%20a%20subscription%20to%20the%20consent%20management%20source%20should%20fetch%20a%20fresh%20copy%20of%20the%20consent%20at%20the%20time%20of%20each%20authorization%20decision%20rather%20than%20rely%20on%20a%20cached%20copy">https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html</a></li></ul></td></tr><tr><td><b><a name="1183"> </a></b>requirement-1183</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>When a copy of consent travels to a different system, before making decisions based on the consent, the enforcing system needs to ensure it is up to date&lt;br/&gt;&lt;br/&gt;No conformance verb, but this is the key guidance that can drive both black box tests (e.g. A shares with B, B uses access, A revokes, B rejected) as well as tests for specific mechanisms and fallbacks, conditional on systems' support for each technique.</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>References: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=when%20a%20copy%20of%20consent%20travels%20to%20a%20different%20system%2C%20before%20making%20decisions%20based%20on%20the%20consent%2C%20the%20enforcing%20system%20needs%20to%20ensure%20it%20is%20up%20to%20date">https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html</a></li></ul></td></tr><tr><td><b><a name="1181"> </a></b>requirement-1181</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>When the Consent record is created on System A, System A's system identifier SHALL be recorded in the manager extension of the Consent instance</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>References: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=when%20the%20consent%20record%20is%20created%20on%20system%20a%2C%20system%20a%27s%20system%20identifier%20shall%20be%20recorded%20in%20the%20manager%20extension%20of%20the%20consent%20instance">https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html</a></li></ul></td></tr><tr><td><b><a name="1182"> </a></b>requirement-1182</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Systems that ingest a Consent from another system SHALL preserve the manager extension value unchanged</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>References: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=systems%20that%20ingest%20a%20consent%20from%20another%20system%20shall%20preserve%20the%20manager%20extension%20value%20unchanged">https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html</a></li></ul></td></tr></table></div>
  </text>
  <extension
             url="http://hl7.org/fhir/StructureDefinition/structuredefinition-wg">
    <valueCode value="cbcc"/>
  </extension>
  <extension
             url="http://hl7.org/fhir/StructureDefinition/structuredefinition-fmm">
    <valueInteger value="1">
      <extension
                 url="http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom">
        <valueCanonical
                        value="http://hl7.org/fhir/us/consent-management/ImplementationGuide/hl7.fhir.us.consent-management"/>
      </extension>
    </valueInteger>
  </extension>
  <extension
             url="http://hl7.org/fhir/StructureDefinition/structuredefinition-standards-status">
    <valueCode value="trial-use">
      <extension
                 url="http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom">
        <valueCanonical
                        value="http://hl7.org/fhir/us/consent-management/ImplementationGuide/hl7.fhir.us.consent-management"/>
      </extension>
    </valueCode>
  </extension>
  <url
       value="http://hl7.org/fhir/us/consent-management/Requirements/implementation-notes-client-consent-server"/>
  <version value="1.0.0-preview"/>
  <name value="ImplementationNotesClientConsentServer"/>
  <title value="Implementation Notes Client Consent Server"/>
  <status value="active"/>
  <experimental value="false"/>
  <date value="2026-09-02T22:40:54-04:00"/>
  <publisher value="HL7 International / Community Based Collaborative Care"/>
  <contact>
    <name value="HL7 International / Community Based Collaborative Care"/>
    <telecom>
      <system value="url"/>
      <value value="http://www.hl7.org/Special/committees/homehealth"/>
    </telecom>
  </contact>
  <description
               value="Implementation Notes Requirements for Client Consent Server"/>
  <jurisdiction>
    <coding>
      <system value="urn:iso:std:iso:3166"/>
      <code value="US"/>
      <display value="United States of America"/>
    </coding>
  </jurisdiction>
  <actor
         value="http://hl7.org/fhir/us/consent-management/ActorDefinition/client"/>
  <actor
         value="http://hl7.org/fhir/us/consent-management/ActorDefinition/consent-server"/>
  <statement>
    <key value="1185"/>
    <label value="requirement-1185"/>
    <conformance value="SHOULD"/>
    <conditionality value="false"/>
    <requirement
                 value="A consent administration service receiving a POST Subscription request SHOULD verify that the subscribing system is authorized to access the consents it is requesting to be notified about&lt;br/&gt;&lt;br/&gt;Can test by combining Consent and Security tests."/>
    <derivedFrom value="HL7 FAST Consent IG"/>
    <reference
               value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=a%20consent%20administration%20service%20receiving%20a%20post%20subscription%20request%20should%20verify%20that%20the%20subscribing%20system%20is%20authorized%20to%20access%20the%20consents%20it%20is%20requesting%20to%20be%20notified%20about"/>
  </statement>
  <statement>
    <key value="1186"/>
    <label value="requirement-1186"/>
    <conformance value="SHALL"/>
    <conditionality value="false"/>
    <requirement
                 value="Access should be limited to consents where the requesting system is a named participant: for example, consents where the system's organization is identified as a controller, manager, or actor within a consent's provision"/>
    <derivedFrom value="HL7 FAST Consent IG"/>
    <reference
               value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=access%20should%20be%20limited%20to%20consents%20where%20the%20requesting%20system%20is%20a%20named%20participant%3A%20for%20example%2C%20consents%20where%20the%20system%27s%20organization%20is%20identified%20as%20a%20controller%2C%20manager%2C%20or%20actor%20within%20a%20consent%27s%20provision"/>
  </statement>
  <statement>
    <key value="1187"/>
    <label value="requirement-1187"/>
    <conformance value="SHALL"/>
    <conditionality value="false"/>
    <requirement
                 value="Implementers of consent administration services should apply appropriate access control filters when processing search queries"/>
    <derivedFrom value="HL7 FAST Consent IG"/>
    <reference
               value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=implementers%20of%20consent%20administration%20services%20should%20apply%20appropriate%20access%20control%20filters%20when%20processing%20search%20queries"/>
  </statement>
  <statement>
    <key value="1184"/>
    <label value="requirement-1184"/>
    <conformance value="SHOULD"/>
    <conditionality value="false"/>
    <requirement
                 value="A system that cannot maintain a subscription to the consent management source SHOULD fetch a fresh copy of the consent at the time of each authorization decision rather than rely on a cached copy"/>
    <derivedFrom value="HL7 FAST Consent IG"/>
    <reference
               value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=a%20system%20that%20cannot%20maintain%20a%20subscription%20to%20the%20consent%20management%20source%20should%20fetch%20a%20fresh%20copy%20of%20the%20consent%20at%20the%20time%20of%20each%20authorization%20decision%20rather%20than%20rely%20on%20a%20cached%20copy"/>
  </statement>
  <statement>
    <key value="1183"/>
    <label value="requirement-1183"/>
    <conformance value="SHALL"/>
    <conditionality value="false"/>
    <requirement
                 value="When a copy of consent travels to a different system, before making decisions based on the consent, the enforcing system needs to ensure it is up to date&lt;br/&gt;&lt;br/&gt;No conformance verb, but this is the key guidance that can drive both black box tests (e.g. A shares with B, B uses access, A revokes, B rejected) as well as tests for specific mechanisms and fallbacks, conditional on systems' support for each technique."/>
    <derivedFrom value="HL7 FAST Consent IG"/>
    <reference
               value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=when%20a%20copy%20of%20consent%20travels%20to%20a%20different%20system%2C%20before%20making%20decisions%20based%20on%20the%20consent%2C%20the%20enforcing%20system%20needs%20to%20ensure%20it%20is%20up%20to%20date"/>
  </statement>
  <statement>
    <key value="1181"/>
    <label value="requirement-1181"/>
    <conformance value="SHALL"/>
    <conditionality value="false"/>
    <requirement
                 value="When the Consent record is created on System A, System A's system identifier SHALL be recorded in the manager extension of the Consent instance"/>
    <derivedFrom value="HL7 FAST Consent IG"/>
    <reference
               value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=when%20the%20consent%20record%20is%20created%20on%20system%20a%2C%20system%20a%27s%20system%20identifier%20shall%20be%20recorded%20in%20the%20manager%20extension%20of%20the%20consent%20instance"/>
  </statement>
  <statement>
    <key value="1182"/>
    <label value="requirement-1182"/>
    <conformance value="SHALL"/>
    <conditionality value="false"/>
    <requirement
                 value="Systems that ingest a Consent from another system SHALL preserve the manager extension value unchanged"/>
    <derivedFrom value="HL7 FAST Consent IG"/>
    <reference
               value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/implementation_notes.html#:~:text=systems%20that%20ingest%20a%20consent%20from%20another%20system%20shall%20preserve%20the%20manager%20extension%20value%20unchanged"/>
  </statement>
</Requirements>