Scalable Consent Management, published by HL7 International / Community Based Collaborative Care. This guide is not an authorized publication; it is the continuous build for version 1.0.0-preview built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/fhir-consent-management/ and changes regularly. See the Directory of published versions
| Page standards status: Trial-use | Maturity Level: 1 |
<Requirements xmlns="http://hl7.org/fhir">
<id value="technical-specification-consent-server"/>
<text>
<status value="generated"/>
<div xmlns="http://www.w3.org/1999/xhtml"><p class="res-header-id"><b>Generated Narrative: Requirements technical-specification-consent-server</b></p><a name="technical-specification-consent-server"> </a><a name="hctechnical-specification-consent-server"> </a><p>These requirements apply to the actor <a href="ActorDefinition-consent-server.html">Consent Server</a></p><table class="grid"><tr><td><b><a name="69"> </a></b>requirement-69</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-MAY">MAY</a></td><td><div><p>Consent Administration Service MAY return OperationOutcome for a successful operation<br/><br/>I believe they are referring only to extended operations defined by the IG.</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Consent%20Server%20systems%20MAY%20return%20an%20OperationOutcome%20with%20a%20success%20when%20they%20wish%20to%20provide%20additional%20structured%20information%20alongside%20a%20successful%20operation%20response">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="68"> </a></b>requirement-68</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHOULD">SHOULD</a></td><td><div><p>Consent Administration Service SHOULD return OperationOutcome with details of which business rules did not allow an operation to be successful if an HTTP status code of 4xx or 5xx is returned<br/><br/>I believe they are referring only to extended operations defined by the IG.</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Systems%20SHOULD%20return%20an%20OperationOutcome%20with%20the%20details%20if%20an%20HTTP%20status%20code%20of%204xx%20or%205xx%20is%20returned">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="62"> </a></b>requirement-62</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL support File Consent operation<br/><br/>Redundant with CapStmt</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=are%20defined%20that-,a%20consent%20administration%20service%20SHALL%20support%3A,-File%20Consent&text=service%20SHALL%20support%3A-,File%20Consent,-and%20Revoke%20Consent">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="101"> </a></b>requirement-101</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL support Revoke Consent operation<br/><br/>Redundant with CapStmt</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=are%20defined%20that-,a%20consent%20administration%20service%20SHALL%20support%3A,-File%20Consent&text=File%20Consent%20and-,Revoke%20Consent,-.%20%C2%A7OP1">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="63"> </a></b>requirement-63</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL support Consent search</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=consent%20administration%20service%20systems%20SHALL%20support%20searching%20for%20consents">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="64"> </a></b>requirement-64</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL support Consent subscriptions (as defined by the FAST Subscription Topic for FHIR R4 with Subscriptions Backport)<br/><br/>Fix: "a consent administration service SHALL support subscriptions to allow other systems to be informed when consents for a patient have changed." - this should be more precise, like "a consent administration service SHALL support subscriptions as defined by the FAST Subscription Topic, e.g. to allow other systems to be informed when consents for a patient have changed."</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=consent%20administration%20service%20SHALL%20support%20subscriptions%20to%20allow%20other%20systems%20to%20be%20informed%20when%20consents%20for%20a%20patient%20have%20changed">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="727"> </a></b>requirement-727</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL set Consent status element to 'active' when a File Consent operation has succeeded.</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=When%20filing%20a%20consent%2C%20the%20Consent%20status%20element%20SHALL%20be%20set%20to%20%27active%27">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="634"> </a></b>requirement-634</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL set Consent status element to 'inactive' when a Revoke Consent operation has succeeded.</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=After%20a%20consent%20has%20been%20revoked%2C%20the%20Consent%20status%20element%20for%20the%20revoked%20consent%20SHALL%20be%20set%20to%20%27inactive%27.">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="760"> </a></b>requirement-760</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL NOT delete a Consent resource as a result of a Revoke Consent operation.</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=A%20revoked%20consent%20SHALL%20NOT%20be%20deleted%20from%20the%20consent%20management%20system">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="71"> </a></b>requirement-71</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL support Consent search by patient</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Searching%20for%20Consents-,To%20support%20searching%20for%20consents%2C%20the%20following%20search%20parameters%20SHALL%20be%20supported,-%2D%20patient%2C%20controller%2C%20manager&text=scope.%20%C2%A7OP7-,patient,-controller">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="364"> </a></b>requirement-364</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL support Consent search by FASTConsentController</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Searching%20for%20Consents-,To%20support%20searching%20for%20consents%2C%20the%20following%20search%20parameters%20SHALL%20be%20supported,-%2D%20patient%2C%20controller%2C%20manager&text=patient-,controller,-manager">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="367"> </a></b>requirement-367</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL support Consent search by FASTConsentManager</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Searching%20for%20Consents-,To%20support%20searching%20for%20consents%2C%20the%20following%20search%20parameters%20SHALL%20be%20supported,-%2D%20patient%2C%20controller%2C%20manager&text=controller-,manager,-date">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="365"> </a></b>requirement-365</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL support Consent search by date</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Searching%20for%20Consents-,To%20support%20searching%20for%20consents%2C%20the%20following%20search%20parameters%20SHALL%20be%20supported,-%2D%20patient%2C%20controller%2C%20manager&text=manager-,date,-status">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="73"> </a></b>requirement-73</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL support Consent search by status</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Searching%20for%20Consents-,To%20support%20searching%20for%20consents%2C%20the%20following%20search%20parameters%20SHALL%20be%20supported,-%2D%20patient%2C%20controller%2C%20manager&text=date-,status,-scope">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="201"> </a></b>requirement-201</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL support Consent search by scope</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Searching%20for%20Consents-,To%20support%20searching%20for%20consents%2C%20the%20following%20search%20parameters%20SHALL%20be%20supported,-%2D%20patient%2C%20controller%2C%20manager&text=status-,scope,-The%20controller%20and">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="827"> </a></b>requirement-827</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL be able to record disclosures of when a consent was accessed to determine whether patient information could be accessed<br/><br/>- Need to clarify which system has the responsibility for calling this - assuming Consent Client, calling the CAS.</p>
<ul>
<li>For now, assuming client calls after accessing.</li>
</ul>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=consent%20administration%20services%20SHALL%20be%20able%20to%20record%20and%20retrieve%20disclosures%20of%20when%20a%20consent%20was%20accessed%20to%20determine%20whether%20patient%20information%20could%20be%20accessed.">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="828"> </a></b>requirement-828</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL be able to retrieve disclosures of when a consent was accessed to determine whether patient information could be accessed<br/><br/>- Need to clarify which system has the responsibility for calling this - assuming Consent Client, calling the CAS.</p>
<ul>
<li>For now, assuming client calls after accessing.</li>
</ul>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=consent%20administration%20services%20SHALL%20be%20able%20to%20record%20and%20retrieve%20disclosures%20of%20when%20a%20consent%20was%20accessed%20to%20determine%20whether%20patient%20information%20could%20be%20accessed.">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="1166"> </a></b>requirement-1166</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Systems SHALL create a FAST Consent Audit Event via a RESTful FHIR POST AuditEvent whenever a Consent instance is accessed to determine whether patient information can be accessed<br/><br/>See 7.2.6.1 - not always the Consent Admin Service, so if we test this in a workflow with a CAS, need to allow a different configurable actor to be the one that POSTs.</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=systems%20shall%20create%20a%20fast%20consent%20audit%20event%20via%20a%20restful%20fhir%20post%20auditevent%20whenever%20a%20consent%20instance%20is%20accessed%20to%20determine%20whether%20patient%20information%20can%20be%20accessed">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="1163"> </a></b>requirement-1163</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHOULD">SHOULD</a></td><td><div><p>For disclosure events, implementers SHOULD follow the IHE Basic Audit Log Patterns (BALP) guide, specifically the patterns for data disclosure audit events. This guide does not define a custom profile for disclosure events; IHE-BALP patterns should be used directly.<br/><br/>Requires a separate analysis task</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=for%20disclosure%20events%2C%20implementers%20should%20follow%20the%20ihe%20basic%20audit%20log%20patterns%20%28balp%29%20guide%2C%20specifically%20the%20patterns%20for%20data%20disclosure%20audit%20events.%C2%A7op16%20this%20guide%20does%20not%20define%20a%20custom%20profile%20for%20disclosure%20events%3B%20ihe%2Dbalp%20patterns%20should%20be%20used%20directly.">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="1164"> </a></b>requirement-1164</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL support AuditEvent search by Consent (entity)</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=systems%20shall%20support%20searching%20for%20fast%20consent%20audit%20events%C2%A7op9%20using%20the%20following%20search%20parameters&text=entity%20%E2%80%94%20use%20entity%3DConsent/%5Bid%5D%20to%20search%20for%20all%20authorization%20decisions%20made%20against%20a%20specific%20Consent%20instance">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr><tr><td><b><a name="298"> </a></b>requirement-298</td><td><a href="http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL">SHALL</a></td><td><div><p>Consent Administration Service SHALL support AuditEvent search by patient<br/><br/>Need to specify actor(s). For now, assuming CAS SHALL support and Consent Client MAY support</p>
</div><p>Links: </p><ul><li>Derived From: <code>HL7 FAST Consent IG</code></li><li>Satisfied By: <a href="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=systems%20shall%20support%20searching%20for%20fast%20consent%20audit%20events%C2%A7op9%20using%20the%20following%20search%20parameters&text=patient%20%E2%80%94%20use%20patient%3D%5Bref%5D%20to%20search%20for%20all%20authorization%20decisions%20involving%20any%20consent%20for%20a%20specific%20patient">https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html</a></li></ul></td></tr></table></div>
</text>
<extension
url="http://hl7.org/fhir/StructureDefinition/structuredefinition-wg">
<valueCode value="cbcc"/>
</extension>
<extension
url="http://hl7.org/fhir/StructureDefinition/structuredefinition-fmm">
<valueInteger value="1">
<extension
url="http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom">
<valueCanonical
value="http://hl7.org/fhir/us/consent-management/ImplementationGuide/hl7.fhir.us.consent-management"/>
</extension>
</valueInteger>
</extension>
<extension
url="http://hl7.org/fhir/StructureDefinition/structuredefinition-standards-status">
<valueCode value="trial-use">
<extension
url="http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom">
<valueCanonical
value="http://hl7.org/fhir/us/consent-management/ImplementationGuide/hl7.fhir.us.consent-management"/>
</extension>
</valueCode>
</extension>
<url
value="http://hl7.org/fhir/us/consent-management/Requirements/technical-specification-consent-server"/>
<version value="1.0.0-preview"/>
<name value="TechnicalSpecificationConsentServer"/>
<title value="Technical Specification Consent Server"/>
<status value="active"/>
<experimental value="false"/>
<date value="2026-09-02T22:40:54-04:00"/>
<publisher value="HL7 International / Community Based Collaborative Care"/>
<contact>
<name value="HL7 International / Community Based Collaborative Care"/>
<telecom>
<system value="url"/>
<value value="http://www.hl7.org/Special/committees/homehealth"/>
</telecom>
</contact>
<description
value="Technical Specification Requirements for Consent Server"/>
<jurisdiction>
<coding>
<system value="urn:iso:std:iso:3166"/>
<code value="US"/>
<display value="United States of America"/>
</coding>
</jurisdiction>
<actor
value="http://hl7.org/fhir/us/consent-management/ActorDefinition/consent-server"/>
<statement>
<key value="69"/>
<label value="requirement-69"/>
<conformance value="MAY"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service MAY return OperationOutcome for a successful operation<br/><br/>I believe they are referring only to extended operations defined by the IG."/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Consent%20Server%20systems%20MAY%20return%20an%20OperationOutcome%20with%20a%20success%20when%20they%20wish%20to%20provide%20additional%20structured%20information%20alongside%20a%20successful%20operation%20response"/>
</statement>
<statement>
<key value="68"/>
<label value="requirement-68"/>
<conformance value="SHOULD"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHOULD return OperationOutcome with details of which business rules did not allow an operation to be successful if an HTTP status code of 4xx or 5xx is returned<br/><br/>I believe they are referring only to extended operations defined by the IG."/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Systems%20SHOULD%20return%20an%20OperationOutcome%20with%20the%20details%20if%20an%20HTTP%20status%20code%20of%204xx%20or%205xx%20is%20returned"/>
</statement>
<statement>
<key value="62"/>
<label value="requirement-62"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL support File Consent operation<br/><br/>Redundant with CapStmt"/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=are%20defined%20that-,a%20consent%20administration%20service%20SHALL%20support%3A,-File%20Consent&text=service%20SHALL%20support%3A-,File%20Consent,-and%20Revoke%20Consent"/>
</statement>
<statement>
<key value="101"/>
<label value="requirement-101"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL support Revoke Consent operation<br/><br/>Redundant with CapStmt"/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=are%20defined%20that-,a%20consent%20administration%20service%20SHALL%20support%3A,-File%20Consent&text=File%20Consent%20and-,Revoke%20Consent,-.%20%C2%A7OP1"/>
</statement>
<statement>
<key value="63"/>
<label value="requirement-63"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL support Consent search"/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=consent%20administration%20service%20systems%20SHALL%20support%20searching%20for%20consents"/>
</statement>
<statement>
<key value="64"/>
<label value="requirement-64"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL support Consent subscriptions (as defined by the FAST Subscription Topic for FHIR R4 with Subscriptions Backport)<br/><br/>Fix: "a consent administration service SHALL support subscriptions to allow other systems to be informed when consents for a patient have changed." - this should be more precise, like "a consent administration service SHALL support subscriptions as defined by the FAST Subscription Topic, e.g. to allow other systems to be informed when consents for a patient have changed.""/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=consent%20administration%20service%20SHALL%20support%20subscriptions%20to%20allow%20other%20systems%20to%20be%20informed%20when%20consents%20for%20a%20patient%20have%20changed"/>
</statement>
<statement>
<key value="727"/>
<label value="requirement-727"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL set Consent status element to 'active' when a File Consent operation has succeeded."/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=When%20filing%20a%20consent%2C%20the%20Consent%20status%20element%20SHALL%20be%20set%20to%20%27active%27"/>
</statement>
<statement>
<key value="634"/>
<label value="requirement-634"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL set Consent status element to 'inactive' when a Revoke Consent operation has succeeded."/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=After%20a%20consent%20has%20been%20revoked%2C%20the%20Consent%20status%20element%20for%20the%20revoked%20consent%20SHALL%20be%20set%20to%20%27inactive%27."/>
</statement>
<statement>
<key value="760"/>
<label value="requirement-760"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL NOT delete a Consent resource as a result of a Revoke Consent operation."/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=A%20revoked%20consent%20SHALL%20NOT%20be%20deleted%20from%20the%20consent%20management%20system"/>
</statement>
<statement>
<key value="71"/>
<label value="requirement-71"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL support Consent search by patient"/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Searching%20for%20Consents-,To%20support%20searching%20for%20consents%2C%20the%20following%20search%20parameters%20SHALL%20be%20supported,-%2D%20patient%2C%20controller%2C%20manager&text=scope.%20%C2%A7OP7-,patient,-controller"/>
</statement>
<statement>
<key value="364"/>
<label value="requirement-364"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL support Consent search by FASTConsentController"/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Searching%20for%20Consents-,To%20support%20searching%20for%20consents%2C%20the%20following%20search%20parameters%20SHALL%20be%20supported,-%2D%20patient%2C%20controller%2C%20manager&text=patient-,controller,-manager"/>
</statement>
<statement>
<key value="367"/>
<label value="requirement-367"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL support Consent search by FASTConsentManager"/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Searching%20for%20Consents-,To%20support%20searching%20for%20consents%2C%20the%20following%20search%20parameters%20SHALL%20be%20supported,-%2D%20patient%2C%20controller%2C%20manager&text=controller-,manager,-date"/>
</statement>
<statement>
<key value="365"/>
<label value="requirement-365"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL support Consent search by date"/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Searching%20for%20Consents-,To%20support%20searching%20for%20consents%2C%20the%20following%20search%20parameters%20SHALL%20be%20supported,-%2D%20patient%2C%20controller%2C%20manager&text=manager-,date,-status"/>
</statement>
<statement>
<key value="73"/>
<label value="requirement-73"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL support Consent search by status"/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Searching%20for%20Consents-,To%20support%20searching%20for%20consents%2C%20the%20following%20search%20parameters%20SHALL%20be%20supported,-%2D%20patient%2C%20controller%2C%20manager&text=date-,status,-scope"/>
</statement>
<statement>
<key value="201"/>
<label value="requirement-201"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL support Consent search by scope"/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=Searching%20for%20Consents-,To%20support%20searching%20for%20consents%2C%20the%20following%20search%20parameters%20SHALL%20be%20supported,-%2D%20patient%2C%20controller%2C%20manager&text=status-,scope,-The%20controller%20and"/>
</statement>
<statement>
<key value="827"/>
<label value="requirement-827"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL be able to record disclosures of when a consent was accessed to determine whether patient information could be accessed<br/><br/>- Need to clarify which system has the responsibility for calling this - assuming Consent Client, calling the CAS.
- For now, assuming client calls after accessing."/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=consent%20administration%20services%20SHALL%20be%20able%20to%20record%20and%20retrieve%20disclosures%20of%20when%20a%20consent%20was%20accessed%20to%20determine%20whether%20patient%20information%20could%20be%20accessed."/>
</statement>
<statement>
<key value="828"/>
<label value="requirement-828"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL be able to retrieve disclosures of when a consent was accessed to determine whether patient information could be accessed<br/><br/>- Need to clarify which system has the responsibility for calling this - assuming Consent Client, calling the CAS.
- For now, assuming client calls after accessing."/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=consent%20administration%20services%20SHALL%20be%20able%20to%20record%20and%20retrieve%20disclosures%20of%20when%20a%20consent%20was%20accessed%20to%20determine%20whether%20patient%20information%20could%20be%20accessed."/>
</statement>
<statement>
<key value="1166"/>
<label value="requirement-1166"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Systems SHALL create a FAST Consent Audit Event via a RESTful FHIR POST AuditEvent whenever a Consent instance is accessed to determine whether patient information can be accessed<br/><br/>See 7.2.6.1 - not always the Consent Admin Service, so if we test this in a workflow with a CAS, need to allow a different configurable actor to be the one that POSTs."/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=systems%20shall%20create%20a%20fast%20consent%20audit%20event%20via%20a%20restful%20fhir%20post%20auditevent%20whenever%20a%20consent%20instance%20is%20accessed%20to%20determine%20whether%20patient%20information%20can%20be%20accessed"/>
</statement>
<statement>
<key value="1163"/>
<label value="requirement-1163"/>
<conformance value="SHOULD"/>
<conditionality value="false"/>
<requirement
value="For disclosure events, implementers SHOULD follow the IHE Basic Audit Log Patterns (BALP) guide, specifically the patterns for data disclosure audit events. This guide does not define a custom profile for disclosure events; IHE-BALP patterns should be used directly.<br/><br/>Requires a separate analysis task"/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=for%20disclosure%20events%2C%20implementers%20should%20follow%20the%20ihe%20basic%20audit%20log%20patterns%20%28balp%29%20guide%2C%20specifically%20the%20patterns%20for%20data%20disclosure%20audit%20events.%C2%A7op16%20this%20guide%20does%20not%20define%20a%20custom%20profile%20for%20disclosure%20events%3B%20ihe%2Dbalp%20patterns%20should%20be%20used%20directly."/>
</statement>
<statement>
<key value="1164"/>
<label value="requirement-1164"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL support AuditEvent search by Consent (entity)"/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=systems%20shall%20support%20searching%20for%20fast%20consent%20audit%20events%C2%A7op9%20using%20the%20following%20search%20parameters&text=entity%20%E2%80%94%20use%20entity%3DConsent/%5Bid%5D%20to%20search%20for%20all%20authorization%20decisions%20made%20against%20a%20specific%20Consent%20instance"/>
</statement>
<statement>
<key value="298"/>
<label value="requirement-298"/>
<conformance value="SHALL"/>
<conditionality value="false"/>
<requirement
value="Consent Administration Service SHALL support AuditEvent search by patient<br/><br/>Need to specify actor(s). For now, assuming CAS SHALL support and Consent Client MAY support"/>
<derivedFrom value="HL7 FAST Consent IG"/>
<satisfiedBy
value="https://build.fhir.org/ig/HL7/fhir-consent-management/en/technical.html#:~:text=systems%20shall%20support%20searching%20for%20fast%20consent%20audit%20events%C2%A7op9%20using%20the%20following%20search%20parameters&text=patient%20%E2%80%94%20use%20patient%3D%5Bref%5D%20to%20search%20for%20all%20authorization%20decisions%20involving%20any%20consent%20for%20a%20specific%20patient"/>
</statement>
</Requirements>