HL7 Personal Health Record System Functional Model, Release 2
2.0.1 - Normative

HL7 Personal Health Record System Functional Model, Release 2, published by EHR WG. This guide is not an authorized publication; it is the continuous build for version 2.0.1 built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/phrsfm-ig/ and changes regularly. See the Directory of published versions

Requirements: TI.2.1.2.9 User Permissions (Authorization) Security Audit Trigger (Function)

Official URL: http://hl7.org/ehrs/uv/phrsfmr2/Requirements/PHRSFMR2-TI.2.1.2.9 Version: 2.0.1
Standards status: Normative Computable Name: TI_2_1_2_9_User_Permissions__Authorization__Security_Audit_Trigger

Manage Audit Trigger initiated to track user permissions (authorization).

Description I: Capture user permissions (authorization), both routine and exceptional, including key metadata (who, what, when, where, why).
Criteria N:
TI.2.1.2.9#01 SHALL The system SHALL audit each occurrence when user permissions (authorizations) are granted, removed or updated.
TI.2.1.2.9#02 SHALL The system SHALL capture identity of the organization.
TI.2.1.2.9#03 SHALL conditional IF known, THEN the system SHALL capture identity of the user.
TI.2.1.2.9#04 SHALL The system SHALL capture identity of the system.
TI.2.1.2.9#05 SHALL The system SHALL capture the event initiating audit trigger.
TI.2.1.2.9#06 SHALL The system SHALL capture the date and time of the event initiating audit trigger.
TI.2.1.2.9#07 SHALL The system SHALL capture identity of the location (i.e., network address).
TI.2.1.2.9#08 SHOULD The system SHOULD capture the rationale for granting, removing or updating user permissions.
TI.2.1.2.9#09 SHALL The system SHALL capture identity of user to whom permissions apply.
TI.2.1.2.9#10 SHALL The system SHALL capture the new set of applicable user permissions (authorizations).