John Moehrke XACML Consent Example
0.1.0 - ci-build
John Moehrke XACML Consent Example, published by John Moehrke (Moehrke Research LLC). This guide is not an authorized publication; it is the continuous build for version 0.1.0 built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/JohnMoehrke/xacml-consent/ and changes regularly. See the Directory of published versions
Contents:
This page provides a list of the FHIR artifacts defined as part of this implementation guide.
These define constraints on FHIR resources for systems conforming to this implementation guide.
| FHIR Consent with XACML Policies |
A FHIR Consent resource that references XACML policies for access control, without including any rules directly in the Consent. Therefore, it does not include any provisions directly within the Consent. The actual access rules are defined in the referenced XACML policy documents. |
These define sets of codes used by systems conforming to this implementation guide.
| AB352 Segmentation Tags |
ValueSet of security labels used to segment AB352-sensitive health information in meta.security. |
| Abortion-Related Health Topics (Health Net California) |
Health Net explains and references 500073-Abortion-DX-Code-List.pdf file primarily within its Provider Library and through Provider Bulletins related to legislative compliance. The specific explanation is found in the context of Assembly Bill (AB) 352, which mandates the segregation and protection of sensitive health data. Where the Explanation is Located:
How Health Net Directs Providers to Use This File: According to the site's AB 352 guidance, Health Net recommends that IT and Billing departments download this PDF and use the listed codes to create firewalls in EHR systems. If a patient's record contains any code found in 500073-Abortion-DX-Code-List.pdf, the system should automatically:
Direct Link to the Document: 500073-Abortion-DX-Code-List.pdf Note: This list may not be all-inclusive and is subject to change. |
| Contraception-Related Health Topics |
Clinical concepts related to contraception drawn from LOINC, SNOMED CT, and ICD-10-CM. Intended for segmentation of sensitive reproductive health information under AB352. This ValueSet does not include code recommendations from Health Net California. Health Net California does not have a single source document for contraception-related codes similar to their abortion-related code list. Instead, Health Net references multiple sources, including the DHCS Family PACT Code List, within various policy documents.
|
| Gender-Affirming Care Codes (Health Net California) |
CPT and ICD-10-CM codes referenced in Health Net California's clinical policy 'HNCA.CP.MP.496 - Gender Affirming Procedures'. Intended for segmentation of gender-affirming care under AB352. Health Net Bulletin 24-351 Health Net's bulletin 24-351 explicitly tells providers that services defined in policies like HNCA.CP.MP.496 must be:
Where to Find and Download HNCA.CP.MP.496.pdf Health Net maintains this policy in several locations within their provider libraries:
|
These define new code systems used by systems conforming to this implementation guide.
| Health Information Sensitivity Categories |
Code system defining sensitivity categories for health information segmentation under California AB352. Note did not use HL7 v2-ActCodes as two of the three categories are not represented there, and the GENDER code may be more broad than GENDER_AFFIRMING_CARE as intended here. |
These are example instances that show what data produced and consumed by systems conforming with this implementation guide might look like.
| AB352 Organizational Privacy Consent - Allow All |
A FHIR Consent instance that is an explicit consent for AB 352 protected data, with provisions that reflect Patient allowing all access.
|
| AB352 Organizational Privacy Consent - breath |
A FHIR Consent instance that is an explicit consent for AB 352 protected data, with provisions that reflect the statutory requirements, with auto-filter bypassed for in-state recipients. Breath first - not possible with R6 consent structure, but shown here for clarity.
|
| AB352 Organizational Privacy Consent - depth |
A FHIR Consent instance that is an explicit consent for AB 352 protected data, with provisions that reflect the statutory requirements, with auto-filter bypassed for in-state recipients.
|
| California Location |
Location resource representing California for use in Consent provisions. |
| DocumentReference of the XACML Consent policy |
Example of a xml XACML Consent policy for Patient 12345 in a DocumentReference. |
| DocumentReference of the XACML overriding policy |
Example of a xml XACML overriding policy DocumentReference. |
| Dummy Patient example |
Dummy patient example for completeness sake. No actual use of this resource other than an example target |
| Example FHIR Consent with copy of XACML Policies |
An example instance of a FHIR Consent resource that references XACML policies for access, and a copy of the patient specific XACML policy is included as a DocumentReference. |
| Example FHIR Consent with references to XACML Policies |
An example instance of a FHIR Consent resource that references XACML policies for access, and does not include any rules directly in the Consent. |