AuthZconsent

Basic AuditEvent pattern for when an Authorization permit is decided

activeBasic Audit Log Patterns (BALP)1.1.4resource36 key elements

An AduitEvent recording a permit authorization decision by a Consent Decision Service,

  • Given an Authorization Decision resulted in a permit
  • And based on a Consent resource (C1)
  • And filed by a patient (P1),
  • And in response to a request by an organization (Org1)
  • And for the purpose of treatment (TREAT).
  • And the given request is authorized
  • When an AuditEvent is recorded for the activity
  • Then that AuditEvent would follow this profile regarding recording the authorization decision

- Security Alert - Authorization Decison by Consent - Execute action - date/time recorded - outcome - success when Permit - failure when Deny - outcomeDesc would explain why a deny - recorded by the authorization server - Agents - client app - user - user requested purposeOfUse - user organization - authorization service - Entity - patient subject - consent on file for that patient - the token id (JWT ID) issued (if one is issued) should be recorded - other data may be recorded that was used in the decision

Metadata

hl7.org/fhir
Canonical URL
https://profiles.ihe.net/ITI/BALP/StructureDefinition/IHE.BasicAudit.AuthZconsent
ID
IHE.BasicAudit.AuthZconsent
Type
Base Definition
Derivation
constraint
Mandatory and Must-Support Elements

Elements with cardinality > 0 or marked as Must Support (S)

PathCard.TypeFlagsDescription
subtype
1+
outcome
1+
outcomeDesc
S
purposeOfEvent
S
agent
1+
:client1..1
1+
agent.type
1+
agent.who
1+
agent.policy
S
agent.network
1+
:user1..1
1+
agent.type
1+
agent.role
S
agent.who
1+
agent.name
S
agent.policy
S
agent.purposeOfUse
S
:userorg1..1
1+
agent.type
1+
agent.who
S1+
agent.purposeOfUse
S
:authorizer1..1
1+
agent.type
1+
agent.who
1+
entity
1+
:patient1..1
1+
entity.what
Reference
1+
entity.type
1+
entity.role
1+
:consent1..*
1+
entity.what
S1+
entity.type
1+
entity.what
1+
entity.what.identifier
1+
entity.what.identifier.value
1+
jti (JWT ID)
entity.type
1+