AuthZconsent
Basic AuditEvent pattern for when an Authorization permit is decided
activeBasic Audit Log Patterns (BALP)1.1.4resource36 key elements
An AduitEvent recording a permit authorization decision by a Consent Decision Service,
- Given an Authorization Decision resulted in a permit
- And based on a Consent resource (C1)
- And filed by a patient (P1),
- And in response to a request by an organization (Org1)
- And for the purpose of treatment (TREAT).
- And the given request is authorized
- When an AuditEvent is recorded for the activity
- Then that AuditEvent would follow this profile regarding recording the authorization decision
- Security Alert - Authorization Decison by Consent - Execute action - date/time recorded - outcome - success when Permit - failure when Deny - outcomeDesc would explain why a deny - recorded by the authorization server - Agents - client app - user - user requested purposeOfUse - user organization - authorization service - Entity - patient subject - consent on file for that patient - the token id (JWT ID) issued (if one is issued) should be recorded - other data may be recorded that was used in the decision
Metadata
hl7.org/fhir- Canonical URL
- https://profiles.ihe.net/ITI/BALP/StructureDefinition/IHE.BasicAudit.AuthZconsent
- ID
- IHE.BasicAudit.AuthZconsent
- Type
- Base Definition
- Derivation
- constraint
Mandatory and Must-Support Elements
Elements with cardinality > 0 or marked as Must Support (S)