SAMLaccessTokenUseComprehensive

Basic AuditEvent pattern for when an activity was authorized by an SAML access token Comprehensive

activeBasic Audit Log Patterns (BALP)1.1.4resource10 key elements

A basic AuditEvent profile for when an activity was authorized by an SAML access token. This profile is expected to be used with some other detail that explains the activity. This profile only covers the SAML access token.

The following table uses a short-hand for the SAML fields and FHIR AuditEvent elements to keep the table compact. It is presumed the reader can understand the SAML field and the FHIR AuditEvent element given. Note the `~` character represents attributes under the SAML `AttributeStatement`.

Builds upon the Minimal

| SAML field | Comprehensive AuditEvent |------------------------------|-----------------------------------| | ID | agent[user].policy | Issuer | agent[user].who.identifier.system | Subject.NameID | agent[user].who.identifier.value | AuthnContextClassRef | agent[user].extension[assuranceLevel] | ~subject:role | agent[user].role | ~subject:purposeofuse | agent[user].purposeOfUse | ~subject:subject-id | agent[user].extension[otherId][subject-id].value | ~subject:npi | agent[user].extension[otherId][npi].value | ~subject:provider-identifier | agent[user].extension[otherId][provider-id].value | ~subject:organization | agent[userorg].who.display | ~subject:organization-id | agent[userorg].who.identifier.value | ~homeCommunityId | agent[homeCommunityId].who.identifier.value | ~bppc:2007:docid | entity[consent].what.identifier.value | ~xua:2012:acp | entity[consent].detail.valueString | ~resource:resource-id | entity[consent-patient].what.identifier.value

Metadata

hl7.org/fhir
Canonical URL
https://profiles.ihe.net/ITI/BALP/StructureDefinition/IHE.BasicAudit.SAMLaccessTokenUse.Comprehensive
ID
IHE.BasicAudit.SAMLaccessTokenUse.Comprehensive
Type
Base Definition
IHE.BasicAudit.SAMLaccessTokenUse.Minimal
Derivation
constraint
Mandatory and Must-Support Elements

Elements with cardinality > 0 or marked as Must Support (S)

PathCard.TypeFlagsDescription
:assuranceLevel0..*
Extension
S
:otherId0..*
Extension
S
agent.role
S
SAML subject:role(s)
agent.type
1+
agent.who.identifier.value
1+
SAML Attribute urn:oasis:names:tc:xspa:1.0:subject:organization-id
agent.who.display
1+
SAML Attribute urn:oasis:names:tc:xspa:1.0:subject:organization
agent.type
1+
agent.who.identifier
1+
homeCommunityId
entity.what.identifier
S
BPPC Patient Privacy Policy Acknowledgement Document unique id
entity.type
1+