-
Type:
Change Request
-
Resolution: Not Persuasive
-
Priority:
Medium
-
FHIR Core (FHIR)
-
DSTU2
-
Community-Based Care and Privacy
-
Consent
-
-
Ken/Lori: 14-0-1
-
Correction
I agree with the vocabulary creation in the Policies section. There is a need for the most basic of Consent.policy values for grant NO authority, and grant the authority enfoced by Consent.organization (see CP 10695)
However the terms of opt-in and opt-out must not be used. (See CP 10693).
I would prefer terms such as "Permit" and "Deny"; as these are terms used in the exceptions, and are also terms used in general IT access control standards (e.g. XACML).
Note "grant NO Authority" is more clear than all authority.. but also comes with implied exceptions around emergency-mode access (such as break-glass), and required governmental reporting (such as public health). It also can't forbid database maintenance (such as indexing, backup). In the context of non-Treatment relationships, NO can be much closer to NO. So I recommend we recognize some flavors of "Deny".
Hence, why this is not a simple vocabulary, and hence why Consent;policy needs to be a uri and not be expected to be a vocabulary managed by HL7.
- is voted on by
-
BALLOT-2694 Affirmative - John Moehrke : 2018-Sep-FHIR R1
- Closed