-
Type:
Change Request
-
Resolution: Persuasive
-
Priority:
Medium
-
US Da Vinci CDex (FHIR)
-
Financial Mgmt
-
(many)
-
Overall
-
-
Bob Dieterle / Laura Herrman : 15-0-0
-
Clarification
-
Non-substantive
Comment:
It seems like authorization has not been addressed at all. There are out-references to HRex ballot which has a one-line security and privacy section deferring to FHIR Security and SMART on FHIR.
http://build.fhir.org/ig/HL7/davinci-ehrx/Security_and_Privacy.html
However, the specific transactions defined in this profile do not straightforwardly align with the specifics for OAuth 2.0 details defined by SMART on FHIR. For example, how do the scopes look like for a solicited communication transaction which pushes a task and what details are included in the OAuth 2.0 scopes carried by the Access Token for such a transaction? Not addressing these basic authorization details creates a possibility for vulnerable implementations with flawed authorizaiton.
Summary:
It seems like authorization has not been addressed at all.
- is voted on by
-
BALLOT-9528 Negative - Kenneth Rubin : 2019-Sep-FHIR IG CDex R1
- Balloted