-
Type:
Change Request
-
Resolution: Not Persuasive
-
Priority:
Highest
-
US Da Vinci HRex (FHIR)
-
current
-
Clinical Interoperability Council
-
Approaches to Exchanging FHIR Data
-
3.0.3.20 Subcription Capability
-
-
Marti Velezis / James Tcheng : 6-0-1
Add sentence
Existing Wording:
Subscription also involves an enhancement of the data source's security model because the authorization that is in place at the time the subscription is established will not necessarily be the same as what is in place when the subscription triggers a notification. For example, if a subscription is established with patient consent conveyed via an OAuth token, it is unlikely that the OAuth token will still be valid during the subsequent time-period when event notifications are triggered by the subscription. Consents may have changed, user privileges may have changed, etc. Also, the subscription notifications will be directed to a 'system', not necessarily a 'user'. The security design of the data source will have to take these differences into account.
Proposed Wording:
Add sentence: Implementers are strongly encouraged to coordinate with their organization’s legal and compliance office prior to establishing a subscription.
- is voted on by
-
BALLOT-13483 Negative - Celine Lefebvre : 2020-Sep-FHIR IG HRex R1 STU
- Balloted