• Item:operations-top-levelMoreItem:operations-workItem:greenhopper_issue...Item:operations-archiveItem:operations-attach...Item:operations-votesw...Item:operations-subtasksItem:devstatus-cta-listItem:operations-operat...Item:operations-deleteItem:operations-manual...
  • Published
  • AdminItem:operations-fieldsItem:operations-admin-...
  • Item:operations-restore
Item:jira.issue.tools ExportXMLWordPrintableJSON

    • Type: Change Request
    • Resolution: Not Persuasive with Modification
    • Priority: Medium
    • FHIR Core (FHIR)
    • DSTU1 [deprecated]
    • FHIR Infrastructure
    • REST (http)
    • Hide

      add note about consent in the implementation check list

      Show
      add note about consent in the implementation check list
    • James Agnew / Grahame Grieve: 4-0-0
    • Enhancement
    • Non-substantive
    • DSTU1 [deprecated]

      Proposed Wording: Add something like: ".Only authorized systems/user (those that meet the access control including "Consent" directives) will be allowed to "read" the resource.

      Comment:

      This operation needs additional explicit caveats to avoid this authorized unauthorized "read".

      We need to explain precisely how the security guidance should be applied to this *specific" operation including the use of Consent and Provenance to make access control decisions. (http://hl7.org/fhir/2015May/security.html) including consent to make sure only authorized systems an users are viewing, changing, updating, or reviewing the update history of a resource.

            Panel: location:atl.jira.view.issue.left.context

              Assignee:
              Unassigned
              Reporter:
              jim_kretz
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved:

                  Panel: location:atl.jira.view.issue.right.context