2015May sdc #74 - Add authorization qualifier to 'delete'

XMLWordPrintableJSON

    • Type: Change Request
    • Resolution: Not Persuasive
    • Priority: Medium
    • FHIR Core (FHIR)
    • DSTU1 [deprecated]
    • FHIR Infrastructure
    • REST (http)
    • Hide

      add general note about security and access to API page.

      Show
      add general note about security and access to API page.
    • James Agnew / Grahame Grieve: 4-0-0
    • Enhancement

      Proposed Wording: Add something like: "In case a resource is deleted., a record of Provenance will attest to that change. Only authorized systems/user (i.e. the system/user responsible for its "authorship" according the related "Provenance" record) will be allowed to "delete".

      Comment:

      This operation needs additional explicit caveats to protect unauthorized "delete" especially if the resource is expected to be remove. The only record of its existence should be "Provenance.

      We need to explain precisely how the security guidance should be applied to this *specific" operation including the use of Consent and Provenance to make access control decisions. (http://hl7.org/fhir/2015May/security.html) including consent to make sure only authorized systems an users are viewing, changing, updating, or reviewing the update history of a resource.

            Assignee:
            Unassigned
            Reporter:
            jim_kretz
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: