The Restricted Women's Shelter use case requires that system have some sort of access control list mechanism to differentiate public data from restricted data. The FHIR Consent resource offers the ability to record consent provisions on resource type, user role, and security label, which is sufficiently specific to generate an access control list.
As such, the National Directory Attestation IG ought to include sample Consent records for the Protected Women's Shelter usecase, to help users implement access control.
Additionally, in order for these Consent records to be converted to access control lists, a change is proposed to the profile, to include a Consent.provision.provision structure.
The Restricted Women's Shelter use case requires that system have some sort of access control list mechanism to differentiate public data from restricted data. The FHIR Consent resource offers the ability to record consent provisions on resource type, user role, and security label, which is sufficiently specific to generate an access control list.
As such, the National Directory Attestation IG ought to include sample Consent records for the Protected Women's Shelter usecase, to help users implement access control.
Additionally, in order for these Consent records to be converted to access control lists, a change is proposed to the profile, to include a
Consent.provision.provision
structure.Be sure to review the updated StructureDefinition for NatlDirEx-restriction profile. https://build.fhir.org/ig/HL7/fhir-directory-attestation/branches/44-profile-consent/StructureDefinition-NatlDirEx-restriction.html