hl7ch / ch-vacd

https://fhir.ch/ig/ch-vacd/index.html
3 stars 0 forks source link

CH VACD Immunization (Carole Kaiser, eHealth Suisse) #239

Open ig-feedback opened 5 months ago

ig-feedback commented 5 months ago

ch.fhir.ig.ch-vacd#4.0.1 /StructureDefinition-ch-vacd-immunization.html

Please remove section 63.4.1.1 Immunisation validation. It makes more sense to check the author of the FHIR resource. This makes it clear who created an entry and in which role. If this is transferred to the EPD, it is also clear who the originalProviderRole is and the author can be analysed. This is because the user has undergone a certain validation in the EPD or in the primary system environment.

The immunisation module only uses the role that brings a document into the EPD for validation; I see the addition in the exchange format https://fhir.ch/ig/ch-vacd/StructureDefinition-ch-vacd-immunization.html#immunization-validation as problematic, as a citizen could change the resource and then receive a validated entry, as this PractitionerRole is not additionally checked. Can we remove this functionality from the exchange format? We currently ignore this for the vaccination module.

Carole Kaiser, eHealth Suisse

ralych commented 4 months ago

Mixing the metadata of XDS (EPR) and the content metadata in the document which are not connected is not possible. The exchangeformat ch-vacd is not only for "EPR" purposes. It is a generic thing. Fraud by changing contents to make an entry valid can always be done, except we start with signatures and signature validations by strong cryptographic methods.

From this point of view we have to explain the validation mechanism.