Onyx Consent Authorization SAFHIR Implementation and Operations Guide
0.0.2 - ci-build

Onyx Consent Authorization SAFHIR Implementation and Operations Guide - Local Development build (v0.0.2). See the Directory of published versions

Example Consent: SafhirAppRegByDataHolder

Use Cases

Granting an App Access to APIs controlled by the Dataholder

This App Registration Consent record is an example of Use Case 1. Where a dataholder, such as a payer, grants a third-party application created by a third-party app developer to a set of APIs that are governed by a specific terms of service.

Generated Narrative

Resource "1000"

Profile: SafhirAppRegConsent

status: active

scope: patient-privacy (patientconsentscopesubset#patient-privacy)

category: Privacy policy Organization Document (LOINC#57017-6)

dateTime: Mar 21, 2021, 11:13:00 PM

performer: Organization/AppDeveloper "Onyx Health App Development, LLC"

organization: Organization/Diamond-Health-Plan-01

Policies

-AuthorityUri
*https://clientname.safhir.iohttps://clientname.safhir.io/fhir/api/patient_access_api_v1.html

policyRule: HIPAA Authorization (Consent PolicyRule Codes#hipaa-auth)

provision

type: permit

period: Mar 21, 2021, 11:13:00 PM --> Mar 21, 2022, 11:13:00 PM

Actors

-RoleReference
*grantee (RoleCode#GRANTEE)Device/myCareAI-v1

action: Use (Consent Action Codes#use)

Data

-MeaningReference
*dependents: patient/Patient.read,patient/ExplanationOfBenefit.read,patient/Coverage.read