Uploaded image for project: 'FHIR Specification Feedback'
  1. FHIR Specification Feedback
  2. FHIR-23293

It is not clear who issues this Access Token and who it is issued to - PDex #101

    XMLWordPrintableJSON

Details

    • Icon: Change Request Change Request
    • Resolution: Persuasive with Modification
    • Icon: Medium Medium
    • US Da Vinci PDex (FHIR)
    • STU3
    • Financial Mgmt
    • (profiles) [deprecated]
    •  Hook Configuration
    • Hide

      A token for access to the Payer FHIR API and the URI of the appropriate endpoint  is issued by the Payer CDS service in response to a successful CDS-Hook request. 

      Show
      A token for access to the Payer FHIR API and the URI of the appropriate endpoint  is issued by the Payer CDS service in response to a successful CDS-Hook request. 
    • Bob Dieterle / Mark Scrimshire : 15-0-0
    • Clarification
    • Non-substantive

    Description

      Existing Wording: When a Card is returned from the CDS Hooks appointment-book service by a Health Plan it will provide the following elements:

      • An Access Token for secure access to the Health Plan's FHIR API

      Comment:

      It is not clear who issues this Access Token and who it is issued to. If this is an OAuth access token, the flow for issuing it and identifying the client to the OAuth server must be clarified. It is also a major flaw from the OAuth perspective that the Access Token which must be known only to the specific client (in order to ensure accounntability) is shared with the CDS service. Generally access tokens should not be known to any party other than the Client and the OAuth Server.

      Moreover, it must be clearly stated that this acess token must be restricted only to the Member in question and the recipient must not be able to recover any other members' information using this access token.

      Summary:

      It is not clear who issues this Access Token and who it is issued to

      Attachments

        Activity

          People

            Unassigned Unassigned
            k.connor Kathleen Connor
            Kathleen Connor
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: