Details
-
Change Request
-
Resolution: Persuasive with Modification
-
FHIRCast (FHIR)
-
2.0.0
-
Infrastructure & Messaging
-
Security considerations
-
4.3
-
-
Bas van den Heuvel / Eric Martin: 6-0-0
-
Clarification
-
Non-substantive
Description
Security should include discussion of PHI in event context and content, and context/content that a particular subscriber may not have SMART on FHIR scope or other authorization to see (e.g., a client is permitted to subscribe to DiagnosticReport-update events, but isn't permitted to see ImagingStudy resources).
(Comment 45 - imported by: Lloyd McKenzie)
Attachments
Issue Links
- is voted on by
-
BALLOT-37151 Affirmative - Elliot Silver : 2022-May-FHIR IG FHIRCast R1 STU
- Balloted
- relates to
-
FHIR-37086 GET call should only return authorized content
-
- Resolved - No Change
-
- mentioned in
-
Page Loading...