visit the hl7 website
Ontario Provincial Consent Override Interface HL7® FHIR® Implementation Guide v1.0.0-draft1
fhir-logo
  • Index
  • Home
    • Home
    • Introduction
    • Relationship to Other Specifications
    • Scope
    • Glossary
  • Business Context
    • Business Context
    • Business Model
    • Business Data
    • Use Cases
    • Business Rules
  • Technical Context
    • Technical Context
    • Implementer Responsibility
    • Conformance Rules
    • Connectivity Summary
  • FHIR Artifacts
    • FHIR Artifacts
    • Interactions
    • Profiles
    • Extensions
    • Terminology
    • System URIs
    • Examples
    • Capability Statement
    • Response Handling
    • Downloads
  • Change Log
    • Change Log
    • Known Issues & Future Developments
    • Revision History
    1. Index
    2. Technical Context
    3. Implementer Responsibility

For a full list of available versions, see the Directory of published versions

3.1. Implementer Responsibility

Note: Although HICs do not implement the PCOI IG directly at this time, they must conform to the privacy and security rules of the EHR where consent override through PCOI may be applicable.

3.1.1. Privacy and Security

Prior to implementing this guide, each health information custodian must complete the following, as applicable and specified by Ontario Health: To provide personal health information to Ontario Health as a Prescribed Organization for the purposes of the electronic health record, each health information custodian must:

  • Complete all EHR onboarding requirements, as specified by Ontario Health;
  • Comply with all applicable Ontario Health privacy and security policies, procedures, and standards; and
  • Execute the relevant Ontario Health EHR Contributor Agreements.

To access PHI that is accessible by means of the EHR, each HIC must:

  • Complete all EHR onboarding requirements, as specified by Ontario Health;
  • Comply with all applicable Ontario Health privacy and security policies, procedures, and standards; and
  • Execute the relevant Ontario Health EHR Services Agreements.

In accordance with section 30 of O. Reg. 329/04, the health information custodian is responsible for ensuring that every digital health asset that it selects, develops or uses complies with every applicable interoperability specification, as it may be amended from time to time, and within the time period set out in the specification. In addition to complying with the requirements set out in each applicable interoperability specification, the health information custodian is responsible for complying with PHIPA and its regulations, including but not limited to the health information custodian’s obligations related to ensuring accuracy (section 11(1) of PHIPA), security (section 12 of PHIPA), and the handling of records (section 13 of PHIPA).

3.1.2. User Credentials

Any requests to the PCOI service must be authorized by the PCOI service. Authorization is granted via a trust model where OAuth2 tokens are exchanged.

The HIC organization under whose authority the interaction is initiated SHALL be identified in the OAuth token.

For any user-initiated access to the PCOI service, the individual user must identified by the PoS within the token for auditing purposes with the PCOI service. Refer to the Connectivity section for further details.

3.1.3. System Responsibility for User Authorization, Authentication

System level integration is when a Point of Service (POS) system representing many users, registers for access to the PCOI service, instead of registering individual users. The responsibility to Authenticate and Authorize individual access is delegated from the PCOI service to the Point of Service. The Point of Service must ensure individual users access the PCOI service as required by Ontario Health’s privacy policies.

The Point of Service System is responsible for ensuring the accuracy of the identity of the individual requester specified in the message. User identities must be tied to authenticated user accounts.

3.1.4. Auditing

The POS must audit user-initiated activities such as GET or POST requests. Audit logs are maintained by the POS System to audit PHI disclosure to their end users. PPS Systems must audit PHI disclosed to their end users.

3.1.5. Logging

POS Systems must log all activities utilizing the PCOI service. The POS System must log all user-initiated activities such as GET or POST requests.

  • Application logs are tracked by the POS System for activities performed by the system. PHI must not be stored in application log files.
  • Access logs are tracked by the POS System when the user accesses the POS System. PI may be stored in access logs.
  • Application logs should log the API request/response HTTP responses codes and operational outcome.

All of the above logs are retained in accordance with the HIC's privacy policies and any supporting agreements with Ontario Health.

3.1.6. Conformance

A PCOI Consent FHIR resource submitted to Ontario Health SHALL be well-formed and conform with this specification.

Version: 1.0.0 FHIR Version: R4.0.1

Powered by SIMPLIFIER.NET

HL7® and FHIR® are the registered trademarks of Health Level Seven International