CH EPR FHIR (R4)
4.0.1-ballot - ballot
This page is part of the CH EPR FHIR (R4) (v4.0.1-ballot: DSTU 4 Ballot 2) based on FHIR (HL7® FHIR® Standard) R4. The current version which supersedes this version is 5.0.0-ballot. For a full list of available versions, see the Directory of published versions
This transaction is used by the Policy Source to add, update, or delete a set of privacy policies. The only HTTP
method which SHALL be supported is POST.
The Policy Source uses HTTP method POST to perform an operation on a set of privacy policies in the Policy Repository,
as an ACID transaction.
The request body SHALL represent a single Bundle resource compliant to the PpqmFeedRequestBundle profile.
The request SHALL be sent to [baseUrl].
Upon receiving the HTTP POST request, the Policy Repository SHALL:
entry.request.method on the embedded or
referenced PpqmConsent resource:
The PPQ-4 response SHALL be created according to the section 3.1.0.11 of the FHIR R4 specification.
TLS SHALL be used. For user authentication and authorization, the IUA profile with extended access token SHALL be used as described in the Amendment mHealth of Annex 5, Section 3.2. Consequently, the Mobile Privacy Policy Bundle Feed [PPQ-4] transaction SHALL be combined with Incorporate Access Token [ITI-72] transaction of the IUA profile.
The traceparent header is required, as described in Trace Context header.
The involved actors SHALL record audit events. The Policy Source SHALL use the ATNA FHIR Feed option thereby, the Policy Repository SHALL use either the ATNA FHIR Feed option or the ATNA TLS Syslog option.
The audit records correspond to the ones of PPQ-1, with the following adaptations:
EventTypeCode SHALL be set to EV("PPQ-4", "e-health-suisse", "Mobile Privacy Policy Bundle Feed").