Model and query FHIR Consent resources to enforce data sharing restrictions when responding to FHIR queries, applying patient consent to filter what data is returned

domain: hl7.org/fhir · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Create Consent resources with scope (patient-privacy, treatment, research), category codes, patient reference, dateTime, performer, organization, and provision elements that define permit or deny rules
  2. Use provision.actor to specify which practitioners or organizations the consent applies to, provision.action to restrict specific activities (access, correct, disclose), and provision.purpose for treatment vs research
  3. Implement a consent enforcement layer that intercepts FHIR queries, retrieves the requesting user's identity from the access token, and evaluates applicable Consent resources for the target patient
  4. Apply consent-driven filtering by excluding resources whose data class or sensitivity label (e.g., 42 CFR Part 2 substance use, HIV, mental health) is covered by a deny provision for the requester
  5. Return filtered bundles that omit restricted resources, and optionally include an OperationOutcome with an information-level issue explaining that results may be incomplete due to consent restrictions

Known gotchas

Related routes

Model and submit a FHIR Consent resource to enforce data sharing restrictions on patient data
hl7.org/fhir · 5 steps · unrated
Enforce patient Consent resource policies for data sharing restrictions in a FHIR server
hl7.org/fhir/R4 · 5 steps · unrated
Query a payer Patient Access API (CMS-9115 mandate) to retrieve member claims and clinical data
fhir · 6 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans