IHE Pharmacy Medication Overview
1.0.0-preview2 - Preview
IHE Pharmacy Medication Overview, published by Integrating the Healthcare Enterprise (IHE). This guide is not an authorized publication; it is the continuous build for version 1.0.0-preview2 built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/IHE/pharm-meow/tree/r4 and changes regularly. See the Directory of published versions
Built from commit b1e06305. Branch: r4.
This section describes security and privacy considerations for the IHE Medication Overview (MEOW) Profile. The guidance below is preliminary and will be expanded in a future version.
A medication overview is sensitive clinical information. Implementations are expected to address the following areas.
Actors should authenticate users and systems and enforce an authorization policy before granting access to a medication overview. The use of IHE Internet User Authorization (IUA) is recommended for authorizing access in a RESTful environment.
Communication between actors should be protected for confidentiality and integrity in transit, for example using TLS.
Actors should record security-relevant events. Alignment with IHE Audit Trail and Node Authentication (ATNA) audit events for the query and submission transactions is anticipated.
Access to a patient's medication overview may be subject to consent and access-control policy. Implementations should enforce the applicable policy; specific consent and access-control mechanisms (for example IHE BPPC/APPC) are referenced rather than mandated in this version.
Some medications can reveal particularly sensitive conditions. Confidentiality handling (for example via Composition.confidentiality and access-control policy) and emergency ("break-the-glass") access with enhanced audit logging are under consideration and will be detailed in a future version.