Assertion

AssertionId
CH-ADR-073 Testable
predicate
The PEP authorizing ITI-18 transactions by implementing an Authorization Decision Consumer MUST, in addition to the result from the Authorization Decision Query, validate that the resource-id from the SAML Assertion identifies the same patient as the MPI-PID supplied in the Registry Stored Query transaction. If not true, the transaction MUST be denied (see Section 3.1.6.1 CH:ADRdue to XDS Registry Stored Query [ITI-18])
Prescription level
Mandatory / Required / Shall
Page
14
Section
3.1.6.1
Status
reviewed
Last changed
3/8/24 10:54:03 AM by vhofman
Comment

Applies to

Audit Messages

Integration Profiles

Standards

Covered by (Deprecated)

Test Steps

Rules

Document name
Provenance
Revision
Action
EPDV-EDI_Anhang_5_E2.1_DE_Ausgabe_1_ADRPPQ20230504