Assertion

AssertionId
CH-ADR-077 Testable
predicate
PEP authorizing PPQ-1 and PPQ-2 transactions by implementing an Authorization Decision Consumer MUST, in addition to the result from the Authorization Decision Query, validate that the resource-id of the SAML Assertion identifies the same patient (EPR-sPID) as the resource-id* supplied in the policies to be added, updated deleted or queried for. If not true, the transaction MUST be denied (see Section 3.1.6.3 CH:ADR due to CH:PPQ)
Prescription level
Mandatory / Required / Shall
Page
15
Section
3.1.6.3
Status
reviewed
Last changed
3/8/24 10:54:03 AM by vhofman
Comment

Applies to

Covered by (Deprecated)

Test Steps

Rules

Document name
Provenance
Revision
Action
EPDV-EDI_Anhang_5_E2.1_DE_Ausgabe_1_ADRPPQ20230504