Purpose
This WS allows to mark Specimen as entered-in-error.
Specification
Link | |
Resource | /api/patients/patient_id/specimens/id/actions/ |
Scope | specimen:cancel |
Components | Specimen |
Microservices |
|
Protocol type | REST |
Request type | PATCH |
Sync/Async | Async |
Public/Private/Internal | Public |
Key points
Only an employee who registered a Specimen, has an approval or a med_admin from the same legal entity, if they have an appropriate scope, are able to cancel the Specimen.
Request should be signed with DS.
The specimen is cancelled asynchronously
Signed content of a Specimen must be equal to the Specimen stored in DB. See Get Specimen details
status_reason must be added to signed content
status must be changed to
entered_in_error
for the purpose of displaying in the signed content
Logic
Input parameters
Input parameter | Values | Type | Description | Example |
---|---|---|---|---|
patient_id |
| String | Unique patient identifier |
|
id |
| String | Unique specimen identifier | aff00bf6-68bf-4b49-b66d-f031d48922b3 |
Dictionaries
specimen_cancel_reasons
Request structure
See on Apiary
Authorization
Verify the validity of access token
in case of error - return 401 (“Invalid access token”) in case of validation fails
Verify that token is not expired
in case of error - return 401 (“Invalid access token”)
Check user scopes in order to perform this action (scope = 'specimen:cancel')
return 403 (“Your scope does not allow to access this resource. Missing allowances: specimen:cancel”) in case of invalid scope(s)
If BLOCK_UNVERIFIED_PARTY_USERS is true, then check party's data match following condition: verification_status != NOT_VERIFIED or (verification_status = NOT_VERIFIED and updated_at > current_date - UNVERIFIED_PARTY_PERIOD_DAYS_ALLOWED):
in case not match - return 403 ("Access denied. Party is not verified")
If BLOCK_DECEASED_PARTY_USERS is true, check that party is not deceased (party_verification record does not equal to: dracs_death_verification_status = VERIFIED and dracs_death_verification_reason = MANUAL_CONFIRMED):
in case of error - return 403 ("Access denied. Party is deceased")
Headers
Content-Type:application/json
Authorization:Bearer mF_9.B5f-4.1JqM
api-key:aFBLVTZ6Z2dON1V
X-Custom-PSK:a2aa05c76f3f2d91870f923a53cc8aa8f23bbc01a8238d1c2c26d4299715a7e4
Request data validation
Validate Digital Sign
Validate request is signed
in case of error - return 422 (“Invalid signed content”)
Check DS is valid and not expired
Validate that DS belongs to the user
Check that DRFO from DS and user's party.tax_id matches
in case of error - return 409 (“Does not match the signer drfo“)
Validate legal entity
Extract client_id from token
Check legal entity status (status = ACTIVE)
In case of error - return 409 ('client_id refers to legal entity that is not active')
Validate the Specimen belongs to the legal entity where the current user works
Check $.specimen.managing_organization==token.client_id
in case of error - return 409 ("User is not allowed to perform actions with an enity that belongs to another legal entity")
Validate user
Cancelation of a Specimen is allowed for a user if he has one of the following active and approved employee that:
is an author of the Specimen (registered_by)
has a Med_Admin employee type
has an approval granted by the patient with access_level:write for the Specimen resource (approvals.granted_resources) and has a DOCTOR or SPECIALIST employee type
in case of error - return 409 ("Employee is not the one who registered the specimen, doesn't have an approval or required employee type")
Validate data consistency
Ensure that submitted Specimen relates to the Patient (from URL)
in case of error - return 404 (not found)
Validate status transition
Get Specimen by id
Check Specimen’s status is available, unsatisfactory or unavailable
in case of error - return 409 ('Specimen in status <status> cannot be cancelled')
Validate request
Validate request by schema and return 422 error code with the list of validation errors in case of fails. User fills following fields in the request:
1. Status reason
Validate value in the field $.status_reason, CodeableConcept type, required.
Check that value is in allowed values from
specimen_cancel_reasons
dictionary.in case of error - return 422 ('value is not allowed in enum')
2. Status
The target status value must be submitted in the order to display in the signed content (media storage)
Validate $.status is entered_in_error
in case of error - return 422 ("value is not allowed in enum")
Validate content
Signed content must match to the specimen from DB in order to be canceled
Render the specimen from DB
Exclude $status, $.status_reason from signed content
Compare rendered specimen and signed content
In case both object doesn't match - return 422 ('Signed content doesn't match with previously created specimen')
Processing
Create job and return it’s id.
Update specimen record with following:
status = $.status
status_reason = $.status_reason
updated_at = current datetime
updated_by = user_id from token
Response structure
See on Apiary
HTTP status codes
HTTP status code | Message | What caused the error |
401 | Invalid access token |
|
403 | Your scope does not allow to access this resource. Missing allowances: specimen:cancel |
|
403 | Access denied. Party is not verified |
|
403 | Access denied. Party is deceased |
|
404 | not found |
|
409 | Does not match the signer drfo |
|
409 | client_id refers to legal entity that is not active |
|
409 | User is not allowed to perform actions with an enity that belongs to another legal entity |
|
409 | Employee is not the one who registered the specimen, doesn't have an approval or required employee type |
|
409 | Specimen in status <status> cannot be cancelled |
|
422 | Invalid signed content |
|
422 | value is not allowed in enum |
|
422 | Signed content doesn't match with previously created specimen |
|