ЕСОЗ - публічна документація

Medical Events filtration by Forbidden groups_EN

Filtration Logic

For each method described in Table “Medical events to filter“ use following logic to define if User has an access to medical events with data included in the Forbidden groups.

1. Define forbidden group Items

Define forbidden group Items presented in Medical events the User should not see

  • Get all active Forbidden group Items from cache.

    • if cache is empty - fill it with all active forbidden group items (forbidden_group_codes and forbidden_group_services)

  • Get all active and approved user's employees

  • Get all Approvals on forbidden groups granted by patient to all user's employees

    • if it merged person/preperson - get all active Approvals on forbidden groups granted by active master_person to all user's employees

  • Form list of forbidden group items that still are restricted for the User: eliminate items in approvals from the all forbidden group items.

2. Check Medical event is allowed to access

Check Medical event data is allowed to access according to Forbidden groups

  • Do usual validations in methods described in the table “Medical events to filter” (column “Method”)

  • Additionally filter Medical events by rule (values in fields (column “Filter by“) are not in the forbidden list of items defined at p.1  OR user is an author of the ME)

    • in case of error - look at “Result“ column

How to define user is author of the Medical event?

Check party_users table: If inserted_by user in ME belongs to the same party as user from the token, then this is an author.

Medical events to filter

Medical event

Method

Filter by

Forbidden group items

Result

Additional info

Medical event

Method

Filter by

Forbidden group items

Result

Additional info

Episode

Get Episode by id

diagnoses_history 
(with is_active=true )

codes from dictionaries:

  • eHealth/ICD10_AM/condition_codes

  • eHealth/ICPC2/condition_codes

Return 403 error with type “forbidden“

Get Episode by id?archived

Get Episode by search params

Do not render in the response

Get Episodes of Care by search paramsarchived

Get approved Episodes

Do not render in the response

Get Approved Episodes of Carearchived

Get Active Diagnoses Summary

current_diagnoses

Do not render in the response

Patient summary

Summary active Diagnoses

Get Short Episodes Summary

diagnoses_history

Do not render in the response

Patient summary

Encounter

Get encounter by id

diagnoses

actions

reasons

action_references

 

  1. diagnoses by codes from dictionaries:

  • eHealth/ICD10_AM/condition_codes

  • eHealth/ICPC2/condition_codes

  1. actions by codes from dictionary eHealth/ICPC2/actions

  1. reasons by codes from dictionary eHealth/ICPC2/reasons

  1. code by service_id

Return 403 error with type “forbidden“

Get Encounterarchived

Get encounters by search params

Do not render in the response

Get Encounterarchived

Get encounters in episode context

Do not render in the response

 

Get encounter details in episode context

Return 403 error with type “forbidden“

 

Condition

Get conditions in episode context

code

evidences

  1. code by codes from dictionaries:

  • eHealth/ICD10_AM/condition_codes

  • eHealth/ICPC2/condition_codes

  1. evidences by codes from dictionary eHealth/ICPC2/reasons

Do not render in the response

 

Get condition details in episode context

Return 403 error with type “forbidden“

 

Get conditions by search params

Do not render in the response

Get Conditionsarchived

Get condition by id

Return 403 error with type “forbidden“

Get Conditionsarchived

Get Conditions Summary

Do not render in the response

Summary Conditions

Get Condition Summary by id

Return 403 error with type “forbidden“

Summary Conditions

Diagnostic report

Get Diagnostic report by id

conclusion_code

code

  1. conclusion_code by codes from dictionary eHealth/ICD10_AM/condition_codes

  2. code by service_id

Return 403 error with type “forbidden“

Get Diagnostic Reportarchived

Get Diagnostic reports by search params

Do not render in the response

Get Diagnostic Reportarchived

Get approved Diagnostic report

Do not render in the response

Get Approved Diagnostic Reports

Get Diagnostic report Summary by id

Return 403 error with type “forbidden“

Summary Diagnostic Reports

Get Diagnostic reports Summary

Do not render in the response

Summary Diagnostic Reports

Procedure

Get Procedure by id

code

service_id

Return 403 error with type “forbidden“

https://e-health-ua.atlassian.net/wiki/spaces/EH/pages/583404094

Get Procedures by search params

Do not render in the response

https://e-health-ua.atlassian.net/wiki/spaces/EH/pages/583404094

Get Procedure Summary by id

Return 403 error with type “forbidden“

https://e-health-ua.atlassian.net/wiki/spaces/EH/pages/583404058

Get Procedures Summary

Do not render in the response

https://e-health-ua.atlassian.net/wiki/spaces/EH/pages/583404058

Care plan

Get Care plan by id

addresses

codes from dictionaries:

  • eHealth/ICD10_AM/condition_codes

  • eHealth/ICPC2/condition_codes

Return 403 error with type “forbidden“

https://e-health-ua.atlassian.net/wiki/spaces/MRIN/pages/1969520673

Care plan activity

Get Activity by id

reason_code

product_reference (if kind=service_request)

  1. reason_code by codes from dictionaries:

  • eHealth/ICD10AM/condition_codes

  • eHealth/ICPC2/condition_codes

  1. product_reference by:

  • service_id if resource type=service

  • service_group_id if resource type=service_group

Return 403 error with type “forbidden“

https://e-health-ua.atlassian.net/wiki/spaces/MRIN/pages/1957232737

Get Activities

Do not render in the response

https://e-health-ua.atlassian.net/wiki/spaces/MRIN/pages/1969455146

Service request

Get Service request by search params

code

code by:

  • service_id if resource type=service

  • service_group_id if resource type=service_group

Do not render in the response

 

Get Service request by id

Return 403 error with type “forbidden“

 

Get Service request list in episode context

Do not render in the response

https://e-health-ua.atlassian.net/wiki/spaces/EH/pages/583402514

Get Service request details in episode context

Return 403 error with type “forbidden“

https://e-health-ua.atlassian.net/wiki/spaces/EH/pages/583402514

Get Service request by requisition

Do not render in the response

https://e-health-ua.atlassian.net/wiki/spaces/EH/pages/583402289

 

ЕСОЗ - публічна документація