Audit Trail Consumption [CH ATC]
The eMedication service supports the retrieval of patient audit trail events, in FHIR format as specified by the implementation guide, and in compliance with the Supplement 2.2 to the Annex 5 of the EPR Act and itself based on IHE’s Retrieve ATNA Audit Event [ITI-81] transaction as specified by the Add RESTful ATNA (Query and Feed) supplement to IHE IT Infrastructure Technical Framework.
This transaction is implemented by the eMedication service as specified by the resources linked in the previous paragraph with the following particularities:
- All the query parameters defined by the IHE supplement are supported, but with the following limitations:- addresstesting does not take into account modifiers, only case sensitive exact matches.
- agent.identifiertesting does not take into account modifiers and is always case sensitive.
- patient.identifiertesting is done without taking into account modifiers and it is always case sensitive. Matching does not additionally filter by type: it is assumed that if the identifier matches, that is good enough.
- entity.identifiertesting is done without taking modifiers into account and it is always case sensitive.- ORcriteria for this parameter is not supported.
- entity.typetesting is done without taking modifiers inot account and it is always case sensitive.
- entity.roletesting is done without taking modifiers into account and it is always case sensitive.
- source.identifiertesting is done without taking modifiers into account and it is always case sensitive.- ORcriteria for this parameter is not supported.
- typetesting is done without taking modifiers into account and it is always case sensitive.
- subtypetesting is done without taking modifiers into account and it is always case sensitive.
- outcometesting is done without taking modifiers into account and it is always case sensitive.
- The FHIR standard parameters that apply to all resources (_content,_id,_lastUpdated) are not supported.
- FHIR search parameters are not supported.
 
Security Considerations
Note that beside the security considerations expressed (directly or indirectly) by the CH EPR FHIR profile, the eMedication service implementation supports only, for now, the SAML Token option, which means that the authorization token conveyed with the HTTP request must be an XUA token.