R4 Authorization Breaking Change

148 views
Skip to first unread message

Matthew Beermann (Cerner)

unread,
Mar 30, 2022, 12:42:51 PM3/30/22
to Cerner FHIR Developers
Cross-posting from [1]; the exact deployment date is TBD but is expected to occur in Q2:

This solution change applies to applications that use OpenID Connect (OIDC), which returns an ID token containing the URL to a Fast Healthcare Interoperability Resources (FHIR) resource representing the current user (fhirUser field).

If a user is known to the electronic health record (EHR) as a patient, but selects someone else's data to send to an application (such as a dependent), the Authorization server will now return the URL to the user's Person resource. Previously, the URL to the Patient resource was returned in this scenario.

This change is required for the Cerner implementation of FHIR to comply with certain requirements of the Office of the National Coordinator for Health Information Technology (ONC) Final Rules implementing the 21st Century Cures Act.

Matthew Beermann (Cerner)

unread,
Jun 2, 2022, 3:18:51 PM6/2/22
to Cerner FHIR Developers
Update: This change is currently planned for deployment on the evening of Tuesday, June 7th, 2022.

Andrew Hosokawa

unread,
Jun 2, 2022, 3:44:13 PM6/2/22
to Cerner FHIR Developers
Is this currently deployed to the development sandbox so we can test for any issues?

Matthew Beermann (Cerner)

unread,
Jun 3, 2022, 9:57:56 AM6/3/22
to Cerner FHIR Developers
While some changes can be (and are) rolled out in that fashion, this is unfortunately not one of them.
Reply all
Reply to author
Forward
0 new messages