Mandate a Trustworthy and Accountable Architecture for All TEFCA Individual Access Services (IAS)

Recommendation: The TEFCA Common Agreement and QTF must mandate a high-assurance security and authorization architecture for all Individual Access Services (whether commercial IAS providers or services facilitating the Patient-Developer Credential). This architecture must ensure that applications accessing data on behalf of an individual do so based on explicit, verifiable individual consent, mediated by a narrow set of trusted identity and authorization service providers, with verifiable binding between identity and authorization.

Rationale & Specifics: Protecting patient data shared via any individual access pathway within TEFCA requires a robust, standardized architecture that clearly separates roles and ensures accountability. This model prevents applications from self-attesting permissions and helps limit the potential impact of a compromised application.

1. Federated Trust with Approved Identity Providers (IdPs) for All IAS:

All Individual Access Service pathways, including those used by commercial providers and those facilitating the Patient-Developer Credential, must rely on a defined, limited set of federally recognized or TEFCA-approved, high-assurance Identity Providers (IdPs) for initial individual identity verification. This establishes a "narrow waist" for trusted identity proofing.

2. Explicit, Verifiable Individual Authorization Mediated by Trusted Services:

The act of an individual authorizing an application to access their data must be a distinct, explicit step mediated by a trusted authorization service that leverages the verified identity from an approved IdP. The resulting authorization artifact (e.g., a SMART on FHIR authorization code exchanged for an access token, a FHIR Consent resource, or other digitally signed permission) must be cryptographically bound to the verified individual identity and the specific application being authorized, ensuring non-repudiation and that permissions are granted by the legitimate data subject to a specific recipient for defined purposes.

Critical Architecture Constraints:

3. Scoped Access Based on Authorization:

Applications, upon presenting a valid, identity-bound authorization credential, are granted access only to the data permitted by that specific authorization. This principle, combined with fine-grained consent capabilities, helps limit the "blast radius" of any single compromised application or token. Repeated user authentication should not be needed in the context of an ongoing authorization providing long-term network-based access in TEFCA.

4. Support for Diverse IAS Provider Models, Including Non-Reciprocal Patient-Controlled Storage:

5. Facilitation of Individual Data Retrieval within this Architecture:

Within this trustworthy and flexible framework, QHINs must provide or ensure individuals have access to functionalities enabling them to:

Mandate a Trustworthy and Accountable Architecture for All TEFCA Individual Access Services (IAS)