HL7 Personal Health Record System Functional Model, Release 2
2.0.1-ballot - Normative Ballot

Publication Build: This will be filled in by the publication tooling

Requirements: TI.2.1.2.7 User Attempts to Access Data (Unsuccessful -- Access Denied) Security Audit Trigger (Function)

Page standards status: Informative
Statement N:

Manage Audit Trigger initiated to track user attempts to access data (unsuccessful -- access denied).

Description I:

Capture user attempts to access data (unsuccessful -- access denied), both routine and exceptional, including key metadata (who, what, when, where, why).

Actors:
ehr
Criteria N:
TI.2.1.2.7#01 SHALL

The system SHALL audit each occurrence when user access is unsuccessful (denied).

TI.2.1.2.7#02 SHALL

The system SHALL capture identity of the organization.

TI.2.1.2.7#03 conditional SHALL

IF known, THEN the system SHALL capture identity of the user.

TI.2.1.2.7#04 SHALL

The system SHALL capture identity of the system.

TI.2.1.2.7#05 SHALL

The system SHALL capture the event initiating audit trigger.

TI.2.1.2.7#06 SHALL

The system SHALL capture the date and time of the event initiating audit trigger.

TI.2.1.2.7#07 SHALL

The system SHALL capture identity of the location (i.e., network address).