70.4.1Consent Management

 

Data sharing follows an opt-out model, ensuring that members’ preferences are respected. Key consent features include:

  • Default Sharing – Member data is shared with in-network providers by default for treatment purposes. This is determined through Provider Attribution Lists maintained by the payer.
  • Opt-Out Handling – If a member has opted out, any API request for their data returns a 403 Forbidden response.
  • Enforcement & Audit – Consent preferences are recorded, enforced, and fully auditable within the payer system.

Opting out of Provider Access may be managed by an upstream system or directly within Smile CDR. Regardless of where the preference is set, the opt-out must be reflected by removing the member from the appropriate Member Attribution List(s) (FHIR Group resources).

Provider Access is driven by group-based member attribution; therefore, removing opted-out members from their assigned groups is essential to ensure proper consent enforcement.