72.5.1Manage Consent

 

Consent management ensures that only members who have not opted out are included in any $davinci-data-export operation. This protects member privacy and ensures compliance with CMS regulations.

72.5.1.1Enable Manage Consent

Determine the Consent Mechanism Members may opt-out or opt back in to sharing their records. Smile supports two approaches:

  1. Using FHIR Consent Resources
    • Create PDex Provider Access Consent resources in the FHIR repository.
    • When a member opts out, the Consent resource should trigger a process that excludes the member from Provider Access attributed Group. This is an implementation detail to be implemented based on client's workflow.
    • Ensures $davinci-data-export only includes authorized members.
  2. Using an External Attribution (Access) List
    • Member consent and attribution are managed outside Smile.
    • The payer provides a regularly updated external file containing:
      • Member identifiers (Patient/Member ID)
      • Provider system identifiers (NPI, TIN, etc.)
      • Consent status (opt-in / opt-out)
    • A script or automated process parses this file and updates FHIR Group resources:
      • Members with opt-in consent are included in the Group.
      • Members with opt-out consent are removed from the Group.
      • Ensures $davinci-data-export respects current consent and access state.

Notes:

  • Proper consent management is essential to comply with CMS regulations.
  • This configuration ensures provider systems only retrieve authorized member data.