Scope
Subject, purpose, data category, recipient/role and validity period can constrain authorization.
TRUST
Represent consent as a versioned, purpose- and scope-aware state that can be evaluated by applications and integrations at decision time.
Subject, purpose, data category, recipient/role and validity period can constrain authorization.
Capture, activation, renewal, withdrawal and expiry are explicit states.
Current consent is evaluated together with role/policy rather than treated as a static checkbox.
Version, actor/channel, timestamp, policy context and resulting state are retained where required.
Withdrawal affects future authorization decisions; historical evidence may remain where retention/accountability policy requires it.
Consent disputes or corrections should include the affected service/context and consent event without exposing unrelated health information.
A useful consent record answers who granted what, for which purpose, to which recipient, for how long and under which policy/version. It also preserves later revocation or supersession.
Identify the person granting consent and, for caregiver/delegated scenarios, the authority/relationship under which they act.
Record data/resource categories, intended purpose, recipient/controller context and any restrictions—not only a yes/no flag.
Preserve grant time, effective period, policy/notice version and the evidence shown at the decision point.
Make withdrawal/supersession effective prospectively, preserve historical evidence and communicate the changed state to dependent workflows.
Every transition is visible to the user and to systems that depend on the permission state.