Our Users already have Smartcards (or modern equivilent) with relevant Orgs (either Trust or ICB orgs), roles and activities for authentication for PDS and other relevant APIs, and they will authenticate at the point of login to the appplication using CIS2 separate authentication and authorisation.
However, they also have a seperate cost code centre, or in some cases up to 7 different cost code centres for precribing based on the PCN that the patient GP surgery is in.
What we are trying to clarify is, for the authorisation for the Digital Signing Service API and EPS FHIR API:
• Does having the correct role and activity codes at trust/ICB Org level allow prescribing without the Cost Code Centre being added to the Smartcard?
• If the Cost Code Centre is assigned to the Smartcard and included within the user’s roles, and sent in the access token, the users could still, authentication using the provider org?
• Or does the prescriber need to log in and authenticate against each individual Cost Code Centre when signing or cancelling prescriptions, so could be up to 7 times even with a low volume to sign?
Thanks