Kanta’s authorisation of an outsourcing service provider can be used to process patient data if the party responsible for providing a health service (e.g. a wellbeing services county) purchases the service from another health care provider as an outsourced service or using service vouchers. This allows information to move quickly and securely between the service organiser and the service provider.
The service organiser is responsible for the patient’s treatment, so the patient data generated in connection with the outsourced service belong to the service organiser's patient register. With authorisation of an outsourcing service provider, information can conveniently be stored directly in the correct register.
The updated version, authorisation of purchased services 2.0, facilitates, for example, the organisation of services produced using service vouchers. For example, the service organiser can leave the information about service provider blank and add it later after the patient has selected the service provider. In addition, as new features:
- under the authorisation, the service organiser can give the service provider additional information on the ordered service
- the service provider can retrieve the authorisations assigned to it without identifying the patient
- the monitoring of purchased services is improved
- a minor with decision-making capacity may prohibit a guardian from receiving information about the service voucher through MyKanta.
These features will streamline operations and reduce the workload of the service organiser and the service provider.
Support for the old version will end on 31 December 2026. During the transition period, the different versions will work together. However, you can only get the full benefit of the new features when both the service organiser and the service provider are using the updated version.
Enquire your information system supplier when you can start using the updated version.
Deployment of the authorisation of an outsourcing service provider functionality
The authorisation of an outsourcing service provider is a form with which the service organiser assigns access rights to the service provider (access or storage rights).
Authorisation for an outsourcing service provider allows
- the service provider to store the information from their own patient information system directly in the service organiser’s register in Kanta.
- the service provider can retrieve information from Kanta that is necessary for the implementation of the care. The information is visible regardless of whether the patient has restricted the disclosure of their information, for example, by means of denials.
The manner of organisation of the outsourced service determines whether patient-specific or register-specific authorisation is used.
A patient-specific authorisation is used when an outsourcing service or voucher-based service is provided for a specific patient.
A patient-specific authorisation allows the service provider to access either all patient documents or specific patient documents indicated in the authorisation that have been stored for the patient in question by the service organiser in the Patient Data Repository.
In addition, the service provider is given the right to store the patient’s documents in the service organiser’s register.
How to start using the authorisation of outsourcing service providers
The deployment of the authorisation function for outsourcing service providers requires that both the service organiser and provider use the Patient Data Repository. In addition, the authorisation function for outsourcing service providers must have been implemented in both the organiser’s and provider’s patient information systems.
When the authorisation of outsourcing service providers is used for imaging materials, at least the service provider must use the Imaging Data Repository. The service organiser must also have a certified viewer if it wishes to view the images produced as an outsourced service via the Imaging Data Repository.
To deploy the authorisation of outsourcing service providers function:
Contact your information system provider to ensure that the authorisation of outsourcing service providers can be used in your patient information system.
Ensure that the other party (service organiser or service provider) in the outsourced service is also ready to begin using the authorisation for outsourcing service providers.
Read and understand the operating models related to the authorisation function for outsourcing service providers:
Conduct a deployment test together with the other party in the outsourcing service before deployment.
The test is carried out using the test case for either a patient-specific or register-specific authorisation of an outsourcing service provider in accordance with instructions. Both the service organiser and service provider play a role in the testing.
The functionality may be taken into use immediately once its proper operation within the information system has been verified.