HL7 FHIR Implementation Guide: Data Access Policies
1.0.0-current - ci-build International flag

HL7 FHIR Implementation Guide: Data Access Policies, published by HL7 International / Security. This guide is not an authorized publication; it is the continuous build for version 1.0.0-current built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/data-access-policies/ and changes regularly. See the Directory of published versions

Example Bundle: Example of a SearchSet Bundle with Permission

Bundle ex-SearchSet-withPermission of type searchset


Entry 1 - fullUrl = http://test.fhir.net/R4/fhir/Observation/in-Observation

Search:Mode = match

Resource Observation:

Generated Narrative: Observation

Resource Observation "in-Observation"

Security Labels: http://terminology.hl7.org/CodeSystem/v3-ActCode, http://terminology.hl7.org/CodeSystem/v3-Confidentiality

status: FINAL

code: Alcoholic drinks per day (LOINC#74013-4)

subject: Patient/ex-patient " SCHMIDT"

effective: 2022-06-13

performer: Patient/ex-patient " SCHMIDT"

value: 5 wine glasses per day (Details: UCUM code /d = '/d')


Entry 2 - fullUrl = http://test.fhir.net/R4/fhir/Permission/in-permission-redisclose-forbidden-without-consent

Search:Mode = include

Resource Permission:

Generated Narrative: Permission

Resource Permission "in-permission-redisclose-forbidden-without-consent"

Security Labels: http://terminology.hl7.org/CodeSystem/v3-ActReason

status: ACTIVE

asserter: Organization/ex-organization "nowhere"

date: 2023-11-22

combining: DENYUNLESSPERMIT

rule

type: PERMIT

Activities

-Purpose
*treatment (ActReason#TREAT), healthcare payment (ActReason#HPAYMT), healthcare operations (ActReason#HOPERAT)

limit: no disclosure without information subject's consent directive (ActCode#NODSCLCDS)