Security and PrivacyThis is the Continuous Integration Build of FHIR (will be incorrect/inconsistent at times).
See the Directory of published versions
| Security Work Group | Maturity Level: N/A | Standards Status: Informative | Compartments: No defined compartments |
Raw JSON (canonical form + also see JSON Format Specification)
Example Bundle with included Permission with residual restrictions
{
"resourceType" : "Bundle",
"id" : "ex-SearchSet-withPermission",
"meta" : {
"security" : [{
"system" : "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"code" : "HTEST"
},
{
"system" : "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"code" : "CPLYPOL"
}]
},
"type" : "searchset",
"timestamp" : "2023-11-22T09:32:24Z",
"total" : 2,
"link" : [{
"relation" : "self",
"url" : "http://test.fhir.net/R4/fhir/Observation?patient=example&status=current"
}],
"entry" : [{
"fullUrl" : "http://test.fhir.net/R4/fhir/Observation/in-Observation",
"resource" : {
"resourceType" : "Observation",
"id" : "in-Observation",
"meta" : {
"security" : [{
"system" : "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"code" : "ETH"
},
{
"system" : "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"code" : "R"
}]
},
"text" : {
"status" : "generated",
"div" : "<div xmlns=\"http://www.w3.org/1999/xhtml\"><p class=\"res-header-id\"><b>Generated Narrative: Observation in-Observation</b></p><a name=\"in-Observation\"> </a><a name=\"hcin-Observation\"> </a><div style=\"display: inline-block; background-color: #d9e0e7; padding: 6px; margin: 4px; border: 1px solid #8da1b4; border-radius: 5px; line-height: 60%\"><p style=\"margin-bottom: 0px\"/><p style=\"margin-bottom: 0px\">Security Labels: substance abuse information sensitivity (Details: ActCode code ETH = 'substance abuse information sensitivity'), restricted (Details: Confidentiality code R = 'restricted')</p></div><p><b>status</b>: Final</p><p><b>code</b>: <span title=\"Codes:{http://loinc.org 74013-4}\">Alcoholic drinks per day</span></p><p><b>subject</b>: <a href=\"patient-example.html\">Jim Male, DoB: 1974-12-25 ( Medical record number\u00a0(use:\u00a0usual,\u00a0period:\u00a02001-05-06 --> (ongoing)))</a></p><p><b>effective</b>: 2022-06-13</p><p><b>performer</b>: <a href=\"patient-example.html\">Jim Male, DoB: 1974-12-25 ( Medical record number\u00a0(use:\u00a0usual,\u00a0period:\u00a02001-05-06 --> (ongoing)))</a></p><p><b>value</b>: 5 wine glasses per day<span style=\"background: LightGoldenRodYellow\"> (Details: UCUM code/d = '/d')</span></p></div>"
},
"status" : "final",
"code" : {
"coding" : [{
"system" : "http://loinc.org",
"code" : "74013-4"
}]
},
"subject" : {
"reference" : "Patient/example"
},
"effectiveDateTime" : "2022-06-13",
"performer" : [{
"reference" : "Patient/example"
}],
"valueQuantity" : {
"value" : 5,
"unit" : "wine glasses per day",
"system" : "http://unitsofmeasure.org",
"code" : "/d"
}
},
"search" : {
"mode" : "match"
}
},
{
"fullUrl" : "http://test.fhir.net/R4/fhir/Permission/in-permission-redisclose-forbidden-without-consent",
"resource" : {
"resourceType" : "Permission",
"id" : "in-permission-redisclose-forbidden-without-consent",
"meta" : {
"security" : [{
"system" : "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"code" : "HTEST"
}]
},
"text" : {
"status" : "generated",
"div" : "<div xmlns=\"http://www.w3.org/1999/xhtml\"><p class=\"res-header-id\"><b>Generated Narrative: Permission in-permission-redisclose-forbidden-without-consent</b></p><a name=\"in-permission-redisclose-forbidden-without-consent\"> </a><a name=\"hcin-permission-redisclose-forbidden-without-consent\"> </a><div style=\"display: inline-block; background-color: #d9e0e7; padding: 6px; margin: 4px; border: 1px solid #8da1b4; border-radius: 5px; line-height: 60%\"><p style=\"margin-bottom: 0px\"/><p style=\"margin-bottom: 0px\">Security Label: test health data (Details: ActReason code HTEST = 'test health data')</p></div><p><b>status</b>: Active</p><p><b>asserter</b>: <a href=\"organization-example.html\">Organization ACME Health</a></p><p><b>date</b>: 2023-11-22</p><p><b>combining</b>: Deny-unless-permit</p><blockquote><p><b>rule</b></p><p><b>type</b>: Permit</p><blockquote><p><b>activity</b></p><p><b>purpose</b>: <span title=\"Codes:{http://terminology.hl7.org/CodeSystem/v3-ActReason TREAT}\">treatment</span>, <span title=\"Codes:{http://terminology.hl7.org/CodeSystem/v3-ActReason HPAYMT}\">healthcare payment</span>, <span title=\"Codes:{http://terminology.hl7.org/CodeSystem/v3-ActReason HOPERAT}\">healthcare operations</span></p></blockquote><blockquote><p><b>limit</b></p></blockquote></blockquote></div>"
},
"status" : "active",
"asserter" : {
"reference" : "Organization/example"
},
"date" : ["2023-11-22"],
"combining" : "deny-unless-permit",
"rule" : [{
"type" : "permit",
"activity" : [{
"purpose" : [{
"coding" : [{
"system" : "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"code" : "TREAT"
}]
},
{
"coding" : [{
"system" : "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"code" : "HPAYMT"
}]
},
{
"coding" : [{
"system" : "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"code" : "HOPERAT"
}]
}]
}],
"limit" : [null]
}]
},
"search" : {
"mode" : "include"
}
}]
}
Usage note: every effort has been made to ensure that the examples are correct and useful, but they are not a normative part of the specification.
FHIR ®© HL7.org 2011+. FHIR R6 hl7.fhir.core#6.0.0-ballot3 generated on Thu, Oct 23, 2025 19:47+0000.
Links: Search |
Version History |
Contents |
Glossary |
QA |
Compare to R5 |
|
Propose a change