<?xml version="1.0" encoding="UTF-8"?>

<Requirements xmlns="http://hl7.org/fhir">
  <id value="DHFPR2-TI.2"/>
  <meta>
    <profile value="http://hl7.org/ehrs/uv/ehrsfmr2/StructureDefinition/FMFunction"/>
  </meta>
  <language value="en"/>
  <text>
    <status value="extensions"/><div xml:lang="en" xmlns="http://www.w3.org/1999/xhtml" lang="en">
    
             
    
    
    <div id="description"><b>Description <a href="https://hl7.org/fhir/versions.html#std-process" title="Informative Content" class="informative-flag">I</a>:</b> <div><p>EHR Systems have built in audit triggers to capture key events in real-time, including events related to record management, security, system operations or performance or clinical situations.</p>
<p>Event details, including key metadata (who, what, when, where), are captured in an Audit Log.</p>
<p>Audit Review functions allow various methods of critical event notification as well as routine log review.</p>
<p>Audit functions implement requirements according to scope of practice, organizational policy, and jurisdictional law.</p>
</div></div>
    
    
    
    <div id="requirements"><b>Criteria <a href="https://hl7.org/fhir/versions.html#std-process" title="Normative Content" class="normative-flag">N</a>:</b></div>
    
    <table id="statements" class="grid dict">
        
        <tr>
            <td style="padding-left: 4px;">
            TI.2#01
            </td>
            <td style="padding-left: 4px;">
            SHALL
            
                
                <span style="border-radius: 999px;margin: 2px 2px;font-size: 10px;display: inline-block;padding: 3px 5px;letter-spacing: 0.5px;line-height: 1;white-space: nowrap;background-color: #e5f5e5;color: #388e3c;border: 1px solid #a2d1a2;">dependent</span>
                
            
            
            
                
            
            </td>
            <td style="padding-left: 4px;" class="requirement">
                <div><p>The system SHALL conform to function <a href="Requirements-DHFPR2-TI.1.3.html">TI.1.3</a> (Entity Access Control) to limit access to, or modification of, audit record information to appropriate entities according to scope of practice, organizational policy, and/or jurisdictional law.</p>
</div>
                
            </td>
        </tr>
        
        <tr>
            <td style="padding-left: 4px;">
            TI.2#02
            </td>
            <td style="padding-left: 4px;">
            SHALL
            
                
                <span style="border-radius: 999px;margin: 2px 2px;font-size: 10px;display: inline-block;padding: 3px 5px;letter-spacing: 0.5px;line-height: 1;white-space: nowrap;background-color: #e5f5e5;color: #388e3c;border: 1px solid #a2d1a2;">dependent</span>
                
            
            
            
                
            
            </td>
            <td style="padding-left: 4px;" class="requirement">
                <div><p>The system SHALL conform to function <a href="Requirements-DHFPR2-TI.1.3.html">TI.1.3</a> (Entity Access Control) to limit access to audit record information for purposes of deletion according to scope of practice, organizational policy, and/or jurisdictional law (e.g., limit access to only allow a specific system administrator to delete audit record information).</p>
</div>
                
            </td>
        </tr>
        
    </table>
</div>
  </text>
  <extension url="http://hl7.org/fhir/StructureDefinition/structuredefinition-standards-status">
    <valueCode value="informative"/>
  </extension>
  <extension url="http://hl7.org/ehrs/uv/ehrsfmr2/StructureDefinition/requirements-change-info">
    <valueCode value="NC"/>
  </extension>
  <extension url="http://hl7.org/fhir/StructureDefinition/structuredefinition-wg">
    <valueCode value="ehr"/>
  </extension>
  <extension url="http://hl7.org/fhir/StructureDefinition/structuredefinition-fmm">
    <valueInteger value="1">
      <extension url="http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom">
        <valueCanonical value="http://hl7.org/ehrs/us/dhfpr2/ImplementationGuide/hl7.ehrs.us.dhfpr2"/>
      </extension>
    </valueInteger>
  </extension>
  <url value="http://hl7.org/ehrs/us/dhfpr2/Requirements/DHFPR2-TI.2"/>
  <version value="2.0.0-ballot"/>
  <name value="TI_2_Audit"/>
  <title value="TI.2 Audit (Function)"/>
  <status value="active"/>
  <date value="2025-12-19T08:44:27+00:00"/>
  <publisher value="HL7 International / Electronic Health Records"/>
  <contact>
    <telecom>
      <system value="url"/>
      <value value="http://www.hl7.org/Special/committees/ehr"/>
    </telecom>
  </contact>
  <description value="Audit Key Record, Security, System and Clinical Events"/>
  <jurisdiction>
    <coding>
      <system value="urn:iso:std:iso:3166"/>
      <code value="US"/>
    </coding>
  </jurisdiction>
  <purpose value="EHR Systems have built in audit triggers to capture key events in real-time, including events related to record management, security, system operations or performance or clinical situations.&#xA;&#xA;Event details, including key metadata (who, what, when, where), are captured in an Audit Log.&#xA;&#xA;Audit Review functions allow various methods of critical event notification as well as routine log review.&#xA;&#xA;Audit functions implement requirements according to scope of practice, organizational policy, and jurisdictional law."/>
  <derivedFrom value="http://hl7.org/ehrs/uv/ehrsfmr2/Requirements/EHRSFMR2-TI.2"/>
  <statement>
    <extension url="http://hl7.org/ehrs/uv/ehrsfmr2/StructureDefinition/requirements-dependent">
      <valueBoolean value="true"/>
    </extension>
    <extension url="http://hl7.org/ehrs/uv/ehrsfmr2/StructureDefinition/requirements-change-info">
      <valueCode value="NC"/>
    </extension>
    <key value="DHFPR2-TI.2-01"/>
    <label value="TI.2#01"/>
    <conformance value="SHALL"/>
    <conditionality value="false"/>
    <requirement value="The system SHALL conform to function [TI.1.3](Requirements-DHFPR2-TI.1.3.html) (Entity Access Control) to limit access to, or modification of, audit record information to appropriate entities according to scope of practice, organizational policy, and/or jurisdictional law."/>
    <derivedFrom value="TI.2#1"/>
  </statement>
  <statement>
    <extension url="http://hl7.org/ehrs/uv/ehrsfmr2/StructureDefinition/requirements-dependent">
      <valueBoolean value="true"/>
    </extension>
    <extension url="http://hl7.org/ehrs/uv/ehrsfmr2/StructureDefinition/requirements-change-info">
      <valueCode value="NC"/>
    </extension>
    <key value="DHFPR2-TI.2-02"/>
    <label value="TI.2#02"/>
    <conformance value="SHALL"/>
    <conditionality value="false"/>
    <requirement value="The system SHALL conform to function [TI.1.3](Requirements-DHFPR2-TI.1.3.html) (Entity Access Control) to limit access to audit record information for purposes of deletion according to scope of practice, organizational policy, and/or jurisdictional law (e.g., limit access to only allow a specific system administrator to delete audit record information)."/>
    <derivedFrom value="TI.2#2"/>
  </statement>
</Requirements>