FHIR Extensions Pack
5.2.0-ballot - 5.2.0 Ballot - September 2024) International flag

FHIR Extensions Pack, published by HL7 International / FHIR Infrastructure. This guide is not an authorized publication; it is the continuous build for version 5.2.0-ballot built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/fhir-extensions/ and changes regularly. See the Directory of published versions

ValueSet: resource security category value set

Official URL: http://hl7.org/fhir/ValueSet/resource-security-category Version: 5.2.0-ballot
Standards status: Trial-use Maturity Level: 3 Computable Name: ResourceSecurityCategory
Other Identifiers: OID:2.16.840.1.113883.4.642.3.1403

Description Needed Here

References

Changes since version 1.0.0:

  • The resource metadata has changed (title)
  • Logical Definition (CLD)

    Generated Narrative: ValueSet resource-security-category

    Last updated: 2023-01-31 07:07:38+1100

    Profile: Shareable ValueSet

     

    Expansion

    Generated Narrative: ValueSet

    Last updated: 2023-01-31 07:07:38+1100

    Profile: Shareable ValueSet

    Expansion based on codesystem resource security category code system v5.2.0-ballot (CodeSystem)

    This value set contains 5 concepts

    CodeSystemDisplayDefinition
      anonymoushttp://hl7.org/fhir/resource-security-categoryAnonymous READ Access Resource

    These resources tend to not contain any individual data, or business sensitive data. Most often these Resources will be available for anonymous access, meaning there is no access control based on the user or system requesting. However these Resources do tend to contain important information that must be authenticated back to the source publishing them, and protected from integrity failures in communication. For this reason server authenticated https (TLS) is recommended to provide authentication of the server and integrity protection in transit. This is normal web-server use of https.

      businesshttp://hl7.org/fhir/resource-security-categoryBusiness Sensitive Resource

    These Resources tend to not contain any individual data, but do have data that describe business or service sensitive data. The use of the term Business is not intended to only mean an incorporated business, but rather the more broad concept of an organization, location, or other group that is not identifable as individuals. Often these resources will require some for of client authentication to assure that only authorized access is given. The client access control may be to individuals, or may be to system identity. For this purpose possible client authentication methods such as: mutual-authenticated-TLS, APIKey, App signed JWT, or App OAuth client-id JWT For example: a App that uses a Business protected Provider Directory to determine other business endpoint details.

      individualhttp://hl7.org/fhir/resource-security-categoryIndividual Sensitive Resource

    These Resources do NOT contain Patient data, but do contain individual information about other participants. These other individuals are Practitioners, PractitionerRole, CareTeam, or other users. These identities are needed to enable the practice of healthcare. These identities are identities under general privacy regulations, and thus must consider Privacy risk. Often access to these other identities are covered by business relationships. For this purpose access to these Resources will tend to be Role specific using methods such as RBAC or ABAC.

      patienthttp://hl7.org/fhir/resource-security-categoryPatient Sensitive Resource

    These Resources make up the bulk of FHIR and therefore are the most commonly understood. These Resources contain highly sesitive health information, or are closely linked to highly sensitive health information. These Resources will often use the security labels to differentiate various confidentiality levels within this broad group of Patient Sensitive data. Access to these Resources often requires a declared Purpose Of Use. Access to these Resources is often controlled by a Privacy Consent.

      not-classifiedhttp://hl7.org/fhir/resource-security-categoryNo Dominant Category

    Some Resources can be used for a wide scope of use-cases that span very sensitive to very non-sensitive. These Resources do not fall into any of the above classifications, as their sensitivity is highly variable. These Resources will need special handling. These Resources often contain metadata that describes the content in a way that can be used for Access Control decisions.


    Explanation of the columns that may appear on this page:

    Level A few code lists that FHIR defines are hierarchical - each code is assigned a level. In this scheme, some codes are under other codes, and imply that the code they are under also applies
    System The source of the definition of the code (when the value set draws in codes defined elsewhere)
    Code The code (used as the code in the resource instance)
    Display The display (used in the display element of a Coding). If there is no display, implementers should not simply display the code, but map the concept into their application
    Definition An explanation of the meaning of the concept
    Comments Additional notes about how to use the code