Interoperable Digital Identity and Patient Matching
3.0.0-current - STU 3 United States of America flag

Interoperable Digital Identity and Patient Matching, published by HL7 International / Patient Administration. This guide is not an authorized publication; it is the continuous build for version 3.0.0-current built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/fhir-identity-matching-ig/ and changes regularly. See the Directory of published versions

Artifacts Summary

This page provides a list of the FHIR artifacts defined as part of this implementation guide.

Behavior: Operation Definitions

These are custom operations that can be supported by and/or invoked by systems conforming to this implementation guide.

IDI Match Operation

§1:This operation is an alternative of the $match operation, constrained to meet the additional requirements found in this IG. One of the IDI Patient profiles outline in this guide (IDI-Patient, IDI-Patient-L0, IDI-Patient-L1, IDI-Patient-L2) SHALL be used as the input for the match request. An IDI-Match-Bundle will be returned to the requesting entity. This Bundle will contain the full URLs of the sourced information, an Organization resource, and any matched Patient resources.

Structures: Resource Profiles

These define constraints on FHIR resources for systems conforming to this implementation guide.

A Patient resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI)

A Patient resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI), and may carry the verified LEI (vLEI). This profile is used to represent a patient who has a legal entity identifier, which is typically used for individuals who are associated with legal entities in financial transactions. The profile includes an extension for the verified LEI (vLEI) to indicate that the LEI has been verified and is valid.

A Person resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI)

A Person resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI), and may carry the verified LEI (vLEI). This profile is used to represent a person who has a legal entity identifier, which is typically used for individuals who are associated with legal entities in financial transactions. The profile includes an extension for the verified LEI (vLEI) to indicate that the LEI has been verified and is valid.

A Practitioner resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI)

A Practitioner resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI), and may carry the verified LEI (vLEI). This profile is used to represent a practitioner who has a legal entity identifier, which is typically used for individuals who are associated with legal entities in financial transactions. The profile includes an extension for the verified LEI (vLEI) to indicate that the LEI has been verified and is valid.

A PractitionerRole resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI)

A PractitionerRole resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI), and may carry the verified LEI (vLEI). This profile is used to represent a practitioner role that has a legal entity identifier, which is typically used for roles that are associated with legal entities in financial transactions. The profile includes an extension for the verified LEI (vLEI) to indicate that the LEI has been verified and is valid.

A RelatedPerson resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI)

A RelatedPerson resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI), and may carry the verified LEI (vLEI). This profile is used to represent a related person who has a legal entity identifier, which is typically used for individuals who are associated with legal entities in financial transactions. The profile includes an extension for the verified LEI (vLEI) to indicate that the LEI has been verified and is valid.

An Organization resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI)

An Organization resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI), and may carry the verified LEI (vLEI). This profile is used to represent an organization that has a legal entity identifier, which is typically used for organizations that are involved in financial transactions. The profile includes an extension for the verified LEI (vLEI) to indicate that the LEI has been verified and is valid.

FAST Identity Organization

US Core 6.1.0 Organization constrained for FAST Identity STU3: adds the LEI as the organizational 'golden record' identifier and a verifiable LEI (vLEI) reference. US Core NPI/CLIA identifier slices and open slicing are preserved.

FAST Identity Patient

US Core 6.1.0 Patient constrained for FAST Identity STU3: adds jurisdiction-scoped Golden Record Identifier(s) and CSP-issued identifier(s) with assurance metadata. Slicing is open, so US Core / local identifiers (MRN, member ID) remain valid.

Golden Record Patient (US Core)

US Realm adapter: applies the Golden Record Identifier slice within a US Core Patient. Inherits US Core / USCDI must-supports in addition to the Golden Identifier slice.

Golden Record Patient (Universal)

Patient carrying a Golden Record Identifier, derived from base FHIR Patient so it is usable by any assigner — EHRs, payers, HIEs, and Credential Service Providers (CSPs) — and portable across realms. Must-support flags express the Golden Record identity boundary (brief §3): core identity attributes are Must Support; contextual data (employment, organizational role, coverage, clinical/USCDI demographics) is intentionally not required by this profile and lives in other resources.

IDI Match Bundle

Bundle requirements for responders to an $IDI-match request. Responders SHALL include only absolute URL FHIR server addresses, and SHALL NOT include URIs for UUIDs or OIDs, in the fullURL returned. This additional constraint on a response to $IDI-match is intended to help recipients understand the source of the response, particularly when a patient match is invoked as part of record location–such that the URL would be needed for additional health data requests performed subsequent to matching. Additionally, the .identifier.assigner element within the returned Bundle SHOULD include an Organization resource that contains at least one appropriate contact point.

IDI Match Input Parameters

The Parameters profile used to define the inputs of the $IDI-match operation using an IDI-Patient profile for submission.

IDI Match Output Parameters

The Parameters profile used to define the outputs of the $IDI-match operation.

Structures: Data Type Profiles

These define constraints on FHIR data types for systems conforming to this implementation guide.

An Identifier with a value that is a Legal Entity Identifier (LEI)

An Identifier with a value that is a Legal Entity Identifier (LEI), and may carry the verified LEI (vLEI)

Structures: Extension Definitions

These define constraints on FHIR data types for systems conforming to this implementation guide.

CSP Assurance

Assurance metadata for a CSP-issued person identity, aligned to NIST SP 800-63-3.

Identity Jurisdiction

The governing jurisdiction (nation and, optionally, state/region) that issues and maintains a Golden Record Identifier. Enables multiple jurisdiction-scoped GRIs for one person.

Organization vLEI

A verifiable LEI (vLEI) credential attesting the organization's LEI. Carries the content-addressed credential identifier (SAID) and a resolvable source (OOBI / .well-known) for discovery. Verification is cryptographic against the GLEIF chain of trust, not the hosting domain.

vLEI

An extension to hold the verified LEI (vLEI) indicating that the LEI has been verified and is valid. Note that the vLEI is not further decomposed into the Attachment elements, as pulling these values outside of the vLEI leaves them unprotected. Thus any access to the vLEI elements should go through the proper vLEI validation process and use the values in the then validated vLEI.

Terminology: Value Sets

These define sets of codes used by systems conforming to this implementation guide.

FAST Authenticator Assurance Level (AAL) Value Set

Permitted NIST 800-63-3 Authenticator Assurance Levels.

FAST Identity Assurance Level (IAL) Value Set

Permitted NIST 800-63-3 Identity Assurance Levels.

Golden Identifier Type Value Set

Type code(s) that mark a Patient.identifier as a Golden Record Identifier.

vLEI Credential Status Value Set

Lifecycle status of a verifiable LEI (vLEI) credential.

Terminology: Code Systems

These define new code systems used by systems conforming to this implementation guide.

FAST Identity Assurance Level Code System

NIST SP 800-63-3 assurance levels used to qualify a CSP-issued identity.

FAST Identity Identifier Type Code System

Identifier type codes distinguishing Golden Record and CSP-issued person identifiers within FAST Identity.

Golden Identifier Type

Code system for the type of golden identifier used in the .identifier element of the Patient resource.

vLEI Credential Status Code System

Lifecycle status of a verifiable LEI (vLEI) credential.

Example: Example Instances

These are example instances that show what data produced and consumed by systems conforming with this implementation guide might look like.

Example of a Patient with a Legal Entity Identifier (LEI)

This is an example of a Patient resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI). The Identifier uses the LEI profile to specify that the value is a valid LEI, and includes the system URI for the LEI. The example also includes an extension for the verified LEI (vLEI) to indicate that the LEI has been verified and is valid.

Example of a Person with a Legal Entity Identifier (LEI)

This is an example of a Person resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI). The Identifier uses the LEI profile to specify that the value is a valid LEI, and includes the system URI for the LEI. The example also includes an extension for the verified LEI (vLEI) to indicate that the LEI has been verified and is valid.

Example of a Practitioner with a Legal Entity Identifier (LEI)

This is an example of a Practitioner resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI). The Identifier uses the LEI profile to specify that the value is a valid LEI, and includes the system URI for the LEI. The example also includes an extension for the verified LEI (vLEI) to indicate that the LEI has been verified and is valid.

Example of a PractitionerRole with a Legal Entity Identifier (LEI)

This is an example of a PractitionerRole resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI). The Identifier uses the LEI profile to specify that the value is a valid LEI, and includes the system URI for the LEI. The example also includes an extension for the verified LEI (vLEI) to indicate that the LEI has been verified and is valid.

Example of a RelatedPerson with a Legal Entity Identifier (LEI)

This is an example of a RelatedPerson resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI). The Identifier uses the LEI profile to specify that the value is a valid LEI, and includes the system URI for the LEI. The example also includes an extension for the verified LEI (vLEI) to indicate that the LEI has been verified and is valid.

Example of an Organization with a Legal Entity Identifier (LEI)

This is an example of an Organization resource that includes an Identifier with a value that is a Legal Entity Identifier (LEI). The Identifier uses the LEI profile to specify that the value is a valid LEI, and includes the system URI for the LEI. The example also includes an extension for the verified LEI (vLEI) to indicate that the LEI has been verified and is valid.

FAST Dual Citizen Example

Jordan Alexander Rivera — dual US/UK citizen. Two jurisdiction-scoped Golden Record Identifiers plus two CSP identities (CLEAR, ID.me) with NIST 800-63-3 assurance metadata.

FAST Organization Example

Example Health System — NPI plus LEI (golden record) and a vLEI credential referenced by OOBI/.well-known with its content-addressed SAID.

Golden Record CSP Example

Jane Marie Doe — a Golden Record Identifier asserted by a Credential Service Provider on a base FHIR Patient. Universal-ready: no USCDI demographics required (design brief 2.3, 2.3,

Golden Record Multi-CSP Example

Jane Doe — one person carrying Golden Record Identifiers from two different CSPs, distinguished by system and assigner (multi-CSP scenario, design brief §4 Q6).

Golden Record Patient — CSP assigner (base FHIR Patient)

A Credential Service Provider asserts a Golden Record Identifier on a base FHIR Patient. Demonstrates the universal-ready authoritative profile (brief 2.3): the assigner is not a US Core producer, yet the record is fully conformant because only core identity attributes are required. No USCDI demographics are present, by design (brief 2.3): the assigner is not a US Core producer, yet the record is fully conformant because only core identity attributes are required. No USCDI demographics are present, by design (brief

Golden Record Patient — US Core realm adapter (EHR)

An EHR persists the Golden Record Identifier inside a US Core Patient. Beyond the shared Golden Identifier slice it satisfies US Core / USCDI must-supports (race, ethnicity, birth sex, name, telecom, gender, birthDate, address). Contrast with Examples A and B: those USCDI demographics are contextual to identity resolution and are only present here because US Core requires them — the reason the authoritative profile stays on base Patient (brief 2.3, 2.3,

Golden Record Patient — multiple CSP-issued identifiers

Illustrates action item #7: the same person carrying Golden Identifiers from two different CSPs, distinguished by system/assigner (brief §4 Q6).

Golden Record Patient — single CSP

Patient with one Golden Record Identifier issued by a CSP.

Golden Record Patient — two CSP-issued identifiers (base FHIR Patient)

One person, two Golden Record Identifiers from different CSPs (multi-CSP scenario, brief §4 Q6). The identifiers share the #golden type but differ in system and assigner, which is how a matcher tells the issuing authorities apart.

Golden Record US Core Example

Jane Doe — the same Golden Record Identifier persisted inside a US Core Patient by an EHR. Carries USCDI must-supports (race, ethnicity, birth sex) alongside the shared Golden Identifier slice (design brief §2.3 realm adapter).