HL7 Electronic Health Record System Functional Model, Release 2.1.1
            
            2.1.1 - 
  
            
          
HL7 Electronic Health Record System Functional Model, Release 2.1.1, published by HL7 International / Electronic Health Records. This guide is not an authorized publication; it is the continuous build for version 2.1.1 built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/mvdzel/ehrsfm-fhir-r5/ and changes regularly. See the Directory of published versions
| Page standards status: Normative | 
<Requirements xmlns="http://hl7.org/fhir">
  <id value="EHRSFMR2-TI.2"/>
  <meta>
    <profile
             value="http://hl7.org/ehrs/uv/ehrsfmr2/StructureDefinition/FMFunction"/>
  </meta>
  <language value="en"/>
  <text>
    <status value="extensions"/>
    <div xml:lang="en" xmlns="http://www.w3.org/1999/xhtml" lang="en">
    <div id="description"><b>Statement <a href="https://hl7.org/fhir/versions.html#std-process" title="Normative Content" class="normative-flag">N</a>:</b> <div><p>Audit Key Record, Security, System and Clinical Events</p>
</div></div>
    
    <div id="purpose"><b>Description <a href="https://hl7.org/fhir/versions.html#std-process" title="Informative Content" class="informative-flag">I</a>:</b> <div><p>EHR Systems have built in audit triggers to capture key events in real-time, including events related to record management, security, system operations or performance or clinical situations.</p>
<p>Event details, including key metadata (who, what, when, where), are captured in an Audit Log.</p>
<p>Audit Review functions allow various methods of critical event notification as well as routine log review.</p>
<p>Audit functions implement requirements according to scope of practice, organizational policy, and jurisdictional law.</p>
</div></div>
    
    
    
    
    
    
    
    <div id="requirements"><b>Criteria <a href="https://hl7.org/fhir/versions.html#std-process" title="Normative Content" class="normative-flag">N</a>:</b></div>
    
    <table id="statements" class="grid dict">
        
        <tr>
            <td style="padding-left: 4px;">
                
                <div>TI.2#01</div>
                
            </td>
            <td style="padding-left: 4px;">
                
                <i>dependent</i>
                
                
                
                <div>SHALL</div>
                
            </td>
            <td style="padding-left: 4px;" class="requirement">
                
                <div><div><p>The system SHALL conform to function <a href="Requirements-EHRSFMR2-TI.1.3.html">TI.1.3</a> (Entity Access Control) to limit access to, or modification of, audit record information to appropriate entities according to scope of practice, organizational policy, and/or jurisdictional law.</p>
</div></div>
                
                
            </td>
        </tr>
        
        <tr>
            <td style="padding-left: 4px;">
                
                <div>TI.2#02</div>
                
            </td>
            <td style="padding-left: 4px;">
                
                <i>dependent</i>
                
                
                
                <div>SHALL</div>
                
            </td>
            <td style="padding-left: 4px;" class="requirement">
                
                <div><div><p>The system SHALL conform to function <a href="Requirements-EHRSFMR2-TI.1.3.html">TI.1.3</a> (Entity Access Control) to limit access to audit record information for purposes of deletion according to scope of practice, organizational policy, and/or jurisdictional law (e.g., limit access to only allow a specific system administrator to delete audit record information).</p>
</div></div>
                
                
            </td>
        </tr>
        
    </table>
</div>
  </text>
  <extension
             url="http://hl7.org/fhir/StructureDefinition/structuredefinition-standards-status">
    <valueCode value="normative"/>
  </extension>
  <extension
             url="http://hl7.org/fhir/StructureDefinition/structuredefinition-wg">
    <valueCode value="ehr"/>
  </extension>
  <url value="http://hl7.org/ehrs/uv/ehrsfmr2/Requirements/EHRSFMR2-TI.2"/>
  <version value="2.1.1"/>
  <name value="TI_2_Audit"/>
  <title value="TI.2 Audit (Function)"/>
  <status value="active"/>
  <date value="2025-10-31T19:25:08+00:00"/>
  <publisher value="HL7 International / Electronic Health Records"/>
  <contact>
    <telecom>
      <system value="url"/>
      <value value="http://www.hl7.org/Special/committees/ehr"/>
    </telecom>
  </contact>
  <description
               value="Audit Key Record, Security, System and Clinical Events"/>
  <jurisdiction>
    <coding>
      <system value="http://unstats.un.org/unsd/methods/m49/m49.htm"/>
      <code value="001"/>
      <display value="World"/>
    </coding>
  </jurisdiction>
  <purpose
           value="EHR Systems have built in audit triggers to capture key events in real-time, including events related to record management, security, system operations or performance or clinical situations.
Event details, including key metadata (who, what, when, where), are captured in an Audit Log.
Audit Review functions allow various methods of critical event notification as well as routine log review.
Audit functions implement requirements according to scope of practice, organizational policy, and jurisdictional law."/>
  <statement>
    <extension
               url="http://hl7.org/ehrs/uv/ehrsfmr2/StructureDefinition/requirements-dependent">
      <valueBoolean value="true"/>
    </extension>
    <key value="EHRSFMR2-TI.2-01"/>
    <label value="TI.2#01"/>
    <conformance value="SHALL"/>
    <conditionality value="false"/>
    <requirement
                 value="The system SHALL conform to function [TI.1.3](Requirements-EHRSFMR2-TI.1.3.html) (Entity Access Control) to limit access to, or modification of, audit record information to appropriate entities according to scope of practice, organizational policy, and/or jurisdictional law."/>
    <derivedFrom value="EHR-S_FM_R1.1 IN.2.2#13"/>
  </statement>
  <statement>
    <extension
               url="http://hl7.org/ehrs/uv/ehrsfmr2/StructureDefinition/requirements-dependent">
      <valueBoolean value="true"/>
    </extension>
    <key value="EHRSFMR2-TI.2-02"/>
    <label value="TI.2#02"/>
    <conformance value="SHALL"/>
    <conditionality value="false"/>
    <requirement
                 value="The system SHALL conform to function [TI.1.3](Requirements-EHRSFMR2-TI.1.3.html) (Entity Access Control) to limit access to audit record information for purposes of deletion according to scope of practice, organizational policy, and/or jurisdictional law (e.g., limit access to only allow a specific system administrator to delete audit record information)."/>
  </statement>
</Requirements>