Security
and
Privacy
This
page
is
part
of
the
Continuous
Integration
Build
of
FHIR
Specification
(v4.0.1:
R4
-
Mixed
Normative
and
STU
)
in
it's
permanent
home
(it
will
always
(will
be
available
incorrect/inconsistent
at
this
URL).
The
current
version
which
supercedes
this
version
is
5.0.0
.
For
a
full
list
of
available
versions,
see
times).
See
the
Directory
of
published
versions
.
Page
versions:
R5
R4B
R4
R3
R2
| Responsible Owner: Security Work Group | Standards Status : Informative | Compartments : Device , Group , Patient , Practitioner |
Raw JSON ( canonical form + also see JSON Format Specification )
Accounting of a Disclosure
{
"resourceType": "AuditEvent",
"id": "example-disclosure",
"text": {
"status": "generated",
"div": "<div xmlns=\"http://www.w3.org/1999/xhtml\">Disclosure by some idiot, for marketing reasons, to places unknown, of a Poor Sap, data about Everthing important.</div>"
"resourceType" : "AuditEvent",
"id" : "example-disclosure",
"type" : {
"coding" : [{
"system" : "http://dicom.nema.org/resources/ontology/DCM",
"code" : "110106",
"display" : "Export"
}]
},
"type": {
"system": "http://dicom.nema.org/resources/ontology/DCM",
"code": "110106",
"display": "Export"
"subtype" : [{
"coding" : [{
"code" : "Disclosure",
"display" : "HIPAA disclosure"
}]
}],
"action" : "R",
"severity" : "notice",
"recorded" : "2013-09-22T00:08:00Z",
"outcome" : {
"code" : {
"system" : "http://terminology.hl7.org/CodeSystem/audit-event-outcome",
"code" : "0",
"display" : "Success"
},
"detail" : [{
"text" : "Successful Disclosure"
}]
},
"subtype": [
{
"code": "Disclosure",
"display": "HIPAA disclosure"
}
],
"action": "R",
"recorded": "2013-09-22T00:08:00Z",
"outcome": "0",
"outcomeDesc": "Successful Disclosure",
"purposeOfEvent": [
{
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"code": "HMARKT",
"display": "healthcare marketing"
}
]
}
],
"agent": [
{
"type": {
"coding": [
{
"system": "http://dicom.nema.org/resources/ontology/DCM",
"code": "110153",
"display": "Source Role ID"
}
]
},
"who": {
"identifier": {
"value": "SomeIdiot@nowhere"
}
},
"altId": "notMe",
"name": "That guy everyone wishes would be caught",
"requestor": true,
"location": {
"reference": "Location/1"
},
"policy": [
"http://consent.com/yes"
],
"network": {
"address": "custodian.net",
"type": "1"
}
"authorization" : [{
"coding" : [{
"system" : "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"code" : "HMARKT",
"display" : "healthcare marketing"
}]
}],
"patient" : {
"reference" : "Patient/example"
},
"agent" : [{
"type" : {
"coding" : [{
"system" : "http://dicom.nema.org/resources/ontology/DCM",
"code" : "110153",
"display" : "Source Role ID"
}]
},
{
"type": {
"coding": [
{
"system": "http://dicom.nema.org/resources/ontology/DCM",
"code": "110152",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Practitioner/example",
"display": "Where"
},
"requestor": false,
"network": {
"address": "marketing.land",
"type": "1"
"who" : {
"identifier" : {
"value" : "SomeIdiot@nowhere"
},
"purposeOfUse": [
{
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"code": "HMARKT",
"display": "healthcare marketing"
}
]
}
]
}
],
"source": {
"site": "Watcher",
"observer": {
"display": "Watchers Accounting of Disclosures Application"
"display" : "That guy everyone wishes would be caught"
},
"type": [
{
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"code": "4",
"display": "Application Server"
}
]
"requestor" : true,
"location" : {
"reference" : "Location/1"
},
"policy" : ["http://consent.com/yes"],
"networkString" : "custodian.net"
},
"entity": [
{
"what": {
"reference": "Patient/example"
},
"type": {
"system": "http://terminology.hl7.org/CodeSystem/audit-entity-type",
"code": "1",
"display": "Person"
{
"type" : {
"coding" : [{
"system" : "http://dicom.nema.org/resources/ontology/DCM",
"code" : "110152",
"display" : "Destination Role ID"
}]
},
"who" : {
"reference" : "Practitioner/example",
"display" : "Where"
},
"requestor" : false,
"networkString" : "marketing.land",
"authorization" : [{
"coding" : [{
"system" : "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"code" : "HMARKT",
"display" : "healthcare marketing"
}]
}]
}],
"source" : {
"observer" : {
"display" : "Watchers Accounting of Disclosures Application"
},
"type" : [{
"coding" : [{
"system" : "http://terminology.hl7.org/CodeSystem/security-source-type",
"code" : "4",
"display" : "Application Server"
}]
}]
},
"entity" : [{
"what" : {
"reference" : "Patient/example/_history/1",
"identifier" : {
"value" : "What.id"
},
"role": {
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"code": "1",
"display": "Patient"
}
"display" : "data about Everthing important"
},
"role" : {
"coding" : [{
"system" : "http://terminology.hl7.org/CodeSystem/object-role",
"code" : "4",
"display" : "Domain Resource"
}]
},
"securityLabel" : [{
"coding" : [{
"system" : "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"code" : "V",
"display" : "very restricted"
}]
},
{
"what": {
"reference": "Patient/example/_history/1",
"identifier": {
"value": "What.id"
}
},
"type": {
"system": "http://terminology.hl7.org/CodeSystem/audit-entity-type",
"code": "2",
"display": "System Object"
},
"role": {
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"code": "4",
"display": "Domain Resource"
},
"lifecycle": {
"system": "http://terminology.hl7.org/CodeSystem/dicom-audit-lifecycle",
"code": "11",
"display": "Disclosure"
},
"securityLabel": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"code": "V",
"display": "very restricted"
},
{
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"code": "STD",
"display": "sexually transmitted disease information sensitivity"
},
{
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"code": "DELAU",
"display": "delete after use"
}
],
"name": "Namne of What",
"description": "data about Everthing important"
}
]
"coding" : [{
"system" : "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"code" : "STD",
"display" : "sexually transmitted disease information sensitivity"
}]
},
{
"coding" : [{
"system" : "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"code" : "DELAU",
"display" : "delete after use"
}]
}]
}]
}
Usage note: every effort has been made to ensure that the examples are correct and useful, but they are not a normative part of the specification.
FHIR
®©
HL7.org
2011+.
FHIR
Release
4
(Technical
Correction
#1)
(v4.0.1)
R6
hl7.fhir.core#6.0.0-ballot3
generated
on
Fri,
Nov
1,
2019
09:34+1100.
QA
Page
7,
2025
23:59+0000.
Links:
Search
|
Version
History
|
Table
of
Contents
|
Credits
Glossary
|
QA
|
Compare
to
R3
R4
|
Compare
to
R5
|
Compare
to
Last
Ballot
|
|
Propose
a
change