This
page
is
part
of
the
FHIR
Specification
(v5.0.0:
R5
-
STU
v6.0.0-ballot1:
Release
6
Ballot
(1st
Draft)
(see
Ballot
Notes
).
This
is
the
The
current
published
version
in
it's
permanent
home
(it
will
always
be
available
at
this
URL).
is
5.0.0
.
For
a
full
list
of
available
versions,
see
the
Directory
of
published
versions
Security
Work
Group
|
Maturity Level : 1 | Draft | Use Context : Country: World, Not Intended for Production use |
Official
URL
:
http://hl7.org/fhir/ValueSet/security-label-examples
|
Version
:
|
|||
| draft as of 2022-05-10 | Computable Name : SecurityLabelExamples | |||
| Flags : Experimental | OID : 2.16.840.1.113883.4.642.3.3011 | |||
This value set is used in the following places:
A sample of security labels from Healthcare Privacy and Security Classification System as the combination of data and event codes.
This value set includes codes based on the following rules:
This
expansion
generated
26
Mar
18
Dec
2023
Expansion based on:



This value set contains 11 concepts
| Code | System | Display | Definition |
N
|
http://terminology.hl7.org/CodeSystem/v3-Confidentiality | normal |
Privacy metadata indicating the level of protection required to safeguard personal and healthcare information, which if disclosed without authorization, would present a considerable risk of harm to an individual's reputation and sense of privacy. Usage Note: The level of protection afforded normatively confidential information is dictated by the prevailing normative privacy policies, which are intended to engender patient trust in their healthcare providers. Privacy policies mandating normative levels of protection, which preempt less protective privacy policies when the information is used in the delivery and management of healthcare. May be pre-empted by jurisdictional law (e.g., for public health reporting or emergency treatment). Confidentiality code total order hierarchy: Normal (N) is less protective than V and R , and subsumes all other protection levels (i.e., M, L, and U ). **Map:**Partial Map to ISO 13606-4 Sensitivity Level (3) Clinical Care when purpose of use is treatment: Default for normal clinical care access (i.e., most clinical staff directly caring for the patient should be able to access nearly all of the EHR). Maps to normal confidentiality for treatment information but not to ancillary care, payment and operations. Examples: n the US, this includes what HIPAA identifies as protected health information (PHI) under 45 CFR Section 160.103. |
R
|
http://terminology.hl7.org/CodeSystem/v3-Confidentiality | restricted |
Privacy metadata indicating the level of protection required to safeguard potentially stigmatizing information, which if disclosed without authorization, would present a high risk of harm to an individual's reputation and sense of privacy.
Usage
Note:
The
level
of
protection
afforded
restricted
confidential
information
is
dictated
by
specially
protective
organizational
or
jurisdictional
privacy
policies,
including
at
an
authorized
Privacy policies mandating additional levels of protection by restricting information access preempt less protective privacy policies when the information is used in the delivery and management of healthcare. May be pre-empted by jurisdictional law (e.g., for public health reporting or emergency treatment). Confidentiality code total order hierarchy: Restricted (R) is less protective than V , and subsumes all other protection levels (i.e., N, M, L, and U ). Examples:
Includes
information
that
is
additionally
protected
such
as
sensitive
conditions
mental
health,
HIV,
substance
abuse,
domestic
violence,
child
abuse,
genetic
disease,
and
reproductive
health;
or
sensitive
demographic
information
such
as
a
|
ETH
|
http://terminology.hl7.org/CodeSystem/v3-ActCode | substance abuse information sensitivity |
Policy for handling alcohol or drug-abuse information, which will be afforded heightened confidentiality. Information handling protocols based on organizational policies related to alcohol or drug-abuse information that is deemed sensitive. Usage Note: If there is a jurisdictional mandate, then use the applicable ActPrivacyLaw code system, and specify the law rather than or in addition to this more generic code. |
PSY
|
http://terminology.hl7.org/CodeSystem/v3-ActCode | psychiatry disorder information sensitivity |
Policy for handling psychiatry psychiatric disorder information, which is afforded heightened confidentiality. Usage Note: If there is a jurisdictional mandate, then use the applicable ActPrivacyLaw code system, and specify the law rather than or in addition to this more generic code. |
STD
|
http://terminology.hl7.org/CodeSystem/v3-ActCode | sexually transmitted disease information sensitivity |
Policy for handling sexually transmitted disease information, which will be afforded heightened confidentiality. Information handling protocols based on organizational policies related to sexually transmitted disease information that is deemed sensitive. Usage Note: If there is a jurisdictional mandate, then use the applicable ActPrivacyLaw code system, and specify the law rather than or in addition to this more generic code. |
TREAT
|
http://terminology.hl7.org/CodeSystem/v3-ActReason | treatment |
To perform one or more operations on information for provision of health care. |
HPAYMT
|
http://terminology.hl7.org/CodeSystem/v3-ActReason | healthcare payment |
To perform one or more operations on information for conducting financial or contractual activities related to payment for provision of health care. |
ETREAT
|
http://terminology.hl7.org/CodeSystem/v3-ActReason | Emergency Treatment |
To perform one or more operations on information for provision of immediately needed health care for an emergent condition. |
NOAUTH
|
http://terminology.hl7.org/CodeSystem/v3-ActCode | no disclosure without subject authorization |
Prohibition on disclosure without information subject's authorization. |
DELAU
|
http://terminology.hl7.org/CodeSystem/v3-ActCode | delete after use |
Custodian system must remove target information from access after use. |
NORDSCLCD
|
http://terminology.hl7.org/CodeSystem/v3-ActCode | no redisclosure without consent directive |
Prohibition on redisclosure without patient consent directive. |
Additional Designations and Language Displays
| Code | http://terminology.hl7.org/CodeSystem/designation-usage#display | English (English, en) |
| N | ||
| R | ||
| ETH | ||
| PSY | ||
| STD | ||
| TREAT | treatment | treatment |
| HPAYMT | healthcare payment | healthcare payment |
| ETREAT | Emergency Treatment | Emergency Treatment |
| NOAUTH | ||
| DELAU | ||
| NORDSCLCD |
See the full registry of value sets defined as part of FHIR.
Explanation of the columns that may appear on this page:
| Lvl | A few code lists that FHIR defines are hierarchical - each code is assigned a level. For value sets, levels are mostly used to organize codes for user convenience, but may follow code system hierarchy - see Code System for further information |
| Source | The source of the definition of the code (when the value set draws in codes defined elsewhere) |
| Code | The code (used as the code in the resource instance). If the code is in italics, this indicates that the code is not selectable ('Abstract') |
| Display | The display (used in the display element of a Coding ). If there is no display, implementers should not simply display the code, but map the concept into their application |
| Definition | An explanation of the meaning of the concept |
| Comments | Additional notes about how to use the code |