This
page
is
part
of
the
FHIR
Specification
(v3.0.2:
(v4.0.1:
R4
-
Mixed
Normative
and
STU
3).
)
in
it's
permanent
home
(it
will
always
be
available
at
this
URL).
The
current
version
which
supercedes
this
version
is
5.0.0
.
For
a
full
list
of
available
versions,
see
the
Directory
of
published
versions
.
Page
versions:
R4
R3
R4
R3
Vocabulary
Work
Group
|
Maturity
Level
:
|
|
Use Context : Any |
This
value
set
(http://hl7.org/fhir/ValueSet/v3-ConfidentialityClassification)
(http://terminology.hl7.org/ValueSet/v3-ConfidentialityClassification)
is
defined
as
part
of
HL7
v3.
Related
FHIR
content:
ConfidentialityClassification
.
Summary
| Defining URL: |
|
| Version: | 2014-03-26 |
| Name: |
|
| Title: | V3 Value SetConfidentialityClassification |
| Definition: |
Set
of
codes
used
to
value
Act.Confidentiality
and
Role.Confidentiality
attribute
in
accordance
with
the
definition
for
concept
domain
|
| OID: | 2.16.840.1.113883.1.11.10228 (for OID based terminology systems) |
| Source Resource | XML / JSON |
This value set is used in the following places:
This value set includes codes from the following code systems:
http://hl7.org/fhir/v3/Confidentiality
http://terminology.hl7.org/CodeSystem/v3-Confidentiality
| Code | Display | |
| U | unrestricted |
Definition:
Privacy
metadata
indicating
that
the
information
is
not
classified
as
sensitive.
Examples: Includes publicly available information, e.g., business name, phone, email or physical address. Usage Note: This metadata indicates that the receiver has no obligation to consider additional policies when making access control decisions. Note that in some jurisdictions, personally identifiable information must be protected as confidential, so it would not be appropriate to assign a confidentiality code of |
| L | low |
Definition:
Privacy
metadata
indicating
that
the
information
has
been
de-identified,
and
there
are
mitigating
circumstances
that
prevent
re-identification,
which
minimize
risk
of
harm
from
unauthorized
disclosure.
The
information
requires
protection
to
maintain
low
sensitivity.
Examples: Includes anonymized, pseudonymized, or non-personally identifiable information such as HIPAA limited data sets. Map: No clear map to ISO 13606-4 Sensitivity Level (1) Care Management: RECORD_COMPONENTs that might need to be accessed by a wide range of administrative staff to manage the subject of care's access to health services. Usage Note: This metadata indicates the receiver may have an obligation to comply with a data use agreement. |
| M | moderate |
Definition:
Privacy
metadata
indicating
moderately
sensitive
information,
which
presents
moderate
risk
of
harm
if
disclosed
without
authorization.
Examples: Includes allergies of non-sensitive nature used inform food service; health information a patient authorizes to be used for marketing, released to a bank for a health credit card or savings account; or information in personal health record systems that are not governed under health privacy laws. Map: Partial Map to ISO 13606-4 Sensitivity Level (2) Clinical Management: Less sensitive RECORD_COMPONENTs that might need to be accessed by a wider range of personnel not all of whom are actively caring for the patient (e.g. radiology staff). Usage Note: This metadata indicates that the receiver may be obligated to comply with the receiver's terms of use or privacy policies. |
| N | normal |
Definition:
Privacy
metadata
indicating
that
the
information
is
typical,
non-stigmatizing
health
information,
which
presents
typical
risk
of
harm
if
disclosed
without
authorization.
Examples: In the US, this includes what HIPAA identifies as the minimum necessary protected health information (PHI) given a covered purpose of use (treatment, payment, or operations). Includes typical, non-stigmatizing health information disclosed in an application for health, workers compensation, disability, or life insurance. Map: Partial Map to ISO 13606-4 Sensitivity Level (3) Clinical Care: Default for normal clinical care access (i.e. most clinical staff directly caring for the patient should be able to access nearly all of the EHR). Maps to normal confidentiality for treatment information but not to ancillary care, payment and operations. Usage Note: This metadata indicates that the receiver may be obligated to comply with applicable jurisdictional privacy law or disclosure authorization. |
| R | restricted |
Privacy
metadata
indicating
highly
sensitive,
potentially
stigmatizing
information,
which
presents
a
high
risk
to
the
information
subject
if
disclosed
without
authorization.
May
be
pre-empted
by
jurisdictional
law,
e.g.,
for
public
health
reporting
or
emergency
treatment.
Examples: Includes information that is additionally protected such as sensitive conditions mental health, HIV, substance abuse, domestic violence, child abuse, genetic disease, and reproductive health; or sensitive demographic information such as a patient's standing as an employee or a celebrity. May be used to indicate proprietary or classified information that is not related to an individual, e.g., secret ingredients in a therapeutic substance; or the name of a manufacturer. Map: Partial Map to ISO 13606-4 Sensitivity Level (3) Clinical Care: Default for normal clinical care access (i.e. most clinical staff directly caring for the patient should be able to access nearly all of the EHR). Maps to normal confidentiality for treatment information but not to ancillary care, payment and operations.. Usage Note: This metadata indicates that the receiver may be obligated to comply with applicable, prevailing (default) jurisdictional privacy law or disclosure authorization.. |
| V | very restricted | .
Privacy
metadata
indicating
that
the
information
is
extremely
sensitive
and
likely
stigmatizing
health
information
that
presents
a
very
high
risk
if
disclosed
without
authorization.
This
information
must
be
kept
in
the
highest
confidence.
Examples: Includes information about a victim of abuse, patient requested information sensitivity, and taboo subjects relating to health status that must be discussed with the patient by an attending provider before sharing with the patient. May also include information held under “legal lock� or attorney-client privilege Map: This metadata indicates that the receiver may not disclose this information except as directed by the information custodian, who may be the information subject. Usage Note: This metadata indicates that the receiver may not disclose this information except as directed by the information custodian, who may be the information subject. |