Skip to content

Privacy Directive Profile

Canonical../StructureDefinition/nexus-privacy-directive
Statusdraft (experimental) · 1.26.0
BaseConsent (constraint)
SourceFSH · JSON

A patient's standing restriction on the collection, use or disclosure of their own personal health information -- the instruction PHIPA calls a lockbox.

Elements / Details

Every element this profile touches, with its full definition. Element names in the tables link here.

Consent.id

Short Logical id of this artifact
Definition The logical id of the resource, as used in the URL for the resource. Once assigned, this value never changes.
Comments The only time that a resource does not have an id is when it is being submitted to the server using a create operation.
Cardinality 0..1
Type http://hl7.org/fhirpath/System.String

Consent.meta

Short Metadata about the resource
Definition The metadata about the resource. This is content that is maintained by the infrastructure. Changes to the content might not always be associated with version changes to the resource.
Cardinality 0..1
Type Meta
Invariants ele-1

Consent.meta.id

Short Unique id for inter-element referencing
Definition Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.
Cardinality 0..1
Type http://hl7.org/fhirpath/System.String

Consent.meta.extension

Short Additional content defined by implementations
Definition May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Invariants ele-1, ext-1
Also called extensions, user content

Consent.meta.versionId

Short Version specific identifier
Definition The version specific identifier, as it appears in the version portion of the URL. This value changes when the resource is created, updated, or deleted.
Comments The server assigns this value, and ignores what the client specifies, except in the case that the server is imposing version integrity on updates/deletes.
Cardinality 0..1
Type id
Invariants ele-1

Consent.meta.lastUpdated

Short When the resource version last changed
Definition When the resource last changed - e.g. when the version changed.
Comments This value is always populated except when the resource is first being created. The server / resource manager sets this value; what a client provides is irrelevant. This is equivalent to the HTTP Last-Modified and SHOULD have the same value on a read interaction.
Cardinality 0..1
Type instant
Invariants ele-1

Consent.meta.source

Short Identifies EMR instance & pipeline version the resource came from
Definition A URI that identifies the EMR pipeline and version from which this resource originated. This tells you which EMR instance (recommend using the instance identifier), and the version of the pipeline code/transformations.
Comments In the provenance resource, this corresponds to Provenance.entity.what[x]. The exact use of the source (and the implied Provenance.entity.role) is left to implementer discretion. Only one nominated source is allowed; for additional provenance details, a full Provenance resource should be used. This element can be used to indicate where the current master source of a resource that has a canonical URL if the resource is no longer hosted at the canonical URL.
Cardinality 0..1
Type uri
Must Support yes
Invariants ele-1

Consent.meta.profile

Short Profiles this resource claims to conform to
Definition A list of profiles (references to StructureDefinition resources) that this resource claims to conform to. The URL is a reference to StructureDefinition.url.
Comments It is up to the server and/or other infrastructure of policy to determine whether/how these claims are verified and/or updated over time. The list of profile URLs is a set.
Cardinality 0..*
Type canonical
Invariants ele-1

Consent.meta.security

Short Security Labels applied to this resource
Definition Security labels applied to this resource. These tags connect specific resources to the overall security policy and infrastructure.
Comments The security labels can be updated without changing the stated version of the resource. The list of security labels is a set. Uniqueness is based the system/code, and version and display are ignored.
Cardinality 0..*
Type Coding
Binding security-labels (extensible)
Invariants ele-1

Consent.meta.tag

Short Tags applied to this resource
Definition Tags applied to this resource. Tags are intended to be used to identify and relate resources to process and workflow, and applications are not required to consider the tags when interpreting the meaning of a resource.
Comments The tags can be updated without changing the stated version of the resource. The list of tags is a set. Uniqueness is based the system/code, and version and display are ignored.
Cardinality 0..*
Type Coding
Binding common-tags (example)
Invariants ele-1

Consent.implicitRules

Short A set of rules under which this content was created
Definition A reference to a set of rules that were followed when the resource was constructed, and which must be understood when processing the content. Often, this is a reference to an implementation guide that defines the special rules along with other profiles etc.
Comments Asserting this rule set restricts the content to be only understood by a limited set of trading partners. This inherently limits the usefulness of the data in the long term. However, the existing health eco-system is highly fractured, and not yet ready to define, collect, and exchange data in a generally computable sense. Wherever possible, implementers and/or specification writers should avoid using this element. Often, when used, the URL is a reference to an implementation guide that defines these special rules as part of it's narrative along with other profiles, value sets, etc.
Cardinality 0..1
Type uri
Modifier yes — This element is labeled as a modifier because the implicit rules may provide additional knowledge about the resource that modifies it's meaning or interpretation
Invariants ele-1

Consent.language

Short Language of the resource content
Definition The base language in which the resource is written.
Comments Language is provided to support indexing and accessibility (typically, services such as text to speech use the language tag). The html language tag in the narrative applies to the narrative. The language tag on the resource may be used to specify the language of other presentations generated from the data in the resource. Not all the content has to be in the base language. The Resource.language should not be assumed to apply to the narrative automatically. If a language is specified, it should it also be specified on the div element in the html (see rules in HTML5 for information about the relationship between xml:lang and the html lang attribute).
Cardinality 0..1
Type code
Binding languages (preferred)
Invariants ele-1

Consent.text

Short Text summary of the resource, for human interpretation
Definition A human-readable narrative that contains a summary of the resource and can be used to represent the content of the resource to a human. The narrative need not encode all the structured data, but is required to contain sufficient detail to make it "clinically safe" for a human to just read the narrative. Resource definitions may define what content should be represented in the narrative to ensure clinical safety.
Comments Contained resources do not have narrative. Resources that are not contained SHOULD have a narrative. In some cases, a resource may only have text with little or no additional discrete data (as long as all minOccurs=1 elements are satisfied). This may be necessary for data from legacy systems where information is captured as a "text blob" or where text is additionally entered raw or narrated and encoded information is added later.
Cardinality 0..1
Type Narrative
Invariants ele-1
Also called narrative, html, xhtml, display

Consent.contained

Short Contained, inline Resources
Definition These resources do not have an independent existence apart from the resource that contains them - they cannot be identified independently, and nor can they have their own independent transaction scope.
Comments This should never be done when the content can be identified properly, as once identification is lost, it is extremely difficult (and context dependent) to restore it again. Contained resources may have profiles and tags In their meta elements, but SHALL NOT have security labels.
Cardinality 0..*
Type Resource
Also called inline resources, anonymous resources, contained resources

Consent.extension

Short Additional content defined by implementations
Definition May be used to represent additional information that is not part of the basic definition of the resource. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Invariants ele-1, ext-1
Also called extensions, user content

Consent.modifierExtension

Short Extensions that cannot be ignored
Definition May be used to represent additional information that is not part of the basic definition of the resource and that modifies the understanding of the element that contains it and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer is allowed to define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions. Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).
Requirements Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Modifier yes — Modifier extensions are expected to modify the meaning or interpretation of the resource that contains them
Invariants ele-1, ext-1
Also called extensions, user content

Consent.identifier

Short Business identifier(s) for the directive
Definition Stable identifier for the instruction, carried so that a directive can be correlated with the paper or portal request that created it, with a superseding directive, and with an audit entry that names the directive a decision relied on. Deliberately NOT a deterministic key derived from patient and type. Item consent uses such a key because exactly one resource exists per pair and a writer needs to create-or-update in one call. A directive is the opposite case: several may be active for one patient at once, and a conditional update keyed on the patient would overwrite an unrelated restriction.
Comments This identifier identifies this copy of the consent. Where this identifier is also used elsewhere as the identifier for a consent record (e.g. a CDA consent document) then the consent details are expected to be the same.
Cardinality 0..*
Type Identifier
Must Support yes
Invariants ele-1

Consent.identifier.id

Short Unique id for inter-element referencing
Definition Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.
Cardinality 0..1
Type http://hl7.org/fhirpath/System.String

Consent.identifier.extension

Short Additional content defined by implementations
Definition May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Invariants ele-1, ext-1
Also called extensions, user content

Consent.identifier.use

Short usual | official | temp | secondary | old (If known)
Definition The purpose of this identifier.
Requirements Allows the appropriate identifier for a particular context of use to be selected from among a set of identifiers.
Comments Applications can assume that an identifier is permanent unless it explicitly says that it is temporary.
Cardinality 0..1
Type code
Modifier yes — This is labeled as "Is Modifier" because applications should not mistake a temporary id for a permanent one.
Binding identifier-use (required)
Invariants ele-1

Consent.identifier.type

Short Description of identifier
Definition A coded type for the identifier that can be used to determine which identifier to use for a specific purpose.
Requirements Allows users to make use of identifiers when the identifier system is not known.
Comments This element deals only with general categories of identifiers. It SHOULD not be used for codes that correspond 1..1 with the Identifier.system. Some identifiers may fall into multiple categories due to common usage. Where the system is known, a type is unnecessary because the type is always part of the system definition. However systems often need to handle identifiers where the system is not known. There is not a 1:1 relationship between type and system, since many different systems have the same type.
Cardinality 0..1
Type CodeableConcept
Binding identifier-type (extensible)
Invariants ele-1

Consent.identifier.system

Short The namespace for the identifier value
Definition Establishes the namespace for the value - that is, a URL that describes a set values that are unique.
Requirements There are many sets of identifiers. To perform matching of two identifiers, we need to know what set we're dealing with. The system identifies a particular set of unique identifiers.
Comments Identifier.system is always case sensitive.
Cardinality 1..1
Type uri
Invariants ele-1

Consent.identifier.value

Short The value that is unique
Definition The portion of the identifier typically relevant to the user and which is unique within the context of the system.
Comments If the value is a full URI, then the system SHALL be urn:ietf:rfc:3986. The value's primary purpose is computational mapping. As a result, it may be normalized for comparison purposes (e.g. removing non-significant whitespace, dashes, etc.) A value formatted for human display can be conveyed using the Rendered Value extension. Identifier.value is to be treated as case sensitive unless knowledge of the Identifier.system allows the processer to be confident that non-case-sensitive processing is safe.
Cardinality 1..1
Type string
Invariants ele-1

Consent.identifier.period

Short Time period when id is/was valid for use
Definition Time period during which identifier is/was valid for use.
Cardinality 0..1
Type Period
Invariants ele-1

Consent.identifier.assigner

Short Organization that issued id (may be just text)
Definition Organization that issued/manages the identifier.
Comments The Identifier.assigner may omit the .reference element and only contain a .display element reflecting the name or other textual information about the assigning organization.
Cardinality 0..1
Type Reference(Organization)
Invariants ele-1

Consent.status

Short active (in force) | inactive (superseded or withdrawn) | entered-in-error
Definition Whether this directive is currently operative. It is not the decision. The decision -- what is restricted, from whom -- is in the provision tree. - activein force. The restriction stated in the provisions applies now, subject to provision.period where one is given. - inactiveno longer operative. R4 defines this as terminated or replaced, which is exactly right here: the patient withdrew the restriction, or a superseding directive replaced it. Both are recoverable from identifier and version history. - entered-in-error — recorded wrongly. Ignore it; it was never an instruction. draft and proposed are legal against the required base binding and carry no meaning in this profile. rejected is legal too and MUST NOT be written here: on the item-consent profile it means the patient declined, and a reader who has seen that family will carry the wrong reading across. Why inactive here and rejected there. The two profiles take opposite readings of the same vocabulary, deliberately. Item consent keeps one resource per item and updates it in place, so it needs one current-state code meaning "not permitted" whether the patient declined or withdrew; rejected carries that. A directive is superseded rather than updated, so a withdrawn restriction is a terminated one, which is what inactive means. Neither profile is reading the vocabulary loosely; they are modelling different lifecycles and the codes follow.
Requirements The Consent Directive that is pointed to might be in various lifecycle states, e.g., a revoked Consent Directive.
Comments This element is labeled as a modifier because the status contains the codes rejected and entered-in-error that mark the Consent as not currently valid.
Cardinality 1..1
Type code
Must Support yes
Modifier yes — This element is labelled as a modifier because it is a status element that contains status entered-in-error which means that the resource should not be treated as valid
Binding consent-state-codes (required)
Invariants ele-1

Consent.scope

Short patient-privacy - Privacy consent
Definition Fixed to patient-privacy. Required by R4 and correct here, but it is NOT a discriminator: app consent and item consent fix the same value, so a consumer separating families on scope will separate nothing. Use the category family slice.
Cardinality 1..1
Type CodeableConcept
Must Support yes
Modifier yes — Allows changes to codes based on scope selection
Binding consent-scope (required)
Fixed value {"coding":[{"system":"http://terminology.hl7.org/CodeSystem/consentscope","code":"patient-privacy","display":"Privacy C…
Invariants ele-1

Consent.category

Short MUST carry the privacy-directive family code; this is how a reader knows what status means
Definition Required. Carries the family code that tells a consumer which interpretation contract applies before it reads any other element. Slicing is open, so a deployment may carry additional classifications alongside — a jurisdictional code, a workflow bin — but only the family slice identifies the family, and a consumer MUST NOT infer the family from any other category, from scope, or from the shape of the provision tree.
Comments The family coding sits outside HL7's consent-category value set on purpose, for the same reason the item-consent catalogue does: that value set classifies consent DOCUMENTS (advance directive, notice of privacy practices, research information access) and holds no concept for "which interpretation contract governs this resource", which is what this element answers. Terminology-aware validators may note that the base extensible binding is unmet. That note is expected.
Cardinality 1..*
Type CodeableConcept
Must Support yes
Binding consent-category (extensible)
Invariants ele-1

Consent.category:family

Short Fixed: this Consent is a privacy directive
Definition Required. Carries the family code that tells a consumer which interpretation contract applies before it reads any other element. Slicing is open, so a deployment may carry additional classifications alongside — a jurisdictional code, a workflow bin — but only the family slice identifies the family, and a consumer MUST NOT infer the family from any other category, from scope, or from the shape of the provision tree.
Comments The family coding sits outside HL7's consent-category value set on purpose, for the same reason the item-consent catalogue does: that value set classifies consent DOCUMENTS (advance directive, notice of privacy practices, research information access) and holds no concept for "which interpretation contract governs this resource", which is what this element answers. Terminology-aware validators may note that the base extensible binding is unmet. That note is expected.
Cardinality 1..1
Type CodeableConcept
Must Support yes
Binding Consent Families Value Set (required)
Invariants ele-1

Consent.category:family.id

Short Unique id for inter-element referencing
Definition Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.
Cardinality 0..1
Type http://hl7.org/fhirpath/System.String

Consent.category:family.extension

Short Additional content defined by implementations
Definition May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Invariants ele-1, ext-1
Also called extensions, user content

Consent.category:family.coding

Short Code defined by a terminology system
Definition A reference to a code defined by a terminology system.
Requirements Allows for alternative encodings within a code system, and translations to other code systems.
Comments Codes may be defined very casually in enumerations, or code lists, up to very formal definitions such as SNOMED CT - see the HL7 v3 Core Principles for more information. Ordering of codings is undefined and SHALL NOT be used to infer meaning. Generally, at most only one of the coding values will be labeled as UserSelected = true.
Cardinality 1..1
Type Coding
Invariants ele-1

Consent.category:family.coding.id

Short Unique id for inter-element referencing
Definition Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.
Cardinality 0..1
Type http://hl7.org/fhirpath/System.String

Consent.category:family.coding.extension

Short Additional content defined by implementations
Definition May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Invariants ele-1, ext-1
Also called extensions, user content

Consent.category:family.coding.system

Short Identity of the terminology system
Definition The identification of the code system that defines the meaning of the symbol in the code.
Requirements Need to be unambiguous about the source of the definition of the symbol.
Comments The URI may be an OID (urn:oid:...) or a UUID (urn:uuid:...). OIDs and UUIDs SHALL be references to the HL7 OID registry. Otherwise, the URI should come from HL7's list of FHIR defined special URIs or it should reference to some definition that establishes the system clearly and unambiguously.
Cardinality 1..1
Type uri
Fixed value ../CodeSystem/nexus-consent-family
Invariants ele-1

Consent.category:family.coding.version

Short Version of the system - if relevant
Definition The version of the code system which was used when choosing this code. Note that a well-maintained code system does not need the version reported, because the meaning of codes is consistent across versions. However this cannot consistently be assured, and when the meaning is not guaranteed to be consistent, the version SHOULD be exchanged.
Comments Where the terminology does not clearly define what string should be used to identify code system versions, the recommendation is to use the date (expressed in FHIR date format) on which that version was officially published as the version date.
Cardinality 0..1
Type string
Invariants ele-1

Consent.category:family.coding.code

Short Symbol in syntax defined by the system
Definition A symbol in syntax defined by the system. The symbol may be a predefined code or an expression in a syntax defined by the coding system (e.g. post-coordination).
Requirements Need to refer to a particular code in the system.
Cardinality 1..1
Type code
Fixed value privacy-directive
Invariants ele-1

Consent.category:family.coding.display

Short Representation defined by the system
Definition A representation of the meaning of the code in the system, following the rules of the system.
Requirements Need to be able to carry a human-readable meaning of the code for readers that do not know the system.
Cardinality 0..1
Type string
Invariants ele-1

Consent.category:family.coding.userSelected

Short If this coding was chosen directly by the user
Definition Indicates that this coding was chosen by a user directly - e.g. off a pick list of available items (codes or displays).
Requirements This has been identified as a clinical safety criterium - that this exact system/code pair was chosen explicitly, rather than inferred by the system based on some rules or language processing.
Comments Amongst a set of alternatives, a directly chosen code is the most appropriate starting point for new translations. There is some ambiguity about what exactly 'directly chosen' implies, and trading partner agreement may be needed to clarify the use of this element and its consequences more completely.
Cardinality 0..1
Type boolean
Invariants ele-1

Consent.category:family.text

Short Plain text representation of the concept
Definition A human language representation of the concept as seen/selected/uttered by the user who entered the data and/or which represents the intended meaning of the user.
Requirements The codes from the terminologies do not always capture the correct meaning with all the nuances of the human using them, or sometimes there is no appropriate code at all. In these cases, the text is used to capture the full meaning of the source.
Comments Very often the text is the same as a displayName of one of the codings.
Cardinality 0..1
Type string
Invariants ele-1

Consent.patient

Short The patient whose record is restricted
Definition The patient/healthcare consumer to whom this consent applies.
Comments Required by this profile rather than inherited. R4's ppc-2 invariant is meant to require a patient whenever scope is privacy, but its published expression tests system='something' and therefore never fires. Do not rely on it.
Cardinality 1..1
Type Reference(Patient Profile)
Must Support yes
Invariants ele-1

Consent.dateTime

Short When the instruction was given
Definition When the patient gave this instruction — not when the resource was stored, and not when the restriction takes effect. Effect is provision.period.start, which may be later. Three different times matter to an auditor reconstructing a decision and they must not be conflated: when the patient said it (here), when it started applying (provision.period.start), and when the server learned about it (meta.lastUpdated). A directive given on Monday, effective Wednesday, entered Friday is an ordinary and lawful record.
Comments This is not the time of the original consent, but the time that this statement was made or derived.
Cardinality 1..1
Type dateTime
Must Support yes
Invariants ele-1

Consent.performer

Short Who gave the instruction -- the patient, or a substitute decision-maker
Definition Who made this decision. The patient, or the RelatedPerson authorized to decide on their behalf. A substitute decision-maker is a RelatedPerson, never the Patient. The tender requires access and correction rights to be exercisable by an individual "and their Substitute Decision Makers", and recording an SDM's instruction as though the patient gave it destroys the fact that authority was delegated — which is the fact a privacy office checks when the instruction is challenged. Practitioner and PractitionerRole are permitted for the staff member who RECORDED the instruction. Both may appear together, and where they do the reading is that the patient decided and the staff member wrote it down. A resource naming ONLY staff is not malformed. A restriction is applied by an administrator acting on what the patient asked for, and a deployment that captures the administrator without separately identifying the patient as decision-maker is recording what it actually knows. What it costs is the ability to show, later, that the instruction came from the individual rather than from the clinic -- which is worth capturing where the workflow can.
Comments Commonly, the patient the consent pertains to is the consentor, but particularly for young and old people, it may be some other person - e.g. a legal guardian.
Cardinality 0..*
Type Reference(Patient Profile | RelatedPerson Profile | Practitioner Profile | PractitionerRole Profile)
Must Support yes
Invariants ele-1
Also called consentor

Consent.organization

Short The custodian whose records this directive restricts
Definition The health information custodian this instruction is addressed to. Load-bearing where it is present, because a restriction on one custodian's records says nothing about another's. A patient who locks their record at this clinic has not thereby locked the provincial EHR, and a patient who restricts the provincial EHR has not restricted this clinic. A directive that names no organization is scoped by the deployment's own policy, which must state what that scope is rather than leaving a reader to assume it means "everywhere".
Cardinality 0..*
Type Reference(Organization Profile)
Must Support yes
Invariants ele-1
Also called custodian

Consent.source[x]

Short Source from which this consent is taken
Definition The source on which this consent statement is based. The source might be a scanned original paper form, or a reference to a consent that links back to such a source, a reference to a document repository (e.g. XDS) that stores the original consent document.
Comments The source can be contained inline (Attachment), referenced directly (Consent), referenced in a consent repository (DocumentReference), or simply by an identifier (Identifier), e.g. a CDA document id.
Cardinality 0..1
Type Reference(DocumentReference Profile)
Invariants ele-1

Consent.source[x]:sourceReference

Short The signed instruction, where one was captured
Definition The document the patient signed, or the portal submission that recorded the instruction. Routed through DocumentReference rather than carried inline so that DocumentReference read permission gates the document itself: a reader entitled to know THAT a restriction exists is not automatically entitled to read the patient's written explanation of why.
Comments The source can be contained inline (Attachment), referenced directly (Consent), referenced in a consent repository (DocumentReference), or simply by an identifier (Identifier), e.g. a CDA document id.
Cardinality 0..1
Type Reference(DocumentReference Profile)
Must Support yes
Invariants ele-1

Consent.policy

Short The policy or statutory provision this directive is made under
Definition A URI identifying the policy under which this instruction is given and must be honoured — a PHIPA provision, an Ontario Health EHR policy, or the custodian's own published privacy policy. Required here, and it is what satisfies R4's ppc-1 invariant ("Either a Policy or PolicyRule"). policyRule is deliberately NOT used on this profile. Its binding is to consentpolicycodes, a code system that contains no Canadian policy concept at all — its 27 codes are US federal and state instruments plus Netherlands, Austria and Switzerland. There is no code in it that means "a restriction under PHIPA", and the nearest-looking one, cric, is 45 CFR 46: the US Common Rule for human-subjects research. A privacy directive is not research consent, and a policy element that pointed at one would be a false statement about the legal basis of the restriction, made in the resource an auditor reads to check exactly that. Carrying the actual policy URI says the true thing and stays machine-readable. Where a Canadian policy code system emerges, policyRule becomes available without this element changing.
Cardinality 1..*
Type BackboneElement
Must Support yes
Invariants ele-1

Consent.policy.id

Short Unique id for inter-element referencing
Definition Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.
Cardinality 0..1
Type http://hl7.org/fhirpath/System.String

Consent.policy.extension

Short Additional content defined by implementations
Definition May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Invariants ele-1, ext-1
Also called extensions, user content

Consent.policy.modifierExtension

Short Extensions that cannot be ignored even if unrecognized
Definition May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions. Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).
Requirements Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Modifier yes — Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
Invariants ele-1, ext-1
Also called extensions, user content, modifiers

Consent.policy.authority

Short Enforcement source for policy
Definition Entity or Organization having regulatory jurisdiction or accountability for enforcing policies pertaining to Consent Directives.
Cardinality 0..1
Type uri
Invariants ele-1

Consent.policy.uri

Short Specific policy covered by this consent
Definition The references to the policies that are included in this consent scope. Policies may be organizational, but are often defined jurisdictionally, or in law.
Comments This element is for discoverability / documentation and does not modify or qualify the policy rules.
Cardinality 1..1
Type uri
Invariants ele-1

Consent.policyRule

Short Regulation that this consents to
Definition A reference to the specific base computable regulation or policy.
Requirements Might be a unique identifier of a policy set in XACML, or other rules engine.
Comments If the policyRule is absent, computable consent would need to be constructed from the elements of the Consent resource.
Cardinality 0..1
Type CodeableConcept
Binding consent-policy (extensible)
Invariants ele-1

Consent.verification

Short Consent Verified by patient or family
Definition Whether a treatment instruction (e.g. artificial respiration yes or no) was verified with the patient, his/her family or another authorized person.
Cardinality 0..*
Type BackboneElement
Invariants ele-1

Consent.verification.id

Short Unique id for inter-element referencing
Definition Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.
Cardinality 0..1
Type http://hl7.org/fhirpath/System.String

Consent.verification.extension

Short Additional content defined by implementations
Definition May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Invariants ele-1, ext-1
Also called extensions, user content

Consent.verification.modifierExtension

Short Extensions that cannot be ignored even if unrecognized
Definition May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions. Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).
Requirements Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Modifier yes — Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
Invariants ele-1, ext-1
Also called extensions, user content, modifiers

Consent.verification.verified

Short Has been verified
Definition Has the instruction been verified.
Cardinality 1..1
Type boolean
Invariants ele-1

Consent.verification.verifiedWith

Short Person who verified
Definition Who verified the instruction (Patient, Relative or other Authorized Person).
Cardinality 0..1
Type Reference(Patient | RelatedPerson)
Invariants ele-1

Consent.verification.verificationDate

Short When consent verified
Definition Date verification was collected.
Cardinality 0..1
Type dateTime
Invariants ele-1

Consent.provision

Short The restriction: type states the decision, and nested provisions carve out exceptions
Definition The base rule. type = deny for a lockbox: the patient is restricting something. Exceptions are NESTED provisions with type = permit, describing what the restriction does not reach -- a care team that may still see the record, or a standing break-glass carve-out.
Cardinality 1..1
Type BackboneElement
Must Support yes
Invariants ele-1

Consent.provision.id

Short Unique id for inter-element referencing
Definition Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.
Cardinality 0..1
Type http://hl7.org/fhirpath/System.String

Consent.provision.extension

Short Additional content defined by implementations
Definition May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Invariants ele-1, ext-1
Also called extensions, user content

Consent.provision.modifierExtension

Short Extensions that cannot be ignored even if unrecognized
Definition May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions. Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).
Requirements Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Modifier yes — Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
Invariants ele-1, ext-1
Also called extensions, user content, modifiers

Consent.provision.type

Short deny for a lockbox | permit for a base consent
Definition The decision this directive states. deny restricts; permit grants. Required on the root, which diverges from R4's element text. R4 says type is "Not permitted in root rule, required in all nested rules". IHE PCF and Ontario's PCOI both require it on the root anyway, and this guide follows them: a directive whose base rule states no decision states none where a reader looks first, and every reader of this family will be looking there. A consumer reading a directive that carries no root type MUST NOT infer permit. Treat it as malformed and fail closed.
Cardinality 1..1
Type code
Must Support yes
Binding consent-provision-type (required)
Invariants ele-1

Consent.provision.period

Short When the restriction is effective, if it is time-bounded
Definition The window in which this restriction applies. An absent period means the restriction applies for as long as the directive is active, with no end. An absent period.end means the same thing and must be read that way. A consumer that treats a missing end as "expired" or as "unknown, therefore ignore" will release restricted information.
Cardinality 0..1
Type Period
Must Support yes
Invariants ele-1

Consent.provision.actor

Short Whom the restriction is against, where it names anyone
Definition The recipient, agent or class of agents the restriction applies to. actor.reference names an individual practitioner, an organization, or a Group standing for a class of recipients. actor.role says how they are involved. The tender requires restrictions naming "specific HIC's, agents, classes of HICs or agents, or individual providers", and a class is expressed as a Group rather than as a bare code, because a consumer has to be able to test membership at decision time rather than interpret a label. An absent actor restricts EVERYONE, on the same fail-closed reasoning as action. A first-pass limit, stated because the tender asks for the case this does not yet cover. The requirement names restrictions against "classes of HICs or agents", and a class is properly a Group whose membership a consumer can test at decision time. Reference(Group) is permitted here, but this guide does not profile Group and publishes no example of one, so a deployment naming a class today is pointing at a resource with no agreed shape. Naming an Organization instead works and is coarser: it covers everyone at that custodian rather than a named subset. What would settle it is a Group profile and a decision about who maintains membership.
Cardinality 0..*
Type BackboneElement
Must Support yes
Invariants ele-1

Consent.provision.actor.id

Short Unique id for inter-element referencing
Definition Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.
Cardinality 0..1
Type http://hl7.org/fhirpath/System.String

Consent.provision.actor.extension

Short Additional content defined by implementations
Definition May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Invariants ele-1, ext-1
Also called extensions, user content

Consent.provision.actor.modifierExtension

Short Extensions that cannot be ignored even if unrecognized
Definition May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions. Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).
Requirements Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Modifier yes — Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
Invariants ele-1, ext-1
Also called extensions, user content, modifiers

Consent.provision.actor.role

Short How the actor is involved
Definition How the individual is involved in the resources content that is described in the exception.
Cardinality 1..1
Type CodeableConcept
Binding security-role-type (extensible)
Invariants ele-1

Consent.provision.actor.reference

Short Resource for the actor (or group, by role)
Definition The resource that identifies the actor. To identify actors by type, use group to identify a set of actors by some property they share (e.g. 'admitting officers').
Cardinality 1..1
Type Reference(Practitioner Profile | PractitionerRole Profile | Organization Profile | App Device Profile | Group)
Invariants ele-1

Consent.provision.action

Short Which acts are restricted: collect | access | use | disclose
Definition The acts this directive restricts, matching PHIPA's collection / use / disclosure triad plus access for retrieval that permits none of them. A deliberate divergence from IHE PCF, which prohibits this element entirely (0..0 in all three of its tiers). PCF targets document-sharing environments, where disclosure is effectively the only act in play, so the axis buys nothing there. A primary-care EMR is the case it does not cover: a restriction on internal USE of a record by staff who already hold it is a different instruction from a restriction on DISCLOSING it outward, and Ontario requires both to be expressible. A directive exported toward a PCF-conformant system loses this element, and what it meant has to be carried some other way or declared unsupported at the boundary. An absent action restricts EVERY action. This is stated rather than left to inference because the opposite reading — an unnamed action is unrestricted — fails open, and a privacy control that fails open is not a control. A writer who means to restrict only disclosure must say disclose.
Comments Note that this is the direct action (not the grounds for the action covered in the purpose element). At present, the only action in the understood and tested scope of this resource is 'read'.
Cardinality 0..*
Type CodeableConcept
Must Support yes
Binding Privacy Restriction Actions Value Set (extensible)
Invariants ele-1

Consent.provision.securityLabel

Short Restrict by sensitivity class -- read the high-water-mark warning first
Definition Restricts records carrying a given security label rather than records named individually. R4 matching here is not equality, and the difference is dangerous. The specification states: "If the consent specifies a security label of 'R' then it applies to all resources that are labeled 'R' or lower. E.g. for Confidentiality, it's a high water mark." So a directive written to restrict only restricted material also restricts everything normal, moderate, low and unrestricted — which, in a chart where most resources carry no elevated label at all, is very close to restricting the entire record. A writer meaning "restrict the sensitive material" and reaching for R will get a far broader restriction than intended. Because that error over-restricts rather than over-discloses it will not cause a privacy breach, but it will cause a clinician to be denied information they are entitled to, at a moment when they may need it. Prefer explicit provision.data selectors for a first implementation. Use this element only where the deployment has tested subsumption behaviour against both a higher and a lower classification than the one it names.
Comments If the consent specifies a security label of "R" then it applies to all resources that are labeled "R" or lower. E.g. for Confidentiality, it's a high water mark. For other kinds of security labels, subsumption logic applies. When the purpose of use tag is on the data, access request purpose of use shall not conflict.
Cardinality 0..*
Type Coding
Must Support yes
Binding security-labels (extensible)
Invariants ele-1

Consent.provision.purpose

Short Context of activities covered by this rule
Definition The context of the activities a user is taking - why the user is accessing the data - that are controlled by this rule.
Comments When the purpose of use tag is on the data, access request purpose of use shall not conflict.
Cardinality 0..*
Type Coding
Binding v3-PurposeOfUse (extensible)
Invariants ele-1

Consent.provision.class

Short e.g. Resource Type, Profile, CDA, etc.
Definition The class of information covered by this rule. The type can be a FHIR resource type, a profile on a type, or a CDA document, or some other type that indicates what sort of information the consent relates to.
Comments Multiple types are or'ed together. The intention of the contentType element is that the codes refer to profiles or document types defined in a standard or an implementation guide somewhere.
Cardinality 0..*
Type Coding
Binding consent-content-class (extensible)
Invariants ele-1

Consent.provision.code

Short e.g. LOINC or SNOMED CT code, etc. in the content
Definition If this code is found in an instance, then the rule applies.
Comments Typical use of this is a Document code with class = CDA.
Cardinality 0..*
Type CodeableConcept
Binding consent-content-code (example)
Invariants ele-1

Consent.provision.dataPeriod

Short Timeframe for data controlled by this rule
Definition Clinical or Operational Relevant period of time that bounds the data controlled by this rule.
Comments This has a different sense to the Consent.period - that is when the consent agreement holds. This is the time period of the data that is controlled by the agreement.
Cardinality 0..1
Type Period
Invariants ele-1

Consent.provision.data

Short Which records are restricted, where the directive names records
Definition The specific records this restriction covers. Absent means the restriction covers the patient's whole record, which is the ordinary lockbox case. data.meaning is required by R4 and decides how far the reference reaches: instance is that resource alone, related includes what it points at, dependents includes what points at it, authoredby covers everything authored by the referenced actor. Choosing instance where the patient meant "this visit and everything from it" under-restricts, and it under-restricts silently. A first-pass limit worth knowing before designing against it. These selectors enumerate records that exist NOW. A directive meant to cover future information — "nothing from this clinic, ever" — cannot be expressed as a list, and this release does not define a criteria-based selector. Express a whole-record restriction by naming no data at all; that reading does extend to future records. A directive naming a data list does NOT.
Cardinality 0..*
Type BackboneElement
Must Support yes
Invariants ele-1

Consent.provision.data.id

Short Unique id for inter-element referencing
Definition Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.
Cardinality 0..1
Type http://hl7.org/fhirpath/System.String

Consent.provision.data.extension

Short Additional content defined by implementations
Definition May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Invariants ele-1, ext-1
Also called extensions, user content

Consent.provision.data.modifierExtension

Short Extensions that cannot be ignored even if unrecognized
Definition May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions. Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).
Requirements Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Modifier yes — Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
Invariants ele-1, ext-1
Also called extensions, user content, modifiers

Consent.provision.data.meaning

Short instance | related | dependents | authoredby
Definition How the resource reference is interpreted when testing consent restrictions.
Cardinality 1..1
Type code
Binding consent-data-meaning (required)
Invariants ele-1

Consent.provision.data.reference

Short The actual data reference
Definition A reference to a specific resource that defines which resources are covered by this consent.
Cardinality 1..1
Type Reference(Resource)
Invariants ele-1

Consent.provision.provision

Short Exceptions: what the restriction does NOT reach
Definition Carve-outs from the base rule, each with an explicit type (R4 requires one here and so does this profile). On a deny directive these are the permissions that survive the restriction. This is where break-glass lives. A standing exception naming the users who may reach the record in an emergency is a nested permit whose purpose is BTG and whose actor names the privileged group:
provision.type                = deny
  provision.provision.type    = permit
  provision.provision.actor   = Group/privileged-users   (role: IRCP)
  provision.provision.purpose = BTG
That shape is IHE PCF's, adopted rather than reinvented. It says who MAY break the glass. It never says that anybody did -- the record of an actual override, by whom, when, on what lawful ground and reaching what, is an AuditEvent following IHE BALP's authorization pattern. A deployment that recorded override events by editing this resource would rewrite the patient's instruction every time a clinician acted on it, and would make "what did the patient actually ask for" unanswerable. Nested exceptions do not nest further. R4 permits deeper trees and PCF forbids them; this profile follows PCF, because a rule whose meaning depends on three levels of precedence is one nobody implements the same way twice.
Cardinality 0..*
Type BackboneElement
Must Support yes
Invariants ele-1

Consent.provision.provision.id

Short Unique id for inter-element referencing
Definition Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.
Cardinality 0..1
Type http://hl7.org/fhirpath/System.String

Consent.provision.provision.extension

Short Additional content defined by implementations
Definition May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Invariants ele-1, ext-1
Also called extensions, user content

Consent.provision.provision.modifierExtension

Short Extensions that cannot be ignored even if unrecognized
Definition May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions. Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).
Requirements Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Modifier yes — Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
Invariants ele-1, ext-1
Also called extensions, user content, modifiers

Consent.provision.provision.type

Short permit (an exception to a deny directive) | deny
Definition Action to take - permit or deny - when the rule conditions are met. Not permitted in root rule, required in all nested rules.
Cardinality 1..1
Type code
Must Support yes
Binding consent-provision-type (required)
Invariants ele-1

Consent.provision.provision.period

Short Timeframe for this rule
Definition The timeframe in this rule is valid.
Cardinality 0..1
Type Period
Invariants ele-1

Consent.provision.provision.actor

Short Who|what controlled by this rule (or group, by role)
Definition Who or what is controlled by this rule. Use group to identify a set of actors by some property they share (e.g. 'admitting officers').
Cardinality 0..*
Type BackboneElement
Invariants ele-1

Consent.provision.provision.actor.id

Short Unique id for inter-element referencing
Definition Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.
Cardinality 0..1
Type http://hl7.org/fhirpath/System.String

Consent.provision.provision.actor.extension

Short Additional content defined by implementations
Definition May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Invariants ele-1, ext-1
Also called extensions, user content

Consent.provision.provision.actor.modifierExtension

Short Extensions that cannot be ignored even if unrecognized
Definition May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions. Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).
Requirements Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Modifier yes — Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
Invariants ele-1, ext-1
Also called extensions, user content, modifiers

Consent.provision.provision.actor.role

Short How the actor is involved
Definition How the individual is involved in the resources content that is described in the exception.
Cardinality 1..1
Type CodeableConcept
Binding security-role-type (extensible)
Invariants ele-1

Consent.provision.provision.actor.reference

Short Resource for the actor (or group, by role)
Definition The resource that identifies the actor. To identify actors by type, use group to identify a set of actors by some property they share (e.g. 'admitting officers').
Cardinality 1..1
Type Reference(Device | Group | CareTeam | Organization | Patient | Practitioner | RelatedPerson | PractitionerRole)
Invariants ele-1

Consent.provision.provision.action

Short Actions controlled by this rule
Definition Actions controlled by this Rule.
Comments Note that this is the direct action (not the grounds for the action covered in the purpose element). At present, the only action in the understood and tested scope of this resource is 'read'.
Cardinality 0..*
Type CodeableConcept
Binding consent-action (example)
Invariants ele-1

Consent.provision.provision.securityLabel

Short Security Labels that define affected resources
Definition A security label, comprised of 0..* security label fields (Privacy tags), which define which resources are controlled by this exception.
Comments If the consent specifies a security label of "R" then it applies to all resources that are labeled "R" or lower. E.g. for Confidentiality, it's a high water mark. For other kinds of security labels, subsumption logic applies. When the purpose of use tag is on the data, access request purpose of use shall not conflict.
Cardinality 0..*
Type Coding
Binding security-labels (extensible)
Invariants ele-1

Consent.provision.provision.purpose

Short Why this exception exists -- BTG marks the break-glass carve-out
Definition The context of the activities a user is taking - why the user is accessing the data - that are controlled by this rule.
Comments When the purpose of use tag is on the data, access request purpose of use shall not conflict.
Cardinality 0..*
Type Coding
Must Support yes
Binding Privacy Exception Purposes Value Set (extensible)
Invariants ele-1

Consent.provision.provision.class

Short e.g. Resource Type, Profile, CDA, etc.
Definition The class of information covered by this rule. The type can be a FHIR resource type, a profile on a type, or a CDA document, or some other type that indicates what sort of information the consent relates to.
Comments Multiple types are or'ed together. The intention of the contentType element is that the codes refer to profiles or document types defined in a standard or an implementation guide somewhere.
Cardinality 0..*
Type Coding
Binding consent-content-class (extensible)
Invariants ele-1

Consent.provision.provision.code

Short e.g. LOINC or SNOMED CT code, etc. in the content
Definition If this code is found in an instance, then the rule applies.
Comments Typical use of this is a Document code with class = CDA.
Cardinality 0..*
Type CodeableConcept
Binding consent-content-code (example)
Invariants ele-1

Consent.provision.provision.dataPeriod

Short Timeframe for data controlled by this rule
Definition Clinical or Operational Relevant period of time that bounds the data controlled by this rule.
Comments This has a different sense to the Consent.period - that is when the consent agreement holds. This is the time period of the data that is controlled by the agreement.
Cardinality 0..1
Type Period
Invariants ele-1

Consent.provision.provision.data

Short Data controlled by this rule
Definition The resources controlled by this rule if specific resources are referenced.
Cardinality 0..*
Type BackboneElement
Invariants ele-1

Consent.provision.provision.data.id

Short Unique id for inter-element referencing
Definition Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.
Cardinality 0..1
Type http://hl7.org/fhirpath/System.String

Consent.provision.provision.data.extension

Short Additional content defined by implementations
Definition May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Invariants ele-1, ext-1
Also called extensions, user content

Consent.provision.provision.data.modifierExtension

Short Extensions that cannot be ignored even if unrecognized
Definition May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions. Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).
Requirements Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.
Comments There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.
Cardinality 0..*
Type Extension
Modifier yes — Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
Invariants ele-1, ext-1
Also called extensions, user content, modifiers

Consent.provision.provision.data.meaning

Short instance | related | dependents | authoredby
Definition How the resource reference is interpreted when testing consent restrictions.
Cardinality 1..1
Type code
Binding consent-data-meaning (required)
Invariants ele-1

Consent.provision.provision.data.reference

Short The actual data reference
Definition A reference to a specific resource that defines which resources are covered by this consent.
Cardinality 1..1
Type Reference(Resource)
Invariants ele-1

Consent.provision.provision.provision

Short Not used -- exceptions do not nest further, matching IHE PCF
Definition Rules which provide exceptions to the base rule or subrules.
Cardinality 0..0
Invariants ele-1