Skip to content

Privacy Directive Profile

Canonical../StructureDefinition/nexus-privacy-directive
Statusdraft (experimental) · 1.26.0
BaseConsent (constraint)
SourceFSH · JSON

A patient's standing restriction on the collection, use or disclosure of their own personal health information -- the instruction PHIPA calls a lockbox.

Elements / Key elements

The working view: must-support, required, modifier and sliced elements from the effective (snapshot) definition.

Element Flags Card. Type Description & Constraints
Consent 0..* A patient's standing restriction on their own record (lockbox) i
Invariants: dom-2, dom-3, dom-4, dom-5, dom-6, ppc-1, ppc-2, ppc-3, ppc-4, ppc-5, privacy-directive-exception-states-a-purpose
meta 0..1 Meta Metadata about the resource
Invariants: ele-1
source S 0..1 uri Identifies EMR instance & pipeline version the resource came from i
Invariants: ele-1
implicitRules ?! 0..1 uri A set of rules under which this content was created i
Invariants: ele-1
identifier S 0..* Identifier Business identifier(s) for the directive i
Invariants: ele-1
use ?! 0..1 code usual | official | temp | secondary | old (If known) i
Binding: identifier-use (required)
Invariants: ele-1
system 1..1 uri The namespace for the identifier value i
Invariants: ele-1
value 1..1 string The value that is unique i
Invariants: ele-1
status S ?! 1..1 code active (in force) | inactive (superseded or withdrawn) | entered-in-error i
Binding: consent-state-codes (required)
Invariants: ele-1
scope S ?! 1..1 CodeableConcept patient-privacy - Privacy consent
Fixed: {"coding":[{"system":"http://terminology.hl7.org/CodeSystem/consentscope","code":"patient-privacy","display":"Privacy C…
Binding: consent-scope (required)
Invariants: ele-1
category S 1..* CodeableConcept MUST carry the privacy-directive family code; this is how a reader knows what status means i
Slicing: pattern:coding.system (open)
Binding: consent-category (extensible)
Invariants: ele-1
category:family S 1..1 CodeableConcept Fixed: this Consent is a privacy directive i
Binding: Consent Families Value Set (required)
e.g. app · item · privacy-directive
Invariants: ele-1
coding 1..1 Coding Code defined by a terminology system i
Invariants: ele-1
system 1..1 uri Identity of the terminology system i
Fixed: ../CodeSystem/nexus-consent-family
Invariants: ele-1
code 1..1 code Symbol in syntax defined by the system
Fixed: privacy-directive
Invariants: ele-1
patient S 1..1 Reference(Patient Profile) The patient whose record is restricted i
Invariants: ele-1
dateTime S 1..1 dateTime When the instruction was given i
Invariants: ele-1
performer S 0..* Reference(Patient Profile | RelatedPerson Profile | Practitioner Profile | PractitionerRole Profile) Who gave the instruction -- the patient, or a substitute decision-maker i
Invariants: ele-1
organization S 0..* Reference(Organization Profile) The custodian whose records this directive restricts
Invariants: ele-1
source[x]:sourceReference S 0..1 Reference(DocumentReference Profile) The signed instruction, where one was captured i
Invariants: ele-1
policy S 1..* BackboneElement The policy or statutory provision this directive is made under
Invariants: ele-1
uri 1..1 uri Specific policy covered by this consent i
Invariants: ele-1
verification 0..* BackboneElement Consent Verified by patient or family
Invariants: ele-1
verified 1..1 boolean Has been verified
Invariants: ele-1
provision S 1..1 BackboneElement The restriction: type states the decision, and nested provisions carve out exceptions
Invariants: ele-1
type S 1..1 code deny for a lockbox | permit for a base consent
Binding: consent-provision-type (required)
Invariants: ele-1
period S 0..1 Period When the restriction is effective, if it is time-bounded
Invariants: ele-1
actor S 0..* BackboneElement Whom the restriction is against, where it names anyone
Invariants: ele-1
role 1..1 CodeableConcept How the actor is involved
Binding: security-role-type (extensible)
Invariants: ele-1
reference 1..1 Reference(Practitioner Profile | PractitionerRole Profile | Organization Profile | App Device Profile | Group) Resource for the actor (or group, by role)
Invariants: ele-1
action S 0..* CodeableConcept Which acts are restricted: collect | access | use | disclose i
Binding: Privacy Restriction Actions Value Set (extensible)
e.g. collect · access · use
Invariants: ele-1
securityLabel S 0..* Coding Restrict by sensitivity class -- read the high-water-mark warning first i
Binding: security-labels (extensible)
Invariants: ele-1
data S 0..* BackboneElement Which records are restricted, where the directive names records
Invariants: ele-1
meaning 1..1 code instance | related | dependents | authoredby
Binding: consent-data-meaning (required)
Invariants: ele-1
reference 1..1 Reference(Resource) The actual data reference
Invariants: ele-1
provision S 0..* BackboneElement Exceptions: what the restriction does NOT reach
Invariants: ele-1
type S 1..1 code permit (an exception to a deny directive) | deny
Binding: consent-provision-type (required)
Invariants: ele-1
actor 0..* BackboneElement Who|what controlled by this rule (or group, by role)
Invariants: ele-1
role 1..1 CodeableConcept How the actor is involved
Binding: security-role-type (extensible)
Invariants: ele-1
reference 1..1 Reference(Device | Group | CareTeam | Organization | Patient | Practitioner | RelatedPerson | PractitionerRole) Resource for the actor (or group, by role)
Invariants: ele-1
purpose S 0..* Coding Why this exception exists -- BTG marks the break-glass carve-out i
Binding: Privacy Exception Purposes Value Set (extensible)
e.g. TREAT · HPAYMT · HOPERAT
Invariants: ele-1
data 0..* BackboneElement Data controlled by this rule
Invariants: ele-1
meaning 1..1 code instance | related | dependents | authoredby
Binding: consent-data-meaning (required)
Invariants: ele-1
reference 1..1 Reference(Resource) The actual data reference
Invariants: ele-1