Skip to content

Privacy Directive Profile

Canonical../StructureDefinition/nexus-privacy-directive
Statusdraft (experimental) · 1.26.0
BaseConsent (constraint)
SourceFSH · JSON

A patient's standing restriction on the collection, use or disclosure of their own personal health information -- the instruction PHIPA calls a lockbox.

Elements / Snapshot

The full effective definition: base Consent with this profile's constraints applied.

Element Flags Card. Type Description & Constraints
Consent 0..* A patient's standing restriction on their own record (lockbox) i
Invariants: dom-2, dom-3, dom-4, dom-5, dom-6, ppc-1, ppc-2, ppc-3, ppc-4, ppc-5, privacy-directive-exception-states-a-purpose
id 0..1 http://hl7.org/fhirpath/System.String Logical id of this artifact i
meta 0..1 Meta Metadata about the resource
Invariants: ele-1
id 0..1 http://hl7.org/fhirpath/System.String Unique id for inter-element referencing
extension 0..* Extension Additional content defined by implementations i
Slicing: value:url (open)
Invariants: ele-1, ext-1
versionId 0..1 id Version specific identifier i
Invariants: ele-1
lastUpdated 0..1 instant When the resource version last changed i
Invariants: ele-1
source S 0..1 uri Identifies EMR instance & pipeline version the resource came from i
Invariants: ele-1
profile 0..* canonical Profiles this resource claims to conform to i
Invariants: ele-1
security 0..* Coding Security Labels applied to this resource i
Binding: security-labels (extensible)
Invariants: ele-1
tag 0..* Coding Tags applied to this resource i
Binding: common-tags (example)
Invariants: ele-1
implicitRules ?! 0..1 uri A set of rules under which this content was created i
Invariants: ele-1
language 0..1 code Language of the resource content i
Binding: languages (preferred)
Invariants: ele-1
text 0..1 Narrative Text summary of the resource, for human interpretation i
Invariants: ele-1
contained 0..* Resource Contained, inline Resources i
extension 0..* Extension Additional content defined by implementations i
Invariants: ele-1, ext-1
modifierExtension ?! 0..* Extension Extensions that cannot be ignored i
Invariants: ele-1, ext-1
identifier S 0..* Identifier Business identifier(s) for the directive i
Invariants: ele-1
id 0..1 http://hl7.org/fhirpath/System.String Unique id for inter-element referencing
extension 0..* Extension Additional content defined by implementations i
Slicing: value:url (open)
Invariants: ele-1, ext-1
use ?! 0..1 code usual | official | temp | secondary | old (If known) i
Binding: identifier-use (required)
Invariants: ele-1
type 0..1 CodeableConcept Description of identifier i
Binding: identifier-type (extensible)
Invariants: ele-1
system 1..1 uri The namespace for the identifier value i
Invariants: ele-1
value 1..1 string The value that is unique i
Invariants: ele-1
period 0..1 Period Time period when id is/was valid for use
Invariants: ele-1
assigner 0..1 Reference(Organization) Organization that issued id (may be just text) i
Invariants: ele-1
status S ?! 1..1 code active (in force) | inactive (superseded or withdrawn) | entered-in-error i
Binding: consent-state-codes (required)
Invariants: ele-1
scope S ?! 1..1 CodeableConcept patient-privacy - Privacy consent
Fixed: {"coding":[{"system":"http://terminology.hl7.org/CodeSystem/consentscope","code":"patient-privacy","display":"Privacy C…
Binding: consent-scope (required)
Invariants: ele-1
category S 1..* CodeableConcept MUST carry the privacy-directive family code; this is how a reader knows what status means i
Slicing: pattern:coding.system (open)
Binding: consent-category (extensible)
Invariants: ele-1
category:family S 1..1 CodeableConcept Fixed: this Consent is a privacy directive i
Binding: Consent Families Value Set (required)
e.g. app · item · privacy-directive
Invariants: ele-1
id 0..1 http://hl7.org/fhirpath/System.String Unique id for inter-element referencing
extension 0..* Extension Additional content defined by implementations i
Slicing: value:url (open)
Invariants: ele-1, ext-1
coding 1..1 Coding Code defined by a terminology system i
Invariants: ele-1
id 0..1 http://hl7.org/fhirpath/System.String Unique id for inter-element referencing
extension 0..* Extension Additional content defined by implementations i
Slicing: value:url (open)
Invariants: ele-1, ext-1
system 1..1 uri Identity of the terminology system i
Fixed: ../CodeSystem/nexus-consent-family
Invariants: ele-1
version 0..1 string Version of the system - if relevant i
Invariants: ele-1
code 1..1 code Symbol in syntax defined by the system
Fixed: privacy-directive
Invariants: ele-1
display 0..1 string Representation defined by the system
Invariants: ele-1
userSelected 0..1 boolean If this coding was chosen directly by the user i
Invariants: ele-1
text 0..1 string Plain text representation of the concept i
Invariants: ele-1
patient S 1..1 Reference(Patient Profile) The patient whose record is restricted i
Invariants: ele-1
dateTime S 1..1 dateTime When the instruction was given i
Invariants: ele-1
performer S 0..* Reference(Patient Profile | RelatedPerson Profile | Practitioner Profile | PractitionerRole Profile) Who gave the instruction -- the patient, or a substitute decision-maker i
Invariants: ele-1
organization S 0..* Reference(Organization Profile) The custodian whose records this directive restricts
Invariants: ele-1
source[x] 0..1 Reference(DocumentReference Profile) Source from which this consent is taken i
Slicing: type:$this (open)
Invariants: ele-1
source[x]:sourceReference S 0..1 Reference(DocumentReference Profile) The signed instruction, where one was captured i
Invariants: ele-1
policy S 1..* BackboneElement The policy or statutory provision this directive is made under
Invariants: ele-1
id 0..1 http://hl7.org/fhirpath/System.String Unique id for inter-element referencing
extension 0..* Extension Additional content defined by implementations i
Invariants: ele-1, ext-1
modifierExtension ?! 0..* Extension Extensions that cannot be ignored even if unrecognized i
Invariants: ele-1, ext-1
authority 0..1 uri Enforcement source for policy
Invariants: ele-1
uri 1..1 uri Specific policy covered by this consent i
Invariants: ele-1
policyRule 0..1 CodeableConcept Regulation that this consents to i
Binding: consent-policy (extensible)
Invariants: ele-1
verification 0..* BackboneElement Consent Verified by patient or family
Invariants: ele-1
id 0..1 http://hl7.org/fhirpath/System.String Unique id for inter-element referencing
extension 0..* Extension Additional content defined by implementations i
Invariants: ele-1, ext-1
modifierExtension ?! 0..* Extension Extensions that cannot be ignored even if unrecognized i
Invariants: ele-1, ext-1
verified 1..1 boolean Has been verified
Invariants: ele-1
verifiedWith 0..1 Reference(Patient | RelatedPerson) Person who verified
Invariants: ele-1
verificationDate 0..1 dateTime When consent verified
Invariants: ele-1
provision S 1..1 BackboneElement The restriction: type states the decision, and nested provisions carve out exceptions
Invariants: ele-1
id 0..1 http://hl7.org/fhirpath/System.String Unique id for inter-element referencing
extension 0..* Extension Additional content defined by implementations i
Invariants: ele-1, ext-1
modifierExtension ?! 0..* Extension Extensions that cannot be ignored even if unrecognized i
Invariants: ele-1, ext-1
type S 1..1 code deny for a lockbox | permit for a base consent
Binding: consent-provision-type (required)
Invariants: ele-1
period S 0..1 Period When the restriction is effective, if it is time-bounded
Invariants: ele-1
actor S 0..* BackboneElement Whom the restriction is against, where it names anyone
Invariants: ele-1
id 0..1 http://hl7.org/fhirpath/System.String Unique id for inter-element referencing
extension 0..* Extension Additional content defined by implementations i
Invariants: ele-1, ext-1
modifierExtension ?! 0..* Extension Extensions that cannot be ignored even if unrecognized i
Invariants: ele-1, ext-1
role 1..1 CodeableConcept How the actor is involved
Binding: security-role-type (extensible)
Invariants: ele-1
reference 1..1 Reference(Practitioner Profile | PractitionerRole Profile | Organization Profile | App Device Profile | Group) Resource for the actor (or group, by role)
Invariants: ele-1
action S 0..* CodeableConcept Which acts are restricted: collect | access | use | disclose i
Binding: Privacy Restriction Actions Value Set (extensible)
e.g. collect · access · use
Invariants: ele-1
securityLabel S 0..* Coding Restrict by sensitivity class -- read the high-water-mark warning first i
Binding: security-labels (extensible)
Invariants: ele-1
purpose 0..* Coding Context of activities covered by this rule i
Binding: v3-PurposeOfUse (extensible)
Invariants: ele-1
class 0..* Coding e.g. Resource Type, Profile, CDA, etc. i
Binding: consent-content-class (extensible)
Invariants: ele-1
code 0..* CodeableConcept e.g. LOINC or SNOMED CT code, etc. in the content i
Binding: consent-content-code (example)
Invariants: ele-1
dataPeriod 0..1 Period Timeframe for data controlled by this rule i
Invariants: ele-1
data S 0..* BackboneElement Which records are restricted, where the directive names records
Invariants: ele-1
id 0..1 http://hl7.org/fhirpath/System.String Unique id for inter-element referencing
extension 0..* Extension Additional content defined by implementations i
Invariants: ele-1, ext-1
modifierExtension ?! 0..* Extension Extensions that cannot be ignored even if unrecognized i
Invariants: ele-1, ext-1
meaning 1..1 code instance | related | dependents | authoredby
Binding: consent-data-meaning (required)
Invariants: ele-1
reference 1..1 Reference(Resource) The actual data reference
Invariants: ele-1
provision S 0..* BackboneElement Exceptions: what the restriction does NOT reach
Invariants: ele-1
id 0..1 http://hl7.org/fhirpath/System.String Unique id for inter-element referencing
extension 0..* Extension Additional content defined by implementations i
Invariants: ele-1, ext-1
modifierExtension ?! 0..* Extension Extensions that cannot be ignored even if unrecognized i
Invariants: ele-1, ext-1
type S 1..1 code permit (an exception to a deny directive) | deny
Binding: consent-provision-type (required)
Invariants: ele-1
period 0..1 Period Timeframe for this rule
Invariants: ele-1
actor 0..* BackboneElement Who|what controlled by this rule (or group, by role)
Invariants: ele-1
id 0..1 http://hl7.org/fhirpath/System.String Unique id for inter-element referencing
extension 0..* Extension Additional content defined by implementations i
Invariants: ele-1, ext-1
modifierExtension ?! 0..* Extension Extensions that cannot be ignored even if unrecognized i
Invariants: ele-1, ext-1
role 1..1 CodeableConcept How the actor is involved
Binding: security-role-type (extensible)
Invariants: ele-1
reference 1..1 Reference(Device | Group | CareTeam | Organization | Patient | Practitioner | RelatedPerson | PractitionerRole) Resource for the actor (or group, by role)
Invariants: ele-1
action 0..* CodeableConcept Actions controlled by this rule i
Binding: consent-action (example)
Invariants: ele-1
securityLabel 0..* Coding Security Labels that define affected resources i
Binding: security-labels (extensible)
Invariants: ele-1
purpose S 0..* Coding Why this exception exists -- BTG marks the break-glass carve-out i
Binding: Privacy Exception Purposes Value Set (extensible)
e.g. TREAT · HPAYMT · HOPERAT
Invariants: ele-1
class 0..* Coding e.g. Resource Type, Profile, CDA, etc. i
Binding: consent-content-class (extensible)
Invariants: ele-1
code 0..* CodeableConcept e.g. LOINC or SNOMED CT code, etc. in the content i
Binding: consent-content-code (example)
Invariants: ele-1
dataPeriod 0..1 Period Timeframe for data controlled by this rule i
Invariants: ele-1
data 0..* BackboneElement Data controlled by this rule
Invariants: ele-1
id 0..1 http://hl7.org/fhirpath/System.String Unique id for inter-element referencing
extension 0..* Extension Additional content defined by implementations i
Invariants: ele-1, ext-1
modifierExtension ?! 0..* Extension Extensions that cannot be ignored even if unrecognized i
Invariants: ele-1, ext-1
meaning 1..1 code instance | related | dependents | authoredby
Binding: consent-data-meaning (required)
Invariants: ele-1
reference 1..1 Reference(Resource) The actual data reference
Invariants: ele-1
provision 0..0 Not used -- exceptions do not nest further, matching IHE PCF
Invariants: ele-1