Skip to content

Privacy Directive Profile

Canonical../StructureDefinition/nexus-privacy-directive
Statusdraft (experimental) · 1.26.0
BaseConsent (constraint)
SourceFSH · JSON

A patient's standing restriction on the collection, use or disclosure of their own personal health information -- the instruction PHIPA calls a lockbox.

Invariants

Every rule in force on a conforming instance. This profile rows are stated here; inherited rows come from the base resource and are listed so that a constraint named on an element is findable. Invariant keys elsewhere on this page link into this table.

Key Source Severity On Rule
privacy-directive-exception-states-a-purpose this profile warning Consent A nested exception on a privacy directive SHOULD name the purpose it exists for. Without one, a standing break-glass carve-out cannot be distinguished from an ordinary permission, and the two carry different review obligations
provision.provision.all(purpose.exists())
dom-2 inherited error Consent If the resource is contained in another resource, it SHALL NOT contain nested Resources
contained.contained.empty()
dom-3 inherited error Consent If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource
contained.where((('#'+id in (%resource.descendants().reference
dom-4 inherited error Consent If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated
contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
dom-5 inherited error Consent If a resource is contained in another resource, it SHALL NOT have a security label
contained.meta.security.empty()
dom-6 inherited warning Consent A resource should have narrative for robust management
text.div.exists()
ele-1 inherited error Consent.meta All FHIR elements must have a @value or children
hasValue() or (children().count() > id.count())
ext-1 inherited error Consent.meta.extension Must have either extensions or value[x], not both
extension.exists() != value.exists()
ppc-1 inherited error Consent Either a Policy or PolicyRule
policy.exists() or policyRule.exists()
ppc-2 inherited error Consent IF Scope=privacy, there must be a patient
patient.exists() or scope.coding.where(system='something' and code='patient-privacy').exists().not()
ppc-3 inherited error Consent IF Scope=research, there must be a patient
patient.exists() or scope.coding.where(system='something' and code='research').exists().not()
ppc-4 inherited error Consent IF Scope=adr, there must be a patient
patient.exists() or scope.coding.where(system='something' and code='adr').exists().not()
ppc-5 inherited error Consent IF Scope=treatment, there must be a patient
patient.exists() or scope.coding.where(system='something' and code='treatment').exists().not()