HL7 Vietnam VN Core FHIR Implementation Guide

Hướng dẫn triển khai FHIR cốt lõi Việt Nam — VN Core FHIR Implementation Guide
0.10.0 - Draft for Community Review Viet Nam cờ

Hướng dẫn triển khai FHIR cốt lõi Việt Nam — VN Core FHIR Implementation Guide - Draft for Community Review (v0.10.0) built by the FHIR (HL7® FHIR® Standard) Build Tools. See the Directory of published versions

Hồ sơ tài nguyên: Đồng ý xử lý dữ liệu VN Core — VN Core Consent Profile

URL chính thức: http://fhir.hl7.org.vn/core/StructureDefinition/vn-core-consent Phiên bản: 0.10.0
Computable Name: VNCoreConsent
Định danh khác: OID:2.25.161089673617632664299011809196868855799.42.48

Profile Consent cho Việt Nam CHỈ biểu diễn lựa chọn của chủ thể dữ liệu: đồng ý, từ chối, rút lại hoặc giới hạn xử lý/chia sẻ dữ liệu y tế cá nhân. Xử lý không cần đồng ý theo Luật 91/2025/QH15 Điều 19 khoản 1 không được authoring bằng Consent trong 0.9; dùng VNCoreAuditEventLegalBasisDecision cho quyết định, AuditEvent tiếp theo cho truy cập/tiết lộ thực tế, và Provenance nếu tạo/sửa/dẫn xuất dữ liệu. Context extension trên Consent được giữ tạm để đọc legacy 0.8 và dự kiến gỡ ở 1.0.

Profile hỗ trợ biểu diễn sự đồng ý/từ chối xử lý dữ liệu y tế cá nhân theo các yêu cầu được tham chiếu từ Luật 91/2025/QH15 (Bảo vệ dữ liệu cá nhân) và NĐ 356/2025/NĐ-CP, bao gồm mục đích xử lý, phạm vi, thời hạn, và quyền rút lại đồng ý. Phù hợp với profile này chỉ xác nhận cấu trúc FHIR; không tự chứng minh sự đồng ý hợp lệ hoặc việc tuân thủ pháp luật. Bên triển khai phải đánh giá vai trò, căn cứ, bằng chứng và quy trình thực tế. Dữ liệu y tế = dữ liệu cá nhân nhạy cảm (Luật 91/2025/QH15 Điều 2 khoản 3; danh mục tại NĐ 356/2025/NĐ-CP Điều 4 khoản 1 điểm d — tình trạng sức khoẻ). Căn cứ (theo bản BAN HÀNH — ma trận điều khoản: governance/legal-article-map.json):

  • Luật 91/2025/QH15 — thông qua 26/6/2025, hiệu lực 01/01/2026 — quyền chủ thể dữ liệu (Điều 4), sự đồng ý (Điều 9), rút lại/hạn chế xử lý (Điều 10), xử lý không cần đồng ý (Điều 19 — dùng VNCoreAuditEventLegalBasisDecision), chuyển xuyên biên giới (Điều 20), trẻ em/người mất năng lực hành vi dân sự (Điều 24), thông tin sức khoẻ (Điều 26)
  • NĐ 356/2025/NĐ-CP — 31/12/2025, hiệu lực 01/01/2026 — phương thức đồng ý (Điều 6), hồ sơ đánh giá tác động (Điều 19) và lưu bằng chứng đồng ý (Điều 6 khoản 2)
  • NĐ 278/2025/NĐ-CP — ban hành 22/10/2025, hiệu lực từ ngày ký 22/10/2025 — nghĩa vụ chia sẻ, chuẩn hoá hoặc kết nối chỉ áp dụng theo đúng phạm vi của từng quy định; Consent/policy là lựa chọn biểu diễn của IG cho kiểm soát chia sẻ, không phải định dạng do Nghị định quy định
  • NĐ 102/2025/NĐ-CP — 13/5/2025 — quản lý dữ liệu y tế số.

Ánh xạ trạng thái của IG (dựa trên các quyền/nghĩa vụ tại Luật 91/2025/QH15 Điều 4/9/10; Luật không quy định mã trạng thái FHIR R4):

  • Từ chối đang hiệu lực (chủ thể chủ động không cho phép một phạm vi xử lý) = status=active + rule nested provision.provision.type=deny;
  • rejected = đề nghị đồng ý bị TỪ CHỐI ngay từ đầu, chưa từng có hiệu lực;
  • inactive = đồng ý đã CHẤM DỨT hiệu lực: rút lại theo Điều 10, hết thời hạn, hoặc bị thay bằng bản mới. Yêu cầu rút lại không áp dụng hồi tố (Điều 10 khoản 4) — hoạt động xử lý trước thời điểm rút không bị tác động bởi YÊU CẦU RÚT; tính hợp pháp của xử lý trước đó được đánh giá độc lập theo căn cứ tại thời điểm xử lý. / This profile represents only the data subject's choices: consent, refusal, withdrawal, or limits on processing and sharing. Processing without consent under Article 19(1) SHALL NOT be newly authored as Consent in 0.9. Use VNCoreAuditEventLegalBasisDecision for the authorization decision, a subsequent AuditEvent for actual access/disclosure, and Provenance when data is created, updated, or derived. The Consent extension context is retained only for legacy 0.8 reads during the 0.9 line and is planned for removal in 1.0. Conformance to this profile validates FHIR structure only and does not itself prove valid consent or legal compliance.

Usages:

You can also check for usages in the FHIR IG Statistics

Các dạng xem hình thức của nội dung hồ sơ

Mô tả profile, differential, snapshot và các biểu diễn liên quan.

NameFlagsCard.TypeDescription & Constraints    Filter: Filtersdoco
.. Consent C 0..* Consent A healthcare consumer's choices to permit or deny recipients or roles to perform actions for specific purposes and periods of time
Constraints: ppc-1, ppc-2, ppc-3, ppc-4, ppc-5, vn-consent-rejected-not-permit, vn-consent-provision-structure, vn-consent-no-processing-legal-basis, vn-consent-permit-requires-disclosure, vn-consent-permit-evidence-retained, vn-consent-choice-actor-identifiable, vn-consent-permit-purpose-required, vn-consent-disclosed-controller-role, vn-consent-rights-notice-versioned, vn-consent-sensitive-notice-required, vn-consent-disclosure-before-consent
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... Slices for extension 0..* Extension Extension
Slice: Unordered, Open by value:url
.... extension:consentMethod SO 0..1 CodeableConcept Phương thức chủ thể dữ liệu thể hiện sự đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-method
Binding: Phương thức thể hiện đồng ý — VN Consent Method VS (required)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... extension:consentDisclosure SO 0..1 (Complex) Nội dung đã thông báo cho chủ thể khi xin đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... modifierExtension ?! 0..* Extension Extensions that cannot be ignored
... scope ?!SOΣ 1..1 CodeableConcept Phạm vi đồng ý
Binding: ConsentScopeCodes (extensible): The four anticipated uses for the Consent Resource.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... category SOΣ 1..* CodeableConcept Loại đồng ý
Binding: Loại đồng ý — VN Consent Category ValueSet (extensible)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... patient SOΣ 1..1 Reference(Bệnh nhân VN Core — VN Core Patient Profile) Chủ thể dữ liệu
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... dateTime SOΣ 1..1 dateTime Thời điểm đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... performer SOΣ 0..* Reference(Bệnh nhân VN Core — VN Core Patient Profile | Người liên quan/người giám hộ VN Core — VN Core RelatedPerson Profile | Nhân viên y tế VN Core — VN Core Practitioner Profile) Người đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... organization SOΣ 0..* Reference(Cơ sở y tế VN Core — VN Core Organization Profile) CSKCB quản lý đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... source[x] SOΣ 0..1 Bản gốc đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... sourceAttachment Attachment
.... sourceReference Reference(Consent | DocumentReference | Contract | QuestionnaireResponse)
... policy SO 0..* BackboneElement Căn cứ pháp lý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... authority C 0..1 uri Cơ quan ban hành
.... uri SC 0..1 uri URL văn bản pháp lý
... provision SOΣ 0..1 BackboneElement Quy tắc đồng ý chi tiết
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... period SΣ 0..1 Period Thời hạn hiệu lực
.... actor 0..* BackboneElement Bên liên quan
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... role 1..1 CodeableConcept How the actor is involved
Binding: SecurityRoleType (extensible): How an actor is involved in the consent considerations.
..... reference 1..1 Reference(Device | Group | CareTeam | Organization | Patient | Practitioner | RelatedPerson | PractitionerRole) Resource for the actor (or group, by role)
.... purpose SΣ 0..* Coding Mục đích xử lý
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)
.... class Σ 0..* Coding Loại dữ liệu
Binding: ConsentContentClass (extensible): The class (type) of information a consent rule covers.
.... provision S 0..* BackboneElement Các rule permit/deny
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... type SΣ 1..1 code Cho phép / Từ chối
Binding: ConsentProvisionType (required): How a rule statement is applied, such as adding additional consent or removing consent.
..... Slices for actor 0..* BackboneElement Who|what controlled by this rule (or group, by role)
Slice: Unordered, Open by exists:extension('http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-representation-authority')
...... actor:All Slices Content/Rules for all slices
....... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
....... role 1..1 CodeableConcept How the actor is involved
Binding: SecurityRoleType (extensible): How an actor is involved in the consent considerations.
....... reference 1..1 Reference(Device | Group | CareTeam | Organization | Patient | Practitioner | RelatedPerson | PractitionerRole) Resource for the actor (or group, by role)
...... actor:representative S 0..* BackboneElement Người đại diện/giám hộ — mang token thẩm quyền
....... Slices for extension 1..* Extension Extension
Slice: Unordered, Open by value:url
....... Slices for extension Content/Rules for all slices
........ extension:representationAuthority SC 1..1 (Complex) Thẩm quyền đại diện truy cập dữ liệu — Representation Authority Extension
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-representation-authority
Constraints: vn-representation-domain-basis, vn-representation-type-selection-basis, vn-representation-proxy-evidence, vn-representation-proxy-bounded
....... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
....... role 1..1 CodeableConcept How the actor is involved
Binding: SecurityRoleType (extensible): How an actor is involved in the consent considerations.
....... reference 1..1 Reference(Người liên quan/người giám hộ VN Core — VN Core RelatedPerson Profile) Resource for the actor (or group, by role)
..... securityLabel SΣ 0..* Coding Lớp nhạy cảm dữ liệu áp cho rule
Binding: Lớp nhạy cảm dữ liệu y tế — Vietnam Health Data Sensitivity Class ValueSet (extensible)
..... purpose Σ 0..* Coding Mục đích xử lý của rule này
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)

doco Documentation for this format
NameKho hồ sơ EMR (Repository)Ứng dụng người dân (Citizen App)Nguồn tạo hồ sơ lâm sàng (Document Source)doco
.. Consent
... Slices for extension
.... extension:consentMethod
.... extension:consentDisclosure
... status
... scope
... patient
... dateTime
... performer
... organization
... source[x]
... policy
... provision

doco Documentation for this format

Terminology Bindings

Path Status Usage ValueSet Version Source
Consent.status Base required ConsentState 📍4.0.1 FHIR Std.
Consent.scope Base extensible Consent Scope Codes 📍4.0.1 FHIR Std.
Consent.category Base extensible Loại đồng ý — VN Consent Category ValueSet 📦0.10.0 This IG
Consent.provision.actor.​role Base extensible SecurityRoleType 📍4.0.1 FHIR Std.
Consent.provision.purpose Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG
Consent.provision.class Base extensible Consent Content Class 📍4.0.1 FHIR Std.
Consent.provision.provision.​type Base required ConsentProvisionType 📍4.0.1 FHIR Std.
Consent.provision.provision.​actor.role Base extensible SecurityRoleType 📍4.0.1 FHIR Std.
Consent.provision.provision.​actor:representative.​role Base extensible SecurityRoleType 📍4.0.1 FHIR Std.
Consent.provision.provision.​securityLabel Base extensible Lớp nhạy cảm dữ liệu y tế — Vietnam Health Data Sensitivity Class ValueSet 📦0.10.0 This IG
Consent.provision.provision.​purpose Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG

Constraints

Id Grade Path(s) Description Expression
dom-2 error Consent If the resource is contained in another resource, it SHALL NOT contain nested Resources contained.contained.empty()
dom-3 error Consent If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().as(canonical) | %resource.descendants().as(uri) | %resource.descendants().as(url))) or descendants().where(reference = '#').exists() or descendants().where(as(canonical) = '#').exists() or descendants().where(as(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
dom-4 error Consent If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
dom-5 error Consent If a resource is contained in another resource, it SHALL NOT have a security label contained.meta.security.empty()
dom-6 best practice Consent A resource should have narrative for robust management text.`div`.exists()
ele-1 error **ALL** elements All FHIR elements must have a @value or children hasValue() or (children().count() > id.count())
ext-1 error **ALL** extensions Must have either extensions or value[x], not both extension.exists() != value.exists()
ppc-1 error Consent Either a Policy or PolicyRule policy.exists() or policyRule.exists()
ppc-2 error Consent IF Scope=privacy, there must be a patient patient.exists() or scope.coding.where(system='something' and code='patient-privacy').exists().not()
ppc-3 error Consent IF Scope=research, there must be a patient patient.exists() or scope.coding.where(system='something' and code='research').exists().not()
ppc-4 error Consent IF Scope=adr, there must be a patient patient.exists() or scope.coding.where(system='something' and code='adr').exists().not()
ppc-5 error Consent IF Scope=treatment, there must be a patient patient.exists() or scope.coding.where(system='something' and code='treatment').exists().not()
vn-consent-choice-actor-identifiable error Consent Bản ghi có rule permit/deny phải xác định được NGƯỜI thực hiện lựa chọn: performer, hoặc bằng chứng trỏ được tới người đó (source[x] trong FHIR / evidenceLocator ngoài FHIR) — Luật 91/2025/QH15 Điều 9 khoản 3 (sự đồng ý phải kiểm chứng được), Điều 4 khoản 1 điểm b (quyền không đồng ý), Điều 24 (đại diện). A subject-choice record SHALL identify who made the choice via performer or locatable evidence. provision.repeat(provision).type.exists() implies (performer.where(reference.exists() or identifier.exists()).exists() or source.exists() or extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'evidenceLocator').exists())
vn-consent-disclosed-controller-role error Consent Vai trò được thông báo cho chủ thể chỉ có thể là bên kiểm soát hoặc bên kiểm soát và xử lý — Luật 91/2025/QH15 Điều 9 khoản 2 điểm b. Bên xử lý và bên thứ ba không phải chủ thể của nghĩa vụ thông báo này. The disclosed party role SHALL be controller or controller-processor. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'controllerRole').value.ofType(Coding).code.all($this in ('controller' | 'controller-processor'))
vn-consent-disclosure-before-consent error Consent Thời điểm trình nội dung thông báo không được sau thời điểm đồng ý — sự đồng ý chỉ có hiệu lực khi chủ thể ĐÃ biết rõ các thông tin đó (Luật 91/2025/QH15 Điều 9 khoản 2). Disclosure SHALL NOT be timestamped after the consent itself. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'disclosedAt').value.ofType(dateTime).all($this <= %resource.dateTime)
vn-consent-no-processing-legal-basis error Consent VNCoreConsent 0.9 chỉ biểu diễn lựa chọn của chủ thể và không được mang vn-ext-processing-legal-basis; xử lý không qua đồng ý dùng VNCoreAuditEventLegalBasisDecision / VNCoreConsent 0.9 represents data-subject choices only and SHALL NOT carry vn-ext-processing-legal-basis; processing without consent uses VNCoreAuditEventLegalBasisDecision extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-processing-legal-basis').empty()
vn-consent-permit-evidence-retained error Consent Bản ghi có rule permit phải trỏ tới bằng chứng đồng ý đã lưu: source[x] trong FHIR hoặc evidenceLocator ngoài FHIR — NĐ 356/2025/NĐ-CP Điều 6 khoản 2 (bên kiểm soát lưu trữ sự đồng ý và chịu trách nhiệm chứng minh khi tranh chấp). Retained consent evidence SHALL be locatable. provision.repeat(provision).type.where($this = 'permit').exists() implies (source.exists() or extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'evidenceLocator').exists())
vn-consent-permit-purpose-required error Consent Mỗi rule permit phải nêu mục đích xử lý — Luật 91/2025/QH15 Điều 9 khoản 2 điểm a (mục đích xử lý là nội dung phải thông báo) và khoản 4 điểm a (đồng ý theo TỪNG mục đích). Every permit rule SHALL state its processing purpose. provision.repeat(provision).where(type = 'permit').all(purpose.exists())
vn-consent-permit-requires-disclosure error Consent Bản ghi có rule permit phải mang nội dung đã thông báo (vn-ext-consent-disclosure) và phương thức thể hiện đồng ý (vn-ext-consent-method) — Luật 91/2025/QH15 Điều 9 khoản 2 và khoản 3; NĐ 356/2025/NĐ-CP Điều 6 khoản 1. A consent granting any permit rule SHALL carry the disclosure evidence and the declared consent method. provision.repeat(provision).type.where($this = 'permit').exists() implies (extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').exists() and extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-method').exists())
vn-consent-provision-structure error Consent Theo R4: root rule (Consent.provision) KHÔNG mang type; mọi rule permit/deny khai ở nested (provision.provision[*]) và bắt buộc có type provision.exists() implies (provision.type.empty() and provision.provision.exists() and provision.repeat(provision).all(type.exists()))
vn-consent-rejected-not-permit error Consent Bản ghi status=rejected (từ chối ngay từ đầu) không được chứa rule permit ở BẤT KỲ độ sâu nested nào — cho phép đang hiệu lực phải dùng status=active (status = 'rejected') implies provision.repeat(provision).type.where($this = 'permit').empty()
vn-consent-rights-notice-versioned error Consent Bản thông báo quyền và nghĩa vụ phải xác định được ĐÚNG bản đã trình: dùng DocumentReference, hoặc URL có ghim phiên bản. The rights notice SHALL be identifiable as the exact version presented. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'rightsNotice').all(value.ofType(Reference).exists() or value.ofType(url).matches('/v[0-9]'))
vn-consent-sensitive-notice-required error Consent Nếu nội dung đã thông báo có loại dữ liệu thuộc danh mục nhạy cảm (NĐ 356/2025/NĐ-CP Điều 4 khoản 1) thì phải khai đã thông báo cho chủ thể rằng dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm — NĐ 356/2025/NĐ-CP Điều 6 khoản 4. Disclosing a sensitive-category data type SHALL come with the explicit sensitive-data notice. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'dataCategory').value.ofType(CodeableConcept).coding.where(system = 'http://fhir.hl7.org.vn/core/CodeSystem/vn-sensitive-personal-data-cs').exists() implies extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'sensitiveDataNotice').value.ofType(boolean) = true
vn-representation-domain-basis error Consent.provision.provision.actor:representative.extension:representationAuthority Miền quyết định khám chữa bệnh bắt buộc có căn cứ lựa chọn theo Luật KCB Điều 8 khoản 2; miền quyền chủ thể dữ liệu không dùng trục căn cứ đó. The healthcare-decision domain SHALL carry a selectionBasis; the data-subject-rights domain SHALL NOT. (extension.where(url='domain').value.ofType(Coding).code = 'healthcare-decision' implies extension.where(url='selectionBasis').exists()) and (extension.where(url='domain').value.ofType(Coding).code = 'data-subject-rights' implies extension.where(url='selectionBasis').empty())
vn-representation-proxy-bounded error Consent.provision.provision.actor:representative.extension:representationAuthority Thẩm quyền theo uỷ quyền phải có GIỚI HẠN máy-đọc: NGÀY KẾT THÚC (period.end của token hoặc validity.end trong bằng chứng — chỉ có ngày bắt đầu là uỷ quyền vô thời hạn) VÀ phạm vi (scope trong ít nhất một bằng chứng) — Bộ luật Dân sự Điều 138/140/141. A delegated-proxy authority SHALL carry a machine-readable validity bound AND scope. extension.where(url='type').value.ofType(Coding).code != 'delegated-proxy' or ((extension.where(url='period').value.ofType(Period).end.exists() or extension.where(url='evidence').extension.where(url='validity').value.ofType(Period).end.exists()) and extension.where(url='evidence').extension.where(url='scope').exists())
vn-representation-proxy-evidence error Consent.provision.provision.actor:representative.extension:representationAuthority Thẩm quyền theo uỷ quyền phải kèm ít nhất một bằng chứng (văn bản uỷ quyền). A delegated-proxy authority SHALL carry at least one evidence entry. extension.where(url='type').value.ofType(Coding).code = 'delegated-proxy' implies extension.where(url='evidence').exists()
vn-representation-type-selection-basis error Consent.provision.provision.actor:representative.extension:representationAuthority Loại thẩm quyền phải tương thích với nhóm căn cứ lựa chọn tại Luật KCB Điều 8 khoản 2. The authority type SHALL be consistent with the statutory selection basis. extension.where(url='selectionBasis').empty() or ((extension.where(url='selectionBasis').value.ofType(Coding).code = 'civil-code-representative') and (extension.where(url='type').value.ofType(Coding).code = 'legal-representative' or extension.where(url='type').value.ofType(Coding).code = 'guardian' or extension.where(url='type').value.ofType(Coding).code = 'delegated-proxy')) or ((extension.where(url='selectionBasis').value.ofType(Coding).code = 'responsible-legal-entity-appointed') and (extension.where(url='type').value.ofType(Coding).code = 'legal-representative' or extension.where(url='type').value.ofType(Coding).code = 'healthcare-agent')) or ((extension.where(url='selectionBasis').value.ofType(Coding).code = 'adult-patient-selected' or extension.where(url='selectionBasis').value.ofType(Coding).code = 'family-selected' or extension.where(url='selectionBasis').value.ofType(Coding).code = 'voluntary-obligation-performer') and extension.where(url='type').value.ofType(Coding).code = 'healthcare-agent')

NameFlagsCard.TypeDescription & Constraints    Filter: Filtersdoco
.. Consent C 0..* Consent A healthcare consumer's choices to permit or deny recipients or roles to perform actions for specific purposes and periods of time
Constraints: vn-consent-rejected-not-permit, vn-consent-provision-structure, vn-consent-no-processing-legal-basis, vn-consent-permit-requires-disclosure, vn-consent-permit-evidence-retained, vn-consent-choice-actor-identifiable, vn-consent-permit-purpose-required, vn-consent-disclosed-controller-role, vn-consent-rights-notice-versioned, vn-consent-sensitive-notice-required, vn-consent-disclosure-before-consent
... Slices for extension 0..* Extension Extension
Slice: Unordered, Open by value:url
.... extension:processingLegalBasis 0..0 CodeableConcept Cấm authoring căn cứ Điều 19 trên Consent / No Article 19 authoring on Consent
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-processing-legal-basis
Binding: Căn cứ xử lý DLCN không cần sự đồng ý — VN Processing Legal Basis ValueSet (required)
.... extension:consentMethod SO 0..1 CodeableConcept Phương thức chủ thể dữ liệu thể hiện sự đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-method
Binding: Phương thức thể hiện đồng ý — VN Consent Method VS (required)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... extension:consentDisclosure SO 0..1 (Complex) Nội dung đã thông báo cho chủ thể khi xin đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... status SO 1..1 code Trạng thái đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... scope SO 1..1 CodeableConcept Phạm vi đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... patient SO 1..1 Reference(Bệnh nhân VN Core — VN Core Patient Profile) Chủ thể dữ liệu
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... dateTime SO 1..1 dateTime Thời điểm đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... performer SO 0..* Reference(Bệnh nhân VN Core — VN Core Patient Profile | Người liên quan/người giám hộ VN Core — VN Core RelatedPerson Profile | Nhân viên y tế VN Core — VN Core Practitioner Profile) Người đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... organization SO 0..* Reference(Cơ sở y tế VN Core — VN Core Organization Profile) CSKCB quản lý đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... source[x] SO 0..1 Attachment, Reference(Consent | DocumentReference | Contract | QuestionnaireResponse) Bản gốc đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... policy SO 0..* BackboneElement Căn cứ pháp lý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... authority 0..1 uri Cơ quan ban hành
.... uri S 0..1 uri URL văn bản pháp lý
... provision SO 0..1 BackboneElement Quy tắc đồng ý chi tiết
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... type 0..0 deny | permit
.... period S 0..1 Period Thời hạn hiệu lực
.... actor 0..* BackboneElement Bên liên quan
.... purpose S 0..* Coding Mục đích xử lý
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)
.... class 0..* Coding Loại dữ liệu
.... provision S 0..* BackboneElement Các rule permit/deny
..... type S 1..1 code Cho phép / Từ chối
..... Slices for actor 0..* BackboneElement Who|what controlled by this rule (or group, by role)
Slice: Unordered, Open by exists:extension('http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-representation-authority')
...... actor:representative S 0..* BackboneElement Người đại diện/giám hộ — mang token thẩm quyền
....... Slices for extension 1..* Extension Extension
Slice: Unordered, Open by value:url
....... Slices for extension Content/Rules for all slices
........ extension:representationAuthority S 1..1 (Complex) Thẩm quyền đại diện truy cập dữ liệu — Representation Authority Extension
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-representation-authority
....... reference 1..1 Reference(Người liên quan/người giám hộ VN Core — VN Core RelatedPerson Profile) Resource for the actor (or group, by role)
..... securityLabel S 0..* Coding Lớp nhạy cảm dữ liệu áp cho rule
Binding: Lớp nhạy cảm dữ liệu y tế — Vietnam Health Data Sensitivity Class ValueSet (extensible)
..... purpose 0..* Coding Mục đích xử lý của rule này
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)

doco Documentation for this format
NameKho hồ sơ EMR (Repository)Ứng dụng người dân (Citizen App)Nguồn tạo hồ sơ lâm sàng (Document Source)doco
.. Consent
... Slices for extension
.... extension:consentMethod
.... extension:consentDisclosure
... status
... scope
... patient
... dateTime
... performer
... organization
... source[x]
... policy
... provision

doco Documentation for this format

Terminology Bindings (Differential)

Path Status Usage ValueSet Version Source
Consent.category Base extensible Loại đồng ý — VN Consent Category ValueSet 📦0.10.0 This IG
Consent.provision.purpose Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG
Consent.provision.provision.​securityLabel Base extensible Lớp nhạy cảm dữ liệu y tế — Vietnam Health Data Sensitivity Class ValueSet 📦0.10.0 This IG
Consent.provision.provision.​purpose Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG

Constraints

Id Grade Path(s) Description Expression
vn-consent-choice-actor-identifiable error Consent Bản ghi có rule permit/deny phải xác định được NGƯỜI thực hiện lựa chọn: performer, hoặc bằng chứng trỏ được tới người đó (source[x] trong FHIR / evidenceLocator ngoài FHIR) — Luật 91/2025/QH15 Điều 9 khoản 3 (sự đồng ý phải kiểm chứng được), Điều 4 khoản 1 điểm b (quyền không đồng ý), Điều 24 (đại diện). A subject-choice record SHALL identify who made the choice via performer or locatable evidence. provision.repeat(provision).type.exists() implies (performer.where(reference.exists() or identifier.exists()).exists() or source.exists() or extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'evidenceLocator').exists())
vn-consent-disclosed-controller-role error Consent Vai trò được thông báo cho chủ thể chỉ có thể là bên kiểm soát hoặc bên kiểm soát và xử lý — Luật 91/2025/QH15 Điều 9 khoản 2 điểm b. Bên xử lý và bên thứ ba không phải chủ thể của nghĩa vụ thông báo này. The disclosed party role SHALL be controller or controller-processor. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'controllerRole').value.ofType(Coding).code.all($this in ('controller' | 'controller-processor'))
vn-consent-disclosure-before-consent error Consent Thời điểm trình nội dung thông báo không được sau thời điểm đồng ý — sự đồng ý chỉ có hiệu lực khi chủ thể ĐÃ biết rõ các thông tin đó (Luật 91/2025/QH15 Điều 9 khoản 2). Disclosure SHALL NOT be timestamped after the consent itself. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'disclosedAt').value.ofType(dateTime).all($this <= %resource.dateTime)
vn-consent-no-processing-legal-basis error Consent VNCoreConsent 0.9 chỉ biểu diễn lựa chọn của chủ thể và không được mang vn-ext-processing-legal-basis; xử lý không qua đồng ý dùng VNCoreAuditEventLegalBasisDecision / VNCoreConsent 0.9 represents data-subject choices only and SHALL NOT carry vn-ext-processing-legal-basis; processing without consent uses VNCoreAuditEventLegalBasisDecision extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-processing-legal-basis').empty()
vn-consent-permit-evidence-retained error Consent Bản ghi có rule permit phải trỏ tới bằng chứng đồng ý đã lưu: source[x] trong FHIR hoặc evidenceLocator ngoài FHIR — NĐ 356/2025/NĐ-CP Điều 6 khoản 2 (bên kiểm soát lưu trữ sự đồng ý và chịu trách nhiệm chứng minh khi tranh chấp). Retained consent evidence SHALL be locatable. provision.repeat(provision).type.where($this = 'permit').exists() implies (source.exists() or extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'evidenceLocator').exists())
vn-consent-permit-purpose-required error Consent Mỗi rule permit phải nêu mục đích xử lý — Luật 91/2025/QH15 Điều 9 khoản 2 điểm a (mục đích xử lý là nội dung phải thông báo) và khoản 4 điểm a (đồng ý theo TỪNG mục đích). Every permit rule SHALL state its processing purpose. provision.repeat(provision).where(type = 'permit').all(purpose.exists())
vn-consent-permit-requires-disclosure error Consent Bản ghi có rule permit phải mang nội dung đã thông báo (vn-ext-consent-disclosure) và phương thức thể hiện đồng ý (vn-ext-consent-method) — Luật 91/2025/QH15 Điều 9 khoản 2 và khoản 3; NĐ 356/2025/NĐ-CP Điều 6 khoản 1. A consent granting any permit rule SHALL carry the disclosure evidence and the declared consent method. provision.repeat(provision).type.where($this = 'permit').exists() implies (extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').exists() and extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-method').exists())
vn-consent-provision-structure error Consent Theo R4: root rule (Consent.provision) KHÔNG mang type; mọi rule permit/deny khai ở nested (provision.provision[*]) và bắt buộc có type provision.exists() implies (provision.type.empty() and provision.provision.exists() and provision.repeat(provision).all(type.exists()))
vn-consent-rejected-not-permit error Consent Bản ghi status=rejected (từ chối ngay từ đầu) không được chứa rule permit ở BẤT KỲ độ sâu nested nào — cho phép đang hiệu lực phải dùng status=active (status = 'rejected') implies provision.repeat(provision).type.where($this = 'permit').empty()
vn-consent-rights-notice-versioned error Consent Bản thông báo quyền và nghĩa vụ phải xác định được ĐÚNG bản đã trình: dùng DocumentReference, hoặc URL có ghim phiên bản. The rights notice SHALL be identifiable as the exact version presented. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'rightsNotice').all(value.ofType(Reference).exists() or value.ofType(url).matches('/v[0-9]'))
vn-consent-sensitive-notice-required error Consent Nếu nội dung đã thông báo có loại dữ liệu thuộc danh mục nhạy cảm (NĐ 356/2025/NĐ-CP Điều 4 khoản 1) thì phải khai đã thông báo cho chủ thể rằng dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm — NĐ 356/2025/NĐ-CP Điều 6 khoản 4. Disclosing a sensitive-category data type SHALL come with the explicit sensitive-data notice. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'dataCategory').value.ofType(CodeableConcept).coding.where(system = 'http://fhir.hl7.org.vn/core/CodeSystem/vn-sensitive-personal-data-cs').exists() implies extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'sensitiveDataNotice').value.ofType(boolean) = true
NameFlagsCard.TypeDescription & Constraints    Filter: Filtersdoco
.. Consent C 0..* Consent A healthcare consumer's choices to permit or deny recipients or roles to perform actions for specific purposes and periods of time
Constraints: ppc-1, ppc-2, ppc-3, ppc-4, ppc-5, vn-consent-rejected-not-permit, vn-consent-provision-structure, vn-consent-no-processing-legal-basis, vn-consent-permit-requires-disclosure, vn-consent-permit-evidence-retained, vn-consent-choice-actor-identifiable, vn-consent-permit-purpose-required, vn-consent-disclosed-controller-role, vn-consent-rights-notice-versioned, vn-consent-sensitive-notice-required, vn-consent-disclosure-before-consent
... id Σ 0..1 id Logical id of this artifact
... meta Σ 0..1 Meta Metadata about the resource
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... text 0..1 Narrative Text summary of the resource, for human interpretation
This profile does not constrain the narrative in regard to content, language, or traceability to data elements
... contained 0..* Resource Contained, inline Resources
... Slices for extension 0..* Extension Extension
Slice: Unordered, Open by value:url
.... extension:consentMethod SO 0..1 CodeableConcept Phương thức chủ thể dữ liệu thể hiện sự đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-method
Binding: Phương thức thể hiện đồng ý — VN Consent Method VS (required)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... extension:consentDisclosure SO 0..1 (Complex) Nội dung đã thông báo cho chủ thể khi xin đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... modifierExtension ?! 0..* Extension Extensions that cannot be ignored
... identifier Σ 0..* Identifier Identifier for this record (external references)

Example General: {"system":"http://acme.org/identifier/local/eCMS","value":"Local eCMS identifier"}
... status ?!SOΣ 1..1 code Trạng thái đồng ý
Binding: ConsentState (required): Indicates the state of the consent.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... scope ?!SOΣ 1..1 CodeableConcept Phạm vi đồng ý
Binding: ConsentScopeCodes (extensible): The four anticipated uses for the Consent Resource.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... category SOΣ 1..* CodeableConcept Loại đồng ý
Binding: Loại đồng ý — VN Consent Category ValueSet (extensible)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... patient SOΣ 1..1 Reference(Bệnh nhân VN Core — VN Core Patient Profile) Chủ thể dữ liệu
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... dateTime SOΣ 1..1 dateTime Thời điểm đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... performer SOΣ 0..* Reference(Bệnh nhân VN Core — VN Core Patient Profile | Người liên quan/người giám hộ VN Core — VN Core RelatedPerson Profile | Nhân viên y tế VN Core — VN Core Practitioner Profile) Người đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... organization SOΣ 0..* Reference(Cơ sở y tế VN Core — VN Core Organization Profile) CSKCB quản lý đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... source[x] SOΣ 0..1 Bản gốc đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... sourceAttachment Attachment
.... sourceReference Reference(Consent | DocumentReference | Contract | QuestionnaireResponse)
... policy SO 0..* BackboneElement Căn cứ pháp lý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... authority C 0..1 uri Cơ quan ban hành
.... uri SC 0..1 uri URL văn bản pháp lý
... policyRule ΣC 0..1 CodeableConcept Regulation that this consents to
Binding: ConsentPolicyRuleCodes (extensible): Regulatory policy examples.
... verification Σ 0..* BackboneElement Consent Verified by patient or family
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... verified Σ 1..1 boolean Has been verified
.... verifiedWith 0..1 Reference(Patient | RelatedPerson) Person who verified
.... verificationDate 0..1 dateTime When consent verified
... provision SOΣ 0..1 BackboneElement Quy tắc đồng ý chi tiết
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... period SΣ 0..1 Period Thời hạn hiệu lực
.... actor 0..* BackboneElement Bên liên quan
..... id 0..1 string Unique id for inter-element referencing
..... extension 0..* Extension Additional content defined by implementations
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... role 1..1 CodeableConcept How the actor is involved
Binding: SecurityRoleType (extensible): How an actor is involved in the consent considerations.
..... reference 1..1 Reference(Device | Group | CareTeam | Organization | Patient | Practitioner | RelatedPerson | PractitionerRole) Resource for the actor (or group, by role)
.... action Σ 0..* CodeableConcept Actions controlled by this rule
Binding: ConsentActionCodes (example): Detailed codes for the consent action.
.... securityLabel Σ 0..* Coding Security Labels that define affected resources
Binding: All Security Labels (extensible): Security Labels from the Healthcare Privacy and Security Classification System.
.... purpose SΣ 0..* Coding Mục đích xử lý
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)
.... class Σ 0..* Coding Loại dữ liệu
Binding: ConsentContentClass (extensible): The class (type) of information a consent rule covers.
.... code Σ 0..* CodeableConcept e.g. LOINC or SNOMED CT code, etc. in the content
Binding: ConsentContentCodes (example): If this code is found in an instance, then the exception applies.
.... dataPeriod Σ 0..1 Period Timeframe for data controlled by this rule
.... data Σ 0..* BackboneElement Data controlled by this rule
..... id 0..1 string Unique id for inter-element referencing
..... extension 0..* Extension Additional content defined by implementations
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... meaning Σ 1..1 code instance | related | dependents | authoredby
Binding: ConsentDataMeaning (required): How a resource reference is interpreted when testing consent restrictions.
..... reference Σ 1..1 Reference(Resource) The actual data reference
.... provision S 0..* BackboneElement Các rule permit/deny
..... id 0..1 string Unique id for inter-element referencing
..... extension 0..* Extension Additional content defined by implementations
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... type SΣ 1..1 code Cho phép / Từ chối
Binding: ConsentProvisionType (required): How a rule statement is applied, such as adding additional consent or removing consent.
..... period Σ 0..1 Period Timeframe for this rule
..... Slices for actor 0..* BackboneElement Who|what controlled by this rule (or group, by role)
Slice: Unordered, Open by exists:extension('http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-representation-authority')
...... actor:All Slices Content/Rules for all slices
....... id 0..1 string Unique id for inter-element referencing
....... extension 0..* Extension Additional content defined by implementations
....... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
....... role 1..1 CodeableConcept How the actor is involved
Binding: SecurityRoleType (extensible): How an actor is involved in the consent considerations.
....... reference 1..1 Reference(Device | Group | CareTeam | Organization | Patient | Practitioner | RelatedPerson | PractitionerRole) Resource for the actor (or group, by role)
...... actor:representative S 0..* BackboneElement Người đại diện/giám hộ — mang token thẩm quyền
....... id 0..1 string Unique id for inter-element referencing
....... Slices for extension 1..* Extension Extension
Slice: Unordered, Open by value:url
....... Slices for extension Content/Rules for all slices
........ extension:representationAuthority SC 1..1 (Complex) Thẩm quyền đại diện truy cập dữ liệu — Representation Authority Extension
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-representation-authority
Constraints: vn-representation-domain-basis, vn-representation-type-selection-basis, vn-representation-proxy-evidence, vn-representation-proxy-bounded
....... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
....... role 1..1 CodeableConcept How the actor is involved
Binding: SecurityRoleType (extensible): How an actor is involved in the consent considerations.
....... reference 1..1 Reference(Người liên quan/người giám hộ VN Core — VN Core RelatedPerson Profile) Resource for the actor (or group, by role)
..... action Σ 0..* CodeableConcept Actions controlled by this rule
Binding: ConsentActionCodes (example): Detailed codes for the consent action.
..... securityLabel SΣ 0..* Coding Lớp nhạy cảm dữ liệu áp cho rule
Binding: Lớp nhạy cảm dữ liệu y tế — Vietnam Health Data Sensitivity Class ValueSet (extensible)
..... purpose Σ 0..* Coding Mục đích xử lý của rule này
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)
..... class Σ 0..* Coding e.g. Resource Type, Profile, CDA, etc.
Binding: ConsentContentClass (extensible): The class (type) of information a consent rule covers.
..... code Σ 0..* CodeableConcept e.g. LOINC or SNOMED CT code, etc. in the content
Binding: ConsentContentCodes (example): If this code is found in an instance, then the exception applies.
..... dataPeriod Σ 0..1 Period Timeframe for data controlled by this rule
..... data Σ 0..* BackboneElement Data controlled by this rule
...... id 0..1 string Unique id for inter-element referencing
...... extension 0..* Extension Additional content defined by implementations
...... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
...... meaning Σ 1..1 code instance | related | dependents | authoredby
Binding: ConsentDataMeaning (required): How a resource reference is interpreted when testing consent restrictions.
...... reference Σ 1..1 Reference(Resource) The actual data reference
..... provision 0..* See provision (Consent) Nested Exception Rules

doco Documentation for this format
NameKho hồ sơ EMR (Repository)Ứng dụng người dân (Citizen App)Nguồn tạo hồ sơ lâm sàng (Document Source)doco
.. Consent
... Slices for extension
.... extension:consentMethod
.... extension:consentDisclosure
... status
... scope
... patient
... dateTime
... performer
... organization
... source[x]
... policy
... provision

doco Documentation for this format

Terminology Bindings

Path Status Usage ValueSet Version Source
Consent.language Base preferred Common Languages 📍4.0.1 FHIR Std.
Consent.status Base required ConsentState 📍4.0.1 FHIR Std.
Consent.scope Base extensible Consent Scope Codes 📍4.0.1 FHIR Std.
Consent.category Base extensible Loại đồng ý — VN Consent Category ValueSet 📦0.10.0 This IG
Consent.policyRule Base extensible Consent PolicyRule Codes 📍4.0.1 FHIR Std.
Consent.provision.actor.​role Base extensible SecurityRoleType 📍4.0.1 FHIR Std.
Consent.provision.action Base example Consent Action Codes 📍4.0.1 FHIR Std.
Consent.provision.securityLabel Base extensible SecurityLabels 📍4.0.1 FHIR Std.
Consent.provision.purpose Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG
Consent.provision.class Base extensible Consent Content Class 📍4.0.1 FHIR Std.
Consent.provision.code Base example Consent Content Codes 📍4.0.1 FHIR Std.
Consent.provision.data.​meaning Base required ConsentDataMeaning 📍4.0.1 FHIR Std.
Consent.provision.provision.​type Base required ConsentProvisionType 📍4.0.1 FHIR Std.
Consent.provision.provision.​actor.role Base extensible SecurityRoleType 📍4.0.1 FHIR Std.
Consent.provision.provision.​actor:representative.​role Base extensible SecurityRoleType 📍4.0.1 FHIR Std.
Consent.provision.provision.​action Base example Consent Action Codes 📍4.0.1 FHIR Std.
Consent.provision.provision.​securityLabel Base extensible Lớp nhạy cảm dữ liệu y tế — Vietnam Health Data Sensitivity Class ValueSet 📦0.10.0 This IG
Consent.provision.provision.​purpose Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG
Consent.provision.provision.​class Base extensible Consent Content Class 📍4.0.1 FHIR Std.
Consent.provision.provision.​code Base example Consent Content Codes 📍4.0.1 FHIR Std.
Consent.provision.provision.​data.meaning Base required ConsentDataMeaning 📍4.0.1 FHIR Std.

Constraints

Id Grade Path(s) Description Expression
dom-2 error Consent If the resource is contained in another resource, it SHALL NOT contain nested Resources contained.contained.empty()
dom-3 error Consent If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().as(canonical) | %resource.descendants().as(uri) | %resource.descendants().as(url))) or descendants().where(reference = '#').exists() or descendants().where(as(canonical) = '#').exists() or descendants().where(as(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
dom-4 error Consent If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
dom-5 error Consent If a resource is contained in another resource, it SHALL NOT have a security label contained.meta.security.empty()
dom-6 best practice Consent A resource should have narrative for robust management text.`div`.exists()
ele-1 error **ALL** elements All FHIR elements must have a @value or children hasValue() or (children().count() > id.count())
ext-1 error **ALL** extensions Must have either extensions or value[x], not both extension.exists() != value.exists()
ppc-1 error Consent Either a Policy or PolicyRule policy.exists() or policyRule.exists()
ppc-2 error Consent IF Scope=privacy, there must be a patient patient.exists() or scope.coding.where(system='something' and code='patient-privacy').exists().not()
ppc-3 error Consent IF Scope=research, there must be a patient patient.exists() or scope.coding.where(system='something' and code='research').exists().not()
ppc-4 error Consent IF Scope=adr, there must be a patient patient.exists() or scope.coding.where(system='something' and code='adr').exists().not()
ppc-5 error Consent IF Scope=treatment, there must be a patient patient.exists() or scope.coding.where(system='something' and code='treatment').exists().not()
vn-consent-choice-actor-identifiable error Consent Bản ghi có rule permit/deny phải xác định được NGƯỜI thực hiện lựa chọn: performer, hoặc bằng chứng trỏ được tới người đó (source[x] trong FHIR / evidenceLocator ngoài FHIR) — Luật 91/2025/QH15 Điều 9 khoản 3 (sự đồng ý phải kiểm chứng được), Điều 4 khoản 1 điểm b (quyền không đồng ý), Điều 24 (đại diện). A subject-choice record SHALL identify who made the choice via performer or locatable evidence. provision.repeat(provision).type.exists() implies (performer.where(reference.exists() or identifier.exists()).exists() or source.exists() or extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'evidenceLocator').exists())
vn-consent-disclosed-controller-role error Consent Vai trò được thông báo cho chủ thể chỉ có thể là bên kiểm soát hoặc bên kiểm soát và xử lý — Luật 91/2025/QH15 Điều 9 khoản 2 điểm b. Bên xử lý và bên thứ ba không phải chủ thể của nghĩa vụ thông báo này. The disclosed party role SHALL be controller or controller-processor. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'controllerRole').value.ofType(Coding).code.all($this in ('controller' | 'controller-processor'))
vn-consent-disclosure-before-consent error Consent Thời điểm trình nội dung thông báo không được sau thời điểm đồng ý — sự đồng ý chỉ có hiệu lực khi chủ thể ĐÃ biết rõ các thông tin đó (Luật 91/2025/QH15 Điều 9 khoản 2). Disclosure SHALL NOT be timestamped after the consent itself. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'disclosedAt').value.ofType(dateTime).all($this <= %resource.dateTime)
vn-consent-no-processing-legal-basis error Consent VNCoreConsent 0.9 chỉ biểu diễn lựa chọn của chủ thể và không được mang vn-ext-processing-legal-basis; xử lý không qua đồng ý dùng VNCoreAuditEventLegalBasisDecision / VNCoreConsent 0.9 represents data-subject choices only and SHALL NOT carry vn-ext-processing-legal-basis; processing without consent uses VNCoreAuditEventLegalBasisDecision extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-processing-legal-basis').empty()
vn-consent-permit-evidence-retained error Consent Bản ghi có rule permit phải trỏ tới bằng chứng đồng ý đã lưu: source[x] trong FHIR hoặc evidenceLocator ngoài FHIR — NĐ 356/2025/NĐ-CP Điều 6 khoản 2 (bên kiểm soát lưu trữ sự đồng ý và chịu trách nhiệm chứng minh khi tranh chấp). Retained consent evidence SHALL be locatable. provision.repeat(provision).type.where($this = 'permit').exists() implies (source.exists() or extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'evidenceLocator').exists())
vn-consent-permit-purpose-required error Consent Mỗi rule permit phải nêu mục đích xử lý — Luật 91/2025/QH15 Điều 9 khoản 2 điểm a (mục đích xử lý là nội dung phải thông báo) và khoản 4 điểm a (đồng ý theo TỪNG mục đích). Every permit rule SHALL state its processing purpose. provision.repeat(provision).where(type = 'permit').all(purpose.exists())
vn-consent-permit-requires-disclosure error Consent Bản ghi có rule permit phải mang nội dung đã thông báo (vn-ext-consent-disclosure) và phương thức thể hiện đồng ý (vn-ext-consent-method) — Luật 91/2025/QH15 Điều 9 khoản 2 và khoản 3; NĐ 356/2025/NĐ-CP Điều 6 khoản 1. A consent granting any permit rule SHALL carry the disclosure evidence and the declared consent method. provision.repeat(provision).type.where($this = 'permit').exists() implies (extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').exists() and extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-method').exists())
vn-consent-provision-structure error Consent Theo R4: root rule (Consent.provision) KHÔNG mang type; mọi rule permit/deny khai ở nested (provision.provision[*]) và bắt buộc có type provision.exists() implies (provision.type.empty() and provision.provision.exists() and provision.repeat(provision).all(type.exists()))
vn-consent-rejected-not-permit error Consent Bản ghi status=rejected (từ chối ngay từ đầu) không được chứa rule permit ở BẤT KỲ độ sâu nested nào — cho phép đang hiệu lực phải dùng status=active (status = 'rejected') implies provision.repeat(provision).type.where($this = 'permit').empty()
vn-consent-rights-notice-versioned error Consent Bản thông báo quyền và nghĩa vụ phải xác định được ĐÚNG bản đã trình: dùng DocumentReference, hoặc URL có ghim phiên bản. The rights notice SHALL be identifiable as the exact version presented. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'rightsNotice').all(value.ofType(Reference).exists() or value.ofType(url).matches('/v[0-9]'))
vn-consent-sensitive-notice-required error Consent Nếu nội dung đã thông báo có loại dữ liệu thuộc danh mục nhạy cảm (NĐ 356/2025/NĐ-CP Điều 4 khoản 1) thì phải khai đã thông báo cho chủ thể rằng dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm — NĐ 356/2025/NĐ-CP Điều 6 khoản 4. Disclosing a sensitive-category data type SHALL come with the explicit sensitive-data notice. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'dataCategory').value.ofType(CodeableConcept).coding.where(system = 'http://fhir.hl7.org.vn/core/CodeSystem/vn-sensitive-personal-data-cs').exists() implies extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'sensitiveDataNotice').value.ofType(boolean) = true
vn-representation-domain-basis error Consent.provision.provision.actor:representative.extension:representationAuthority Miền quyết định khám chữa bệnh bắt buộc có căn cứ lựa chọn theo Luật KCB Điều 8 khoản 2; miền quyền chủ thể dữ liệu không dùng trục căn cứ đó. The healthcare-decision domain SHALL carry a selectionBasis; the data-subject-rights domain SHALL NOT. (extension.where(url='domain').value.ofType(Coding).code = 'healthcare-decision' implies extension.where(url='selectionBasis').exists()) and (extension.where(url='domain').value.ofType(Coding).code = 'data-subject-rights' implies extension.where(url='selectionBasis').empty())
vn-representation-proxy-bounded error Consent.provision.provision.actor:representative.extension:representationAuthority Thẩm quyền theo uỷ quyền phải có GIỚI HẠN máy-đọc: NGÀY KẾT THÚC (period.end của token hoặc validity.end trong bằng chứng — chỉ có ngày bắt đầu là uỷ quyền vô thời hạn) VÀ phạm vi (scope trong ít nhất một bằng chứng) — Bộ luật Dân sự Điều 138/140/141. A delegated-proxy authority SHALL carry a machine-readable validity bound AND scope. extension.where(url='type').value.ofType(Coding).code != 'delegated-proxy' or ((extension.where(url='period').value.ofType(Period).end.exists() or extension.where(url='evidence').extension.where(url='validity').value.ofType(Period).end.exists()) and extension.where(url='evidence').extension.where(url='scope').exists())
vn-representation-proxy-evidence error Consent.provision.provision.actor:representative.extension:representationAuthority Thẩm quyền theo uỷ quyền phải kèm ít nhất một bằng chứng (văn bản uỷ quyền). A delegated-proxy authority SHALL carry at least one evidence entry. extension.where(url='type').value.ofType(Coding).code = 'delegated-proxy' implies extension.where(url='evidence').exists()
vn-representation-type-selection-basis error Consent.provision.provision.actor:representative.extension:representationAuthority Loại thẩm quyền phải tương thích với nhóm căn cứ lựa chọn tại Luật KCB Điều 8 khoản 2. The authority type SHALL be consistent with the statutory selection basis. extension.where(url='selectionBasis').empty() or ((extension.where(url='selectionBasis').value.ofType(Coding).code = 'civil-code-representative') and (extension.where(url='type').value.ofType(Coding).code = 'legal-representative' or extension.where(url='type').value.ofType(Coding).code = 'guardian' or extension.where(url='type').value.ofType(Coding).code = 'delegated-proxy')) or ((extension.where(url='selectionBasis').value.ofType(Coding).code = 'responsible-legal-entity-appointed') and (extension.where(url='type').value.ofType(Coding).code = 'legal-representative' or extension.where(url='type').value.ofType(Coding).code = 'healthcare-agent')) or ((extension.where(url='selectionBasis').value.ofType(Coding).code = 'adult-patient-selected' or extension.where(url='selectionBasis').value.ofType(Coding).code = 'family-selected' or extension.where(url='selectionBasis').value.ofType(Coding).code = 'voluntary-obligation-performer') and extension.where(url='type').value.ofType(Coding).code = 'healthcare-agent')

Dạng xem phần tử chính

NameFlagsCard.TypeDescription & Constraints    Filter: Filtersdoco
.. Consent C 0..* Consent A healthcare consumer's choices to permit or deny recipients or roles to perform actions for specific purposes and periods of time
Constraints: ppc-1, ppc-2, ppc-3, ppc-4, ppc-5, vn-consent-rejected-not-permit, vn-consent-provision-structure, vn-consent-no-processing-legal-basis, vn-consent-permit-requires-disclosure, vn-consent-permit-evidence-retained, vn-consent-choice-actor-identifiable, vn-consent-permit-purpose-required, vn-consent-disclosed-controller-role, vn-consent-rights-notice-versioned, vn-consent-sensitive-notice-required, vn-consent-disclosure-before-consent
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... Slices for extension 0..* Extension Extension
Slice: Unordered, Open by value:url
.... extension:consentMethod SO 0..1 CodeableConcept Phương thức chủ thể dữ liệu thể hiện sự đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-method
Binding: Phương thức thể hiện đồng ý — VN Consent Method VS (required)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... extension:consentDisclosure SO 0..1 (Complex) Nội dung đã thông báo cho chủ thể khi xin đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... modifierExtension ?! 0..* Extension Extensions that cannot be ignored
... scope ?!SOΣ 1..1 CodeableConcept Phạm vi đồng ý
Binding: ConsentScopeCodes (extensible): The four anticipated uses for the Consent Resource.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... category SOΣ 1..* CodeableConcept Loại đồng ý
Binding: Loại đồng ý — VN Consent Category ValueSet (extensible)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... patient SOΣ 1..1 Reference(Bệnh nhân VN Core — VN Core Patient Profile) Chủ thể dữ liệu
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... dateTime SOΣ 1..1 dateTime Thời điểm đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... performer SOΣ 0..* Reference(Bệnh nhân VN Core — VN Core Patient Profile | Người liên quan/người giám hộ VN Core — VN Core RelatedPerson Profile | Nhân viên y tế VN Core — VN Core Practitioner Profile) Người đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... organization SOΣ 0..* Reference(Cơ sở y tế VN Core — VN Core Organization Profile) CSKCB quản lý đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... source[x] SOΣ 0..1 Bản gốc đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... sourceAttachment Attachment
.... sourceReference Reference(Consent | DocumentReference | Contract | QuestionnaireResponse)
... policy SO 0..* BackboneElement Căn cứ pháp lý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... authority C 0..1 uri Cơ quan ban hành
.... uri SC 0..1 uri URL văn bản pháp lý
... provision SOΣ 0..1 BackboneElement Quy tắc đồng ý chi tiết
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... period SΣ 0..1 Period Thời hạn hiệu lực
.... actor 0..* BackboneElement Bên liên quan
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... role 1..1 CodeableConcept How the actor is involved
Binding: SecurityRoleType (extensible): How an actor is involved in the consent considerations.
..... reference 1..1 Reference(Device | Group | CareTeam | Organization | Patient | Practitioner | RelatedPerson | PractitionerRole) Resource for the actor (or group, by role)
.... purpose SΣ 0..* Coding Mục đích xử lý
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)
.... class Σ 0..* Coding Loại dữ liệu
Binding: ConsentContentClass (extensible): The class (type) of information a consent rule covers.
.... provision S 0..* BackboneElement Các rule permit/deny
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... type SΣ 1..1 code Cho phép / Từ chối
Binding: ConsentProvisionType (required): How a rule statement is applied, such as adding additional consent or removing consent.
..... Slices for actor 0..* BackboneElement Who|what controlled by this rule (or group, by role)
Slice: Unordered, Open by exists:extension('http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-representation-authority')
...... actor:All Slices Content/Rules for all slices
....... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
....... role 1..1 CodeableConcept How the actor is involved
Binding: SecurityRoleType (extensible): How an actor is involved in the consent considerations.
....... reference 1..1 Reference(Device | Group | CareTeam | Organization | Patient | Practitioner | RelatedPerson | PractitionerRole) Resource for the actor (or group, by role)
...... actor:representative S 0..* BackboneElement Người đại diện/giám hộ — mang token thẩm quyền
....... Slices for extension 1..* Extension Extension
Slice: Unordered, Open by value:url
....... Slices for extension Content/Rules for all slices
........ extension:representationAuthority SC 1..1 (Complex) Thẩm quyền đại diện truy cập dữ liệu — Representation Authority Extension
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-representation-authority
Constraints: vn-representation-domain-basis, vn-representation-type-selection-basis, vn-representation-proxy-evidence, vn-representation-proxy-bounded
....... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
....... role 1..1 CodeableConcept How the actor is involved
Binding: SecurityRoleType (extensible): How an actor is involved in the consent considerations.
....... reference 1..1 Reference(Người liên quan/người giám hộ VN Core — VN Core RelatedPerson Profile) Resource for the actor (or group, by role)
..... securityLabel SΣ 0..* Coding Lớp nhạy cảm dữ liệu áp cho rule
Binding: Lớp nhạy cảm dữ liệu y tế — Vietnam Health Data Sensitivity Class ValueSet (extensible)
..... purpose Σ 0..* Coding Mục đích xử lý của rule này
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)

doco Documentation for this format
NameKho hồ sơ EMR (Repository)Ứng dụng người dân (Citizen App)Nguồn tạo hồ sơ lâm sàng (Document Source)doco
.. Consent
... Slices for extension
.... extension:consentMethod
.... extension:consentDisclosure
... status
... scope
... patient
... dateTime
... performer
... organization
... source[x]
... policy
... provision

doco Documentation for this format

Terminology Bindings

Path Status Usage ValueSet Version Source
Consent.status Base required ConsentState 📍4.0.1 FHIR Std.
Consent.scope Base extensible Consent Scope Codes 📍4.0.1 FHIR Std.
Consent.category Base extensible Loại đồng ý — VN Consent Category ValueSet 📦0.10.0 This IG
Consent.provision.actor.​role Base extensible SecurityRoleType 📍4.0.1 FHIR Std.
Consent.provision.purpose Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG
Consent.provision.class Base extensible Consent Content Class 📍4.0.1 FHIR Std.
Consent.provision.provision.​type Base required ConsentProvisionType 📍4.0.1 FHIR Std.
Consent.provision.provision.​actor.role Base extensible SecurityRoleType 📍4.0.1 FHIR Std.
Consent.provision.provision.​actor:representative.​role Base extensible SecurityRoleType 📍4.0.1 FHIR Std.
Consent.provision.provision.​securityLabel Base extensible Lớp nhạy cảm dữ liệu y tế — Vietnam Health Data Sensitivity Class ValueSet 📦0.10.0 This IG
Consent.provision.provision.​purpose Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG

Constraints

Id Grade Path(s) Description Expression
dom-2 error Consent If the resource is contained in another resource, it SHALL NOT contain nested Resources contained.contained.empty()
dom-3 error Consent If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().as(canonical) | %resource.descendants().as(uri) | %resource.descendants().as(url))) or descendants().where(reference = '#').exists() or descendants().where(as(canonical) = '#').exists() or descendants().where(as(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
dom-4 error Consent If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
dom-5 error Consent If a resource is contained in another resource, it SHALL NOT have a security label contained.meta.security.empty()
dom-6 best practice Consent A resource should have narrative for robust management text.`div`.exists()
ele-1 error **ALL** elements All FHIR elements must have a @value or children hasValue() or (children().count() > id.count())
ext-1 error **ALL** extensions Must have either extensions or value[x], not both extension.exists() != value.exists()
ppc-1 error Consent Either a Policy or PolicyRule policy.exists() or policyRule.exists()
ppc-2 error Consent IF Scope=privacy, there must be a patient patient.exists() or scope.coding.where(system='something' and code='patient-privacy').exists().not()
ppc-3 error Consent IF Scope=research, there must be a patient patient.exists() or scope.coding.where(system='something' and code='research').exists().not()
ppc-4 error Consent IF Scope=adr, there must be a patient patient.exists() or scope.coding.where(system='something' and code='adr').exists().not()
ppc-5 error Consent IF Scope=treatment, there must be a patient patient.exists() or scope.coding.where(system='something' and code='treatment').exists().not()
vn-consent-choice-actor-identifiable error Consent Bản ghi có rule permit/deny phải xác định được NGƯỜI thực hiện lựa chọn: performer, hoặc bằng chứng trỏ được tới người đó (source[x] trong FHIR / evidenceLocator ngoài FHIR) — Luật 91/2025/QH15 Điều 9 khoản 3 (sự đồng ý phải kiểm chứng được), Điều 4 khoản 1 điểm b (quyền không đồng ý), Điều 24 (đại diện). A subject-choice record SHALL identify who made the choice via performer or locatable evidence. provision.repeat(provision).type.exists() implies (performer.where(reference.exists() or identifier.exists()).exists() or source.exists() or extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'evidenceLocator').exists())
vn-consent-disclosed-controller-role error Consent Vai trò được thông báo cho chủ thể chỉ có thể là bên kiểm soát hoặc bên kiểm soát và xử lý — Luật 91/2025/QH15 Điều 9 khoản 2 điểm b. Bên xử lý và bên thứ ba không phải chủ thể của nghĩa vụ thông báo này. The disclosed party role SHALL be controller or controller-processor. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'controllerRole').value.ofType(Coding).code.all($this in ('controller' | 'controller-processor'))
vn-consent-disclosure-before-consent error Consent Thời điểm trình nội dung thông báo không được sau thời điểm đồng ý — sự đồng ý chỉ có hiệu lực khi chủ thể ĐÃ biết rõ các thông tin đó (Luật 91/2025/QH15 Điều 9 khoản 2). Disclosure SHALL NOT be timestamped after the consent itself. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'disclosedAt').value.ofType(dateTime).all($this <= %resource.dateTime)
vn-consent-no-processing-legal-basis error Consent VNCoreConsent 0.9 chỉ biểu diễn lựa chọn của chủ thể và không được mang vn-ext-processing-legal-basis; xử lý không qua đồng ý dùng VNCoreAuditEventLegalBasisDecision / VNCoreConsent 0.9 represents data-subject choices only and SHALL NOT carry vn-ext-processing-legal-basis; processing without consent uses VNCoreAuditEventLegalBasisDecision extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-processing-legal-basis').empty()
vn-consent-permit-evidence-retained error Consent Bản ghi có rule permit phải trỏ tới bằng chứng đồng ý đã lưu: source[x] trong FHIR hoặc evidenceLocator ngoài FHIR — NĐ 356/2025/NĐ-CP Điều 6 khoản 2 (bên kiểm soát lưu trữ sự đồng ý và chịu trách nhiệm chứng minh khi tranh chấp). Retained consent evidence SHALL be locatable. provision.repeat(provision).type.where($this = 'permit').exists() implies (source.exists() or extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'evidenceLocator').exists())
vn-consent-permit-purpose-required error Consent Mỗi rule permit phải nêu mục đích xử lý — Luật 91/2025/QH15 Điều 9 khoản 2 điểm a (mục đích xử lý là nội dung phải thông báo) và khoản 4 điểm a (đồng ý theo TỪNG mục đích). Every permit rule SHALL state its processing purpose. provision.repeat(provision).where(type = 'permit').all(purpose.exists())
vn-consent-permit-requires-disclosure error Consent Bản ghi có rule permit phải mang nội dung đã thông báo (vn-ext-consent-disclosure) và phương thức thể hiện đồng ý (vn-ext-consent-method) — Luật 91/2025/QH15 Điều 9 khoản 2 và khoản 3; NĐ 356/2025/NĐ-CP Điều 6 khoản 1. A consent granting any permit rule SHALL carry the disclosure evidence and the declared consent method. provision.repeat(provision).type.where($this = 'permit').exists() implies (extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').exists() and extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-method').exists())
vn-consent-provision-structure error Consent Theo R4: root rule (Consent.provision) KHÔNG mang type; mọi rule permit/deny khai ở nested (provision.provision[*]) và bắt buộc có type provision.exists() implies (provision.type.empty() and provision.provision.exists() and provision.repeat(provision).all(type.exists()))
vn-consent-rejected-not-permit error Consent Bản ghi status=rejected (từ chối ngay từ đầu) không được chứa rule permit ở BẤT KỲ độ sâu nested nào — cho phép đang hiệu lực phải dùng status=active (status = 'rejected') implies provision.repeat(provision).type.where($this = 'permit').empty()
vn-consent-rights-notice-versioned error Consent Bản thông báo quyền và nghĩa vụ phải xác định được ĐÚNG bản đã trình: dùng DocumentReference, hoặc URL có ghim phiên bản. The rights notice SHALL be identifiable as the exact version presented. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'rightsNotice').all(value.ofType(Reference).exists() or value.ofType(url).matches('/v[0-9]'))
vn-consent-sensitive-notice-required error Consent Nếu nội dung đã thông báo có loại dữ liệu thuộc danh mục nhạy cảm (NĐ 356/2025/NĐ-CP Điều 4 khoản 1) thì phải khai đã thông báo cho chủ thể rằng dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm — NĐ 356/2025/NĐ-CP Điều 6 khoản 4. Disclosing a sensitive-category data type SHALL come with the explicit sensitive-data notice. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'dataCategory').value.ofType(CodeableConcept).coding.where(system = 'http://fhir.hl7.org.vn/core/CodeSystem/vn-sensitive-personal-data-cs').exists() implies extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'sensitiveDataNotice').value.ofType(boolean) = true
vn-representation-domain-basis error Consent.provision.provision.actor:representative.extension:representationAuthority Miền quyết định khám chữa bệnh bắt buộc có căn cứ lựa chọn theo Luật KCB Điều 8 khoản 2; miền quyền chủ thể dữ liệu không dùng trục căn cứ đó. The healthcare-decision domain SHALL carry a selectionBasis; the data-subject-rights domain SHALL NOT. (extension.where(url='domain').value.ofType(Coding).code = 'healthcare-decision' implies extension.where(url='selectionBasis').exists()) and (extension.where(url='domain').value.ofType(Coding).code = 'data-subject-rights' implies extension.where(url='selectionBasis').empty())
vn-representation-proxy-bounded error Consent.provision.provision.actor:representative.extension:representationAuthority Thẩm quyền theo uỷ quyền phải có GIỚI HẠN máy-đọc: NGÀY KẾT THÚC (period.end của token hoặc validity.end trong bằng chứng — chỉ có ngày bắt đầu là uỷ quyền vô thời hạn) VÀ phạm vi (scope trong ít nhất một bằng chứng) — Bộ luật Dân sự Điều 138/140/141. A delegated-proxy authority SHALL carry a machine-readable validity bound AND scope. extension.where(url='type').value.ofType(Coding).code != 'delegated-proxy' or ((extension.where(url='period').value.ofType(Period).end.exists() or extension.where(url='evidence').extension.where(url='validity').value.ofType(Period).end.exists()) and extension.where(url='evidence').extension.where(url='scope').exists())
vn-representation-proxy-evidence error Consent.provision.provision.actor:representative.extension:representationAuthority Thẩm quyền theo uỷ quyền phải kèm ít nhất một bằng chứng (văn bản uỷ quyền). A delegated-proxy authority SHALL carry at least one evidence entry. extension.where(url='type').value.ofType(Coding).code = 'delegated-proxy' implies extension.where(url='evidence').exists()
vn-representation-type-selection-basis error Consent.provision.provision.actor:representative.extension:representationAuthority Loại thẩm quyền phải tương thích với nhóm căn cứ lựa chọn tại Luật KCB Điều 8 khoản 2. The authority type SHALL be consistent with the statutory selection basis. extension.where(url='selectionBasis').empty() or ((extension.where(url='selectionBasis').value.ofType(Coding).code = 'civil-code-representative') and (extension.where(url='type').value.ofType(Coding).code = 'legal-representative' or extension.where(url='type').value.ofType(Coding).code = 'guardian' or extension.where(url='type').value.ofType(Coding).code = 'delegated-proxy')) or ((extension.where(url='selectionBasis').value.ofType(Coding).code = 'responsible-legal-entity-appointed') and (extension.where(url='type').value.ofType(Coding).code = 'legal-representative' or extension.where(url='type').value.ofType(Coding).code = 'healthcare-agent')) or ((extension.where(url='selectionBasis').value.ofType(Coding).code = 'adult-patient-selected' or extension.where(url='selectionBasis').value.ofType(Coding).code = 'family-selected' or extension.where(url='selectionBasis').value.ofType(Coding).code = 'voluntary-obligation-performer') and extension.where(url='type').value.ofType(Coding).code = 'healthcare-agent')

Dạng xem Differential

NameFlagsCard.TypeDescription & Constraints    Filter: Filtersdoco
.. Consent C 0..* Consent A healthcare consumer's choices to permit or deny recipients or roles to perform actions for specific purposes and periods of time
Constraints: vn-consent-rejected-not-permit, vn-consent-provision-structure, vn-consent-no-processing-legal-basis, vn-consent-permit-requires-disclosure, vn-consent-permit-evidence-retained, vn-consent-choice-actor-identifiable, vn-consent-permit-purpose-required, vn-consent-disclosed-controller-role, vn-consent-rights-notice-versioned, vn-consent-sensitive-notice-required, vn-consent-disclosure-before-consent
... Slices for extension 0..* Extension Extension
Slice: Unordered, Open by value:url
.... extension:processingLegalBasis 0..0 CodeableConcept Cấm authoring căn cứ Điều 19 trên Consent / No Article 19 authoring on Consent
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-processing-legal-basis
Binding: Căn cứ xử lý DLCN không cần sự đồng ý — VN Processing Legal Basis ValueSet (required)
.... extension:consentMethod SO 0..1 CodeableConcept Phương thức chủ thể dữ liệu thể hiện sự đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-method
Binding: Phương thức thể hiện đồng ý — VN Consent Method VS (required)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... extension:consentDisclosure SO 0..1 (Complex) Nội dung đã thông báo cho chủ thể khi xin đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... status SO 1..1 code Trạng thái đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... scope SO 1..1 CodeableConcept Phạm vi đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... patient SO 1..1 Reference(Bệnh nhân VN Core — VN Core Patient Profile) Chủ thể dữ liệu
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... dateTime SO 1..1 dateTime Thời điểm đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... performer SO 0..* Reference(Bệnh nhân VN Core — VN Core Patient Profile | Người liên quan/người giám hộ VN Core — VN Core RelatedPerson Profile | Nhân viên y tế VN Core — VN Core Practitioner Profile) Người đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... organization SO 0..* Reference(Cơ sở y tế VN Core — VN Core Organization Profile) CSKCB quản lý đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... source[x] SO 0..1 Attachment, Reference(Consent | DocumentReference | Contract | QuestionnaireResponse) Bản gốc đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... policy SO 0..* BackboneElement Căn cứ pháp lý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... authority 0..1 uri Cơ quan ban hành
.... uri S 0..1 uri URL văn bản pháp lý
... provision SO 0..1 BackboneElement Quy tắc đồng ý chi tiết
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... type 0..0 deny | permit
.... period S 0..1 Period Thời hạn hiệu lực
.... actor 0..* BackboneElement Bên liên quan
.... purpose S 0..* Coding Mục đích xử lý
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)
.... class 0..* Coding Loại dữ liệu
.... provision S 0..* BackboneElement Các rule permit/deny
..... type S 1..1 code Cho phép / Từ chối
..... Slices for actor 0..* BackboneElement Who|what controlled by this rule (or group, by role)
Slice: Unordered, Open by exists:extension('http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-representation-authority')
...... actor:representative S 0..* BackboneElement Người đại diện/giám hộ — mang token thẩm quyền
....... Slices for extension 1..* Extension Extension
Slice: Unordered, Open by value:url
....... Slices for extension Content/Rules for all slices
........ extension:representationAuthority S 1..1 (Complex) Thẩm quyền đại diện truy cập dữ liệu — Representation Authority Extension
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-representation-authority
....... reference 1..1 Reference(Người liên quan/người giám hộ VN Core — VN Core RelatedPerson Profile) Resource for the actor (or group, by role)
..... securityLabel S 0..* Coding Lớp nhạy cảm dữ liệu áp cho rule
Binding: Lớp nhạy cảm dữ liệu y tế — Vietnam Health Data Sensitivity Class ValueSet (extensible)
..... purpose 0..* Coding Mục đích xử lý của rule này
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)

doco Documentation for this format
NameKho hồ sơ EMR (Repository)Ứng dụng người dân (Citizen App)Nguồn tạo hồ sơ lâm sàng (Document Source)doco
.. Consent
... Slices for extension
.... extension:consentMethod
.... extension:consentDisclosure
... status
... scope
... patient
... dateTime
... performer
... organization
... source[x]
... policy
... provision

doco Documentation for this format

Terminology Bindings (Differential)

Path Status Usage ValueSet Version Source
Consent.category Base extensible Loại đồng ý — VN Consent Category ValueSet 📦0.10.0 This IG
Consent.provision.purpose Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG
Consent.provision.provision.​securityLabel Base extensible Lớp nhạy cảm dữ liệu y tế — Vietnam Health Data Sensitivity Class ValueSet 📦0.10.0 This IG
Consent.provision.provision.​purpose Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG

Constraints

Id Grade Path(s) Description Expression
vn-consent-choice-actor-identifiable error Consent Bản ghi có rule permit/deny phải xác định được NGƯỜI thực hiện lựa chọn: performer, hoặc bằng chứng trỏ được tới người đó (source[x] trong FHIR / evidenceLocator ngoài FHIR) — Luật 91/2025/QH15 Điều 9 khoản 3 (sự đồng ý phải kiểm chứng được), Điều 4 khoản 1 điểm b (quyền không đồng ý), Điều 24 (đại diện). A subject-choice record SHALL identify who made the choice via performer or locatable evidence. provision.repeat(provision).type.exists() implies (performer.where(reference.exists() or identifier.exists()).exists() or source.exists() or extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'evidenceLocator').exists())
vn-consent-disclosed-controller-role error Consent Vai trò được thông báo cho chủ thể chỉ có thể là bên kiểm soát hoặc bên kiểm soát và xử lý — Luật 91/2025/QH15 Điều 9 khoản 2 điểm b. Bên xử lý và bên thứ ba không phải chủ thể của nghĩa vụ thông báo này. The disclosed party role SHALL be controller or controller-processor. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'controllerRole').value.ofType(Coding).code.all($this in ('controller' | 'controller-processor'))
vn-consent-disclosure-before-consent error Consent Thời điểm trình nội dung thông báo không được sau thời điểm đồng ý — sự đồng ý chỉ có hiệu lực khi chủ thể ĐÃ biết rõ các thông tin đó (Luật 91/2025/QH15 Điều 9 khoản 2). Disclosure SHALL NOT be timestamped after the consent itself. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'disclosedAt').value.ofType(dateTime).all($this <= %resource.dateTime)
vn-consent-no-processing-legal-basis error Consent VNCoreConsent 0.9 chỉ biểu diễn lựa chọn của chủ thể và không được mang vn-ext-processing-legal-basis; xử lý không qua đồng ý dùng VNCoreAuditEventLegalBasisDecision / VNCoreConsent 0.9 represents data-subject choices only and SHALL NOT carry vn-ext-processing-legal-basis; processing without consent uses VNCoreAuditEventLegalBasisDecision extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-processing-legal-basis').empty()
vn-consent-permit-evidence-retained error Consent Bản ghi có rule permit phải trỏ tới bằng chứng đồng ý đã lưu: source[x] trong FHIR hoặc evidenceLocator ngoài FHIR — NĐ 356/2025/NĐ-CP Điều 6 khoản 2 (bên kiểm soát lưu trữ sự đồng ý và chịu trách nhiệm chứng minh khi tranh chấp). Retained consent evidence SHALL be locatable. provision.repeat(provision).type.where($this = 'permit').exists() implies (source.exists() or extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'evidenceLocator').exists())
vn-consent-permit-purpose-required error Consent Mỗi rule permit phải nêu mục đích xử lý — Luật 91/2025/QH15 Điều 9 khoản 2 điểm a (mục đích xử lý là nội dung phải thông báo) và khoản 4 điểm a (đồng ý theo TỪNG mục đích). Every permit rule SHALL state its processing purpose. provision.repeat(provision).where(type = 'permit').all(purpose.exists())
vn-consent-permit-requires-disclosure error Consent Bản ghi có rule permit phải mang nội dung đã thông báo (vn-ext-consent-disclosure) và phương thức thể hiện đồng ý (vn-ext-consent-method) — Luật 91/2025/QH15 Điều 9 khoản 2 và khoản 3; NĐ 356/2025/NĐ-CP Điều 6 khoản 1. A consent granting any permit rule SHALL carry the disclosure evidence and the declared consent method. provision.repeat(provision).type.where($this = 'permit').exists() implies (extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').exists() and extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-method').exists())
vn-consent-provision-structure error Consent Theo R4: root rule (Consent.provision) KHÔNG mang type; mọi rule permit/deny khai ở nested (provision.provision[*]) và bắt buộc có type provision.exists() implies (provision.type.empty() and provision.provision.exists() and provision.repeat(provision).all(type.exists()))
vn-consent-rejected-not-permit error Consent Bản ghi status=rejected (từ chối ngay từ đầu) không được chứa rule permit ở BẤT KỲ độ sâu nested nào — cho phép đang hiệu lực phải dùng status=active (status = 'rejected') implies provision.repeat(provision).type.where($this = 'permit').empty()
vn-consent-rights-notice-versioned error Consent Bản thông báo quyền và nghĩa vụ phải xác định được ĐÚNG bản đã trình: dùng DocumentReference, hoặc URL có ghim phiên bản. The rights notice SHALL be identifiable as the exact version presented. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'rightsNotice').all(value.ofType(Reference).exists() or value.ofType(url).matches('/v[0-9]'))
vn-consent-sensitive-notice-required error Consent Nếu nội dung đã thông báo có loại dữ liệu thuộc danh mục nhạy cảm (NĐ 356/2025/NĐ-CP Điều 4 khoản 1) thì phải khai đã thông báo cho chủ thể rằng dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm — NĐ 356/2025/NĐ-CP Điều 6 khoản 4. Disclosing a sensitive-category data type SHALL come with the explicit sensitive-data notice. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'dataCategory').value.ofType(CodeableConcept).coding.where(system = 'http://fhir.hl7.org.vn/core/CodeSystem/vn-sensitive-personal-data-cs').exists() implies extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'sensitiveDataNotice').value.ofType(boolean) = true

Dạng xem SnapshotView

NameFlagsCard.TypeDescription & Constraints    Filter: Filtersdoco
.. Consent C 0..* Consent A healthcare consumer's choices to permit or deny recipients or roles to perform actions for specific purposes and periods of time
Constraints: ppc-1, ppc-2, ppc-3, ppc-4, ppc-5, vn-consent-rejected-not-permit, vn-consent-provision-structure, vn-consent-no-processing-legal-basis, vn-consent-permit-requires-disclosure, vn-consent-permit-evidence-retained, vn-consent-choice-actor-identifiable, vn-consent-permit-purpose-required, vn-consent-disclosed-controller-role, vn-consent-rights-notice-versioned, vn-consent-sensitive-notice-required, vn-consent-disclosure-before-consent
... id Σ 0..1 id Logical id of this artifact
... meta Σ 0..1 Meta Metadata about the resource
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... text 0..1 Narrative Text summary of the resource, for human interpretation
This profile does not constrain the narrative in regard to content, language, or traceability to data elements
... contained 0..* Resource Contained, inline Resources
... Slices for extension 0..* Extension Extension
Slice: Unordered, Open by value:url
.... extension:consentMethod SO 0..1 CodeableConcept Phương thức chủ thể dữ liệu thể hiện sự đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-method
Binding: Phương thức thể hiện đồng ý — VN Consent Method VS (required)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... extension:consentDisclosure SO 0..1 (Complex) Nội dung đã thông báo cho chủ thể khi xin đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... modifierExtension ?! 0..* Extension Extensions that cannot be ignored
... identifier Σ 0..* Identifier Identifier for this record (external references)

Example General: {"system":"http://acme.org/identifier/local/eCMS","value":"Local eCMS identifier"}
... status ?!SOΣ 1..1 code Trạng thái đồng ý
Binding: ConsentState (required): Indicates the state of the consent.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... scope ?!SOΣ 1..1 CodeableConcept Phạm vi đồng ý
Binding: ConsentScopeCodes (extensible): The four anticipated uses for the Consent Resource.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... category SOΣ 1..* CodeableConcept Loại đồng ý
Binding: Loại đồng ý — VN Consent Category ValueSet (extensible)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... patient SOΣ 1..1 Reference(Bệnh nhân VN Core — VN Core Patient Profile) Chủ thể dữ liệu
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... dateTime SOΣ 1..1 dateTime Thời điểm đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... performer SOΣ 0..* Reference(Bệnh nhân VN Core — VN Core Patient Profile | Người liên quan/người giám hộ VN Core — VN Core RelatedPerson Profile | Nhân viên y tế VN Core — VN Core Practitioner Profile) Người đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... organization SOΣ 0..* Reference(Cơ sở y tế VN Core — VN Core Organization Profile) CSKCB quản lý đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... source[x] SOΣ 0..1 Bản gốc đồng ý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... sourceAttachment Attachment
.... sourceReference Reference(Consent | DocumentReference | Contract | QuestionnaireResponse)
... policy SO 0..* BackboneElement Căn cứ pháp lý
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... authority C 0..1 uri Cơ quan ban hành
.... uri SC 0..1 uri URL văn bản pháp lý
... policyRule ΣC 0..1 CodeableConcept Regulation that this consents to
Binding: ConsentPolicyRuleCodes (extensible): Regulatory policy examples.
... verification Σ 0..* BackboneElement Consent Verified by patient or family
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... verified Σ 1..1 boolean Has been verified
.... verifiedWith 0..1 Reference(Patient | RelatedPerson) Person who verified
.... verificationDate 0..1 dateTime When consent verified
... provision SOΣ 0..1 BackboneElement Quy tắc đồng ý chi tiết
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... period SΣ 0..1 Period Thời hạn hiệu lực
.... actor 0..* BackboneElement Bên liên quan
..... id 0..1 string Unique id for inter-element referencing
..... extension 0..* Extension Additional content defined by implementations
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... role 1..1 CodeableConcept How the actor is involved
Binding: SecurityRoleType (extensible): How an actor is involved in the consent considerations.
..... reference 1..1 Reference(Device | Group | CareTeam | Organization | Patient | Practitioner | RelatedPerson | PractitionerRole) Resource for the actor (or group, by role)
.... action Σ 0..* CodeableConcept Actions controlled by this rule
Binding: ConsentActionCodes (example): Detailed codes for the consent action.
.... securityLabel Σ 0..* Coding Security Labels that define affected resources
Binding: All Security Labels (extensible): Security Labels from the Healthcare Privacy and Security Classification System.
.... purpose SΣ 0..* Coding Mục đích xử lý
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)
.... class Σ 0..* Coding Loại dữ liệu
Binding: ConsentContentClass (extensible): The class (type) of information a consent rule covers.
.... code Σ 0..* CodeableConcept e.g. LOINC or SNOMED CT code, etc. in the content
Binding: ConsentContentCodes (example): If this code is found in an instance, then the exception applies.
.... dataPeriod Σ 0..1 Period Timeframe for data controlled by this rule
.... data Σ 0..* BackboneElement Data controlled by this rule
..... id 0..1 string Unique id for inter-element referencing
..... extension 0..* Extension Additional content defined by implementations
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... meaning Σ 1..1 code instance | related | dependents | authoredby
Binding: ConsentDataMeaning (required): How a resource reference is interpreted when testing consent restrictions.
..... reference Σ 1..1 Reference(Resource) The actual data reference
.... provision S 0..* BackboneElement Các rule permit/deny
..... id 0..1 string Unique id for inter-element referencing
..... extension 0..* Extension Additional content defined by implementations
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... type SΣ 1..1 code Cho phép / Từ chối
Binding: ConsentProvisionType (required): How a rule statement is applied, such as adding additional consent or removing consent.
..... period Σ 0..1 Period Timeframe for this rule
..... Slices for actor 0..* BackboneElement Who|what controlled by this rule (or group, by role)
Slice: Unordered, Open by exists:extension('http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-representation-authority')
...... actor:All Slices Content/Rules for all slices
....... id 0..1 string Unique id for inter-element referencing
....... extension 0..* Extension Additional content defined by implementations
....... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
....... role 1..1 CodeableConcept How the actor is involved
Binding: SecurityRoleType (extensible): How an actor is involved in the consent considerations.
....... reference 1..1 Reference(Device | Group | CareTeam | Organization | Patient | Practitioner | RelatedPerson | PractitionerRole) Resource for the actor (or group, by role)
...... actor:representative S 0..* BackboneElement Người đại diện/giám hộ — mang token thẩm quyền
....... id 0..1 string Unique id for inter-element referencing
....... Slices for extension 1..* Extension Extension
Slice: Unordered, Open by value:url
....... Slices for extension Content/Rules for all slices
........ extension:representationAuthority SC 1..1 (Complex) Thẩm quyền đại diện truy cập dữ liệu — Representation Authority Extension
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-representation-authority
Constraints: vn-representation-domain-basis, vn-representation-type-selection-basis, vn-representation-proxy-evidence, vn-representation-proxy-bounded
....... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
....... role 1..1 CodeableConcept How the actor is involved
Binding: SecurityRoleType (extensible): How an actor is involved in the consent considerations.
....... reference 1..1 Reference(Người liên quan/người giám hộ VN Core — VN Core RelatedPerson Profile) Resource for the actor (or group, by role)
..... action Σ 0..* CodeableConcept Actions controlled by this rule
Binding: ConsentActionCodes (example): Detailed codes for the consent action.
..... securityLabel SΣ 0..* Coding Lớp nhạy cảm dữ liệu áp cho rule
Binding: Lớp nhạy cảm dữ liệu y tế — Vietnam Health Data Sensitivity Class ValueSet (extensible)
..... purpose Σ 0..* Coding Mục đích xử lý của rule này
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)
..... class Σ 0..* Coding e.g. Resource Type, Profile, CDA, etc.
Binding: ConsentContentClass (extensible): The class (type) of information a consent rule covers.
..... code Σ 0..* CodeableConcept e.g. LOINC or SNOMED CT code, etc. in the content
Binding: ConsentContentCodes (example): If this code is found in an instance, then the exception applies.
..... dataPeriod Σ 0..1 Period Timeframe for data controlled by this rule
..... data Σ 0..* BackboneElement Data controlled by this rule
...... id 0..1 string Unique id for inter-element referencing
...... extension 0..* Extension Additional content defined by implementations
...... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
...... meaning Σ 1..1 code instance | related | dependents | authoredby
Binding: ConsentDataMeaning (required): How a resource reference is interpreted when testing consent restrictions.
...... reference Σ 1..1 Reference(Resource) The actual data reference
..... provision 0..* See provision (Consent) Nested Exception Rules

doco Documentation for this format
NameKho hồ sơ EMR (Repository)Ứng dụng người dân (Citizen App)Nguồn tạo hồ sơ lâm sàng (Document Source)doco
.. Consent
... Slices for extension
.... extension:consentMethod
.... extension:consentDisclosure
... status
... scope
... patient
... dateTime
... performer
... organization
... source[x]
... policy
... provision

doco Documentation for this format

Terminology Bindings

Path Status Usage ValueSet Version Source
Consent.language Base preferred Common Languages 📍4.0.1 FHIR Std.
Consent.status Base required ConsentState 📍4.0.1 FHIR Std.
Consent.scope Base extensible Consent Scope Codes 📍4.0.1 FHIR Std.
Consent.category Base extensible Loại đồng ý — VN Consent Category ValueSet 📦0.10.0 This IG
Consent.policyRule Base extensible Consent PolicyRule Codes 📍4.0.1 FHIR Std.
Consent.provision.actor.​role Base extensible SecurityRoleType 📍4.0.1 FHIR Std.
Consent.provision.action Base example Consent Action Codes 📍4.0.1 FHIR Std.
Consent.provision.securityLabel Base extensible SecurityLabels 📍4.0.1 FHIR Std.
Consent.provision.purpose Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG
Consent.provision.class Base extensible Consent Content Class 📍4.0.1 FHIR Std.
Consent.provision.code Base example Consent Content Codes 📍4.0.1 FHIR Std.
Consent.provision.data.​meaning Base required ConsentDataMeaning 📍4.0.1 FHIR Std.
Consent.provision.provision.​type Base required ConsentProvisionType 📍4.0.1 FHIR Std.
Consent.provision.provision.​actor.role Base extensible SecurityRoleType 📍4.0.1 FHIR Std.
Consent.provision.provision.​actor:representative.​role Base extensible SecurityRoleType 📍4.0.1 FHIR Std.
Consent.provision.provision.​action Base example Consent Action Codes 📍4.0.1 FHIR Std.
Consent.provision.provision.​securityLabel Base extensible Lớp nhạy cảm dữ liệu y tế — Vietnam Health Data Sensitivity Class ValueSet 📦0.10.0 This IG
Consent.provision.provision.​purpose Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG
Consent.provision.provision.​class Base extensible Consent Content Class 📍4.0.1 FHIR Std.
Consent.provision.provision.​code Base example Consent Content Codes 📍4.0.1 FHIR Std.
Consent.provision.provision.​data.meaning Base required ConsentDataMeaning 📍4.0.1 FHIR Std.

Constraints

Id Grade Path(s) Description Expression
dom-2 error Consent If the resource is contained in another resource, it SHALL NOT contain nested Resources contained.contained.empty()
dom-3 error Consent If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().as(canonical) | %resource.descendants().as(uri) | %resource.descendants().as(url))) or descendants().where(reference = '#').exists() or descendants().where(as(canonical) = '#').exists() or descendants().where(as(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
dom-4 error Consent If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
dom-5 error Consent If a resource is contained in another resource, it SHALL NOT have a security label contained.meta.security.empty()
dom-6 best practice Consent A resource should have narrative for robust management text.`div`.exists()
ele-1 error **ALL** elements All FHIR elements must have a @value or children hasValue() or (children().count() > id.count())
ext-1 error **ALL** extensions Must have either extensions or value[x], not both extension.exists() != value.exists()
ppc-1 error Consent Either a Policy or PolicyRule policy.exists() or policyRule.exists()
ppc-2 error Consent IF Scope=privacy, there must be a patient patient.exists() or scope.coding.where(system='something' and code='patient-privacy').exists().not()
ppc-3 error Consent IF Scope=research, there must be a patient patient.exists() or scope.coding.where(system='something' and code='research').exists().not()
ppc-4 error Consent IF Scope=adr, there must be a patient patient.exists() or scope.coding.where(system='something' and code='adr').exists().not()
ppc-5 error Consent IF Scope=treatment, there must be a patient patient.exists() or scope.coding.where(system='something' and code='treatment').exists().not()
vn-consent-choice-actor-identifiable error Consent Bản ghi có rule permit/deny phải xác định được NGƯỜI thực hiện lựa chọn: performer, hoặc bằng chứng trỏ được tới người đó (source[x] trong FHIR / evidenceLocator ngoài FHIR) — Luật 91/2025/QH15 Điều 9 khoản 3 (sự đồng ý phải kiểm chứng được), Điều 4 khoản 1 điểm b (quyền không đồng ý), Điều 24 (đại diện). A subject-choice record SHALL identify who made the choice via performer or locatable evidence. provision.repeat(provision).type.exists() implies (performer.where(reference.exists() or identifier.exists()).exists() or source.exists() or extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'evidenceLocator').exists())
vn-consent-disclosed-controller-role error Consent Vai trò được thông báo cho chủ thể chỉ có thể là bên kiểm soát hoặc bên kiểm soát và xử lý — Luật 91/2025/QH15 Điều 9 khoản 2 điểm b. Bên xử lý và bên thứ ba không phải chủ thể của nghĩa vụ thông báo này. The disclosed party role SHALL be controller or controller-processor. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'controllerRole').value.ofType(Coding).code.all($this in ('controller' | 'controller-processor'))
vn-consent-disclosure-before-consent error Consent Thời điểm trình nội dung thông báo không được sau thời điểm đồng ý — sự đồng ý chỉ có hiệu lực khi chủ thể ĐÃ biết rõ các thông tin đó (Luật 91/2025/QH15 Điều 9 khoản 2). Disclosure SHALL NOT be timestamped after the consent itself. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'disclosedAt').value.ofType(dateTime).all($this <= %resource.dateTime)
vn-consent-no-processing-legal-basis error Consent VNCoreConsent 0.9 chỉ biểu diễn lựa chọn của chủ thể và không được mang vn-ext-processing-legal-basis; xử lý không qua đồng ý dùng VNCoreAuditEventLegalBasisDecision / VNCoreConsent 0.9 represents data-subject choices only and SHALL NOT carry vn-ext-processing-legal-basis; processing without consent uses VNCoreAuditEventLegalBasisDecision extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-processing-legal-basis').empty()
vn-consent-permit-evidence-retained error Consent Bản ghi có rule permit phải trỏ tới bằng chứng đồng ý đã lưu: source[x] trong FHIR hoặc evidenceLocator ngoài FHIR — NĐ 356/2025/NĐ-CP Điều 6 khoản 2 (bên kiểm soát lưu trữ sự đồng ý và chịu trách nhiệm chứng minh khi tranh chấp). Retained consent evidence SHALL be locatable. provision.repeat(provision).type.where($this = 'permit').exists() implies (source.exists() or extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'evidenceLocator').exists())
vn-consent-permit-purpose-required error Consent Mỗi rule permit phải nêu mục đích xử lý — Luật 91/2025/QH15 Điều 9 khoản 2 điểm a (mục đích xử lý là nội dung phải thông báo) và khoản 4 điểm a (đồng ý theo TỪNG mục đích). Every permit rule SHALL state its processing purpose. provision.repeat(provision).where(type = 'permit').all(purpose.exists())
vn-consent-permit-requires-disclosure error Consent Bản ghi có rule permit phải mang nội dung đã thông báo (vn-ext-consent-disclosure) và phương thức thể hiện đồng ý (vn-ext-consent-method) — Luật 91/2025/QH15 Điều 9 khoản 2 và khoản 3; NĐ 356/2025/NĐ-CP Điều 6 khoản 1. A consent granting any permit rule SHALL carry the disclosure evidence and the declared consent method. provision.repeat(provision).type.where($this = 'permit').exists() implies (extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').exists() and extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-method').exists())
vn-consent-provision-structure error Consent Theo R4: root rule (Consent.provision) KHÔNG mang type; mọi rule permit/deny khai ở nested (provision.provision[*]) và bắt buộc có type provision.exists() implies (provision.type.empty() and provision.provision.exists() and provision.repeat(provision).all(type.exists()))
vn-consent-rejected-not-permit error Consent Bản ghi status=rejected (từ chối ngay từ đầu) không được chứa rule permit ở BẤT KỲ độ sâu nested nào — cho phép đang hiệu lực phải dùng status=active (status = 'rejected') implies provision.repeat(provision).type.where($this = 'permit').empty()
vn-consent-rights-notice-versioned error Consent Bản thông báo quyền và nghĩa vụ phải xác định được ĐÚNG bản đã trình: dùng DocumentReference, hoặc URL có ghim phiên bản. The rights notice SHALL be identifiable as the exact version presented. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'rightsNotice').all(value.ofType(Reference).exists() or value.ofType(url).matches('/v[0-9]'))
vn-consent-sensitive-notice-required error Consent Nếu nội dung đã thông báo có loại dữ liệu thuộc danh mục nhạy cảm (NĐ 356/2025/NĐ-CP Điều 4 khoản 1) thì phải khai đã thông báo cho chủ thể rằng dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm — NĐ 356/2025/NĐ-CP Điều 6 khoản 4. Disclosing a sensitive-category data type SHALL come with the explicit sensitive-data notice. extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'dataCategory').value.ofType(CodeableConcept).coding.where(system = 'http://fhir.hl7.org.vn/core/CodeSystem/vn-sensitive-personal-data-cs').exists() implies extension.where(url = 'http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-consent-disclosure').extension.where(url = 'sensitiveDataNotice').value.ofType(boolean) = true
vn-representation-domain-basis error Consent.provision.provision.actor:representative.extension:representationAuthority Miền quyết định khám chữa bệnh bắt buộc có căn cứ lựa chọn theo Luật KCB Điều 8 khoản 2; miền quyền chủ thể dữ liệu không dùng trục căn cứ đó. The healthcare-decision domain SHALL carry a selectionBasis; the data-subject-rights domain SHALL NOT. (extension.where(url='domain').value.ofType(Coding).code = 'healthcare-decision' implies extension.where(url='selectionBasis').exists()) and (extension.where(url='domain').value.ofType(Coding).code = 'data-subject-rights' implies extension.where(url='selectionBasis').empty())
vn-representation-proxy-bounded error Consent.provision.provision.actor:representative.extension:representationAuthority Thẩm quyền theo uỷ quyền phải có GIỚI HẠN máy-đọc: NGÀY KẾT THÚC (period.end của token hoặc validity.end trong bằng chứng — chỉ có ngày bắt đầu là uỷ quyền vô thời hạn) VÀ phạm vi (scope trong ít nhất một bằng chứng) — Bộ luật Dân sự Điều 138/140/141. A delegated-proxy authority SHALL carry a machine-readable validity bound AND scope. extension.where(url='type').value.ofType(Coding).code != 'delegated-proxy' or ((extension.where(url='period').value.ofType(Period).end.exists() or extension.where(url='evidence').extension.where(url='validity').value.ofType(Period).end.exists()) and extension.where(url='evidence').extension.where(url='scope').exists())
vn-representation-proxy-evidence error Consent.provision.provision.actor:representative.extension:representationAuthority Thẩm quyền theo uỷ quyền phải kèm ít nhất một bằng chứng (văn bản uỷ quyền). A delegated-proxy authority SHALL carry at least one evidence entry. extension.where(url='type').value.ofType(Coding).code = 'delegated-proxy' implies extension.where(url='evidence').exists()
vn-representation-type-selection-basis error Consent.provision.provision.actor:representative.extension:representationAuthority Loại thẩm quyền phải tương thích với nhóm căn cứ lựa chọn tại Luật KCB Điều 8 khoản 2. The authority type SHALL be consistent with the statutory selection basis. extension.where(url='selectionBasis').empty() or ((extension.where(url='selectionBasis').value.ofType(Coding).code = 'civil-code-representative') and (extension.where(url='type').value.ofType(Coding).code = 'legal-representative' or extension.where(url='type').value.ofType(Coding).code = 'guardian' or extension.where(url='type').value.ofType(Coding).code = 'delegated-proxy')) or ((extension.where(url='selectionBasis').value.ofType(Coding).code = 'responsible-legal-entity-appointed') and (extension.where(url='type').value.ofType(Coding).code = 'legal-representative' or extension.where(url='type').value.ofType(Coding).code = 'healthcare-agent')) or ((extension.where(url='selectionBasis').value.ofType(Coding).code = 'adult-patient-selected' or extension.where(url='selectionBasis').value.ofType(Coding).code = 'family-selected' or extension.where(url='selectionBasis').value.ofType(Coding).code = 'voluntary-obligation-performer') and extension.where(url='type').value.ofType(Coding).code = 'healthcare-agent')

 

Biểu diễn khác của hồ sơ: CSV, Excel, Schematron