HL7 Vietnam VN Core FHIR Implementation Guide

Hướng dẫn triển khai FHIR cốt lõi Việt Nam — VN Core FHIR Implementation Guide
0.10.0 - Draft for Community Review Viet Nam cờ

Hướng dẫn triển khai FHIR cốt lõi Việt Nam — VN Core FHIR Implementation Guide - Draft for Community Review (v0.10.0) built by the FHIR (HL7® FHIR® Standard) Build Tools. See the Directory of published versions

Mô hình logic: Dữ liệu truy vết và nhật ký truy cập (QĐ 2113/QĐ-BYT, TT 47/2026/TT-BCA) — Logical Model - Mô tả chi tiết

Draft tại thời điểm 2026-09-22

Các định nghĩa cho vnDataTraceabilityRecordLm mô hình logic

Guidance on how to interpret the contents of this table can be foundhere

0. vnDataTraceabilityRecordLm
Definition

Logical model đặc tả thông tin mà Quyết định 2113/QĐ-BYT buộc lưu trong dữ liệu truy vết, và thông tin mà Thông tư 47/2026/TT-BCA buộc có trong nhật ký truy cập hệ thống — Chỉ phần THỨ NHẤT làm bảng chỉ tiêu văn bản để đối chiếu cardinality của profile Provenance; phần thứ hai KHÔNG đóng vai trò ấy cho AuditEvent, vì lý do phạm vi nêu bên dưới.

QĐ 2113/QĐ-BYT, Lớp 4 của mô hình an toàn dữ liệu, nêu nguyên văn: 'Truy vết dữ liệu (Data Lineage): là yêu cầu bắt buộc đối với tất cả hệ thống có chức năng chia sẻ, tích hợp hoặc phân tích dữ liệu. Dữ liệu truy vết phải bảo đảm lưu lại đầy đủ các thông tin sau: nguồn gốc dữ liệu; thời điểm và điều kiện thu thập; các hành động xử lý đã thực hiện; tổ chức hoặc đơn vị thực hiện hành động đó.'

TT 47/2026/TT-BCA mục 3.9.2.1.4 nêu: 'Nhật ký truy cập hệ thống tối thiểu bao gồm các thông tin: địa chỉ nguồn, địa chỉ đích, tài khoản đích và thời điểm xảy ra sự kiện.' PHẠM VI: TT 47/2026/TT-BCA là QUY CHUẨN cho 'hệ thống thông tin lưu trữ tài liệu điện tử trong các cơ quan Đảng, Nhà nước' (mục 1.1), KHÔNG phải cho cơ sở khám bệnh, chữa bệnh nói chung — nên đây chỉ là căn cứ CÓ ĐIỀU KIỆN, áp khi hệ thống thật sự thuộc phạm vi Quy chuẩn. ĐÍNH CHÍNH 07/09/2026: câu trước đó trong chính Description này nói 'QĐ 2113/QĐ-BYT không quy định gì về nhật ký truy cập' là SAI — phụ lục của quyết định ấy CÓ, ở Lớp 5 'Người dùng an toàn': 'cá nhân truy cập vào hệ thống phải được xác thực định danh... Hệ thống phải ghi nhận đầy đủ lịch sử truy cập và có khả năng kiểm tra, truy vết (audit)', phạm vi tại mục III phủ 'các cơ sở y tế công lập và ngoài công lập'. Đó là nghĩa vụ NĂNG LỰC đúng phạm vi nhưng KHÔNG liệt kê trường — khác hẳn Lớp 4 vốn nói 'là yêu cầu bắt buộc' rồi liệt kê đủ bốn thông tin. Vì vậy MỌI trường của nhóm nhật ký khai 0..1, nhóm này KHÔNG dùng làm bảng chỉ tiêu đối chiếu ở chiều P-A, và ô sổ cái của VNCoreAuditEvent ở trạng thái hoãn.

ShortDữ liệu truy vết và nhật ký truy cập (QĐ 2113/QĐ-BYT, TT 47/2026/TT-BCA) — Logical Model
Control0..*
Is Modifierfalse
Logical ModelInstances of this logical model are not marked to be the target of a Reference
2. vnDataTraceabilityRecordLm.truyVetDuLieu
Definition

Thông tin truy vết phải lưu cho dữ liệu được chia sẻ, tích hợp hoặc phân tích

ShortThông tin truy vết phải lưu cho dữ liệu được chia sẻ, tích hợp hoặc phân tích
Comments

Văn bản nói 'yêu cầu BẮT BUỘC đối với tất cả hệ thống có chức năng chia sẻ, tích hợp hoặc phân tích dữ liệu' — một IG trao đổi dữ liệu nằm trọn trong phạm vi ấy. Truy vết còn 'phải được tổ chức thành hệ thống tập trung hoặc tích hợp với giải pháp SIEM/DAM để phục vụ kiểm toán và cảnh báo sự cố', tức là dữ liệu này phải rút ra được, không chỉ nằm rải trong từng resource.

Control1..1
TypeBackboneElement
Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
4. vnDataTraceabilityRecordLm.truyVetDuLieu.id
Definition

Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.

ShortUnique id for inter-element referencing
Control0..1
Typestring
Is Modifierfalse
XML FormatIn the XML format, this property is represented as an attribute.
Summaryfalse
6. vnDataTraceabilityRecordLm.truyVetDuLieu.extension
Definition

May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.

ShortAdditional content defined by implementations
Comments

There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

Control0..*
TypeExtension
Is Modifierfalse
Summaryfalse
Alternate Namesextensions, user content
Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
SlicingThis element introduces a set of slices on vnDataTraceabilityRecordLm.truyVetDuLieu.extension. The slices areUnordered and Open, and can be differentiated using the following discriminators:
  • value @ url
  • 8. vnDataTraceabilityRecordLm.truyVetDuLieu.modifierExtension
    Definition

    May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions.

    Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).

    ShortExtensions that cannot be ignored even if unrecognized
    Comments

    There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

    Control0..*
    TypeExtension
    Is Modifiertrue because Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
    Summarytrue
    Requirements

    Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.

    Alternate Namesextensions, user content, modifiers
    Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
    ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
    10. vnDataTraceabilityRecordLm.truyVetDuLieu.nguonGocDuLieu
    Definition

    Nguồn gốc dữ liệu

    ShortNguồn gốc dữ liệu
    Control1..1
    Typestring
    Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
    12. vnDataTraceabilityRecordLm.truyVetDuLieu.thoiDiemThuThap
    Definition

    Thời điểm thu thập

    ShortThời điểm thu thập
    Comments

    Sửa 06/09/2026 sau phản biện Fable: recorded là lúc GHI bản ghi truy vết, còn văn bản hỏi thời điểm THU THẬP dữ liệu — đó là occurred[x].

    Control1..1
    TypedateTime
    Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
    14. vnDataTraceabilityRecordLm.truyVetDuLieu.dieuKienThuThap
    Definition

    Điều kiện thu thập

    ShortĐiều kiện thu thập
    Comments

    Văn bản ghép 'thời điểm và điều kiện thu thập' trong một cụm nhưng đó là hai thông tin: khi nào lấy, và lấy theo căn cứ nào. Trên Provenance, căn cứ nằm ở policy (chính sách hoặc quy định cho phép) và reason (lý do xử lý).

    Control1..1
    Typestring
    Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
    16. vnDataTraceabilityRecordLm.truyVetDuLieu.hanhDongXuLy
    Definition

    Các hành động xử lý đã thực hiện

    ShortCác hành động xử lý đã thực hiện
    Control1..1
    Typestring
    Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
    18. vnDataTraceabilityRecordLm.truyVetDuLieu.donViThucHien
    Definition

    Tổ chức hoặc đơn vị thực hiện hành động

    ShortTổ chức hoặc đơn vị thực hiện hành động
    Comments

    Văn bản nói 'tổ chức hoặc đơn vị', tức chủ thể pháp nhân chịu trách nhiệm — trên Provenance là agent.who khi tác nhân là tổ chức, hoặc agent.onBehalfOf khi người thực hiện hành động thay mặt một tổ chức.

    Control1..1
    Typestring
    Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
    20. vnDataTraceabilityRecordLm.nhatKyTruyCap
    Definition

    Bản ghi nhật ký truy cập hệ thống

    ShortBản ghi nhật ký truy cập hệ thống
    Comments

    MỌI trường của nhóm khai 0..1 — không trường nào bắt buộc, vì chưa có văn bản nào liệt kê nội dung bản ghi nhật ký truy cập cho cơ sở khám bệnh, chữa bệnh. Xem khối chú thích trên để biết sáu căn cứ đã thử và vì sao từng cái bị bác. Nhóm vẫn giữ lại vì nó mô tả đúng hình dạng dữ liệu mà một hệ thống thuộc diện TT 47/2026/TT-BCA phải sinh ra, và vì QĐ 2113/QĐ-BYT Lớp 5 có nghĩa vụ NĂNG LỰC đúng phạm vi y tế (ghi nhận đầy đủ lịch sử truy cập và có khả năng kiểm tra, truy vết) dù không liệt kê trường. Ba trường nguoiSuDung, hanhDong, trangThai từng được thêm rồi rút lại trong ngày 07/09/2026: chúng phản ánh bốn thành phần trong ĐỊNH NGHĨA nhật ký hệ thống của Luật 116/2025/QH15 Điều 2 khoản 11, nhưng định nghĩa thuật ngữ không phải nghĩa vụ trường — trangThai đã gỡ hẳn, hai trường còn lại giữ ở 0..1 như cấu trúc thiết kế của IG.

    Control0..1
    TypeBackboneElement
    Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
    22. vnDataTraceabilityRecordLm.nhatKyTruyCap.id
    Definition

    Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.

    ShortUnique id for inter-element referencing
    Control0..1
    Typestring
    Is Modifierfalse
    XML FormatIn the XML format, this property is represented as an attribute.
    Summaryfalse
    24. vnDataTraceabilityRecordLm.nhatKyTruyCap.extension
    Definition

    May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.

    ShortAdditional content defined by implementations
    Comments

    There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

    Control0..*
    TypeExtension
    Is Modifierfalse
    Summaryfalse
    Alternate Namesextensions, user content
    Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
    ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
    SlicingThis element introduces a set of slices on vnDataTraceabilityRecordLm.nhatKyTruyCap.extension. The slices areUnordered and Open, and can be differentiated using the following discriminators:
    • value @ url
    • 26. vnDataTraceabilityRecordLm.nhatKyTruyCap.modifierExtension
      Definition

      May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions.

      Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).

      ShortExtensions that cannot be ignored even if unrecognized
      Comments

      There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

      Control0..*
      TypeExtension
      Is Modifiertrue because Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
      Summarytrue
      Requirements

      Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.

      Alternate Namesextensions, user content, modifiers
      Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
      ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
      28. vnDataTraceabilityRecordLm.nhatKyTruyCap.diaChiNguon
      Definition

      Địa chỉ nguồn (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)

      ShortĐịa chỉ nguồn (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)
      Control0..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      30. vnDataTraceabilityRecordLm.nhatKyTruyCap.diaChiDich
      Definition

      Địa chỉ đích (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)

      ShortĐịa chỉ đích (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)
      Control0..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      32. vnDataTraceabilityRecordLm.nhatKyTruyCap.taiKhoanDich
      Definition

      Tài khoản đích (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)

      ShortTài khoản đích (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)
      Comments

      Tài khoản bị truy cập tới, phân biệt với tài khoản thực hiện truy cập. Trên AuditEvent, tác nhân yêu cầu mang agent.requestor = true, còn đối tượng bị tác động nằm ở entity.

      Control0..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      34. vnDataTraceabilityRecordLm.nhatKyTruyCap.nguoiSuDung
      Definition

      NGƯỜI DÙNG — tài khoản thực hiện thao tác

      ShortNGƯỜI DÙNG — tài khoản thực hiện thao tác
      Comments

      QĐ 2113/QĐ-BYT Lớp 5 nói cá nhân truy cập vào hệ thống phải được xác thực định danh, phân quyền rõ ràng theo vai trò — nghĩa vụ đúng phạm vi y tế nhưng ở mức NĂNG LỰC. TT 54/2017/TT-BYT nhóm VI tiêu chí 94 mô tả ghi vết (log) lại toàn bộ tác động của các người dùng trên hệ thống, nhưng đó là tiêu chí xếp mức, không phải nghĩa vụ. Vì vậy element giữ 0..1. Phân biệt với taiKhoanDich: đây là bên THỰC HIỆN, kia là đối tượng BỊ tác động.

      Control0..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      36. vnDataTraceabilityRecordLm.nhatKyTruyCap.hanhDong
      Definition

      HOẠT ĐỘNG — loại thao tác đã thực hiện

      ShortHOẠT ĐỘNG — loại thao tác đã thực hiện
      Comments

      TT 54/2017/TT-BYT Phụ lục I nhóm VII tiêu chí 116 MÔ TẢ năng lực ghi vết các chức năng cập nhật dữ liệu vào hệ thống và các chức năng khai thác dữ liệu chính — tức cả ghi lẫn đọc. Dùng chữ MÔ TẢ chứ không phải BUỘC là có chủ ý (sửa 07/09/2026 sau phản biện): thông tư ấy là thang xếp mức ứng dụng CNTT, Điều 4 khoản 3 nói không đạt tiêu chí thì xếp ở mức thấp hơn liền kề chứ không phải vi phạm, nên nó không đặt nghĩa vụ trường. Trên AuditEvent, loại thao tác nằm ở action với bộ mã C/R/U/D/E của FHIR. Element giữ 0..1.

      Control0..1
      Typecode
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      38. vnDataTraceabilityRecordLm.nhatKyTruyCap.thoiDiemSuKien
      Definition

      Thời điểm xảy ra sự kiện

      ShortThời điểm xảy ra sự kiện
      Comments

      Thời điểm XẢY RA sự kiện, nên đích là AuditEvent.period — FHIR R4 định nghĩa period là The period during which the activity occurred, còn recorded là The time when the event was recorded. SỬA 07/09/2026 sau phản biện Codex: bản trước trỏ recorded và lấy chính việc recorded có min = 1 làm lý do đóng ô — chọn đích vì nó mạnh chứ không vì nó đúng nghĩa, đúng lớp lỗi XẢY RA ≠ GHI NHẬN mà cổng Fable từng bắt ở một model khác. Element giữ 0..1: QĐ 2113/QĐ-BYT Lớp 5 buộc ghi nhận đầy đủ lịch sử truy cập nhưng đó là nghĩa vụ NĂNG LỰC, không liệt kê trường. TT 47/2026/TT-BCA mục 3.9.1 gắn nghĩa vụ này với ĐỒNG BỘ THỜI GIAN toàn hệ thống — căn cứ bổ sung cho hệ thống thuộc diện Quy chuẩn ấy.

      Control0..1
      TypedateTime
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension

      Guidance on how to interpret the contents of this table can be foundhere

      0. vnDataTraceabilityRecordLm
      Definition

      Logical model đặc tả thông tin mà Quyết định 2113/QĐ-BYT buộc lưu trong dữ liệu truy vết, và thông tin mà Thông tư 47/2026/TT-BCA buộc có trong nhật ký truy cập hệ thống — Chỉ phần THỨ NHẤT làm bảng chỉ tiêu văn bản để đối chiếu cardinality của profile Provenance; phần thứ hai KHÔNG đóng vai trò ấy cho AuditEvent, vì lý do phạm vi nêu bên dưới.

      QĐ 2113/QĐ-BYT, Lớp 4 của mô hình an toàn dữ liệu, nêu nguyên văn: 'Truy vết dữ liệu (Data Lineage): là yêu cầu bắt buộc đối với tất cả hệ thống có chức năng chia sẻ, tích hợp hoặc phân tích dữ liệu. Dữ liệu truy vết phải bảo đảm lưu lại đầy đủ các thông tin sau: nguồn gốc dữ liệu; thời điểm và điều kiện thu thập; các hành động xử lý đã thực hiện; tổ chức hoặc đơn vị thực hiện hành động đó.'

      TT 47/2026/TT-BCA mục 3.9.2.1.4 nêu: 'Nhật ký truy cập hệ thống tối thiểu bao gồm các thông tin: địa chỉ nguồn, địa chỉ đích, tài khoản đích và thời điểm xảy ra sự kiện.' PHẠM VI: TT 47/2026/TT-BCA là QUY CHUẨN cho 'hệ thống thông tin lưu trữ tài liệu điện tử trong các cơ quan Đảng, Nhà nước' (mục 1.1), KHÔNG phải cho cơ sở khám bệnh, chữa bệnh nói chung — nên đây chỉ là căn cứ CÓ ĐIỀU KIỆN, áp khi hệ thống thật sự thuộc phạm vi Quy chuẩn. ĐÍNH CHÍNH 07/09/2026: câu trước đó trong chính Description này nói 'QĐ 2113/QĐ-BYT không quy định gì về nhật ký truy cập' là SAI — phụ lục của quyết định ấy CÓ, ở Lớp 5 'Người dùng an toàn': 'cá nhân truy cập vào hệ thống phải được xác thực định danh... Hệ thống phải ghi nhận đầy đủ lịch sử truy cập và có khả năng kiểm tra, truy vết (audit)', phạm vi tại mục III phủ 'các cơ sở y tế công lập và ngoài công lập'. Đó là nghĩa vụ NĂNG LỰC đúng phạm vi nhưng KHÔNG liệt kê trường — khác hẳn Lớp 4 vốn nói 'là yêu cầu bắt buộc' rồi liệt kê đủ bốn thông tin. Vì vậy MỌI trường của nhóm nhật ký khai 0..1, nhóm này KHÔNG dùng làm bảng chỉ tiêu đối chiếu ở chiều P-A, và ô sổ cái của VNCoreAuditEvent ở trạng thái hoãn.

      ShortDữ liệu truy vết và nhật ký truy cập (QĐ 2113/QĐ-BYT, TT 47/2026/TT-BCA) — Logical Model
      Logical ModelInstances of this logical model are not marked to be the target of a Reference
      2. vnDataTraceabilityRecordLm.truyVetDuLieu
      Definition

      Thông tin truy vết phải lưu cho dữ liệu được chia sẻ, tích hợp hoặc phân tích

      ShortThông tin truy vết phải lưu cho dữ liệu được chia sẻ, tích hợp hoặc phân tích
      Comments

      Văn bản nói 'yêu cầu BẮT BUỘC đối với tất cả hệ thống có chức năng chia sẻ, tích hợp hoặc phân tích dữ liệu' — một IG trao đổi dữ liệu nằm trọn trong phạm vi ấy. Truy vết còn 'phải được tổ chức thành hệ thống tập trung hoặc tích hợp với giải pháp SIEM/DAM để phục vụ kiểm toán và cảnh báo sự cố', tức là dữ liệu này phải rút ra được, không chỉ nằm rải trong từng resource.

      Control1..1
      TypeBackboneElement
      4. vnDataTraceabilityRecordLm.truyVetDuLieu.nguonGocDuLieu
      Definition

      Nguồn gốc dữ liệu

      ShortNguồn gốc dữ liệu
      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      6. vnDataTraceabilityRecordLm.truyVetDuLieu.thoiDiemThuThap
      Definition

      Thời điểm thu thập

      ShortThời điểm thu thập
      Comments

      Sửa 06/09/2026 sau phản biện Fable: recorded là lúc GHI bản ghi truy vết, còn văn bản hỏi thời điểm THU THẬP dữ liệu — đó là occurred[x].

      Control1..1
      TypedateTime
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      8. vnDataTraceabilityRecordLm.truyVetDuLieu.dieuKienThuThap
      Definition

      Điều kiện thu thập

      ShortĐiều kiện thu thập
      Comments

      Văn bản ghép 'thời điểm và điều kiện thu thập' trong một cụm nhưng đó là hai thông tin: khi nào lấy, và lấy theo căn cứ nào. Trên Provenance, căn cứ nằm ở policy (chính sách hoặc quy định cho phép) và reason (lý do xử lý).

      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      10. vnDataTraceabilityRecordLm.truyVetDuLieu.hanhDongXuLy
      Definition

      Các hành động xử lý đã thực hiện

      ShortCác hành động xử lý đã thực hiện
      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      12. vnDataTraceabilityRecordLm.truyVetDuLieu.donViThucHien
      Definition

      Tổ chức hoặc đơn vị thực hiện hành động

      ShortTổ chức hoặc đơn vị thực hiện hành động
      Comments

      Văn bản nói 'tổ chức hoặc đơn vị', tức chủ thể pháp nhân chịu trách nhiệm — trên Provenance là agent.who khi tác nhân là tổ chức, hoặc agent.onBehalfOf khi người thực hiện hành động thay mặt một tổ chức.

      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      14. vnDataTraceabilityRecordLm.nhatKyTruyCap
      Definition

      Bản ghi nhật ký truy cập hệ thống

      ShortBản ghi nhật ký truy cập hệ thống
      Comments

      MỌI trường của nhóm khai 0..1 — không trường nào bắt buộc, vì chưa có văn bản nào liệt kê nội dung bản ghi nhật ký truy cập cho cơ sở khám bệnh, chữa bệnh. Xem khối chú thích trên để biết sáu căn cứ đã thử và vì sao từng cái bị bác. Nhóm vẫn giữ lại vì nó mô tả đúng hình dạng dữ liệu mà một hệ thống thuộc diện TT 47/2026/TT-BCA phải sinh ra, và vì QĐ 2113/QĐ-BYT Lớp 5 có nghĩa vụ NĂNG LỰC đúng phạm vi y tế (ghi nhận đầy đủ lịch sử truy cập và có khả năng kiểm tra, truy vết) dù không liệt kê trường. Ba trường nguoiSuDung, hanhDong, trangThai từng được thêm rồi rút lại trong ngày 07/09/2026: chúng phản ánh bốn thành phần trong ĐỊNH NGHĨA nhật ký hệ thống của Luật 116/2025/QH15 Điều 2 khoản 11, nhưng định nghĩa thuật ngữ không phải nghĩa vụ trường — trangThai đã gỡ hẳn, hai trường còn lại giữ ở 0..1 như cấu trúc thiết kế của IG.

      Control0..1
      TypeBackboneElement
      16. vnDataTraceabilityRecordLm.nhatKyTruyCap.diaChiNguon
      Definition

      Địa chỉ nguồn (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)

      ShortĐịa chỉ nguồn (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)
      Control0..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      18. vnDataTraceabilityRecordLm.nhatKyTruyCap.diaChiDich
      Definition

      Địa chỉ đích (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)

      ShortĐịa chỉ đích (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)
      Control0..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      20. vnDataTraceabilityRecordLm.nhatKyTruyCap.taiKhoanDich
      Definition

      Tài khoản đích (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)

      ShortTài khoản đích (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)
      Comments

      Tài khoản bị truy cập tới, phân biệt với tài khoản thực hiện truy cập. Trên AuditEvent, tác nhân yêu cầu mang agent.requestor = true, còn đối tượng bị tác động nằm ở entity.

      Control0..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      22. vnDataTraceabilityRecordLm.nhatKyTruyCap.nguoiSuDung
      Definition

      NGƯỜI DÙNG — tài khoản thực hiện thao tác

      ShortNGƯỜI DÙNG — tài khoản thực hiện thao tác
      Comments

      QĐ 2113/QĐ-BYT Lớp 5 nói cá nhân truy cập vào hệ thống phải được xác thực định danh, phân quyền rõ ràng theo vai trò — nghĩa vụ đúng phạm vi y tế nhưng ở mức NĂNG LỰC. TT 54/2017/TT-BYT nhóm VI tiêu chí 94 mô tả ghi vết (log) lại toàn bộ tác động của các người dùng trên hệ thống, nhưng đó là tiêu chí xếp mức, không phải nghĩa vụ. Vì vậy element giữ 0..1. Phân biệt với taiKhoanDich: đây là bên THỰC HIỆN, kia là đối tượng BỊ tác động.

      Control0..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      24. vnDataTraceabilityRecordLm.nhatKyTruyCap.hanhDong
      Definition

      HOẠT ĐỘNG — loại thao tác đã thực hiện

      ShortHOẠT ĐỘNG — loại thao tác đã thực hiện
      Comments

      TT 54/2017/TT-BYT Phụ lục I nhóm VII tiêu chí 116 MÔ TẢ năng lực ghi vết các chức năng cập nhật dữ liệu vào hệ thống và các chức năng khai thác dữ liệu chính — tức cả ghi lẫn đọc. Dùng chữ MÔ TẢ chứ không phải BUỘC là có chủ ý (sửa 07/09/2026 sau phản biện): thông tư ấy là thang xếp mức ứng dụng CNTT, Điều 4 khoản 3 nói không đạt tiêu chí thì xếp ở mức thấp hơn liền kề chứ không phải vi phạm, nên nó không đặt nghĩa vụ trường. Trên AuditEvent, loại thao tác nằm ở action với bộ mã C/R/U/D/E của FHIR. Element giữ 0..1.

      Control0..1
      Typecode
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      26. vnDataTraceabilityRecordLm.nhatKyTruyCap.thoiDiemSuKien
      Definition

      Thời điểm xảy ra sự kiện

      ShortThời điểm xảy ra sự kiện
      Comments

      Thời điểm XẢY RA sự kiện, nên đích là AuditEvent.period — FHIR R4 định nghĩa period là The period during which the activity occurred, còn recorded là The time when the event was recorded. SỬA 07/09/2026 sau phản biện Codex: bản trước trỏ recorded và lấy chính việc recorded có min = 1 làm lý do đóng ô — chọn đích vì nó mạnh chứ không vì nó đúng nghĩa, đúng lớp lỗi XẢY RA ≠ GHI NHẬN mà cổng Fable từng bắt ở một model khác. Element giữ 0..1: QĐ 2113/QĐ-BYT Lớp 5 buộc ghi nhận đầy đủ lịch sử truy cập nhưng đó là nghĩa vụ NĂNG LỰC, không liệt kê trường. TT 47/2026/TT-BCA mục 3.9.1 gắn nghĩa vụ này với ĐỒNG BỘ THỜI GIAN toàn hệ thống — căn cứ bổ sung cho hệ thống thuộc diện Quy chuẩn ấy.

      Control0..1
      TypedateTime
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension

      Guidance on how to interpret the contents of this table can be foundhere

      0. vnDataTraceabilityRecordLm
      Definition

      Logical model đặc tả thông tin mà Quyết định 2113/QĐ-BYT buộc lưu trong dữ liệu truy vết, và thông tin mà Thông tư 47/2026/TT-BCA buộc có trong nhật ký truy cập hệ thống — Chỉ phần THỨ NHẤT làm bảng chỉ tiêu văn bản để đối chiếu cardinality của profile Provenance; phần thứ hai KHÔNG đóng vai trò ấy cho AuditEvent, vì lý do phạm vi nêu bên dưới.

      QĐ 2113/QĐ-BYT, Lớp 4 của mô hình an toàn dữ liệu, nêu nguyên văn: 'Truy vết dữ liệu (Data Lineage): là yêu cầu bắt buộc đối với tất cả hệ thống có chức năng chia sẻ, tích hợp hoặc phân tích dữ liệu. Dữ liệu truy vết phải bảo đảm lưu lại đầy đủ các thông tin sau: nguồn gốc dữ liệu; thời điểm và điều kiện thu thập; các hành động xử lý đã thực hiện; tổ chức hoặc đơn vị thực hiện hành động đó.'

      TT 47/2026/TT-BCA mục 3.9.2.1.4 nêu: 'Nhật ký truy cập hệ thống tối thiểu bao gồm các thông tin: địa chỉ nguồn, địa chỉ đích, tài khoản đích và thời điểm xảy ra sự kiện.' PHẠM VI: TT 47/2026/TT-BCA là QUY CHUẨN cho 'hệ thống thông tin lưu trữ tài liệu điện tử trong các cơ quan Đảng, Nhà nước' (mục 1.1), KHÔNG phải cho cơ sở khám bệnh, chữa bệnh nói chung — nên đây chỉ là căn cứ CÓ ĐIỀU KIỆN, áp khi hệ thống thật sự thuộc phạm vi Quy chuẩn. ĐÍNH CHÍNH 07/09/2026: câu trước đó trong chính Description này nói 'QĐ 2113/QĐ-BYT không quy định gì về nhật ký truy cập' là SAI — phụ lục của quyết định ấy CÓ, ở Lớp 5 'Người dùng an toàn': 'cá nhân truy cập vào hệ thống phải được xác thực định danh... Hệ thống phải ghi nhận đầy đủ lịch sử truy cập và có khả năng kiểm tra, truy vết (audit)', phạm vi tại mục III phủ 'các cơ sở y tế công lập và ngoài công lập'. Đó là nghĩa vụ NĂNG LỰC đúng phạm vi nhưng KHÔNG liệt kê trường — khác hẳn Lớp 4 vốn nói 'là yêu cầu bắt buộc' rồi liệt kê đủ bốn thông tin. Vì vậy MỌI trường của nhóm nhật ký khai 0..1, nhóm này KHÔNG dùng làm bảng chỉ tiêu đối chiếu ở chiều P-A, và ô sổ cái của VNCoreAuditEvent ở trạng thái hoãn.

      ShortDữ liệu truy vết và nhật ký truy cập (QĐ 2113/QĐ-BYT, TT 47/2026/TT-BCA) — Logical Model
      Control0..*
      Is Modifierfalse
      Logical ModelInstances of this logical model are not marked to be the target of a Reference
      2. vnDataTraceabilityRecordLm.truyVetDuLieu
      Definition

      Thông tin truy vết phải lưu cho dữ liệu được chia sẻ, tích hợp hoặc phân tích

      ShortThông tin truy vết phải lưu cho dữ liệu được chia sẻ, tích hợp hoặc phân tích
      Comments

      Văn bản nói 'yêu cầu BẮT BUỘC đối với tất cả hệ thống có chức năng chia sẻ, tích hợp hoặc phân tích dữ liệu' — một IG trao đổi dữ liệu nằm trọn trong phạm vi ấy. Truy vết còn 'phải được tổ chức thành hệ thống tập trung hoặc tích hợp với giải pháp SIEM/DAM để phục vụ kiểm toán và cảnh báo sự cố', tức là dữ liệu này phải rút ra được, không chỉ nằm rải trong từng resource.

      Control1..1
      TypeBackboneElement
      Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
      4. vnDataTraceabilityRecordLm.truyVetDuLieu.id
      Definition

      Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.

      ShortUnique id for inter-element referencing
      Control0..1
      Typestring
      Is Modifierfalse
      XML FormatIn the XML format, this property is represented as an attribute.
      Summaryfalse
      6. vnDataTraceabilityRecordLm.truyVetDuLieu.extension
      Definition

      May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.

      ShortAdditional content defined by implementations
      Comments

      There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

      Control0..*
      TypeExtension
      Is Modifierfalse
      Summaryfalse
      Alternate Namesextensions, user content
      Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
      ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
      SlicingThis element introduces a set of slices on vnDataTraceabilityRecordLm.truyVetDuLieu.extension. The slices areUnordered and Open, and can be differentiated using the following discriminators:
      • value @ url
      • 8. vnDataTraceabilityRecordLm.truyVetDuLieu.modifierExtension
        Definition

        May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions.

        Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).

        ShortExtensions that cannot be ignored even if unrecognized
        Comments

        There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

        Control0..*
        TypeExtension
        Is Modifiertrue because Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
        Summarytrue
        Requirements

        Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.

        Alternate Namesextensions, user content, modifiers
        Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
        ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
        10. vnDataTraceabilityRecordLm.truyVetDuLieu.nguonGocDuLieu
        Definition

        Nguồn gốc dữ liệu

        ShortNguồn gốc dữ liệu
        Control1..1
        Typestring
        Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
        12. vnDataTraceabilityRecordLm.truyVetDuLieu.thoiDiemThuThap
        Definition

        Thời điểm thu thập

        ShortThời điểm thu thập
        Comments

        Sửa 06/09/2026 sau phản biện Fable: recorded là lúc GHI bản ghi truy vết, còn văn bản hỏi thời điểm THU THẬP dữ liệu — đó là occurred[x].

        Control1..1
        TypedateTime
        Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
        14. vnDataTraceabilityRecordLm.truyVetDuLieu.dieuKienThuThap
        Definition

        Điều kiện thu thập

        ShortĐiều kiện thu thập
        Comments

        Văn bản ghép 'thời điểm và điều kiện thu thập' trong một cụm nhưng đó là hai thông tin: khi nào lấy, và lấy theo căn cứ nào. Trên Provenance, căn cứ nằm ở policy (chính sách hoặc quy định cho phép) và reason (lý do xử lý).

        Control1..1
        Typestring
        Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
        16. vnDataTraceabilityRecordLm.truyVetDuLieu.hanhDongXuLy
        Definition

        Các hành động xử lý đã thực hiện

        ShortCác hành động xử lý đã thực hiện
        Control1..1
        Typestring
        Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
        18. vnDataTraceabilityRecordLm.truyVetDuLieu.donViThucHien
        Definition

        Tổ chức hoặc đơn vị thực hiện hành động

        ShortTổ chức hoặc đơn vị thực hiện hành động
        Comments

        Văn bản nói 'tổ chức hoặc đơn vị', tức chủ thể pháp nhân chịu trách nhiệm — trên Provenance là agent.who khi tác nhân là tổ chức, hoặc agent.onBehalfOf khi người thực hiện hành động thay mặt một tổ chức.

        Control1..1
        Typestring
        Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
        20. vnDataTraceabilityRecordLm.nhatKyTruyCap
        Definition

        Bản ghi nhật ký truy cập hệ thống

        ShortBản ghi nhật ký truy cập hệ thống
        Comments

        MỌI trường của nhóm khai 0..1 — không trường nào bắt buộc, vì chưa có văn bản nào liệt kê nội dung bản ghi nhật ký truy cập cho cơ sở khám bệnh, chữa bệnh. Xem khối chú thích trên để biết sáu căn cứ đã thử và vì sao từng cái bị bác. Nhóm vẫn giữ lại vì nó mô tả đúng hình dạng dữ liệu mà một hệ thống thuộc diện TT 47/2026/TT-BCA phải sinh ra, và vì QĐ 2113/QĐ-BYT Lớp 5 có nghĩa vụ NĂNG LỰC đúng phạm vi y tế (ghi nhận đầy đủ lịch sử truy cập và có khả năng kiểm tra, truy vết) dù không liệt kê trường. Ba trường nguoiSuDung, hanhDong, trangThai từng được thêm rồi rút lại trong ngày 07/09/2026: chúng phản ánh bốn thành phần trong ĐỊNH NGHĨA nhật ký hệ thống của Luật 116/2025/QH15 Điều 2 khoản 11, nhưng định nghĩa thuật ngữ không phải nghĩa vụ trường — trangThai đã gỡ hẳn, hai trường còn lại giữ ở 0..1 như cấu trúc thiết kế của IG.

        Control0..1
        TypeBackboneElement
        Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
        22. vnDataTraceabilityRecordLm.nhatKyTruyCap.id
        Definition

        Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.

        ShortUnique id for inter-element referencing
        Control0..1
        Typestring
        Is Modifierfalse
        XML FormatIn the XML format, this property is represented as an attribute.
        Summaryfalse
        24. vnDataTraceabilityRecordLm.nhatKyTruyCap.extension
        Definition

        May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.

        ShortAdditional content defined by implementations
        Comments

        There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

        Control0..*
        TypeExtension
        Is Modifierfalse
        Summaryfalse
        Alternate Namesextensions, user content
        Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
        ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
        SlicingThis element introduces a set of slices on vnDataTraceabilityRecordLm.nhatKyTruyCap.extension. The slices areUnordered and Open, and can be differentiated using the following discriminators:
        • value @ url
        • 26. vnDataTraceabilityRecordLm.nhatKyTruyCap.modifierExtension
          Definition

          May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions.

          Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).

          ShortExtensions that cannot be ignored even if unrecognized
          Comments

          There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

          Control0..*
          TypeExtension
          Is Modifiertrue because Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
          Summarytrue
          Requirements

          Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.

          Alternate Namesextensions, user content, modifiers
          Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
          ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
          28. vnDataTraceabilityRecordLm.nhatKyTruyCap.diaChiNguon
          Definition

          Địa chỉ nguồn (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)

          ShortĐịa chỉ nguồn (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)
          Control0..1
          Typestring
          Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
          30. vnDataTraceabilityRecordLm.nhatKyTruyCap.diaChiDich
          Definition

          Địa chỉ đích (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)

          ShortĐịa chỉ đích (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)
          Control0..1
          Typestring
          Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
          32. vnDataTraceabilityRecordLm.nhatKyTruyCap.taiKhoanDich
          Definition

          Tài khoản đích (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)

          ShortTài khoản đích (chỉ bắt buộc với hệ thống thuộc diện TT 47/2026/TT-BCA)
          Comments

          Tài khoản bị truy cập tới, phân biệt với tài khoản thực hiện truy cập. Trên AuditEvent, tác nhân yêu cầu mang agent.requestor = true, còn đối tượng bị tác động nằm ở entity.

          Control0..1
          Typestring
          Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
          34. vnDataTraceabilityRecordLm.nhatKyTruyCap.nguoiSuDung
          Definition

          NGƯỜI DÙNG — tài khoản thực hiện thao tác

          ShortNGƯỜI DÙNG — tài khoản thực hiện thao tác
          Comments

          QĐ 2113/QĐ-BYT Lớp 5 nói cá nhân truy cập vào hệ thống phải được xác thực định danh, phân quyền rõ ràng theo vai trò — nghĩa vụ đúng phạm vi y tế nhưng ở mức NĂNG LỰC. TT 54/2017/TT-BYT nhóm VI tiêu chí 94 mô tả ghi vết (log) lại toàn bộ tác động của các người dùng trên hệ thống, nhưng đó là tiêu chí xếp mức, không phải nghĩa vụ. Vì vậy element giữ 0..1. Phân biệt với taiKhoanDich: đây là bên THỰC HIỆN, kia là đối tượng BỊ tác động.

          Control0..1
          Typestring
          Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
          36. vnDataTraceabilityRecordLm.nhatKyTruyCap.hanhDong
          Definition

          HOẠT ĐỘNG — loại thao tác đã thực hiện

          ShortHOẠT ĐỘNG — loại thao tác đã thực hiện
          Comments

          TT 54/2017/TT-BYT Phụ lục I nhóm VII tiêu chí 116 MÔ TẢ năng lực ghi vết các chức năng cập nhật dữ liệu vào hệ thống và các chức năng khai thác dữ liệu chính — tức cả ghi lẫn đọc. Dùng chữ MÔ TẢ chứ không phải BUỘC là có chủ ý (sửa 07/09/2026 sau phản biện): thông tư ấy là thang xếp mức ứng dụng CNTT, Điều 4 khoản 3 nói không đạt tiêu chí thì xếp ở mức thấp hơn liền kề chứ không phải vi phạm, nên nó không đặt nghĩa vụ trường. Trên AuditEvent, loại thao tác nằm ở action với bộ mã C/R/U/D/E của FHIR. Element giữ 0..1.

          Control0..1
          Typecode
          Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
          38. vnDataTraceabilityRecordLm.nhatKyTruyCap.thoiDiemSuKien
          Definition

          Thời điểm xảy ra sự kiện

          ShortThời điểm xảy ra sự kiện
          Comments

          Thời điểm XẢY RA sự kiện, nên đích là AuditEvent.period — FHIR R4 định nghĩa period là The period during which the activity occurred, còn recorded là The time when the event was recorded. SỬA 07/09/2026 sau phản biện Codex: bản trước trỏ recorded và lấy chính việc recorded có min = 1 làm lý do đóng ô — chọn đích vì nó mạnh chứ không vì nó đúng nghĩa, đúng lớp lỗi XẢY RA ≠ GHI NHẬN mà cổng Fable từng bắt ở một model khác. Element giữ 0..1: QĐ 2113/QĐ-BYT Lớp 5 buộc ghi nhận đầy đủ lịch sử truy cập nhưng đó là nghĩa vụ NĂNG LỰC, không liệt kê trường. TT 47/2026/TT-BCA mục 3.9.1 gắn nghĩa vụ này với ĐỒNG BỘ THỜI GIAN toàn hệ thống — căn cứ bổ sung cho hệ thống thuộc diện Quy chuẩn ấy.

          Control0..1
          TypedateTime
          Primitive ValueThis primitive element may be present, or absent, or replaced by an extension