HL7 Vietnam VN Core FHIR Implementation Guide

Hướng dẫn triển khai FHIR cốt lõi Việt Nam — VN Core FHIR Implementation Guide
0.10.0 - Draft for Community Review Viet Nam cờ

Hướng dẫn triển khai FHIR cốt lõi Việt Nam — VN Core FHIR Implementation Guide - Draft for Community Review (v0.10.0) built by the FHIR (HL7® FHIR® Standard) Build Tools. See the Directory of published versions

Mô hình logic: Bản ghi sự đồng ý và thông báo vi phạm dữ liệu cá nhân (NĐ 356/2025/NĐ-CP) — Logical Model - Mô tả chi tiết

Draft tại thời điểm 2026-09-22

Các định nghĩa cho vnPersonalDataConsentRecordLm mô hình logic

Guidance on how to interpret the contents of this table can be foundhere

0. vnPersonalDataConsentRecordLm
Definition

Logical model đặc tả nội dung mà Nghị định 356/2025/NĐ-CP (ban hành 31/12/2025, hiệu lực 01/01/2026) BUỘC phải có trong bản ghi sự đồng ý của chủ thể dữ liệu và trong thông báo vi phạm quy định bảo vệ dữ liệu cá nhân — làm bảng chỉ tiêu văn bản để đối chiếu cardinality của nhóm profile đồng ý và thông báo vi phạm.

Điều 6 khoản 1 nêu nguyên văn: 'Các phương thức xin sự đồng ý của chủ thể dữ liệu cá nhân phải bảo đảm khả năng kiểm chứng được về việc xác định chủ thể dữ liệu cá nhân đã thực hiện sự đồng ý, thời điểm và nội dung được đồng ý.' Ba thông tin ấy là điều kiện để sự đồng ý KIỂM CHỨNG ĐƯỢC — thiếu một trong ba thì bản ghi không chứng minh được gì. Khoản 2 buộc lưu trữ sự đồng ý và đặt trách nhiệm chứng minh lên bên kiểm soát dữ liệu khi có tranh chấp; khoản 4 buộc thông báo rõ cho chủ thể khi dữ liệu cần xử lý là dữ liệu cá nhân NHẠY CẢM — mọi dữ liệu sức khoẻ đều thuộc nhóm này.

Điều 28 khoản 1 liệt kê bốn nhóm nội dung của thông báo vi phạm: (a) mô tả tính chất vi phạm gồm thời gian, địa điểm, hành vi, tổ chức/cá nhân, các loại dữ liệu và số lượng dữ liệu liên quan; (b) chi tiết liên lạc của bộ phận hoặc nhân sự bảo vệ dữ liệu cá nhân; (c) mô tả hậu quả, thiệt hại có thể xảy ra; (d) mô tả biện pháp giải quyết, giảm thiểu tác hại. / Logical model for the consent record and data-breach notification content required by Decree 356/2025/NĐ-CP.

ShortBản ghi sự đồng ý và thông báo vi phạm dữ liệu cá nhân (NĐ 356/2025/NĐ-CP) — Logical Model
Control0..*
Is Modifierfalse
Logical ModelInstances of this logical model are not marked to be the target of a Reference
2. vnPersonalDataConsentRecordLm.suDongY
Definition

Bản ghi sự đồng ý của chủ thể dữ liệu cá nhân

ShortBản ghi sự đồng ý của chủ thể dữ liệu cá nhân
Comments

Khoản 2: 'Bên kiểm soát dữ liệu, bên kiểm soát và xử lý dữ liệu cá nhân phải LƯU TRỮ sự đồng ý của chủ thể dữ liệu. Trong trường hợp có tranh chấp, trách nhiệm chứng minh sự đồng ý thuộc về bên kiểm soát dữ liệu.' Nghĩa vụ lưu trữ và nghĩa vụ chứng minh đi cùng nhau — bản ghi thiếu một trong ba thông tin dưới đây thì không gánh được trách nhiệm chứng minh ấy.

Control1..1
TypeBackboneElement
Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
4. vnPersonalDataConsentRecordLm.suDongY.id
Definition

Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.

ShortUnique id for inter-element referencing
Control0..1
Typestring
Is Modifierfalse
XML FormatIn the XML format, this property is represented as an attribute.
Summaryfalse
6. vnPersonalDataConsentRecordLm.suDongY.extension
Definition

May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.

ShortAdditional content defined by implementations
Comments

There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

Control0..*
TypeExtension
Is Modifierfalse
Summaryfalse
Alternate Namesextensions, user content
Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
SlicingThis element introduces a set of slices on vnPersonalDataConsentRecordLm.suDongY.extension. The slices areUnordered and Open, and can be differentiated using the following discriminators:
  • value @ url
  • 8. vnPersonalDataConsentRecordLm.suDongY.modifierExtension
    Definition

    May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions.

    Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).

    ShortExtensions that cannot be ignored even if unrecognized
    Comments

    There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

    Control0..*
    TypeExtension
    Is Modifiertrue because Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
    Summarytrue
    Requirements

    Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.

    Alternate Namesextensions, user content, modifiers
    Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
    ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
    10. vnPersonalDataConsentRecordLm.suDongY.chuTheDuLieu
    Definition

    Chủ thể dữ liệu cá nhân đã thực hiện sự đồng ý

    ShortChủ thể dữ liệu cá nhân đã thực hiện sự đồng ý
    Control1..1
    Typestring
    Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
    12. vnPersonalDataConsentRecordLm.suDongY.thoiDiemDongY
    Definition

    Thời điểm đồng ý

    ShortThời điểm đồng ý
    Control1..1
    TypedateTime
    Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
    14. vnPersonalDataConsentRecordLm.suDongY.noiDungDuocDongY
    Definition

    Nội dung được đồng ý

    ShortNội dung được đồng ý
    Comments

    Phạm vi xử lý mà chủ thể đã đồng ý — trên Consent nó là cây provision với loại cho phép hoặc từ chối, mục đích xử lý và phạm vi dữ liệu.

    Control1..1
    Typestring
    Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
    16. vnPersonalDataConsentRecordLm.suDongY.phuongThucDongY
    Definition

    Phương thức thể hiện sự đồng ý

    ShortPhương thức thể hiện sự đồng ý
    Comments

    Điều 6 khoản 1 liệt kê năm phương thức: bằng văn bản; bằng cuộc gọi ghi âm; cú pháp đồng ý qua tin nhắn điện thoại; qua thư điện tử hoặc trang thông tin điện tử, nền tảng, ứng dụng có thiết lập kỹ thuật xin sự đồng ý; và các phương thức khác 'có thể in, sao chép bằng văn bản, bao gồm cả dưới dạng điện tử hoặc định dạng kiểm chứng được'. Phương thức phải ghi lại vì chính nó quyết định bản ghi có kiểm chứng được hay không.

    Control1..1
    Typestring
    Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
    18. vnPersonalDataConsentRecordLm.suDongY.thongBaoDuLieuNhayCam
    Definition

    Đã thông báo dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm

    ShortĐã thông báo dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm
    Comments

    Điều 6 khoản 4: 'Đối với việc xin sự đồng ý xử lý dữ liệu cá nhân NHẠY CẢM, chủ thể dữ liệu phải được thông báo rằng dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm.' min = 0 vì nghĩa vụ gắn với loại dữ liệu; nhưng trong phạm vi IG này nó gần như luôn áp — Luật 91/2025/QH15 xếp dữ liệu sức khoẻ vào nhóm nhạy cảm, nên mọi Consent cho dữ liệu lâm sàng đều rơi vào khoản 4.

    Control0..1
    Typeboolean
    Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
    20. vnPersonalDataConsentRecordLm.thongBaoViPham
    Definition

    Nội dung thông báo vi phạm quy định bảo vệ dữ liệu cá nhân

    ShortNội dung thông báo vi phạm quy định bảo vệ dữ liệu cá nhân
    Comments

    min = 0 vì thông báo chỉ phát sinh KHI có vi phạm; nhưng khi phát sinh thì đủ bốn nhóm nội dung của Điều 28 khoản 1 là bắt buộc. Model dừng ở mức bốn nhóm ấy: chưa có bằng chứng rằng từng ô của Mẫu 08 hay từng section hiện có của profile đều là nghĩa vụ riêng.

    Control0..1
    TypeBackboneElement
    Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
    22. vnPersonalDataConsentRecordLm.thongBaoViPham.id
    Definition

    Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.

    ShortUnique id for inter-element referencing
    Control0..1
    Typestring
    Is Modifierfalse
    XML FormatIn the XML format, this property is represented as an attribute.
    Summaryfalse
    24. vnPersonalDataConsentRecordLm.thongBaoViPham.extension
    Definition

    May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.

    ShortAdditional content defined by implementations
    Comments

    There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

    Control0..*
    TypeExtension
    Is Modifierfalse
    Summaryfalse
    Alternate Namesextensions, user content
    Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
    ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
    SlicingThis element introduces a set of slices on vnPersonalDataConsentRecordLm.thongBaoViPham.extension. The slices areUnordered and Open, and can be differentiated using the following discriminators:
    • value @ url
    • 26. vnPersonalDataConsentRecordLm.thongBaoViPham.modifierExtension
      Definition

      May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions.

      Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).

      ShortExtensions that cannot be ignored even if unrecognized
      Comments

      There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

      Control0..*
      TypeExtension
      Is Modifiertrue because Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
      Summarytrue
      Requirements

      Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.

      Alternate Namesextensions, user content, modifiers
      Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
      ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
      28. vnPersonalDataConsentRecordLm.thongBaoViPham.tinhChatViPham
      Definition

      Mô tả tính chất của việc vi phạm

      ShortMô tả tính chất của việc vi phạm
      Comments

      Điểm a: 'bao gồm: thời gian, địa điểm, hành vi, tổ chức, cá nhân, các loại dữ liệu cá nhân và số lượng dữ liệu liên quan' — bảy thành phần trong MỘT nhóm nội dung, không phải bảy trường độc lập.

      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      30. vnPersonalDataConsentRecordLm.thongBaoViPham.chiTietLienLac
      Definition

      Chi tiết liên lạc của bộ phận hoặc nhân sự bảo vệ dữ liệu cá nhân

      ShortChi tiết liên lạc của bộ phận hoặc nhân sự bảo vệ dữ liệu cá nhân
      Comments

      Điểm b cho phép ba khả năng: bộ phận bảo vệ dữ liệu cá nhân, nhân sự bảo vệ dữ liệu cá nhân, hoặc tổ chức/cá nhân cung cấp dịch vụ bảo vệ dữ liệu cá nhân.

      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      32. vnPersonalDataConsentRecordLm.thongBaoViPham.hauQuaThietHai
      Definition

      Mô tả hậu quả, thiệt hại có thể xảy ra

      ShortMô tả hậu quả, thiệt hại có thể xảy ra
      Comments

      Điểm c nói 'có thể xảy ra' — nghĩa vụ mô tả rủi ro dự kiến, không phải thiệt hại đã xác định. Không được để trống với lý do chưa đánh giá xong.

      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      34. vnPersonalDataConsentRecordLm.thongBaoViPham.bienPhapGiaiQuyet
      Definition

      Mô tả biện pháp giải quyết, giảm thiểu tác hại

      ShortMô tả biện pháp giải quyết, giảm thiểu tác hại
      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension

      Guidance on how to interpret the contents of this table can be foundhere

      0. vnPersonalDataConsentRecordLm
      Definition

      Logical model đặc tả nội dung mà Nghị định 356/2025/NĐ-CP (ban hành 31/12/2025, hiệu lực 01/01/2026) BUỘC phải có trong bản ghi sự đồng ý của chủ thể dữ liệu và trong thông báo vi phạm quy định bảo vệ dữ liệu cá nhân — làm bảng chỉ tiêu văn bản để đối chiếu cardinality của nhóm profile đồng ý và thông báo vi phạm.

      Điều 6 khoản 1 nêu nguyên văn: 'Các phương thức xin sự đồng ý của chủ thể dữ liệu cá nhân phải bảo đảm khả năng kiểm chứng được về việc xác định chủ thể dữ liệu cá nhân đã thực hiện sự đồng ý, thời điểm và nội dung được đồng ý.' Ba thông tin ấy là điều kiện để sự đồng ý KIỂM CHỨNG ĐƯỢC — thiếu một trong ba thì bản ghi không chứng minh được gì. Khoản 2 buộc lưu trữ sự đồng ý và đặt trách nhiệm chứng minh lên bên kiểm soát dữ liệu khi có tranh chấp; khoản 4 buộc thông báo rõ cho chủ thể khi dữ liệu cần xử lý là dữ liệu cá nhân NHẠY CẢM — mọi dữ liệu sức khoẻ đều thuộc nhóm này.

      Điều 28 khoản 1 liệt kê bốn nhóm nội dung của thông báo vi phạm: (a) mô tả tính chất vi phạm gồm thời gian, địa điểm, hành vi, tổ chức/cá nhân, các loại dữ liệu và số lượng dữ liệu liên quan; (b) chi tiết liên lạc của bộ phận hoặc nhân sự bảo vệ dữ liệu cá nhân; (c) mô tả hậu quả, thiệt hại có thể xảy ra; (d) mô tả biện pháp giải quyết, giảm thiểu tác hại. / Logical model for the consent record and data-breach notification content required by Decree 356/2025/NĐ-CP.

      ShortBản ghi sự đồng ý và thông báo vi phạm dữ liệu cá nhân (NĐ 356/2025/NĐ-CP) — Logical Model
      Logical ModelInstances of this logical model are not marked to be the target of a Reference
      2. vnPersonalDataConsentRecordLm.suDongY
      Definition

      Bản ghi sự đồng ý của chủ thể dữ liệu cá nhân

      ShortBản ghi sự đồng ý của chủ thể dữ liệu cá nhân
      Comments

      Khoản 2: 'Bên kiểm soát dữ liệu, bên kiểm soát và xử lý dữ liệu cá nhân phải LƯU TRỮ sự đồng ý của chủ thể dữ liệu. Trong trường hợp có tranh chấp, trách nhiệm chứng minh sự đồng ý thuộc về bên kiểm soát dữ liệu.' Nghĩa vụ lưu trữ và nghĩa vụ chứng minh đi cùng nhau — bản ghi thiếu một trong ba thông tin dưới đây thì không gánh được trách nhiệm chứng minh ấy.

      Control1..1
      TypeBackboneElement
      4. vnPersonalDataConsentRecordLm.suDongY.chuTheDuLieu
      Definition

      Chủ thể dữ liệu cá nhân đã thực hiện sự đồng ý

      ShortChủ thể dữ liệu cá nhân đã thực hiện sự đồng ý
      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      6. vnPersonalDataConsentRecordLm.suDongY.thoiDiemDongY
      Definition

      Thời điểm đồng ý

      ShortThời điểm đồng ý
      Control1..1
      TypedateTime
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      8. vnPersonalDataConsentRecordLm.suDongY.noiDungDuocDongY
      Definition

      Nội dung được đồng ý

      ShortNội dung được đồng ý
      Comments

      Phạm vi xử lý mà chủ thể đã đồng ý — trên Consent nó là cây provision với loại cho phép hoặc từ chối, mục đích xử lý và phạm vi dữ liệu.

      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      10. vnPersonalDataConsentRecordLm.suDongY.phuongThucDongY
      Definition

      Phương thức thể hiện sự đồng ý

      ShortPhương thức thể hiện sự đồng ý
      Comments

      Điều 6 khoản 1 liệt kê năm phương thức: bằng văn bản; bằng cuộc gọi ghi âm; cú pháp đồng ý qua tin nhắn điện thoại; qua thư điện tử hoặc trang thông tin điện tử, nền tảng, ứng dụng có thiết lập kỹ thuật xin sự đồng ý; và các phương thức khác 'có thể in, sao chép bằng văn bản, bao gồm cả dưới dạng điện tử hoặc định dạng kiểm chứng được'. Phương thức phải ghi lại vì chính nó quyết định bản ghi có kiểm chứng được hay không.

      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      12. vnPersonalDataConsentRecordLm.suDongY.thongBaoDuLieuNhayCam
      Definition

      Đã thông báo dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm

      ShortĐã thông báo dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm
      Comments

      Điều 6 khoản 4: 'Đối với việc xin sự đồng ý xử lý dữ liệu cá nhân NHẠY CẢM, chủ thể dữ liệu phải được thông báo rằng dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm.' min = 0 vì nghĩa vụ gắn với loại dữ liệu; nhưng trong phạm vi IG này nó gần như luôn áp — Luật 91/2025/QH15 xếp dữ liệu sức khoẻ vào nhóm nhạy cảm, nên mọi Consent cho dữ liệu lâm sàng đều rơi vào khoản 4.

      Control0..1
      Typeboolean
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      14. vnPersonalDataConsentRecordLm.thongBaoViPham
      Definition

      Nội dung thông báo vi phạm quy định bảo vệ dữ liệu cá nhân

      ShortNội dung thông báo vi phạm quy định bảo vệ dữ liệu cá nhân
      Comments

      min = 0 vì thông báo chỉ phát sinh KHI có vi phạm; nhưng khi phát sinh thì đủ bốn nhóm nội dung của Điều 28 khoản 1 là bắt buộc. Model dừng ở mức bốn nhóm ấy: chưa có bằng chứng rằng từng ô của Mẫu 08 hay từng section hiện có của profile đều là nghĩa vụ riêng.

      Control0..1
      TypeBackboneElement
      16. vnPersonalDataConsentRecordLm.thongBaoViPham.tinhChatViPham
      Definition

      Mô tả tính chất của việc vi phạm

      ShortMô tả tính chất của việc vi phạm
      Comments

      Điểm a: 'bao gồm: thời gian, địa điểm, hành vi, tổ chức, cá nhân, các loại dữ liệu cá nhân và số lượng dữ liệu liên quan' — bảy thành phần trong MỘT nhóm nội dung, không phải bảy trường độc lập.

      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      18. vnPersonalDataConsentRecordLm.thongBaoViPham.chiTietLienLac
      Definition

      Chi tiết liên lạc của bộ phận hoặc nhân sự bảo vệ dữ liệu cá nhân

      ShortChi tiết liên lạc của bộ phận hoặc nhân sự bảo vệ dữ liệu cá nhân
      Comments

      Điểm b cho phép ba khả năng: bộ phận bảo vệ dữ liệu cá nhân, nhân sự bảo vệ dữ liệu cá nhân, hoặc tổ chức/cá nhân cung cấp dịch vụ bảo vệ dữ liệu cá nhân.

      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      20. vnPersonalDataConsentRecordLm.thongBaoViPham.hauQuaThietHai
      Definition

      Mô tả hậu quả, thiệt hại có thể xảy ra

      ShortMô tả hậu quả, thiệt hại có thể xảy ra
      Comments

      Điểm c nói 'có thể xảy ra' — nghĩa vụ mô tả rủi ro dự kiến, không phải thiệt hại đã xác định. Không được để trống với lý do chưa đánh giá xong.

      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
      22. vnPersonalDataConsentRecordLm.thongBaoViPham.bienPhapGiaiQuyet
      Definition

      Mô tả biện pháp giải quyết, giảm thiểu tác hại

      ShortMô tả biện pháp giải quyết, giảm thiểu tác hại
      Control1..1
      Typestring
      Primitive ValueThis primitive element may be present, or absent, or replaced by an extension

      Guidance on how to interpret the contents of this table can be foundhere

      0. vnPersonalDataConsentRecordLm
      Definition

      Logical model đặc tả nội dung mà Nghị định 356/2025/NĐ-CP (ban hành 31/12/2025, hiệu lực 01/01/2026) BUỘC phải có trong bản ghi sự đồng ý của chủ thể dữ liệu và trong thông báo vi phạm quy định bảo vệ dữ liệu cá nhân — làm bảng chỉ tiêu văn bản để đối chiếu cardinality của nhóm profile đồng ý và thông báo vi phạm.

      Điều 6 khoản 1 nêu nguyên văn: 'Các phương thức xin sự đồng ý của chủ thể dữ liệu cá nhân phải bảo đảm khả năng kiểm chứng được về việc xác định chủ thể dữ liệu cá nhân đã thực hiện sự đồng ý, thời điểm và nội dung được đồng ý.' Ba thông tin ấy là điều kiện để sự đồng ý KIỂM CHỨNG ĐƯỢC — thiếu một trong ba thì bản ghi không chứng minh được gì. Khoản 2 buộc lưu trữ sự đồng ý và đặt trách nhiệm chứng minh lên bên kiểm soát dữ liệu khi có tranh chấp; khoản 4 buộc thông báo rõ cho chủ thể khi dữ liệu cần xử lý là dữ liệu cá nhân NHẠY CẢM — mọi dữ liệu sức khoẻ đều thuộc nhóm này.

      Điều 28 khoản 1 liệt kê bốn nhóm nội dung của thông báo vi phạm: (a) mô tả tính chất vi phạm gồm thời gian, địa điểm, hành vi, tổ chức/cá nhân, các loại dữ liệu và số lượng dữ liệu liên quan; (b) chi tiết liên lạc của bộ phận hoặc nhân sự bảo vệ dữ liệu cá nhân; (c) mô tả hậu quả, thiệt hại có thể xảy ra; (d) mô tả biện pháp giải quyết, giảm thiểu tác hại. / Logical model for the consent record and data-breach notification content required by Decree 356/2025/NĐ-CP.

      ShortBản ghi sự đồng ý và thông báo vi phạm dữ liệu cá nhân (NĐ 356/2025/NĐ-CP) — Logical Model
      Control0..*
      Is Modifierfalse
      Logical ModelInstances of this logical model are not marked to be the target of a Reference
      2. vnPersonalDataConsentRecordLm.suDongY
      Definition

      Bản ghi sự đồng ý của chủ thể dữ liệu cá nhân

      ShortBản ghi sự đồng ý của chủ thể dữ liệu cá nhân
      Comments

      Khoản 2: 'Bên kiểm soát dữ liệu, bên kiểm soát và xử lý dữ liệu cá nhân phải LƯU TRỮ sự đồng ý của chủ thể dữ liệu. Trong trường hợp có tranh chấp, trách nhiệm chứng minh sự đồng ý thuộc về bên kiểm soát dữ liệu.' Nghĩa vụ lưu trữ và nghĩa vụ chứng minh đi cùng nhau — bản ghi thiếu một trong ba thông tin dưới đây thì không gánh được trách nhiệm chứng minh ấy.

      Control1..1
      TypeBackboneElement
      Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
      4. vnPersonalDataConsentRecordLm.suDongY.id
      Definition

      Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.

      ShortUnique id for inter-element referencing
      Control0..1
      Typestring
      Is Modifierfalse
      XML FormatIn the XML format, this property is represented as an attribute.
      Summaryfalse
      6. vnPersonalDataConsentRecordLm.suDongY.extension
      Definition

      May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.

      ShortAdditional content defined by implementations
      Comments

      There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

      Control0..*
      TypeExtension
      Is Modifierfalse
      Summaryfalse
      Alternate Namesextensions, user content
      Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
      ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
      SlicingThis element introduces a set of slices on vnPersonalDataConsentRecordLm.suDongY.extension. The slices areUnordered and Open, and can be differentiated using the following discriminators:
      • value @ url
      • 8. vnPersonalDataConsentRecordLm.suDongY.modifierExtension
        Definition

        May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions.

        Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).

        ShortExtensions that cannot be ignored even if unrecognized
        Comments

        There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

        Control0..*
        TypeExtension
        Is Modifiertrue because Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
        Summarytrue
        Requirements

        Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.

        Alternate Namesextensions, user content, modifiers
        Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
        ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
        10. vnPersonalDataConsentRecordLm.suDongY.chuTheDuLieu
        Definition

        Chủ thể dữ liệu cá nhân đã thực hiện sự đồng ý

        ShortChủ thể dữ liệu cá nhân đã thực hiện sự đồng ý
        Control1..1
        Typestring
        Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
        12. vnPersonalDataConsentRecordLm.suDongY.thoiDiemDongY
        Definition

        Thời điểm đồng ý

        ShortThời điểm đồng ý
        Control1..1
        TypedateTime
        Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
        14. vnPersonalDataConsentRecordLm.suDongY.noiDungDuocDongY
        Definition

        Nội dung được đồng ý

        ShortNội dung được đồng ý
        Comments

        Phạm vi xử lý mà chủ thể đã đồng ý — trên Consent nó là cây provision với loại cho phép hoặc từ chối, mục đích xử lý và phạm vi dữ liệu.

        Control1..1
        Typestring
        Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
        16. vnPersonalDataConsentRecordLm.suDongY.phuongThucDongY
        Definition

        Phương thức thể hiện sự đồng ý

        ShortPhương thức thể hiện sự đồng ý
        Comments

        Điều 6 khoản 1 liệt kê năm phương thức: bằng văn bản; bằng cuộc gọi ghi âm; cú pháp đồng ý qua tin nhắn điện thoại; qua thư điện tử hoặc trang thông tin điện tử, nền tảng, ứng dụng có thiết lập kỹ thuật xin sự đồng ý; và các phương thức khác 'có thể in, sao chép bằng văn bản, bao gồm cả dưới dạng điện tử hoặc định dạng kiểm chứng được'. Phương thức phải ghi lại vì chính nó quyết định bản ghi có kiểm chứng được hay không.

        Control1..1
        Typestring
        Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
        18. vnPersonalDataConsentRecordLm.suDongY.thongBaoDuLieuNhayCam
        Definition

        Đã thông báo dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm

        ShortĐã thông báo dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm
        Comments

        Điều 6 khoản 4: 'Đối với việc xin sự đồng ý xử lý dữ liệu cá nhân NHẠY CẢM, chủ thể dữ liệu phải được thông báo rằng dữ liệu cần xử lý là dữ liệu cá nhân nhạy cảm.' min = 0 vì nghĩa vụ gắn với loại dữ liệu; nhưng trong phạm vi IG này nó gần như luôn áp — Luật 91/2025/QH15 xếp dữ liệu sức khoẻ vào nhóm nhạy cảm, nên mọi Consent cho dữ liệu lâm sàng đều rơi vào khoản 4.

        Control0..1
        Typeboolean
        Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
        20. vnPersonalDataConsentRecordLm.thongBaoViPham
        Definition

        Nội dung thông báo vi phạm quy định bảo vệ dữ liệu cá nhân

        ShortNội dung thông báo vi phạm quy định bảo vệ dữ liệu cá nhân
        Comments

        min = 0 vì thông báo chỉ phát sinh KHI có vi phạm; nhưng khi phát sinh thì đủ bốn nhóm nội dung của Điều 28 khoản 1 là bắt buộc. Model dừng ở mức bốn nhóm ấy: chưa có bằng chứng rằng từng ô của Mẫu 08 hay từng section hiện có của profile đều là nghĩa vụ riêng.

        Control0..1
        TypeBackboneElement
        Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
        22. vnPersonalDataConsentRecordLm.thongBaoViPham.id
        Definition

        Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.

        ShortUnique id for inter-element referencing
        Control0..1
        Typestring
        Is Modifierfalse
        XML FormatIn the XML format, this property is represented as an attribute.
        Summaryfalse
        24. vnPersonalDataConsentRecordLm.thongBaoViPham.extension
        Definition

        May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.

        ShortAdditional content defined by implementations
        Comments

        There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

        Control0..*
        TypeExtension
        Is Modifierfalse
        Summaryfalse
        Alternate Namesextensions, user content
        Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
        ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
        SlicingThis element introduces a set of slices on vnPersonalDataConsentRecordLm.thongBaoViPham.extension. The slices areUnordered and Open, and can be differentiated using the following discriminators:
        • value @ url
        • 26. vnPersonalDataConsentRecordLm.thongBaoViPham.modifierExtension
          Definition

          May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions.

          Modifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).

          ShortExtensions that cannot be ignored even if unrecognized
          Comments

          There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.

          Control0..*
          TypeExtension
          Is Modifiertrue because Modifier extensions are expected to modify the meaning or interpretation of the element that contains them
          Summarytrue
          Requirements

          Modifier extensions allow for extensions that cannot be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the definition of modifier extensions.

          Alternate Namesextensions, user content, modifiers
          Invariantsele-1: All FHIR elements must have a @value or children (hasValue() or (children().count() > id.count()))
          ext-1: Must have either extensions or value[x], not both (extension.exists() != value.exists())
          28. vnPersonalDataConsentRecordLm.thongBaoViPham.tinhChatViPham
          Definition

          Mô tả tính chất của việc vi phạm

          ShortMô tả tính chất của việc vi phạm
          Comments

          Điểm a: 'bao gồm: thời gian, địa điểm, hành vi, tổ chức, cá nhân, các loại dữ liệu cá nhân và số lượng dữ liệu liên quan' — bảy thành phần trong MỘT nhóm nội dung, không phải bảy trường độc lập.

          Control1..1
          Typestring
          Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
          30. vnPersonalDataConsentRecordLm.thongBaoViPham.chiTietLienLac
          Definition

          Chi tiết liên lạc của bộ phận hoặc nhân sự bảo vệ dữ liệu cá nhân

          ShortChi tiết liên lạc của bộ phận hoặc nhân sự bảo vệ dữ liệu cá nhân
          Comments

          Điểm b cho phép ba khả năng: bộ phận bảo vệ dữ liệu cá nhân, nhân sự bảo vệ dữ liệu cá nhân, hoặc tổ chức/cá nhân cung cấp dịch vụ bảo vệ dữ liệu cá nhân.

          Control1..1
          Typestring
          Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
          32. vnPersonalDataConsentRecordLm.thongBaoViPham.hauQuaThietHai
          Definition

          Mô tả hậu quả, thiệt hại có thể xảy ra

          ShortMô tả hậu quả, thiệt hại có thể xảy ra
          Comments

          Điểm c nói 'có thể xảy ra' — nghĩa vụ mô tả rủi ro dự kiến, không phải thiệt hại đã xác định. Không được để trống với lý do chưa đánh giá xong.

          Control1..1
          Typestring
          Primitive ValueThis primitive element may be present, or absent, or replaced by an extension
          34. vnPersonalDataConsentRecordLm.thongBaoViPham.bienPhapGiaiQuyet
          Definition

          Mô tả biện pháp giải quyết, giảm thiểu tác hại

          ShortMô tả biện pháp giải quyết, giảm thiểu tác hại
          Control1..1
          Typestring
          Primitive ValueThis primitive element may be present, or absent, or replaced by an extension