HL7 Vietnam VN Core FHIR Implementation Guide

Hướng dẫn triển khai FHIR cốt lõi Việt Nam — VN Core FHIR Implementation Guide
0.10.0 - Draft for Community Review Viet Nam cờ

Hướng dẫn triển khai FHIR cốt lõi Việt Nam — VN Core FHIR Implementation Guide - Draft for Community Review (v0.10.0) built by the FHIR (HL7® FHIR® Standard) Build Tools. See the Directory of published versions

Hồ sơ tài nguyên: Nhật ký truy cập dữ liệu VN Core — VN Core AuditEvent Profile

URL chính thức: http://fhir.hl7.org.vn/core/StructureDefinition/vn-core-audit-event Phiên bản: 0.10.0
Computable Name: VNCoreAuditEvent
Định danh khác: OID:2.25.161089673617632664299011809196868855799.42.25

Profile AuditEvent cho Việt Nam. Dùng để ghi nhận truy cập, chỉnh sửa, chia sẻ, và xuất dữ liệu y tế/định danh nhạy cảm. Căn cứ:

  • Luật 91/2025/QH15 — 26/6/2025 — bảo vệ dữ liệu cá nhân, dữ liệu y tế là dữ liệu nhạy cảm; thông báo vi phạm cho cơ quan chuyên trách chậm nhất 72 giờ kể từ khi phát hiện, KHI vi phạm có thể gây tổn hại (Điều 23 khoản 1); cơ chế giám sát xử lý không cần đồng ý (Điều 19 khoản 2)
  • NĐ 356/2025/NĐ-CP — 31/12/2025 — hướng dẫn BVDLCN; nội dung thông báo vi phạm (Điều 28, Mẫu số 08); riêng dữ liệu vị trí/sinh trắc học: thông báo cho CHỦ THỂ trong 72 giờ và lưu hồ sơ vi phạm tối thiểu 5 năm (Điều 29 khoản 1)
  • QĐ 2113/QĐ-BYT (Khung kiến trúc dữ liệu y tế) — ANCHOR của ô sổ cái chiều P-A theo cửa capability-backed. Phụ lục Lớp 5 Người dùng an toàn: 'Hệ thống phải ghi nhận đầy đủ lịch sử truy cập và có khả năng kiểm tra, truy vết (audit) theo thời gian thực hoặc hậu kiểm', phạm vi mục III phủ 'các cơ sở y tế công lập và ngoài công lập'. Đây là nghĩa vụ NĂNG LỰC — profile thực thi nó bằng cờ Must Support và invariant vn-audit-data-access-traceable, KHÔNG bằng cardinality: profile này không siết min của element nào vượt FHIR base. Phép suy từ nghĩa vụ sang từng cờ MS được viết ra trong governance/review/capability-obligation-anchors.json và cổng kiểm tập MS phải nằm trong tập đã khai
  • Luật 116/2025/QH15 (ban hành 10/12/2025, hiệu lực 01/07/2026 — đang áp dụng; Luật 24/2018/QH14 đã hết hiệu lực) — Luật An ninh mạng mới. PHẠM VI, làm rõ 07/09/2026: Luật định nghĩa nhật ký hệ thống tại Điều 2 khoản 11, nhưng nghĩa vụ lưu nhật ký của Luật (Điều 25 khoản 2 điểm b) áp cho doanh nghiệp cung cấp dịch vụ trên mạng viễn thông, mạng Internet — KHÔNG đặt nghĩa vụ log cho hệ thống khám bệnh, chữa bệnh nói chung. Viện dẫn ở đây là để định nghĩa thuật ngữ và làm bối cảnh an ninh mạng, không phải làm căn cứ cardinality
  • NĐ 102/2025/NĐ-CP — 13/5/2025 — bảo vệ, quản trị, xử lý dữ liệu y tế số
  • Luật KCB 2023 — hồ sơ bệnh án và trách nhiệm cơ sở KCB.

Usages:

You can also check for usages in the FHIR IG Statistics

Các dạng xem hình thức của nội dung hồ sơ

Mô tả profile, differential, snapshot và các biểu diễn liên quan.

NameFlagsCard.TypeDescription & Constraints    Filter: Filtersdoco
.. AuditEvent C 0..* AuditEvent Event record kept for security purposes
Constraints: vn-audit-data-access-traceable
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... Slices for extension 0..* Extension Extension
Slice: Unordered, Open by value:url
.... extension:processingLegalBasis SO 0..1 CodeableConcept Căn cứ Điều 19 khi truy cập không qua đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-processing-legal-basis
Binding: Căn cứ xử lý DLCN không cần sự đồng ý — VN Processing Legal Basis ValueSet (required)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... extension:breachRecordRetention C 0..1 Period Thời hạn lưu hồ sơ sự cố vi phạm (chỉ khi sự kiện là sự cố thuộc Điều 29 NĐ 356/2025/NĐ-CP)
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-audit-retention
Constraints: vn-audit-retention-minimum
... modifierExtension ?! 0..* Extension Extensions that cannot be ignored
... subtype SOΣ 0..* Coding Phân loại sự kiện audit
Binding: AuditEventSub-Type (extensible): Sub-type of event.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... action SOΣ 0..1 code Hành động thực hiện (C/R/U/D/E)
Binding: AuditEventAction (required): Indicator for type of action performed during the event that generated the event.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... recorded SOΣ 1..1 instant Thời điểm ghi nhận audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... outcome SOΣ 0..1 code Kết quả thực hiện
Binding: AuditEventOutcome (required): Indicates whether the event succeeded or failed.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... purposeOfEvent SOΣ 0..* CodeableConcept Mục đích xử lý dữ liệu
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... agent SO 1..* BackboneElement Người/hệ thống thực hiện hành động
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... who SΣ 0..1 Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson) Tác nhân thực hiện
.... requestor SΣ 1..1 boolean Có phải tác nhân khởi tạo yêu cầu hay không
.... network S 0..1 BackboneElement Thông tin mạng truy cập — địa chỉ nguồn của phiên truy cập
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
... source SO 1..1 BackboneElement Nguồn phát sinh audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... observer SΣ 1..1 Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson) Hệ thống/đơn vị ghi log
... entity SOC 0..* BackboneElement Đối tượng dữ liệu bị tác động
Constraints: sev-1
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... what SΣ 0..1 Reference(Resource) Resource hoặc đối tượng dữ liệu liên quan
.... name ΣC 0..1 string Tên đối tượng dữ liệu

doco Documentation for this format
NameKho hồ sơ EMR (Repository)Ứng dụng người dân (Citizen App)Nguồn tạo hồ sơ lâm sàng (Document Source)doco
.. AuditEvent
... Slices for extension
.... extension:processingLegalBasis
... type
... subtype
... recorded
... outcome
... purposeOfEvent
... agent
... source
... entity

doco Documentation for this format

Terminology Bindings

Path Status Usage ValueSet Version Source
AuditEvent.type Base extensible Audit Event ID 📍4.0.1 FHIR Std.
AuditEvent.subtype Base extensible Audit Event Sub-Type 📍4.0.1 FHIR Std.
AuditEvent.action Base required AuditEventAction 📍4.0.1 FHIR Std.
AuditEvent.outcome Base required AuditEventOutcome 📍4.0.1 FHIR Std.
AuditEvent.purposeOfEvent Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG

Constraints

Id Grade Path(s) Description Expression
dom-2 error AuditEvent If the resource is contained in another resource, it SHALL NOT contain nested Resources contained.contained.empty()
dom-3 error AuditEvent If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().as(canonical) | %resource.descendants().as(uri) | %resource.descendants().as(url))) or descendants().where(reference = '#').exists() or descendants().where(as(canonical) = '#').exists() or descendants().where(as(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
dom-4 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
dom-5 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a security label contained.meta.security.empty()
dom-6 best practice AuditEvent A resource should have narrative for robust management text.`div`.exists()
ele-1 error **ALL** elements All FHIR elements must have a @value or children hasValue() or (children().count() > id.count())
ext-1 error **ALL** extensions Must have either extensions or value[x], not both extension.exists() != value.exists()
sev-1 error AuditEvent.entity Either a name or a query (NOT both) name.empty() or query.empty()
vn-audit-data-access-traceable error AuditEvent Bản ghi audit về truy cập dữ liệu phải định danh được tác nhân và đối tượng: ít nhất một `agent.who.reference` và một `entity.what.reference`. An audit record of data access SHALL identify both the acting party and the accessed object by reference. subtype.where((system = 'http://hl7.org/fhir/restful-interaction' and (code = 'read' or code = 'vread' or code = 'search' or code = 'search-type' or code = 'search-system')) or (system = 'http://fhir.hl7.org.vn/core/CodeSystem/vn-audit-event-subtype-cs' and (code = 'legal-basis-access' or code = 'legal-basis-authorization'))).exists() implies (agent.who.reference.exists() and entity.what.reference.exists())
vn-audit-retention-minimum error AuditEvent.extension:breachRecordRetention Ngày kết thúc đã khai không được chắc chắn sớm hơn năm năm sau ngày khắc phục sự cố. A declared end SHALL NOT be demonstrably earlier than five years after remediation. value.ofType(Period).all((end >= start + 5 years).all($this))

NameFlagsCard.TypeDescription & Constraints    Filter: Filtersdoco
.. AuditEvent C 0..* AuditEvent Event record kept for security purposes
Constraints: vn-audit-data-access-traceable
... Slices for extension 0..* Extension Extension
Slice: Unordered, Open by value:url
.... extension:processingLegalBasis SO 0..1 CodeableConcept Căn cứ Điều 19 khi truy cập không qua đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-processing-legal-basis
Binding: Căn cứ xử lý DLCN không cần sự đồng ý — VN Processing Legal Basis ValueSet (required)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... extension:breachRecordRetention 0..1 Period Thời hạn lưu hồ sơ sự cố vi phạm (chỉ khi sự kiện là sự cố thuộc Điều 29 NĐ 356/2025/NĐ-CP)
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-audit-retention
... type SO 1..1 Coding Loại sự kiện audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... subtype SO 0..* Coding Phân loại sự kiện audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... recorded SO 1..1 instant Thời điểm ghi nhận audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... outcome SO 0..1 code Kết quả thực hiện
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... purposeOfEvent SO 0..* CodeableConcept Mục đích xử lý dữ liệu
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... agent SO 1..* BackboneElement Người/hệ thống thực hiện hành động
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... who S 0..1 Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson) Tác nhân thực hiện
.... requestor S 1..1 boolean Có phải tác nhân khởi tạo yêu cầu hay không
.... network S 0..1 BackboneElement Thông tin mạng truy cập — địa chỉ nguồn của phiên truy cập
... source SO 1..1 BackboneElement Nguồn phát sinh audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... observer S 1..1 Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson) Hệ thống/đơn vị ghi log
... entity SO 0..* BackboneElement Đối tượng dữ liệu bị tác động
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... what S 0..1 Reference(Resource) Resource hoặc đối tượng dữ liệu liên quan
.... name 0..1 string Tên đối tượng dữ liệu

doco Documentation for this format
NameKho hồ sơ EMR (Repository)Ứng dụng người dân (Citizen App)Nguồn tạo hồ sơ lâm sàng (Document Source)doco
.. AuditEvent
... Slices for extension
.... extension:processingLegalBasis
... type
... subtype
... recorded
... outcome
... purposeOfEvent
... agent
... source
... entity

doco Documentation for this format

Terminology Bindings (Differential)

Path Status Usage ValueSet Version Source
AuditEvent.purposeOfEvent Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG

Constraints

Id Grade Path(s) Description Expression
vn-audit-data-access-traceable error AuditEvent Bản ghi audit về truy cập dữ liệu phải định danh được tác nhân và đối tượng: ít nhất một `agent.who.reference` và một `entity.what.reference`. An audit record of data access SHALL identify both the acting party and the accessed object by reference. subtype.where((system = 'http://hl7.org/fhir/restful-interaction' and (code = 'read' or code = 'vread' or code = 'search' or code = 'search-type' or code = 'search-system')) or (system = 'http://fhir.hl7.org.vn/core/CodeSystem/vn-audit-event-subtype-cs' and (code = 'legal-basis-access' or code = 'legal-basis-authorization'))).exists() implies (agent.who.reference.exists() and entity.what.reference.exists())
NameFlagsCard.TypeDescription & Constraints    Filter: Filtersdoco
.. AuditEvent C 0..* AuditEvent Event record kept for security purposes
Constraints: vn-audit-data-access-traceable
... id Σ 0..1 id Logical id of this artifact
... meta Σ 0..1 Meta Metadata about the resource
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... text 0..1 Narrative Text summary of the resource, for human interpretation
This profile does not constrain the narrative in regard to content, language, or traceability to data elements
... contained 0..* Resource Contained, inline Resources
... Slices for extension 0..* Extension Extension
Slice: Unordered, Open by value:url
.... extension:processingLegalBasis SO 0..1 CodeableConcept Căn cứ Điều 19 khi truy cập không qua đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-processing-legal-basis
Binding: Căn cứ xử lý DLCN không cần sự đồng ý — VN Processing Legal Basis ValueSet (required)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... extension:breachRecordRetention C 0..1 Period Thời hạn lưu hồ sơ sự cố vi phạm (chỉ khi sự kiện là sự cố thuộc Điều 29 NĐ 356/2025/NĐ-CP)
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-audit-retention
Constraints: vn-audit-retention-minimum
... modifierExtension ?! 0..* Extension Extensions that cannot be ignored
... type SOΣ 1..1 Coding Loại sự kiện audit
Binding: AuditEventID (extensible): Type of event.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... subtype SOΣ 0..* Coding Phân loại sự kiện audit
Binding: AuditEventSub-Type (extensible): Sub-type of event.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... action SOΣ 0..1 code Hành động thực hiện (C/R/U/D/E)
Binding: AuditEventAction (required): Indicator for type of action performed during the event that generated the event.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... period 0..1 Period When the activity occurred
... recorded SOΣ 1..1 instant Thời điểm ghi nhận audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... outcome SOΣ 0..1 code Kết quả thực hiện
Binding: AuditEventOutcome (required): Indicates whether the event succeeded or failed.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... outcomeDesc Σ 0..1 string Description of the event outcome
... purposeOfEvent SOΣ 0..* CodeableConcept Mục đích xử lý dữ liệu
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... agent SO 1..* BackboneElement Người/hệ thống thực hiện hành động
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... type 0..1 CodeableConcept How agent participated
Binding: ParticipationRoleType (extensible): The Participation type of the agent to the event.
.... role 0..* CodeableConcept Agent role in the event
Binding: SecurityRoleType (example): What security role enabled the agent to participate in the event.
.... who SΣ 0..1 Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson) Tác nhân thực hiện
.... altId 0..1 string Alternative User identity
.... name 0..1 string Human friendly name for the agent
.... requestor SΣ 1..1 boolean Có phải tác nhân khởi tạo yêu cầu hay không
.... location 0..1 Reference(Location) Where
.... policy 0..* uri Policy that authorized event
.... media 0..1 Coding Type of media
Binding: MediaTypeCode (extensible): Used when the event is about exporting/importing onto media.
.... network S 0..1 BackboneElement Thông tin mạng truy cập — địa chỉ nguồn của phiên truy cập
..... id 0..1 string Unique id for inter-element referencing
..... extension 0..* Extension Additional content defined by implementations
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... address 0..1 string Identifier for the network access point of the user device
..... type 0..1 code The type of network access point
Binding: AuditEventAgentNetworkType (required): The type of network access point of this agent in the audit event.
.... purposeOfUse 0..* CodeableConcept Reason given for this user
Binding: PurposeOfUse (extensible): The reason the activity took place.
... source SO 1..1 BackboneElement Nguồn phát sinh audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... site 0..1 string Logical source location within the enterprise
.... observer SΣ 1..1 Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson) Hệ thống/đơn vị ghi log
.... type 0..* Coding The type of source where event originated
Binding: AuditEventSourceType (extensible): Code specifying the type of system that detected and recorded the event.
... entity SOC 0..* BackboneElement Đối tượng dữ liệu bị tác động
Constraints: sev-1
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... what SΣ 0..1 Reference(Resource) Resource hoặc đối tượng dữ liệu liên quan
.... type 0..1 Coding Type of entity involved
Binding: AuditEventEntityType (extensible): Code for the entity type involved in the audit event.
.... role 0..1 Coding What role the entity played
Binding: AuditEventEntityRole (extensible): Code representing the role the entity played in the audit event.
.... lifecycle 0..1 Coding Life-cycle stage for the entity
Binding: ObjectLifecycleEvents (extensible): Identifier for the data life-cycle stage for the entity.
.... securityLabel 0..* Coding Security labels on the entity
Binding: All Security Labels (extensible): Security Labels from the Healthcare Privacy and Security Classification System.
.... name ΣC 0..1 string Tên đối tượng dữ liệu
.... description 0..1 string Descriptive text
.... query ΣC 0..1 base64Binary Query parameters
.... detail 0..* BackboneElement Additional Information about the entity
..... id 0..1 string Unique id for inter-element referencing
..... extension 0..* Extension Additional content defined by implementations
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... type 1..1 string Name of the property
..... value[x] 1..1 Property value
...... valueString string
...... valueBase64Binary base64Binary

doco Documentation for this format
NameKho hồ sơ EMR (Repository)Ứng dụng người dân (Citizen App)Nguồn tạo hồ sơ lâm sàng (Document Source)doco
.. AuditEvent
... Slices for extension
.... extension:processingLegalBasis
... type
... subtype
... recorded
... outcome
... purposeOfEvent
... agent
... source
... entity

doco Documentation for this format

Terminology Bindings

Path Status Usage ValueSet Version Source
AuditEvent.language Base preferred Common Languages 📍4.0.1 FHIR Std.
AuditEvent.type Base extensible Audit Event ID 📍4.0.1 FHIR Std.
AuditEvent.subtype Base extensible Audit Event Sub-Type 📍4.0.1 FHIR Std.
AuditEvent.action Base required AuditEventAction 📍4.0.1 FHIR Std.
AuditEvent.outcome Base required AuditEventOutcome 📍4.0.1 FHIR Std.
AuditEvent.purposeOfEvent Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG
AuditEvent.agent.type Base extensible ParticipationRoleType 📍4.0.1 FHIR Std.
AuditEvent.agent.role Base example SecurityRoleType 📍4.0.1 FHIR Std.
AuditEvent.agent.media Base extensible Media Type Code 📍4.0.1 FHIR Std.
AuditEvent.agent.network.​type Base required AuditEventAgentNetworkType 📍4.0.1 FHIR Std.
AuditEvent.agent.purposeOfUse Base extensible PurposeOfUse 📦3.1.0 THO v7.2
AuditEvent.source.type Base extensible Audit Event Source Type 📍4.0.1 FHIR Std.
AuditEvent.entity.type Base extensible Audit event entity type 📍4.0.1 FHIR Std.
AuditEvent.entity.role Base extensible AuditEventEntityRole 📍4.0.1 FHIR Std.
AuditEvent.entity.lifecycle Base extensible ObjectLifecycleEvents 📍4.0.1 FHIR Std.
AuditEvent.entity.securityLabel Base extensible SecurityLabels 📍4.0.1 FHIR Std.

Constraints

Id Grade Path(s) Description Expression
dom-2 error AuditEvent If the resource is contained in another resource, it SHALL NOT contain nested Resources contained.contained.empty()
dom-3 error AuditEvent If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().as(canonical) | %resource.descendants().as(uri) | %resource.descendants().as(url))) or descendants().where(reference = '#').exists() or descendants().where(as(canonical) = '#').exists() or descendants().where(as(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
dom-4 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
dom-5 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a security label contained.meta.security.empty()
dom-6 best practice AuditEvent A resource should have narrative for robust management text.`div`.exists()
ele-1 error **ALL** elements All FHIR elements must have a @value or children hasValue() or (children().count() > id.count())
ext-1 error **ALL** extensions Must have either extensions or value[x], not both extension.exists() != value.exists()
sev-1 error AuditEvent.entity Either a name or a query (NOT both) name.empty() or query.empty()
vn-audit-data-access-traceable error AuditEvent Bản ghi audit về truy cập dữ liệu phải định danh được tác nhân và đối tượng: ít nhất một `agent.who.reference` và một `entity.what.reference`. An audit record of data access SHALL identify both the acting party and the accessed object by reference. subtype.where((system = 'http://hl7.org/fhir/restful-interaction' and (code = 'read' or code = 'vread' or code = 'search' or code = 'search-type' or code = 'search-system')) or (system = 'http://fhir.hl7.org.vn/core/CodeSystem/vn-audit-event-subtype-cs' and (code = 'legal-basis-access' or code = 'legal-basis-authorization'))).exists() implies (agent.who.reference.exists() and entity.what.reference.exists())
vn-audit-retention-minimum error AuditEvent.extension:breachRecordRetention Ngày kết thúc đã khai không được chắc chắn sớm hơn năm năm sau ngày khắc phục sự cố. A declared end SHALL NOT be demonstrably earlier than five years after remediation. value.ofType(Period).all((end >= start + 5 years).all($this))

Dạng xem phần tử chính

NameFlagsCard.TypeDescription & Constraints    Filter: Filtersdoco
.. AuditEvent C 0..* AuditEvent Event record kept for security purposes
Constraints: vn-audit-data-access-traceable
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... Slices for extension 0..* Extension Extension
Slice: Unordered, Open by value:url
.... extension:processingLegalBasis SO 0..1 CodeableConcept Căn cứ Điều 19 khi truy cập không qua đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-processing-legal-basis
Binding: Căn cứ xử lý DLCN không cần sự đồng ý — VN Processing Legal Basis ValueSet (required)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... extension:breachRecordRetention C 0..1 Period Thời hạn lưu hồ sơ sự cố vi phạm (chỉ khi sự kiện là sự cố thuộc Điều 29 NĐ 356/2025/NĐ-CP)
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-audit-retention
Constraints: vn-audit-retention-minimum
... modifierExtension ?! 0..* Extension Extensions that cannot be ignored
... subtype SOΣ 0..* Coding Phân loại sự kiện audit
Binding: AuditEventSub-Type (extensible): Sub-type of event.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... action SOΣ 0..1 code Hành động thực hiện (C/R/U/D/E)
Binding: AuditEventAction (required): Indicator for type of action performed during the event that generated the event.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... recorded SOΣ 1..1 instant Thời điểm ghi nhận audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... outcome SOΣ 0..1 code Kết quả thực hiện
Binding: AuditEventOutcome (required): Indicates whether the event succeeded or failed.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... purposeOfEvent SOΣ 0..* CodeableConcept Mục đích xử lý dữ liệu
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... agent SO 1..* BackboneElement Người/hệ thống thực hiện hành động
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... who SΣ 0..1 Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson) Tác nhân thực hiện
.... requestor SΣ 1..1 boolean Có phải tác nhân khởi tạo yêu cầu hay không
.... network S 0..1 BackboneElement Thông tin mạng truy cập — địa chỉ nguồn của phiên truy cập
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
... source SO 1..1 BackboneElement Nguồn phát sinh audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... observer SΣ 1..1 Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson) Hệ thống/đơn vị ghi log
... entity SOC 0..* BackboneElement Đối tượng dữ liệu bị tác động
Constraints: sev-1
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... what SΣ 0..1 Reference(Resource) Resource hoặc đối tượng dữ liệu liên quan
.... name ΣC 0..1 string Tên đối tượng dữ liệu

doco Documentation for this format
NameKho hồ sơ EMR (Repository)Ứng dụng người dân (Citizen App)Nguồn tạo hồ sơ lâm sàng (Document Source)doco
.. AuditEvent
... Slices for extension
.... extension:processingLegalBasis
... type
... subtype
... recorded
... outcome
... purposeOfEvent
... agent
... source
... entity

doco Documentation for this format

Terminology Bindings

Path Status Usage ValueSet Version Source
AuditEvent.type Base extensible Audit Event ID 📍4.0.1 FHIR Std.
AuditEvent.subtype Base extensible Audit Event Sub-Type 📍4.0.1 FHIR Std.
AuditEvent.action Base required AuditEventAction 📍4.0.1 FHIR Std.
AuditEvent.outcome Base required AuditEventOutcome 📍4.0.1 FHIR Std.
AuditEvent.purposeOfEvent Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG

Constraints

Id Grade Path(s) Description Expression
dom-2 error AuditEvent If the resource is contained in another resource, it SHALL NOT contain nested Resources contained.contained.empty()
dom-3 error AuditEvent If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().as(canonical) | %resource.descendants().as(uri) | %resource.descendants().as(url))) or descendants().where(reference = '#').exists() or descendants().where(as(canonical) = '#').exists() or descendants().where(as(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
dom-4 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
dom-5 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a security label contained.meta.security.empty()
dom-6 best practice AuditEvent A resource should have narrative for robust management text.`div`.exists()
ele-1 error **ALL** elements All FHIR elements must have a @value or children hasValue() or (children().count() > id.count())
ext-1 error **ALL** extensions Must have either extensions or value[x], not both extension.exists() != value.exists()
sev-1 error AuditEvent.entity Either a name or a query (NOT both) name.empty() or query.empty()
vn-audit-data-access-traceable error AuditEvent Bản ghi audit về truy cập dữ liệu phải định danh được tác nhân và đối tượng: ít nhất một `agent.who.reference` và một `entity.what.reference`. An audit record of data access SHALL identify both the acting party and the accessed object by reference. subtype.where((system = 'http://hl7.org/fhir/restful-interaction' and (code = 'read' or code = 'vread' or code = 'search' or code = 'search-type' or code = 'search-system')) or (system = 'http://fhir.hl7.org.vn/core/CodeSystem/vn-audit-event-subtype-cs' and (code = 'legal-basis-access' or code = 'legal-basis-authorization'))).exists() implies (agent.who.reference.exists() and entity.what.reference.exists())
vn-audit-retention-minimum error AuditEvent.extension:breachRecordRetention Ngày kết thúc đã khai không được chắc chắn sớm hơn năm năm sau ngày khắc phục sự cố. A declared end SHALL NOT be demonstrably earlier than five years after remediation. value.ofType(Period).all((end >= start + 5 years).all($this))

Dạng xem Differential

NameFlagsCard.TypeDescription & Constraints    Filter: Filtersdoco
.. AuditEvent C 0..* AuditEvent Event record kept for security purposes
Constraints: vn-audit-data-access-traceable
... Slices for extension 0..* Extension Extension
Slice: Unordered, Open by value:url
.... extension:processingLegalBasis SO 0..1 CodeableConcept Căn cứ Điều 19 khi truy cập không qua đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-processing-legal-basis
Binding: Căn cứ xử lý DLCN không cần sự đồng ý — VN Processing Legal Basis ValueSet (required)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... extension:breachRecordRetention 0..1 Period Thời hạn lưu hồ sơ sự cố vi phạm (chỉ khi sự kiện là sự cố thuộc Điều 29 NĐ 356/2025/NĐ-CP)
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-audit-retention
... type SO 1..1 Coding Loại sự kiện audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... subtype SO 0..* Coding Phân loại sự kiện audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... recorded SO 1..1 instant Thời điểm ghi nhận audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... outcome SO 0..1 code Kết quả thực hiện
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... purposeOfEvent SO 0..* CodeableConcept Mục đích xử lý dữ liệu
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... agent SO 1..* BackboneElement Người/hệ thống thực hiện hành động
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... who S 0..1 Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson) Tác nhân thực hiện
.... requestor S 1..1 boolean Có phải tác nhân khởi tạo yêu cầu hay không
.... network S 0..1 BackboneElement Thông tin mạng truy cập — địa chỉ nguồn của phiên truy cập
... source SO 1..1 BackboneElement Nguồn phát sinh audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... observer S 1..1 Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson) Hệ thống/đơn vị ghi log
... entity SO 0..* BackboneElement Đối tượng dữ liệu bị tác động
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... what S 0..1 Reference(Resource) Resource hoặc đối tượng dữ liệu liên quan
.... name 0..1 string Tên đối tượng dữ liệu

doco Documentation for this format
NameKho hồ sơ EMR (Repository)Ứng dụng người dân (Citizen App)Nguồn tạo hồ sơ lâm sàng (Document Source)doco
.. AuditEvent
... Slices for extension
.... extension:processingLegalBasis
... type
... subtype
... recorded
... outcome
... purposeOfEvent
... agent
... source
... entity

doco Documentation for this format

Terminology Bindings (Differential)

Path Status Usage ValueSet Version Source
AuditEvent.purposeOfEvent Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG

Constraints

Id Grade Path(s) Description Expression
vn-audit-data-access-traceable error AuditEvent Bản ghi audit về truy cập dữ liệu phải định danh được tác nhân và đối tượng: ít nhất một `agent.who.reference` và một `entity.what.reference`. An audit record of data access SHALL identify both the acting party and the accessed object by reference. subtype.where((system = 'http://hl7.org/fhir/restful-interaction' and (code = 'read' or code = 'vread' or code = 'search' or code = 'search-type' or code = 'search-system')) or (system = 'http://fhir.hl7.org.vn/core/CodeSystem/vn-audit-event-subtype-cs' and (code = 'legal-basis-access' or code = 'legal-basis-authorization'))).exists() implies (agent.who.reference.exists() and entity.what.reference.exists())

Dạng xem SnapshotView

NameFlagsCard.TypeDescription & Constraints    Filter: Filtersdoco
.. AuditEvent C 0..* AuditEvent Event record kept for security purposes
Constraints: vn-audit-data-access-traceable
... id Σ 0..1 id Logical id of this artifact
... meta Σ 0..1 Meta Metadata about the resource
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... text 0..1 Narrative Text summary of the resource, for human interpretation
This profile does not constrain the narrative in regard to content, language, or traceability to data elements
... contained 0..* Resource Contained, inline Resources
... Slices for extension 0..* Extension Extension
Slice: Unordered, Open by value:url
.... extension:processingLegalBasis SO 0..1 CodeableConcept Căn cứ Điều 19 khi truy cập không qua đồng ý
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-processing-legal-basis
Binding: Căn cứ xử lý DLCN không cần sự đồng ý — VN Processing Legal Basis ValueSet (required)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... extension:breachRecordRetention C 0..1 Period Thời hạn lưu hồ sơ sự cố vi phạm (chỉ khi sự kiện là sự cố thuộc Điều 29 NĐ 356/2025/NĐ-CP)
URL: http://fhir.hl7.org.vn/core/StructureDefinition/vn-ext-audit-retention
Constraints: vn-audit-retention-minimum
... modifierExtension ?! 0..* Extension Extensions that cannot be ignored
... type SOΣ 1..1 Coding Loại sự kiện audit
Binding: AuditEventID (extensible): Type of event.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... subtype SOΣ 0..* Coding Phân loại sự kiện audit
Binding: AuditEventSub-Type (extensible): Sub-type of event.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... action SOΣ 0..1 code Hành động thực hiện (C/R/U/D/E)
Binding: AuditEventAction (required): Indicator for type of action performed during the event that generated the event.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... period 0..1 Period When the activity occurred
... recorded SOΣ 1..1 instant Thời điểm ghi nhận audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... outcome SOΣ 0..1 code Kết quả thực hiện
Binding: AuditEventOutcome (required): Indicates whether the event succeeded or failed.
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... outcomeDesc Σ 0..1 string Description of the event outcome
... purposeOfEvent SOΣ 0..* CodeableConcept Mục đích xử lý dữ liệu
Binding: Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet (extensible)
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
... agent SO 1..* BackboneElement Người/hệ thống thực hiện hành động
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... type 0..1 CodeableConcept How agent participated
Binding: ParticipationRoleType (extensible): The Participation type of the agent to the event.
.... role 0..* CodeableConcept Agent role in the event
Binding: SecurityRoleType (example): What security role enabled the agent to participate in the event.
.... who SΣ 0..1 Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson) Tác nhân thực hiện
.... altId 0..1 string Alternative User identity
.... name 0..1 string Human friendly name for the agent
.... requestor SΣ 1..1 boolean Có phải tác nhân khởi tạo yêu cầu hay không
.... location 0..1 Reference(Location) Where
.... policy 0..* uri Policy that authorized event
.... media 0..1 Coding Type of media
Binding: MediaTypeCode (extensible): Used when the event is about exporting/importing onto media.
.... network S 0..1 BackboneElement Thông tin mạng truy cập — địa chỉ nguồn của phiên truy cập
..... id 0..1 string Unique id for inter-element referencing
..... extension 0..* Extension Additional content defined by implementations
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... address 0..1 string Identifier for the network access point of the user device
..... type 0..1 code The type of network access point
Binding: AuditEventAgentNetworkType (required): The type of network access point of this agent in the audit event.
.... purposeOfUse 0..* CodeableConcept Reason given for this user
Binding: PurposeOfUse (extensible): The reason the activity took place.
... source SO 1..1 BackboneElement Nguồn phát sinh audit
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... site 0..1 string Logical source location within the enterprise
.... observer SΣ 1..1 Reference(PractitionerRole | Practitioner | Organization | Device | Patient | RelatedPerson) Hệ thống/đơn vị ghi log
.... type 0..* Coding The type of source where event originated
Binding: AuditEventSourceType (extensible): Code specifying the type of system that detected and recorded the event.
... entity SOC 0..* BackboneElement Đối tượng dữ liệu bị tác động
Constraints: sev-1
ObligationsActor
SHALL:populate-if-known Nguồn tạo hồ sơ lâm sàng (Document Source)
SHALL:no-error & SHALL:persist Kho hồ sơ EMR (Repository)
SHALL:no-error & SHALL:handle Ứng dụng người dân (Citizen App)
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... what SΣ 0..1 Reference(Resource) Resource hoặc đối tượng dữ liệu liên quan
.... type 0..1 Coding Type of entity involved
Binding: AuditEventEntityType (extensible): Code for the entity type involved in the audit event.
.... role 0..1 Coding What role the entity played
Binding: AuditEventEntityRole (extensible): Code representing the role the entity played in the audit event.
.... lifecycle 0..1 Coding Life-cycle stage for the entity
Binding: ObjectLifecycleEvents (extensible): Identifier for the data life-cycle stage for the entity.
.... securityLabel 0..* Coding Security labels on the entity
Binding: All Security Labels (extensible): Security Labels from the Healthcare Privacy and Security Classification System.
.... name ΣC 0..1 string Tên đối tượng dữ liệu
.... description 0..1 string Descriptive text
.... query ΣC 0..1 base64Binary Query parameters
.... detail 0..* BackboneElement Additional Information about the entity
..... id 0..1 string Unique id for inter-element referencing
..... extension 0..* Extension Additional content defined by implementations
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... type 1..1 string Name of the property
..... value[x] 1..1 Property value
...... valueString string
...... valueBase64Binary base64Binary

doco Documentation for this format
NameKho hồ sơ EMR (Repository)Ứng dụng người dân (Citizen App)Nguồn tạo hồ sơ lâm sàng (Document Source)doco
.. AuditEvent
... Slices for extension
.... extension:processingLegalBasis
... type
... subtype
... recorded
... outcome
... purposeOfEvent
... agent
... source
... entity

doco Documentation for this format

Terminology Bindings

Path Status Usage ValueSet Version Source
AuditEvent.language Base preferred Common Languages 📍4.0.1 FHIR Std.
AuditEvent.type Base extensible Audit Event ID 📍4.0.1 FHIR Std.
AuditEvent.subtype Base extensible Audit Event Sub-Type 📍4.0.1 FHIR Std.
AuditEvent.action Base required AuditEventAction 📍4.0.1 FHIR Std.
AuditEvent.outcome Base required AuditEventOutcome 📍4.0.1 FHIR Std.
AuditEvent.purposeOfEvent Base extensible Mục đích xử lý dữ liệu y tế — VN Consent Purpose ValueSet 📦0.10.0 This IG
AuditEvent.agent.type Base extensible ParticipationRoleType 📍4.0.1 FHIR Std.
AuditEvent.agent.role Base example SecurityRoleType 📍4.0.1 FHIR Std.
AuditEvent.agent.media Base extensible Media Type Code 📍4.0.1 FHIR Std.
AuditEvent.agent.network.​type Base required AuditEventAgentNetworkType 📍4.0.1 FHIR Std.
AuditEvent.agent.purposeOfUse Base extensible PurposeOfUse 📦3.1.0 THO v7.2
AuditEvent.source.type Base extensible Audit Event Source Type 📍4.0.1 FHIR Std.
AuditEvent.entity.type Base extensible Audit event entity type 📍4.0.1 FHIR Std.
AuditEvent.entity.role Base extensible AuditEventEntityRole 📍4.0.1 FHIR Std.
AuditEvent.entity.lifecycle Base extensible ObjectLifecycleEvents 📍4.0.1 FHIR Std.
AuditEvent.entity.securityLabel Base extensible SecurityLabels 📍4.0.1 FHIR Std.

Constraints

Id Grade Path(s) Description Expression
dom-2 error AuditEvent If the resource is contained in another resource, it SHALL NOT contain nested Resources contained.contained.empty()
dom-3 error AuditEvent If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().as(canonical) | %resource.descendants().as(uri) | %resource.descendants().as(url))) or descendants().where(reference = '#').exists() or descendants().where(as(canonical) = '#').exists() or descendants().where(as(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
dom-4 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
dom-5 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a security label contained.meta.security.empty()
dom-6 best practice AuditEvent A resource should have narrative for robust management text.`div`.exists()
ele-1 error **ALL** elements All FHIR elements must have a @value or children hasValue() or (children().count() > id.count())
ext-1 error **ALL** extensions Must have either extensions or value[x], not both extension.exists() != value.exists()
sev-1 error AuditEvent.entity Either a name or a query (NOT both) name.empty() or query.empty()
vn-audit-data-access-traceable error AuditEvent Bản ghi audit về truy cập dữ liệu phải định danh được tác nhân và đối tượng: ít nhất một `agent.who.reference` và một `entity.what.reference`. An audit record of data access SHALL identify both the acting party and the accessed object by reference. subtype.where((system = 'http://hl7.org/fhir/restful-interaction' and (code = 'read' or code = 'vread' or code = 'search' or code = 'search-type' or code = 'search-system')) or (system = 'http://fhir.hl7.org.vn/core/CodeSystem/vn-audit-event-subtype-cs' and (code = 'legal-basis-access' or code = 'legal-basis-authorization'))).exists() implies (agent.who.reference.exists() and entity.what.reference.exists())
vn-audit-retention-minimum error AuditEvent.extension:breachRecordRetention Ngày kết thúc đã khai không được chắc chắn sớm hơn năm năm sau ngày khắc phục sự cố. A declared end SHALL NOT be demonstrably earlier than five years after remediation. value.ofType(Period).all((end >= start + 5 years).all($this))

 

Biểu diễn khác của hồ sơ: CSV, Excel, Schematron