This page is part of the FHIR Data Segmentation for Privacy (v0.1.0: STU 1 Ballot 1) based on FHIR R4. . For a full list of available versions, see the Directory of published versions
Source view
<ValueSet xmlns="http://hl7.org/fhir"> <id value="valueset-privacy-policy"/> <text> <status value="generated"/> <div xmlns="http://www.w3.org/1999/xhtml"><h2>Privacy Policy ValueSet</h2><div><p>Security label metadata that 'segments' an IT resource by conveying a mandate, obligation, requirement, rule, or expectation relating to its privacy.</p> </div><ul><li>Include codes from <a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html"><code>http://terminology.hl7.org/CodeSystem/v3-ActCode</code></a> where concept is-a <a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-_ActConsentType">_ActConsentType</a></li><li>Include codes from <a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html"><code>http://terminology.hl7.org/CodeSystem/v3-ActCode</code></a> where concept is-a <a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-_ActConsentDirective">_ActConsentDirective</a></li><li>Include codes from <a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html"><code>http://terminology.hl7.org/CodeSystem/v3-ActCode</code></a> where concept is-a <a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-_ActPrivacyLaw">_ActPrivacyLaw</a></li><li>Include these codes as defined in <a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html"><code>http://terminology.hl7.org/CodeSystem/v3-ActCode</code></a><table class="none"><tr><td style="white-space:nowrap"><b>Code</b></td><td><b>Display</b></td></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRCD">GDPRCD</a></td><td>GDPR Consent Directive</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRResearchCD">GDPRResearchCD</a></td><td>GDPR Research Consent Directive</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OIC">OIC</a></td><td>opt-in to personal information or effect collection in a registry or repository</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OIS">OIS</a></td><td>opt-in to personal information or effect sharing via a registry or repository</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OOC">OOC</a></td><td>opt-out of personal information or effect collection in a registry or repository</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OOS">OOS</a></td><td>opt-out of personal information or effect sharing via a registry or repository</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-42CFRPart2CD">42CFRPart2CD</a></td><td>42 CFR Part 2 consent directive</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-CompoundResearchCD">CompoundResearchCD</a></td><td>Compound HIPAA Research Authorization and Informed Consent for Research</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-HIPAAAuthCD">HIPAAAuthCD</a></td><td>HIPAA Authorization Consent Directive</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-HIPAAConsentCD">HIPAAConsentCD</a></td><td>HIPAA Consent Directive</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-HIPAAResearchAuthCD">HIPAAResearchAuthCD</a></td><td>HIPAA Authorization for Disclosure for Research Consent Directive</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-HIPAAROAD">HIPAAROAD</a></td><td>HIPAA Right of Access Directive</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-InformedAssentCD">InformedAssentCD</a></td><td>Informed Assent for Research</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-InformedConsentCD">InformedConsentCD</a></td><td>Informed Consent for Research</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-MDHHS-5515">MDHHS-5515</a></td><td>Michigan Consent to Share Behavioral Health Information for Care Coordination Purposes</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-MDHHS-5515MMHC">MDHHS-5515MMHC</a></td><td>Michigan Consent to Share Behavioral Health Information for Care Coordination Purposes-Michigan Mental Health Code</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-MDHHS-5515Part2">MDHHS-5515Part2</a></td><td>Michigan Consent to Share Behavioral Health Information for Care Coordination Purposes-US 42 CFR Part 2</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisIP">JurisIP</a></td><td>jurisdictional information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisCUI">JurisCUI</a></td><td>jurisdictional controlled unclassified information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisDEID">JurisDEID</a></td><td>jurisdictional de-identified information poli</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisLDS">JurisLDS</a></td><td>jurisdictional limited data set</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisNSI">JurisNSI</a></td><td>jurisdictional non-sensitive information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisPI">JurisPI</a></td><td>jurisdictional public information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisSP-CUI">JurisSP-CUI</a></td><td>jurisdictional specified controlled unclassified information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisUUI">JurisUUI</a></td><td>jurisdictional uncontrolled unclassified information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgIP">OrgIP</a></td><td>organizational information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgCUI">OrgCUI</a></td><td>organizational basic controlled unclassified information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgDEID">OrgDEID</a></td><td>organizational de-identified information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgLDS">OrgLDS</a></td><td>organizational limited data set information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgNSI">OrgNSI</a></td><td>organizational non-sensitive information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgPI">OrgPI</a></td><td>organizational public information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgSP-CUI">OrgSP-CUI</a></td><td>Organizational policy on collection, access, use, or disclosure of specified controlled unclassified information as defined by the organization or by applicable jurisdictional law.</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgUUI">OrgUUI</a></td><td>organizational uncontrolled unclassified information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-PersIP">PersIP</a></td><td>personal information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-PersDEID">PersDEID</a></td><td>personal de-identified information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-PersLDS">PersLDS</a></td><td>personal limited data set information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-PersNSI">PersNSI</a></td><td>personal non-sensitive information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-PersPI">PersPI</a></td><td>personal public information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRCONSENT">GDPRCONSENT</a></td><td>GDPR consent</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRCONTRACT">GDPRCONTRACT</a></td><td>GDPR contract</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRLEGALCLAIM">GDPRLEGALCLAIM</a></td><td>GDPR legal claim</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRLEGALOBL">GDPRLEGALOBL</a></td><td>GDPR legal obligation</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRLEGITINTEREST">GDPRLEGITINTEREST</a></td><td>GDPR legitimate interest</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRPUBLICHEALTH">GDPRPUBLICHEALTH</a></td><td>GDPR public health</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRPUBLICINTEREST">GDPRPUBLICINTEREST</a></td><td>GDPR public interest</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRRESEARCH">GDPRRESEARCH</a></td><td>GDPR research</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRHTHSOCSYS">GDPRHTHSOCSYS</a></td><td>GDPR health or social system management</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRVITALINTEREST">GDPRVITALINTEREST</a></td><td>GDPR vital interest</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-32CFRPart2002">32CFRPart2002</a></td><td>32 CFR Part 2002</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-HIPAAAuth">HIPAAAuth</a></td><td>HIPAA Authorization for Disclosure</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-HIPAAConsent">HIPAAConsent</a></td><td>HIPAA Consent</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-HIPAAROA">HIPAAROA</a></td><td>HIPAA Right of Access</td><td/></tr></table></li></ul><p>This value set includes codes based on the following rules:</p></div> </text> <url value="http://hl7.org/fhir/uv/security-label-ds4p/ValueSet/valueset-privacy-policy"/> <version value="0.2.0"/> <name value="ValueSetPrivacyPolicy"/> <title value="Privacy Policy ValueSet"/> <status value="draft"/> <date value="2020-03-30T00:00:00+00:00"/> <publisher value="HL7 International - Security Work Group"/> <contact> <telecom> <system value="url"/> <value value="http://hl7.org/Special/committees/secure"/> </telecom> </contact> <description value="Security label metadata that 'segments' an IT resource by conveying a mandate, obligation, requirement, rule, or expectation relating to its privacy."/> <jurisdiction> <coding> <system value="http://unstats.un.org/unsd/methods/m49/m49.htm"/> <code value="001"/> </coding> </jurisdiction> <compose> <include> <system value="http://terminology.hl7.org/CodeSystem/v3-ActCode"/> <filter> <property value="concept"/> <op value="is-a"/> <value value="_ActConsentType"/> </filter> </include> <include> <system value="http://terminology.hl7.org/CodeSystem/v3-ActCode"/> <filter> <property value="concept"/> <op value="is-a"/> <value value="_ActConsentDirective"/> </filter> </include> <include> <system value="http://terminology.hl7.org/CodeSystem/v3-ActCode"/> <filter> <property value="concept"/> <op value="is-a"/> <value value="_ActPrivacyLaw"/> </filter> </include> <include> <system value="http://terminology.hl7.org/CodeSystem/v3-ActCode"/> <concept> <code value="GDPRCD"/> <display value="GDPR Consent Directive"/> </concept> <concept> <code value="GDPRResearchCD"/> <display value="GDPR Research Consent Directive"/> </concept> <concept> <code value="OIC"/> <display value="opt-in to personal information or effect collection in a registry or repository"/> </concept> <concept> <code value="OIS"/> <display value="opt-in to personal information or effect sharing via a registry or repository"/> </concept> <concept> <code value="OOC"/> <display value="opt-out of personal information or effect collection in a registry or repository"/> </concept> <concept> <code value="OOS"/> <display value="opt-out of personal information or effect sharing via a registry or repository"/> </concept> <concept> <code value="42CFRPart2CD"/> <display value="42 CFR Part 2 consent directive"/> </concept> <concept> <code value="CompoundResearchCD"/> <display value="Compound HIPAA Research Authorization and Informed Consent for Research"/> </concept> <concept> <code value="HIPAAAuthCD"/> <display value="HIPAA Authorization Consent Directive"/> </concept> <concept> <code value="HIPAAConsentCD"/> <display value="HIPAA Consent Directive"/> </concept> <concept> <code value="HIPAAResearchAuthCD"/> <display value="HIPAA Authorization for Disclosure for Research Consent Directive"/> </concept> <concept> <code value="HIPAAROAD"/> <display value="HIPAA Right of Access Directive"/> </concept> <concept> <code value="InformedAssentCD"/> <display value="Informed Assent for Research"/> </concept> <concept> <code value="InformedConsentCD"/> <display value="Informed Consent for Research"/> </concept> <concept> <code value="MDHHS-5515"/> <display value="Michigan Consent to Share Behavioral Health Information for Care Coordination Purposes"/> </concept> <concept> <code value="MDHHS-5515MMHC"/> <display value="Michigan Consent to Share Behavioral Health Information for Care Coordination Purposes-Michigan Mental Health Code"/> </concept> <concept> <code value="MDHHS-5515Part2"/> <display value="Michigan Consent to Share Behavioral Health Information for Care Coordination Purposes-US 42 CFR Part 2"/> </concept> <concept> <code value="JurisIP"/> <display value="jurisdictional information policy"/> </concept> <concept> <code value="JurisCUI"/> <display value="jurisdictional controlled unclassified information policy"/> </concept> <concept> <code value="JurisDEID"/> <display value="jurisdictional de-identified information poli"/> </concept> <concept> <code value="JurisLDS"/> <display value="jurisdictional limited data set"/> </concept> <concept> <code value="JurisNSI"/> <display value="jurisdictional non-sensitive information policy"/> </concept> <concept> <code value="JurisPI"/> <display value="jurisdictional public information policy"/> </concept> <concept> <code value="JurisSP-CUI"/> <display value="jurisdictional specified controlled unclassified information policy"/> </concept> <concept> <code value="JurisUUI"/> <display value="jurisdictional uncontrolled unclassified information policy"/> </concept> <concept> <code value="OrgIP"/> <display value="organizational information policy"/> </concept> <concept> <code value="OrgCUI"/> <display value="organizational basic controlled unclassified information policy"/> </concept> <concept> <code value="OrgDEID"/> <display value="organizational de-identified information policy"/> </concept> <concept> <code value="OrgLDS"/> <display value="organizational limited data set information policy"/> </concept> <concept> <code value="OrgNSI"/> <display value="organizational non-sensitive information policy"/> </concept> <concept> <code value="OrgPI"/> <display value="organizational public information policy"/> </concept> <concept> <code value="OrgSP-CUI"/> <display value="Organizational policy on collection, access, use, or disclosure of specified controlled unclassified information as defined by the organization or by applicable jurisdictional law."/> </concept> <concept> <code value="OrgUUI"/> <display value="organizational uncontrolled unclassified information policy"/> </concept> <concept> <code value="PersIP"/> <display value="personal information policy"/> </concept> <concept> <code value="PersDEID"/> <display value="personal de-identified information policy"/> </concept> <concept> <code value="PersLDS"/> <display value="personal limited data set information policy"/> </concept> <concept> <code value="PersNSI"/> <display value="personal non-sensitive information policy"/> </concept> <concept> <code value="PersPI"/> <display value="personal public information policy"/> </concept> <concept> <code value="GDPRCONSENT"/> <display value="GDPR consent"/> </concept> <concept> <code value="GDPRCONTRACT"/> <display value="GDPR contract"/> </concept> <concept> <code value="GDPRLEGALCLAIM"/> <display value="GDPR legal claim"/> </concept> <concept> <code value="GDPRLEGALOBL"/> <display value="GDPR legal obligation"/> </concept> <concept> <code value="GDPRLEGITINTEREST"/> <display value="GDPR legitimate interest"/> </concept> <concept> <code value="GDPRPUBLICHEALTH"/> <display value="GDPR public health"/> </concept> <concept> <code value="GDPRPUBLICINTEREST"/> <display value="GDPR public interest"/> </concept> <concept> <code value="GDPRRESEARCH"/> <display value="GDPR research"/> </concept> <concept> <code value="GDPRHTHSOCSYS"/> <display value="GDPR health or social system management"/> </concept> <concept> <code value="GDPRVITALINTEREST"/> <display value="GDPR vital interest"/> </concept> <concept> <code value="32CFRPart2002"/> <display value="32 CFR Part 2002"/> </concept> <concept> <code value="HIPAAAuth"/> <display value="HIPAA Authorization for Disclosure"/> </concept> <concept> <code value="HIPAAConsent"/> <display value="HIPAA Consent"/> </concept> <concept> <code value="HIPAAROA"/> <display value="HIPAA Right of Access"/> </concept> </include> </compose> </ValueSet>