FHIR Data Segmentation for Privacy
0.2.0 - STU 1 Ballot

This page is part of the FHIR Data Segmentation for Privacy (v0.1.0: STU 1 Ballot 1) based on FHIR R4. . For a full list of available versions, see the Directory of published versions

Value set definition for Privacy Policy - XML Representation

(back to description)

Raw xml

Source view


<ValueSet xmlns="http://hl7.org/fhir">
  <id value="valueset-privacy-policy"/>
  <text>
    <status value="generated"/>
    <div xmlns="http://www.w3.org/1999/xhtml"><h2>Privacy Policy ValueSet</h2><div><p>Security label metadata that 'segments' an IT resource by conveying a mandate, obligation, requirement, rule, or expectation relating to its privacy.</p>
</div><ul><li>Include codes from <a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html"><code>http://terminology.hl7.org/CodeSystem/v3-ActCode</code></a> where concept  is-a  <a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-_ActConsentType">_ActConsentType</a></li><li>Include codes from <a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html"><code>http://terminology.hl7.org/CodeSystem/v3-ActCode</code></a> where concept  is-a  <a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-_ActConsentDirective">_ActConsentDirective</a></li><li>Include codes from <a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html"><code>http://terminology.hl7.org/CodeSystem/v3-ActCode</code></a> where concept  is-a  <a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-_ActPrivacyLaw">_ActPrivacyLaw</a></li><li>Include these codes as defined in <a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html"><code>http://terminology.hl7.org/CodeSystem/v3-ActCode</code></a><table class="none"><tr><td style="white-space:nowrap"><b>Code</b></td><td><b>Display</b></td></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRCD">GDPRCD</a></td><td>GDPR Consent Directive</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRResearchCD">GDPRResearchCD</a></td><td>GDPR Research Consent Directive</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OIC">OIC</a></td><td>opt-in to personal information or effect collection in a registry or repository</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OIS">OIS</a></td><td>opt-in to personal information or effect sharing via a registry or repository</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OOC">OOC</a></td><td>opt-out of personal information or effect collection in a registry or repository</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OOS">OOS</a></td><td>opt-out of personal information or effect sharing via a registry or repository</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-42CFRPart2CD">42CFRPart2CD</a></td><td>42 CFR Part 2 consent directive</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-CompoundResearchCD">CompoundResearchCD</a></td><td>Compound HIPAA Research Authorization and Informed Consent for Research</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-HIPAAAuthCD">HIPAAAuthCD</a></td><td>HIPAA Authorization Consent Directive</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-HIPAAConsentCD">HIPAAConsentCD</a></td><td>HIPAA Consent Directive</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-HIPAAResearchAuthCD">HIPAAResearchAuthCD</a></td><td>HIPAA Authorization for Disclosure for Research Consent Directive</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-HIPAAROAD">HIPAAROAD</a></td><td>HIPAA Right of Access Directive</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-InformedAssentCD">InformedAssentCD</a></td><td>Informed Assent for Research</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-InformedConsentCD">InformedConsentCD</a></td><td>Informed Consent for Research</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-MDHHS-5515">MDHHS-5515</a></td><td>Michigan Consent to Share Behavioral Health Information for Care Coordination Purposes</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-MDHHS-5515MMHC">MDHHS-5515MMHC</a></td><td>Michigan Consent to Share Behavioral Health Information for Care Coordination Purposes-Michigan Mental Health Code</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-MDHHS-5515Part2">MDHHS-5515Part2</a></td><td>Michigan Consent to Share Behavioral Health Information for Care Coordination Purposes-US 42 CFR Part 2</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisIP">JurisIP</a></td><td>jurisdictional information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisCUI">JurisCUI</a></td><td>jurisdictional controlled unclassified information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisDEID">JurisDEID</a></td><td>jurisdictional de-identified information poli</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisLDS">JurisLDS</a></td><td>jurisdictional limited data set</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisNSI">JurisNSI</a></td><td>jurisdictional non-sensitive information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisPI">JurisPI</a></td><td>jurisdictional public information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisSP-CUI">JurisSP-CUI</a></td><td>jurisdictional specified controlled unclassified information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-JurisUUI">JurisUUI</a></td><td>jurisdictional uncontrolled unclassified information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgIP">OrgIP</a></td><td>organizational information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgCUI">OrgCUI</a></td><td>organizational basic controlled unclassified information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgDEID">OrgDEID</a></td><td>organizational de-identified information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgLDS">OrgLDS</a></td><td>organizational limited data set information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgNSI">OrgNSI</a></td><td>organizational non-sensitive information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgPI">OrgPI</a></td><td>organizational public information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgSP-CUI">OrgSP-CUI</a></td><td>Organizational policy on collection, access, use, or disclosure of specified controlled unclassified information as defined by the organization or by applicable jurisdictional law.</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-OrgUUI">OrgUUI</a></td><td>organizational uncontrolled unclassified information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-PersIP">PersIP</a></td><td>personal information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-PersDEID">PersDEID</a></td><td>personal de-identified information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-PersLDS">PersLDS</a></td><td>personal limited data set information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-PersNSI">PersNSI</a></td><td>personal non-sensitive information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-PersPI">PersPI</a></td><td>personal public information policy</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRCONSENT">GDPRCONSENT</a></td><td>GDPR consent</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRCONTRACT">GDPRCONTRACT</a></td><td>GDPR contract</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRLEGALCLAIM">GDPRLEGALCLAIM</a></td><td>GDPR legal claim</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRLEGALOBL">GDPRLEGALOBL</a></td><td>GDPR legal obligation</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRLEGITINTEREST">GDPRLEGITINTEREST</a></td><td>GDPR legitimate interest</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRPUBLICHEALTH">GDPRPUBLICHEALTH</a></td><td>GDPR public health</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRPUBLICINTEREST">GDPRPUBLICINTEREST</a></td><td>GDPR public interest</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRRESEARCH">GDPRRESEARCH</a></td><td>GDPR research</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRHTHSOCSYS">GDPRHTHSOCSYS</a></td><td>GDPR health or social system management</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-GDPRVITALINTEREST">GDPRVITALINTEREST</a></td><td>GDPR vital interest</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-32CFRPart2002">32CFRPart2002</a></td><td>32 CFR Part 2002</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-HIPAAAuth">HIPAAAuth</a></td><td>HIPAA Authorization for Disclosure</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-HIPAAConsent">HIPAAConsent</a></td><td>HIPAA Consent</td><td/></tr><tr><td><a href="http://hl7.org/fhir/R4/v3/ActCode/cs.html#v3-ActCode-HIPAAROA">HIPAAROA</a></td><td>HIPAA Right of Access</td><td/></tr></table></li></ul><p>This value set includes codes based on the following rules:</p></div>
  </text>
  <url
       value="http://hl7.org/fhir/uv/security-label-ds4p/ValueSet/valueset-privacy-policy"/>
  <version value="0.2.0"/>
  <name value="ValueSetPrivacyPolicy"/>
  <title value="Privacy Policy ValueSet"/>
  <status value="draft"/>
  <date value="2020-03-30T00:00:00+00:00"/>
  <publisher value="HL7 International - Security Work Group"/>
  <contact>
    <telecom>
      <system value="url"/>
      <value value="http://hl7.org/Special/committees/secure"/>
    </telecom>
  </contact>
  <description
               value="Security label metadata that &#39;segments&#39; an IT resource by conveying a mandate, obligation, requirement, rule, or expectation relating to its privacy."/>
  <jurisdiction>
    <coding>
      <system value="http://unstats.un.org/unsd/methods/m49/m49.htm"/>
      <code value="001"/>
    </coding>
  </jurisdiction>
  <compose>
    <include>
      <system value="http://terminology.hl7.org/CodeSystem/v3-ActCode"/>
      <filter>
        <property value="concept"/>
        <op value="is-a"/>
        <value value="_ActConsentType"/>
      </filter>
    </include>
    <include>
      <system value="http://terminology.hl7.org/CodeSystem/v3-ActCode"/>
      <filter>
        <property value="concept"/>
        <op value="is-a"/>
        <value value="_ActConsentDirective"/>
      </filter>
    </include>
    <include>
      <system value="http://terminology.hl7.org/CodeSystem/v3-ActCode"/>
      <filter>
        <property value="concept"/>
        <op value="is-a"/>
        <value value="_ActPrivacyLaw"/>
      </filter>
    </include>
    <include>
      <system value="http://terminology.hl7.org/CodeSystem/v3-ActCode"/>
      <concept>
        <code value="GDPRCD"/>
        <display value="GDPR Consent Directive"/>
      </concept>
      <concept>
        <code value="GDPRResearchCD"/>
        <display value="GDPR Research Consent Directive"/>
      </concept>
      <concept>
        <code value="OIC"/>
        <display
                 value="opt-in to personal information or effect collection in a registry or repository"/>
      </concept>
      <concept>
        <code value="OIS"/>
        <display
                 value="opt-in to personal information or effect sharing via a registry or repository"/>
      </concept>
      <concept>
        <code value="OOC"/>
        <display
                 value="opt-out of personal information or effect collection in a registry or repository"/>
      </concept>
      <concept>
        <code value="OOS"/>
        <display
                 value="opt-out of personal information or effect sharing via a registry or repository"/>
      </concept>
      <concept>
        <code value="42CFRPart2CD"/>
        <display value="42 CFR Part 2 consent directive"/>
      </concept>
      <concept>
        <code value="CompoundResearchCD"/>
        <display
                 value="Compound HIPAA Research Authorization and Informed Consent for Research"/>
      </concept>
      <concept>
        <code value="HIPAAAuthCD"/>
        <display value="HIPAA Authorization Consent Directive"/>
      </concept>
      <concept>
        <code value="HIPAAConsentCD"/>
        <display value="HIPAA Consent Directive"/>
      </concept>
      <concept>
        <code value="HIPAAResearchAuthCD"/>
        <display
                 value="HIPAA Authorization for Disclosure for Research Consent Directive"/>
      </concept>
      <concept>
        <code value="HIPAAROAD"/>
        <display value="HIPAA Right of Access Directive"/>
      </concept>
      <concept>
        <code value="InformedAssentCD"/>
        <display value="Informed Assent for Research"/>
      </concept>
      <concept>
        <code value="InformedConsentCD"/>
        <display value="Informed Consent for Research"/>
      </concept>
      <concept>
        <code value="MDHHS-5515"/>
        <display
                 value="Michigan Consent to Share Behavioral Health Information for Care Coordination Purposes"/>
      </concept>
      <concept>
        <code value="MDHHS-5515MMHC"/>
        <display
                 value="Michigan Consent to Share Behavioral Health Information for Care Coordination Purposes-Michigan Mental Health Code"/>
      </concept>
      <concept>
        <code value="MDHHS-5515Part2"/>
        <display
                 value="Michigan Consent to Share Behavioral Health Information for Care Coordination Purposes-US 42 CFR Part 2"/>
      </concept>
      <concept>
        <code value="JurisIP"/>
        <display value="jurisdictional information policy"/>
      </concept>
      <concept>
        <code value="JurisCUI"/>
        <display
                 value="jurisdictional controlled unclassified information policy"/>
      </concept>
      <concept>
        <code value="JurisDEID"/>
        <display value="jurisdictional de-identified information poli"/>
      </concept>
      <concept>
        <code value="JurisLDS"/>
        <display value="jurisdictional limited data set"/>
      </concept>
      <concept>
        <code value="JurisNSI"/>
        <display value="jurisdictional non-sensitive information policy"/>
      </concept>
      <concept>
        <code value="JurisPI"/>
        <display value="jurisdictional public information policy"/>
      </concept>
      <concept>
        <code value="JurisSP-CUI"/>
        <display
                 value="jurisdictional specified controlled unclassified information policy"/>
      </concept>
      <concept>
        <code value="JurisUUI"/>
        <display
                 value="jurisdictional uncontrolled unclassified information policy"/>
      </concept>
      <concept>
        <code value="OrgIP"/>
        <display value="organizational information policy"/>
      </concept>
      <concept>
        <code value="OrgCUI"/>
        <display
                 value="organizational basic controlled unclassified information policy"/>
      </concept>
      <concept>
        <code value="OrgDEID"/>
        <display value="organizational de-identified information policy"/>
      </concept>
      <concept>
        <code value="OrgLDS"/>
        <display value="organizational limited data set information policy"/>
      </concept>
      <concept>
        <code value="OrgNSI"/>
        <display value="organizational non-sensitive information policy"/>
      </concept>
      <concept>
        <code value="OrgPI"/>
        <display value="organizational public information policy"/>
      </concept>
      <concept>
        <code value="OrgSP-CUI"/>
        <display
                 value="Organizational policy on collection, access, use, or disclosure of specified controlled unclassified information as defined by the organization or by applicable jurisdictional law."/>
      </concept>
      <concept>
        <code value="OrgUUI"/>
        <display
                 value="organizational uncontrolled unclassified information policy"/>
      </concept>
      <concept>
        <code value="PersIP"/>
        <display value="personal information policy"/>
      </concept>
      <concept>
        <code value="PersDEID"/>
        <display value="personal de-identified information policy"/>
      </concept>
      <concept>
        <code value="PersLDS"/>
        <display value="personal limited data set information policy"/>
      </concept>
      <concept>
        <code value="PersNSI"/>
        <display value="personal non-sensitive information policy"/>
      </concept>
      <concept>
        <code value="PersPI"/>
        <display value="personal public information policy"/>
      </concept>
      <concept>
        <code value="GDPRCONSENT"/>
        <display value="GDPR consent"/>
      </concept>
      <concept>
        <code value="GDPRCONTRACT"/>
        <display value="GDPR contract"/>
      </concept>
      <concept>
        <code value="GDPRLEGALCLAIM"/>
        <display value="GDPR legal claim"/>
      </concept>
      <concept>
        <code value="GDPRLEGALOBL"/>
        <display value="GDPR legal obligation"/>
      </concept>
      <concept>
        <code value="GDPRLEGITINTEREST"/>
        <display value="GDPR legitimate interest"/>
      </concept>
      <concept>
        <code value="GDPRPUBLICHEALTH"/>
        <display value="GDPR public health"/>
      </concept>
      <concept>
        <code value="GDPRPUBLICINTEREST"/>
        <display value="GDPR public interest"/>
      </concept>
      <concept>
        <code value="GDPRRESEARCH"/>
        <display value="GDPR research"/>
      </concept>
      <concept>
        <code value="GDPRHTHSOCSYS"/>
        <display value="GDPR health or social system management"/>
      </concept>
      <concept>
        <code value="GDPRVITALINTEREST"/>
        <display value="GDPR vital interest"/>
      </concept>
      <concept>
        <code value="32CFRPart2002"/>
        <display value="32 CFR Part 2002"/>
      </concept>
      <concept>
        <code value="HIPAAAuth"/>
        <display value="HIPAA Authorization for Disclosure"/>
      </concept>
      <concept>
        <code value="HIPAAConsent"/>
        <display value="HIPAA Consent"/>
      </concept>
      <concept>
        <code value="HIPAAROA"/>
        <display value="HIPAA Right of Access"/>
      </concept>
    </include>
  </compose>
</ValueSet>