FHIR © HL7.org  |  FHIRsmith 4.0.1  |  Server Home  |  XIG Home  |  XIG Stats  | 

FHIR IG analytics

Packagehl7.fhir.uv.xver-r5.r4b
Resource TypeValueSet
IdValueSet-R5-security-label-examples-for-R4B.json
FHIR VersionR4B
Sourcehttp://hl7.org/fhir/uv/xver-r5.r4b/0.1.0/ValueSet-R5-security-label-examples-for-R4B.html
URLhttp://hl7.org/fhir/uv/xver/ValueSet/R5-security-label-examples-for-R4B
Version0.1.0
Statusactive
Date2026-03-17T21:02:03.8104715+00:00
NameR5SecurityLabelExamplesForR4B
TitleCross-version ValueSet R5.SecurityLabelExamples for use in FHIR R4B
Realmuv
Authorityhl7
DescriptionThis cross-version ValueSet represents content from `http://hl7.org/fhir/ValueSet/security-label-examples|5.0.0` for use in FHIR R4B.
PurposeThis value set is part of the cross-version definitions generated to enable use of the value set `http://hl7.org/fhir/ValueSet/security-label-examples|5.0.0` as defined in FHIR R5 in FHIR R4B. The source value set is bound to the following FHIR R5 elements: * `AuditEvent.entity.securityLabel` * `Consent.provision.securityLabel` * `DocumentReference.securityLabel` Note that all concepts are included in this cross-version definition because no concepts have compatible representations Following are the generation technical comments: FHIR ValueSet `http://hl7.org/fhir/ValueSet/security-label-examples|5.0.0`, defined in FHIR R5 does not have any mapping to FHIR R4B

Resources that use this resource

No resources found


Resources that this resource uses

CodeSystem
hl7.terminology#currentv3-ActCodeActCode
hl7.terminology#currentv3-ActReasonActReason
hl7.terminology#currentv3-ConfidentialityConfidentiality

Narrative

Note: links and images are rebased to the (stated) source

Generated Narrative: ValueSet R5-security-label-examples-for-R4B

This value set expansion contains 11 concepts.

SystemVersionCodeDisplayDefinition
http://terminology.hl7.org/CodeSystem/v3-ActCode8.0.0  DELAUdelete after use

Custodian system must remove target information from access after use.

http://terminology.hl7.org/CodeSystem/v3-ActCode8.0.0  ETHsubstance abuse information sensitivity

Policy for handling alcohol or drug-abuse information, which will be afforded heightened confidentiality. Information handling protocols based on organizational policies related to alcohol or drug-abuse information that is deemed sensitive.

Usage Note: If there is a jurisdictional mandate, then use the applicable ActPrivacyLaw code system, and specify the law rather than or in addition to this more generic code.

http://terminology.hl7.org/CodeSystem/v3-ActCode8.0.0  NOAUTHno disclosure without subject authorization

Prohibition on disclosure without information subject's authorization.

http://terminology.hl7.org/CodeSystem/v3-ActCode8.0.0  NORDSCLCDno redisclosure without consent directive

Prohibition on redisclosure without patient consent directive.

http://terminology.hl7.org/CodeSystem/v3-ActCode8.0.0  PSYpsychiatry disorder information sensitivity

Policy for handling psychiatry psychiatric disorder information, which is afforded heightened confidentiality.

Usage Note: If there is a jurisdictional mandate, then use the applicable ActPrivacyLaw code system, and specify the law rather than or in addition to this more generic code.

http://terminology.hl7.org/CodeSystem/v3-ActCode8.0.0  STDsexually transmitted disease information sensitivity

Policy for handling sexually transmitted disease information, which will be afforded heightened confidentiality. Information handling protocols based on organizational policies related to sexually transmitted disease information that is deemed sensitive.

Usage Note: If there is a jurisdictional mandate, then use the applicable ActPrivacyLaw code system, and specify the law rather than or in addition to this more generic code.

http://terminology.hl7.org/CodeSystem/v3-ActReason2.1.0  ETREATEmergency Treatment

To perform one or more operations on information for provision of immediately needed health care for an emergent condition.

http://terminology.hl7.org/CodeSystem/v3-ActReason2.1.0  HPAYMThealthcare payment

To perform one or more operations on information for conducting financial or contractual activities related to payment for provision of health care.

http://terminology.hl7.org/CodeSystem/v3-ActReason2.1.0  TREATtreatment

To perform one or more operations on information for provision of health care.

http://terminology.hl7.org/CodeSystem/v3-Confidentiality2.2.0  Nnormal

Privacy metadata indicating the level of protection required to safeguard personal and healthcare information, which if disclosed without authorization, would present a considerable risk of harm to an individual's reputation and sense of privacy.

Usage Note: The level of protection afforded normatively confidential information is dictated by the prevailing normative privacy policies, which are intended to engender patient trust in their healthcare providers.

Privacy policies mandating normative levels of protection, which preempt less protective privacy policies when the information is used in the delivery and management of healthcare. May be pre-empted by jurisdictional law (e.g., for public health reporting or emergency treatment).

Confidentiality code total order hierarchy: Normal (N) is less protective than V and R, and subsumes all other protection levels (i.e., M, L, and U).

**Map:**Partial Map to ISO 13606-4 Sensitivity Level (3) Clinical Care when purpose of use is treatment: Default for normal clinical care access (i.e., most clinical staff directly caring for the patient should be able to access nearly all of the EHR). Maps to normal confidentiality for treatment information but not to ancillary care, payment and operations.

Examples:

n the US, this includes what HIPAA identifies as protected health information (PHI) under 45 CFR Section 160.103.

http://terminology.hl7.org/CodeSystem/v3-Confidentiality2.2.0  Rrestricted

Privacy metadata indicating the level of protection required to safeguard potentially stigmatizing information, which if disclosed without authorization, would present a high risk of harm to an individual's reputation and sense of privacy.

Usage Note: The level of protection afforded restricted confidential information is dictated by specially protective organizational or jurisdictional privacy policies, including at an authorized individual’s request, intended to engender patient trust in providers of sensitive services.

Privacy policies mandating additional levels of protection by restricting information access preempt less protective privacy policies when the information is used in the delivery and management of healthcare. May be pre-empted by jurisdictional law (e.g., for public health reporting or emergency treatment).

Confidentiality code total order hierarchy: Restricted (R) is less protective than V, and subsumes all other protection levels (i.e., N, M, L, and U).

Examples:

Includes information that is additionally protected such as sensitive conditions mental health, HIV, substance abuse, domestic violence, child abuse, genetic disease, and reproductive health; or sensitive demographic information such as a patient’s standing as an employee or a celebrity. May be used to indicate proprietary or classified information that is not related to an individual (e.g., secret ingredients in a therapeutic substance; or the name of a manufacturer).


Source1

{
  "resourceType": "ValueSet",
  "id": "R5-security-label-examples-for-R4B",
  "text": {
    "status": "generated",
    "div": "<!-- snip (see above) -->"
  },
  "extension": [
    {
      "url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-fmm",
      "valueInteger": 1
    },
    {
      "url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-wg",
      "valueCode": "sec"
    },
    {
      "extension": [
        {
          "url": "packageId",
          "valueId": "hl7.fhir.uv.xver-r5.r4b"
        },
        {
          "url": "version",
          "valueString": "0.1.0"
        },
        {
          "url": "uri",
          "valueUri": "http://hl7.org/fhir/uv/xver/ImplementationGuide/hl7.fhir.uv.xver-r5.r4b"
        }
      ],
      "url": "http://hl7.org/fhir/StructureDefinition/package-source"
    },
    {
      "url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-standards-status",
      "valueCode": "trial-use",
      "_valueCode": {
        "extension": [
          {
            "url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom",
            "valueCanonical": "http://hl7.org/fhir/uv/xver/ImplementationGuide/hl7.fhir.uv.xver-r5.r4b"
          }
        ]
      }
    }
  ],
  "url": "http://hl7.org/fhir/uv/xver/ValueSet/R5-security-label-examples-for-R4B",
  "version": "0.1.0",
  "name": "R5SecurityLabelExamplesForR4B",
  "title": "Cross-version ValueSet R5.SecurityLabelExamples for use in FHIR R4B",
  "status": "active",
  "experimental": false,
  "date": "2026-03-17T21:02:03.8104715+00:00",
  "publisher": "Security",
  "contact": [
    {
      "name": "Security",
      "telecom": [
        {
          "system": "url",
          "value": "http://www.hl7.org/Special/committees/secure"
        }
      ]
    }
  ],
  "description": "This cross-version ValueSet represents content from `http://hl7.org/fhir/ValueSet/security-label-examples|5.0.0` for use in FHIR R4B.",
  "jurisdiction": [
    {
      "coding": [
        {
          "system": "http://unstats.un.org/unsd/methods/m49/m49.htm",
          "code": "001",
          "display": "World"
        }
      ]
    }
  ],
  "purpose": "This value set is part of the cross-version definitions generated to enable use of the\r\nvalue set `http://hl7.org/fhir/ValueSet/security-label-examples|5.0.0` as defined in FHIR R5\r\nin FHIR R4B.\r\n\r\nThe source value set is bound to the following FHIR R5 elements:\r\n* `AuditEvent.entity.securityLabel`\n* `Consent.provision.securityLabel`\n* `DocumentReference.securityLabel`\r\n\r\nNote that all concepts are included in this cross-version definition because no concepts have compatible representations\r\n\r\nFollowing are the generation technical comments:\r\n\nFHIR ValueSet `http://hl7.org/fhir/ValueSet/security-label-examples|5.0.0`, defined in FHIR R5 does not have any mapping to FHIR R4B",
  "compose": {
    "include": [
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
        "version": "8.0.0",
        "concept": [
          {
            "code": "DELAU",
            "display": "delete after use"
          },
          {
            "code": "ETH",
            "display": "substance abuse information sensitivity"
          },
          {
            "code": "NOAUTH",
            "display": "no disclosure without subject authorization"
          },
          {
            "code": "NORDSCLCD",
            "display": "no redisclosure without consent directive"
          },
          {
            "code": "PSY",
            "display": "psychiatry disorder information sensitivity"
          },
          {
            "code": "STD",
            "display": "sexually transmitted disease information sensitivity"
          }
        ]
      },
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
        "version": "2.1.0",
        "concept": [
          {
            "code": "ETREAT",
            "display": "Emergency Treatment"
          },
          {
            "code": "HPAYMT",
            "display": "healthcare payment"
          },
          {
            "code": "TREAT",
            "display": "treatment"
          }
        ]
      },
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
        "version": "2.2.0",
        "concept": [
          {
            "code": "N",
            "display": "normal"
          },
          {
            "code": "R",
            "display": "restricted"
          }
        ]
      }
    ]
  },
  "expansion": {
    "timestamp": "2026-03-17T21:02:03.8104715+00:00",
    "contains": [
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
        "version": "8.0.0",
        "code": "DELAU",
        "display": "delete after use"
      },
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
        "version": "8.0.0",
        "code": "ETH",
        "display": "substance abuse information sensitivity"
      },
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
        "version": "8.0.0",
        "code": "NOAUTH",
        "display": "no disclosure without subject authorization"
      },
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
        "version": "8.0.0",
        "code": "NORDSCLCD",
        "display": "no redisclosure without consent directive"
      },
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
        "version": "8.0.0",
        "code": "PSY",
        "display": "psychiatry disorder information sensitivity"
      },
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
        "version": "8.0.0",
        "code": "STD",
        "display": "sexually transmitted disease information sensitivity"
      },
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
        "version": "2.1.0",
        "code": "ETREAT",
        "display": "Emergency Treatment"
      },
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
        "version": "2.1.0",
        "code": "HPAYMT",
        "display": "healthcare payment"
      },
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
        "version": "2.1.0",
        "code": "TREAT",
        "display": "treatment"
      },
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
        "version": "2.2.0",
        "code": "N",
        "display": "normal"
      },
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
        "version": "2.2.0",
        "code": "R",
        "display": "restricted"
      }
    ]
  }
}