FHIR IG analytics| Package | santeon.careplan.ig |
| Resource Type | StructureDefinition |
| Id | StructureDefinition-deidentification-ruleset.json |
| FHIR Version | R4 |
| Source | https://build.fhir.org/ig/SanteonNL/sim-on-fhir/StructureDefinition-deidentification-ruleset.html |
| URL | https://ig.santeon.nl/careplan/StructureDefinition/deidentification-ruleset |
| Version | 0.1.0 |
| Status | draft |
| Date | 2026-09-23T11:46:32+00:00 |
| Name | DeidentificationRuleset |
| Title | De-identification Ruleset |
| Realm | nl |
| Description | A fully-resolved (effective) set of de-identification rules for one export. It carries the actual rules in force, with no reference to a base ruleset plus differences. Together with the export Parameters (which declare the released elements via _elements), it fully describes how an export is de-identified. |
| Type | https://ig.santeon.nl/careplan/StructureDefinition/deidentification-ruleset |
| Kind | logical |
No resources found
| ValueSet | ||
| santeon.careplan.ig#current | deidentification-action-vs | De-identification Action Value Set |
Note: links and images are rebased to the (stated) source
Generated Narrative: StructureDefinition deidentification-ruleset
| Name | Flags | Card. | Type | Description & Constraints |
|---|---|---|---|---|
![]() | 0..* | Base | De-identification Ruleset | |
![]() ![]() | 1..1 | string | Ruleset identifier, e.g. 'santeon-default'. | |
![]() ![]() | 1..1 | string | Semantic version of this ruleset. | |
![]() ![]() | 0..1 | uri | Canonical URL, when this ruleset is a published resource. | |
![]() ![]() | C | 1..* | BackboneElement | The de-identification rules in force for this export. Constraints: none-requires-reason, hash-requires-algorithm, shift-requires-maxdays, clampage-requires-bounds |
![]() ![]() ![]() | 1..1 | string | FHIRPath expression selecting the element(s) this rule applies to. A rule covers the named element and every element beneath it. | |
![]() ![]() ![]() | 1..1 | code | The transformation to apply. Binding: De-identification Action Value Set (required) | |
![]() ![]() ![]() | 0..1 | integer | Optional explicit ordering. For date elements the canonical order is shift, then first-of-month, then clamp-age; priority is for finer control. | |
![]() ![]() ![]() | 0..1 | code | Hash algorithm (hash only), e.g. 'hmac-sha256'. | |
![]() ![]() ![]() | 0..* | string | Reference paths rewritten with the same hash (hash on an id element),
e.g. '*.subject', '*.patient'. | |
![]() ![]() ![]() | 0..1 | integer | Maximum absolute date shift in days (shift only). Offset drawn from +/- maxDays, never zero. | |
![]() ![]() ![]() | 0..1 | integer | Lower age bound in years (clamp-age only). | |
![]() ![]() ![]() | 0..1 | integer | Upper age bound in years (clamp-age only). | |
![]() ![]() ![]() | 0..1 | string | Justification. Required for action 'none'; required when 'clamp-age' overrides the standard age range. | |
{
"resourceType": "StructureDefinition",
"id": "deidentification-ruleset",
"text": {
"status": "extensions",
"div": "<!-- snip (see above) -->"
},
"url": "https://ig.santeon.nl/careplan/StructureDefinition/deidentification-ruleset",
"version": "0.1.0",
"name": "DeidentificationRuleset",
"title": "De-identification Ruleset",
"status": "draft",
"date": "2026-09-23T11:46:32+00:00",
"publisher": "Santeon",
"contact": [
{
"name": "Santeon",
"telecom": [
{
"system": "url",
"value": "https://www.santeon.nl"
}
]
}
],
"description": "A fully-resolved (effective) set of de-identification rules for one export.\nIt carries the actual rules in force, with no reference to a base ruleset\nplus differences. Together with the export Parameters (which declare the\nreleased elements via _elements), it fully describes how an export is\nde-identified.",
"jurisdiction": [
{
"coding": [
{
"system": "urn:iso:std:iso:3166",
"code": "NL",
"display": "Netherlands"
}
]
}
],
"fhirVersion": "4.0.1",
"kind": "logical",
"abstract": false,
"type": "https://ig.santeon.nl/careplan/StructureDefinition/deidentification-ruleset",
"baseDefinition": "http://hl7.org/fhir/StructureDefinition/Base",
"derivation": "specialization",
"snapshot": {
"extension": [
{
"url": "http://hl7.org/fhir/tools/StructureDefinition/snapshot-base-version",
"valueString": "4.0.1"
}
],
"element": [
{
"id": "deidentification-ruleset",
"path": "deidentification-ruleset",
"short": "De-identification Ruleset",
"definition": "A fully-resolved (effective) set of de-identification rules for one export.\nIt carries the actual rules in force, with no reference to a base ruleset\nplus differences. Together with the export Parameters (which declare the\nreleased elements via _elements), it fully describes how an export is\nde-identified.",
"min": 0,
"max": "*",
"base": {
"path": "Base",
"min": 0,
"max": "*"
},
"isModifier": false
},
{
"id": "deidentification-ruleset.id",
"path": "deidentification-ruleset.id",
"short": "Ruleset identifier, e.g. 'santeon-default'.",
"definition": "Ruleset identifier, e.g. 'santeon-default'.",
"min": 1,
"max": "1",
"base": {
"path": "deidentification-ruleset.id",
"min": 1,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "deidentification-ruleset.version",
"path": "deidentification-ruleset.version",
"short": "Semantic version of this ruleset.",
"definition": "Semantic version of this ruleset.",
"min": 1,
"max": "1",
"base": {
"path": "deidentification-ruleset.version",
"min": 1,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "deidentification-ruleset.url",
"path": "deidentification-ruleset.url",
"short": "Canonical URL, when this ruleset is a published resource.",
"definition": "Canonical URL, when this ruleset is a published resource.",
"min": 0,
"max": "1",
"base": {
"path": "deidentification-ruleset.url",
"min": 0,
"max": "1"
},
"type": [
{
"code": "uri"
}
]
},
{
"id": "deidentification-ruleset.rule",
"path": "deidentification-ruleset.rule",
"short": "The de-identification rules in force for this export.",
"definition": "The de-identification rules in force for this export.",
"min": 1,
"max": "*",
"base": {
"path": "deidentification-ruleset.rule",
"min": 1,
"max": "*"
},
"type": [
{
"code": "BackboneElement"
}
],
"constraint": [
{
"key": "none-requires-reason",
"severity": "error",
"human": "Action 'none' must carry an exceptionReason and no transform parameters.",
"expression": "action = 'none' implies (exceptionReason.exists() and algorithm.empty() and maxDays.empty() and minAge.empty() and maxAge.empty())",
"source": "https://ig.santeon.nl/careplan/StructureDefinition/deidentification-ruleset"
},
{
"key": "hash-requires-algorithm",
"severity": "error",
"human": "Action 'hash' must specify algorithm and carry no date/age parameters.",
"expression": "action = 'hash' implies (algorithm.exists() and maxDays.empty() and minAge.empty() and maxAge.empty())",
"source": "https://ig.santeon.nl/careplan/StructureDefinition/deidentification-ruleset"
},
{
"key": "shift-requires-maxdays",
"severity": "error",
"human": "Action 'shift' must specify maxDays and carry no hash/age parameters.",
"expression": "action = 'shift' implies (maxDays.exists() and algorithm.empty() and minAge.empty() and maxAge.empty())",
"source": "https://ig.santeon.nl/careplan/StructureDefinition/deidentification-ruleset"
},
{
"key": "clampage-requires-bounds",
"severity": "error",
"human": "Action 'clamp-age' must specify both minAge and maxAge.",
"expression": "action = 'clamp-age' implies (minAge.exists() and maxAge.exists() and algorithm.empty() and maxDays.empty())",
"source": "https://ig.santeon.nl/careplan/StructureDefinition/deidentification-ruleset"
},
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
}
]
},
{
"id": "deidentification-ruleset.rule.id",
"path": "deidentification-ruleset.rule.id",
"representation": [
"xmlAttr"
],
"short": "Unique id for inter-element referencing",
"definition": "Unique id for the element within a resource (for internal references). This may be any string value that does not contain spaces.",
"min": 0,
"max": "1",
"base": {
"path": "Element.id",
"min": 0,
"max": "1"
},
"type": [
{
"extension": [
{
"url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-fhir-type",
"valueUrl": "string"
}
],
"code": "http://hl7.org/fhirpath/System.String"
}
],
"isModifier": false,
"isSummary": false,
"mapping": [
{
"identity": "rim",
"map": "n/a"
}
]
},
{
"id": "deidentification-ruleset.rule.extension",
"path": "deidentification-ruleset.rule.extension",
"slicing": {
"discriminator": [
{
"type": "value",
"path": "url"
}
],
"description": "Extensions are always sliced by (at least) url",
"rules": "open"
},
"short": "Additional content defined by implementations",
"definition": "May be used to represent additional information that is not part of the basic definition of the element. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension.",
"comment": "There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.",
"alias": [
"extensions",
"user content"
],
"min": 0,
"max": "*",
"base": {
"path": "Element.extension",
"min": 0,
"max": "*"
},
"type": [
{
"code": "Extension"
}
],
"constraint": [
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
},
{
"key": "ext-1",
"severity": "error",
"human": "Must have either extensions or value[x], not both",
"expression": "extension.exists() != value.exists()",
"xpath": "exists(f:extension)!=exists(f:*[starts-with(local-name(.), \"value\")])",
"source": "http://hl7.org/fhir/StructureDefinition/Extension"
}
],
"isModifier": false,
"isSummary": false,
"mapping": [
{
"identity": "rim",
"map": "n/a"
}
]
},
{
"id": "deidentification-ruleset.rule.modifierExtension",
"path": "deidentification-ruleset.rule.modifierExtension",
"short": "Extensions that cannot be ignored even if unrecognized",
"definition": "May be used to represent additional information that is not part of the basic definition of the element and that modifies the understanding of the element in which it is contained and/or the understanding of the containing element's descendants. Usually modifier elements provide negation or qualification. To make the use of extensions safe and manageable, there is a strict set of governance applied to the definition and use of extensions. Though any implementer can define an extension, there is a set of requirements that SHALL be met as part of the definition of the extension. Applications processing a resource are required to check for modifier extensions.\n\nModifier extensions SHALL NOT change the meaning of any elements on Resource or DomainResource (including cannot change the meaning of modifierExtension itself).",
"comment": "There can be no stigma associated with the use of extensions by any application, project, or standard - regardless of the institution or jurisdiction that uses or defines the extensions. The use of extensions is what allows the FHIR specification to retain a core level of simplicity for everyone.",
"requirements": "Modifier extensions allow for extensions that *cannot* be safely ignored to be clearly distinguished from the vast majority of extensions which can be safely ignored. This promotes interoperability by eliminating the need for implementers to prohibit the presence of extensions. For further information, see the [definition of modifier extensions](http://hl7.org/fhir/R4/extensibility.html#modifierExtension).",
"alias": [
"extensions",
"user content",
"modifiers"
],
"min": 0,
"max": "*",
"base": {
"path": "BackboneElement.modifierExtension",
"min": 0,
"max": "*"
},
"type": [
{
"code": "Extension"
}
],
"constraint": [
{
"key": "ele-1",
"severity": "error",
"human": "All FHIR elements must have a @value or children",
"expression": "hasValue() or (children().count() > id.count())",
"xpath": "@value|f:*|h:div",
"source": "http://hl7.org/fhir/StructureDefinition/Element"
},
{
"key": "ext-1",
"severity": "error",
"human": "Must have either extensions or value[x], not both",
"expression": "extension.exists() != value.exists()",
"xpath": "exists(f:extension)!=exists(f:*[starts-with(local-name(.), \"value\")])",
"source": "http://hl7.org/fhir/StructureDefinition/Extension"
}
],
"isModifier": true,
"isModifierReason": "Modifier extensions are expected to modify the meaning or interpretation of the element that contains them",
"isSummary": true,
"mapping": [
{
"identity": "rim",
"map": "N/A"
}
]
},
{
"id": "deidentification-ruleset.rule.path",
"path": "deidentification-ruleset.rule.path",
"short": "FHIRPath expression selecting the element(s) this rule applies to. A rule\n covers the named element and every element beneath it.",
"definition": "FHIRPath expression selecting the element(s) this rule applies to. A rule\n covers the named element and every element beneath it.",
"min": 1,
"max": "1",
"base": {
"path": "deidentification-ruleset.rule.path",
"min": 1,
"max": "1"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "deidentification-ruleset.rule.action",
"path": "deidentification-ruleset.rule.action",
"short": "The transformation to apply.",
"definition": "The transformation to apply.",
"min": 1,
"max": "1",
"base": {
"path": "deidentification-ruleset.rule.action",
"min": 1,
"max": "1"
},
"type": [
{
"code": "code"
}
],
"binding": {
"strength": "required",
"valueSet": "https://ig.santeon.nl/careplan/ValueSet/deidentification-action-vs"
}
},
{
"id": "deidentification-ruleset.rule.priority",
"path": "deidentification-ruleset.rule.priority",
"short": "Optional explicit ordering. For date elements the canonical order is\n shift, then first-of-month, then clamp-age; priority is for finer control.",
"definition": "Optional explicit ordering. For date elements the canonical order is\n shift, then first-of-month, then clamp-age; priority is for finer control.",
"min": 0,
"max": "1",
"base": {
"path": "deidentification-ruleset.rule.priority",
"min": 0,
"max": "1"
},
"type": [
{
"code": "integer"
}
]
},
{
"id": "deidentification-ruleset.rule.algorithm",
"path": "deidentification-ruleset.rule.algorithm",
"short": "Hash algorithm (hash only), e.g. 'hmac-sha256'.",
"definition": "Hash algorithm (hash only), e.g. 'hmac-sha256'.",
"min": 0,
"max": "1",
"base": {
"path": "deidentification-ruleset.rule.algorithm",
"min": 0,
"max": "1"
},
"type": [
{
"code": "code"
}
]
},
{
"id": "deidentification-ruleset.rule.propagateTo",
"path": "deidentification-ruleset.rule.propagateTo",
"short": "Reference paths rewritten with the same hash (hash on an id element),\n e.g. '*.subject', '*.patient'.",
"definition": "Reference paths rewritten with the same hash (hash on an id element),\n e.g. '*.subject', '*.patient'.",
"min": 0,
"max": "*",
"base": {
"path": "deidentification-ruleset.rule.propagateTo",
"min": 0,
"max": "*"
},
"type": [
{
"code": "string"
}
]
},
{
"id": "deidentification-ruleset.rule.maxDays",
"path": "deidentification-ruleset.rule.maxDays",
"short": "Maximum absolute date shift in days (shift only). Offset drawn from\n +/- maxDays, never zero.",
"definition": "Maximum absolute date shift in days (shift only). Offset drawn from\n +/- maxDays, never zero.",
"min": 0,
"max": "1",
"base": {
"path": "deidentification-ruleset.rule.maxDays",
"min": 0,
"max": "1"
},
"type": [
{
"code": "integer"
}
]
},
{
"id": "deidentification-ruleset.rule.minAge",
"path": "deidentification-ruleset.rule.minAge",
"short": "Lower age bound in years (clamp-age only).",
"definition": "Lower age bound in years (clamp-age only).",
"min": 0,
"max": "1",
"base": {
"path": "deidentification-ruleset.rule.minAge",
"min": 0,
"max": "1"
},
"type": [
{
"code": "integer"
}
]
},
{
"id": "deidentification-ruleset.rule.maxAge",
"path": "deidentification-ruleset.rule.maxAge",
"short": "Upper age bound in years (clamp-age only).",
"definition": "Upper age bound in years (clamp-age only).",
"min": 0,
"max": "1",
"base": {
"path": "deidentification-ruleset.rule.maxAge",
"min": 0,
"max": "1"
},
"type": [
{
"code": "integer"
}
]
},
{
"id": "deidentification-ruleset.rule.exceptionReason",
"path": "deidentification-ruleset.rule.exceptionReason",
"short": "Justification. Required for action 'none'; required when 'clamp-age'\n overrides the standard age range.",
"definition": "Justification. Required for action 'none'; required when 'clamp-age'\n overrides the standard age range.",
"min": 0,
"max": "1",
"base": {
"path": "deidentification-ruleset.rule.exceptionReason",
"min": 0,
"max": "1"
},
"type": [
{
"code": "string"
}
]
}
]
},
"differential": {
"element": [
{
"id": "deidentification-ruleset",
"path": "deidentification-ruleset",
"short": "De-identification Ruleset",
"definition": "A fully-resolved (effective) set of de-identification rules for one export.\nIt carries the actual rules in force, with no reference to a base ruleset\nplus differences. Together with the export Parameters (which declare the\nreleased elements via _elements), it fully describes how an export is\nde-identified."
},
{
"id": "deidentification-ruleset.id",
"path": "deidentification-ruleset.id",
"short": "Ruleset identifier, e.g. 'santeon-default'.",
"definition": "Ruleset identifier, e.g. 'santeon-default'.",
"min": 1,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "deidentification-ruleset.version",
"path": "deidentification-ruleset.version",
"short": "Semantic version of this ruleset.",
"definition": "Semantic version of this ruleset.",
"min": 1,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "deidentification-ruleset.url",
"path": "deidentification-ruleset.url",
"short": "Canonical URL, when this ruleset is a published resource.",
"definition": "Canonical URL, when this ruleset is a published resource.",
"min": 0,
"max": "1",
"type": [
{
"code": "uri"
}
]
},
{
"id": "deidentification-ruleset.rule",
"path": "deidentification-ruleset.rule",
"short": "The de-identification rules in force for this export.",
"definition": "The de-identification rules in force for this export.",
"min": 1,
"max": "*",
"type": [
{
"code": "BackboneElement"
}
],
"constraint": [
{
"key": "none-requires-reason",
"severity": "error",
"human": "Action 'none' must carry an exceptionReason and no transform parameters.",
"expression": "action = 'none' implies (exceptionReason.exists() and algorithm.empty() and maxDays.empty() and minAge.empty() and maxAge.empty())",
"source": "https://ig.santeon.nl/careplan/StructureDefinition/deidentification-ruleset"
},
{
"key": "hash-requires-algorithm",
"severity": "error",
"human": "Action 'hash' must specify algorithm and carry no date/age parameters.",
"expression": "action = 'hash' implies (algorithm.exists() and maxDays.empty() and minAge.empty() and maxAge.empty())",
"source": "https://ig.santeon.nl/careplan/StructureDefinition/deidentification-ruleset"
},
{
"key": "shift-requires-maxdays",
"severity": "error",
"human": "Action 'shift' must specify maxDays and carry no hash/age parameters.",
"expression": "action = 'shift' implies (maxDays.exists() and algorithm.empty() and minAge.empty() and maxAge.empty())",
"source": "https://ig.santeon.nl/careplan/StructureDefinition/deidentification-ruleset"
},
{
"key": "clampage-requires-bounds",
"severity": "error",
"human": "Action 'clamp-age' must specify both minAge and maxAge.",
"expression": "action = 'clamp-age' implies (minAge.exists() and maxAge.exists() and algorithm.empty() and maxDays.empty())",
"source": "https://ig.santeon.nl/careplan/StructureDefinition/deidentification-ruleset"
}
]
},
{
"id": "deidentification-ruleset.rule.path",
"path": "deidentification-ruleset.rule.path",
"short": "FHIRPath expression selecting the element(s) this rule applies to. A rule\n covers the named element and every element beneath it.",
"definition": "FHIRPath expression selecting the element(s) this rule applies to. A rule\n covers the named element and every element beneath it.",
"min": 1,
"max": "1",
"type": [
{
"code": "string"
}
]
},
{
"id": "deidentification-ruleset.rule.action",
"path": "deidentification-ruleset.rule.action",
"short": "The transformation to apply.",
"definition": "The transformation to apply.",
"min": 1,
"max": "1",
"type": [
{
"code": "code"
}
],
"binding": {
"strength": "required",
"valueSet": "https://ig.santeon.nl/careplan/ValueSet/deidentification-action-vs"
}
},
{
"id": "deidentification-ruleset.rule.priority",
"path": "deidentification-ruleset.rule.priority",
"short": "Optional explicit ordering. For date elements the canonical order is\n shift, then first-of-month, then clamp-age; priority is for finer control.",
"definition": "Optional explicit ordering. For date elements the canonical order is\n shift, then first-of-month, then clamp-age; priority is for finer control.",
"min": 0,
"max": "1",
"type": [
{
"code": "integer"
}
]
},
{
"id": "deidentification-ruleset.rule.algorithm",
"path": "deidentification-ruleset.rule.algorithm",
"short": "Hash algorithm (hash only), e.g. 'hmac-sha256'.",
"definition": "Hash algorithm (hash only), e.g. 'hmac-sha256'.",
"min": 0,
"max": "1",
"type": [
{
"code": "code"
}
]
},
{
"id": "deidentification-ruleset.rule.propagateTo",
"path": "deidentification-ruleset.rule.propagateTo",
"short": "Reference paths rewritten with the same hash (hash on an id element),\n e.g. '*.subject', '*.patient'.",
"definition": "Reference paths rewritten with the same hash (hash on an id element),\n e.g. '*.subject', '*.patient'.",
"min": 0,
"max": "*",
"type": [
{
"code": "string"
}
]
},
{
"id": "deidentification-ruleset.rule.maxDays",
"path": "deidentification-ruleset.rule.maxDays",
"short": "Maximum absolute date shift in days (shift only). Offset drawn from\n +/- maxDays, never zero.",
"definition": "Maximum absolute date shift in days (shift only). Offset drawn from\n +/- maxDays, never zero.",
"min": 0,
"max": "1",
"type": [
{
"code": "integer"
}
]
},
{
"id": "deidentification-ruleset.rule.minAge",
"path": "deidentification-ruleset.rule.minAge",
"short": "Lower age bound in years (clamp-age only).",
"definition": "Lower age bound in years (clamp-age only).",
"min": 0,
"max": "1",
"type": [
{
"code": "integer"
}
]
},
{
"id": "deidentification-ruleset.rule.maxAge",
"path": "deidentification-ruleset.rule.maxAge",
"short": "Upper age bound in years (clamp-age only).",
"definition": "Upper age bound in years (clamp-age only).",
"min": 0,
"max": "1",
"type": [
{
"code": "integer"
}
]
},
{
"id": "deidentification-ruleset.rule.exceptionReason",
"path": "deidentification-ruleset.rule.exceptionReason",
"short": "Justification. Required for action 'none'; required when 'clamp-age'\n overrides the standard age range.",
"definition": "Justification. Required for action 'none'; required when 'clamp-age'\n overrides the standard age range.",
"min": 0,
"max": "1",
"type": [
{
"code": "string"
}
]
}
]
}
}