Единая платформа цифрового здравоохранения Узбекистана
0.10.0 - draft Uzbekistan флаг

This page is part of the Uzbekistan Digital Health Platform (v0.10.0: Releases Draft) based on FHIR (HL7® FHIR® Standard) v5.0.0. This is the current published version. For a full list of available versions, see the Directory of published versions

Профиль ресурса: UZ Core AuditEvent ( Экспериментальный )

Официальный URL: https://dhp.uz/fhir/core/StructureDefinition/uz-core-auditevent Версия: 0.10.0
Active по состоянию на 2025-03-29 Вычисляемое имя: UZCoreAuditEvent

Uzbekistan Core AuditEvent profile, used to track user and application activity

UZ Core AuditEvent представляет собой неизменяемый журнал аудита, фиксирующий, кто и к каким данным обращался или что изменял на Цифровой платформе здравоохранения (DHP, Digital Health Platform). Профиль следует модели аудита IHE ATNA / DICOM: платформа регистрирует чтение, создание, обновление, удаление и поиск данных, входы в систему и события экстренного доступа break-glass, сохраняет запрос, на основании которого выполнялся поиск, и отмечает неуспешный или запрещённый доступ (HTTP 401 / 403). Ресурсы AuditEvent создаются платформой и доступны клиентам только для чтения; они содержат reference на Patient, данные которого были затронуты.

Обязательные элементы данных и элементы Must Support

Приведённые ниже элементы должны либо всегда присутствовать (mandatory), либо поддерживаться при наличии данных (Must Support). Не все из них являются обязательными, однако система должна заполнять каждый элемент Must Support, если соответствующие данные имеются, и обрабатывать его при получении. Это человекочитаемое резюме; точные кардинальности, типы и терминологические привязки приведены ниже в формальных представлениях.

Что должен содержать каждый UZ Core AuditEvent (Must Have)

Этот профиль не добавляет собственных обязательных кардинальностей верхнего уровня. Обязательные элементы унаследованы от базового ресурса: code (что произошло), временная метка recorded, как минимум один agent с элементом who, а также source с элементом observer. Если используется slice категории dhpCategory, элементы system (DICOM dcm) и code в нём имеют кардинальность 1..1.

Что должен поддерживать каждый UZ Core AuditEvent (Must Support)

  • категорию - группу события с кодировкой slice dhpCategory из DICOM (обязательная привязка для её code);
  • code - конкретный подтип события (обязательная привязка);
  • action - создание, чтение, обновление, удаление или выполнение операции (обязательная привязка);
  • occurredDateTime и временную метку recorded;
  • outcome, для code которого используется обязательная привязка исхода (успешное выполнение либо ошибка при отказе в доступе с HTTP 401 / 403);
  • patient, данные которого были затронуты;
  • agent с элементами type, role, who и authorization (цель использования данных, обязательная привязка); who может указывать на PractitionerRole, Practitioner, Patient или RelatedPerson;
  • entity с элементами role, what, securityLabel и query (поисковый запрос в кодировке base64, если применимо).

Экстренный доступ break-glass регистрируется как AuditEvent, в котором agent.authorization содержит экстренную цель использования данных.

Пошаговое формирование JSON

Ресурсы AuditEvent создаются платформой, а не клиентами, поэтому в основном их требуется читать; однако важно понимать их структуру. В примерах ниже показаны автономное событие и событие, затронувшее данные пациента. Все приведённые значения проходят валидацию по этому профилю. Полные эталонные экземпляры доступны по ссылкам в нижней части страницы (вход в систему, поиск Condition).

Типовой пример события (вход в систему)

Автономное событие указывает, что произошло (code), его группу (category), действие (action, E = execute), время выполнения (occurredDateTime) и регистрации (recorded), outcome.code, выполнившего действие agent и зарегистрировавший его source. agent.who - обычный Reference, который может указывать на PractitionerRole, Practitioner, Patient или RelatedPerson:

{
  "resourceType": "AuditEvent",
  "meta": { "profile": [ "https://dhp.uz/fhir/core/StructureDefinition/uz-core-auditevent" ] },
  "category": [
    {
      "coding": [
        {
          "system": "http://dicom.nema.org/resources/ontology/DCM",
          "code": "110114",
          "display": "User Authentication"
        }
      ]
    }
  ],
  "code": {
    "coding": [
      {
        "system": "http://dicom.nema.org/resources/ontology/DCM",
        "code": "110122",
        "display": "Login"
      }
    ]
  },
  "action": "E",
  "occurredDateTime": "2023-11-09T15:23:47.123Z",
  "recorded": "2023-11-09T15:23:47.123Z",
  "outcome": { "code": { "system": "http://hl7.org/fhir/issue-severity", "code": "success" } },
  "agent": [
    {
      "type": {
        "coding": [
          {
            "system": "http://terminology.hl7.org/CodeSystem/extra-security-role-type",
            "code": "humanuser"
          }
        ]
      },
      "role": [
        {
          "coding": [
            {
              "system": "http://hl7.org/fhir/sample-security-structural-roles",
              "code": "regulated-health-professionals"
            }
          ]
        }
      ],
      "authorization": [
        {
          "coding": [
            { "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason", "code": "TREAT" }
          ]
        }
      ],
      "who": { "reference": "PractitionerRole/example-practitionerrole" }
    }
  ],
  "source": {
    "observer": { "display": "Uzbekistan Digital Health Platform" },
    "type": [
      {
        "coding": [
          {
            "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
            "code": "4",
            "display": "Application Server"
          }
        ]
      }
    ]
  }
}

category, code, action, outcome.code и кодировки agent (type, role, authorization) используют обязательные привязки: значение должно быть выбрано из соответствующего ValueSet (каждая привязка перечислена ниже в представлении Snapshot). agent.authorization указывает цель использования данных (здесь TREAT); для экстренного доступа break-glass вместо этого указывается экстренная цель использования.

Событие, затронувшее данные пациента

Если событие связано с чтением или изменением записи конкретного пациента, добавьте соответствующий patient и entity, описывающий затронутый ресурс. В данном примере Practitioner выполнял поиск Condition: action имеет значение R (read), code соответствует взаимодействию FHIR search, а entity.what содержит reference на возвращённый ресурс. patient и entity.what имеют тип обычного Reference:

{
  "resourceType": "AuditEvent",
  "meta": { "profile": [ "https://dhp.uz/fhir/core/StructureDefinition/uz-core-auditevent" ] },
  "category": [
    {
      "coding": [
        {
          "system": "http://dicom.nema.org/resources/ontology/DCM",
          "code": "110112",
          "display": "Query"
        }
      ]
    }
  ],
  "code": {
    "coding": [ { "system": "http://hl7.org/fhir/restful-interaction", "code": "search" } ]
  },
  "action": "R",
  "occurredDateTime": "2025-02-15T14:02:52Z",
  "recorded": "2025-02-15T14:02:52Z",
  "outcome": { "code": { "system": "http://hl7.org/fhir/issue-severity", "code": "success" } },
  "patient": { "reference": "Patient/example-patient" },
  "agent": [
    {
      "type": {
        "coding": [
          {
            "system": "http://terminology.hl7.org/CodeSystem/extra-security-role-type",
            "code": "humanuser"
          }
        ]
      },
      "role": [
        {
          "coding": [
            {
              "system": "http://hl7.org/fhir/sample-security-structural-roles",
              "code": "regulated-health-professionals"
            }
          ]
        }
      ],
      "authorization": [
        {
          "coding": [
            { "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason", "code": "TREAT" }
          ]
        }
      ],
      "who": { "reference": "PractitionerRole/example-practitionerrole" }
    }
  ],
  "entity": [
    {
      "role": {
        "coding": [
          {
            "system": "http://terminology.hl7.org/CodeSystem/object-role",
            "code": "4",
            "display": "Domain Resource"
          }
        ]
      },
      "securityLabel": [
        {
          "coding": [
            { "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode", "code": "NOAUTH" }
          ]
        }
      ],
      "what": { "reference": "Condition/example-headache" }
    }
  ],
  "source": {
    "observer": { "display": "Uzbekistan Digital Health Platform" },
    "type": [
      {
        "coding": [
          {
            "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
            "code": "4",
            "display": "Application Server"
          }
        ]
      }
    ]
  }
}

При поиске платформа также сохраняет сам запрос в entity.query в кодировке base64. Неуспешный или запрещённый доступ (HTTP 401 / 403) регистрируется аналогично, но с кодом ошибки в outcome.code.

​Примеры вызовов API и образец полезной нагрузки приведены в разделе Быстрый старт в нижней части этой страницы.

Использование:

You can also check for usages in the FHIR IG Statistics

Формальные представления содержимого профиля

Описание профилей, дифференциалов, снимков и их представлений.

НаименованиеФлагиКарта.ТипОписание и ограничения    Filter: Filtersdoco
.. AuditEvent 0..* AuditEvent(5.0.0) Record of an event
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... contained 0..* Resource Contained, inline Resources
... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored
Constraints: ext-1
.... Разрезы для coding Σ 0..* Coding Code defined by a terminology system
Разрез: Не упорядочено, Открыто от value:system
..... coding:dhpCategory SΣ 0..1 Coding Code defined by a terminology system
...... system SΣ 1..1 uri Identity of the terminology system
Требуемый шаблон: http://dicom.nema.org/resources/ontology/DCM
...... code SΣC 1..1 code Symbol in syntax defined by the system
Привязка: AuditEventTypeVS (0.10.0) (required)
... code SΣ 1..1 CodeableConcept Specific type of event
Привязка: AuditEventSubTypeVS (0.10.0) (required)
... action SΣ 0..1 code Type of action performed during the event
Привязка: AuditEventActionVS (0.10.0) (required)
... Разрезы для occurred[x] 0..1 When the activity occurred
Разрез: Не упорядочено, Открыто от type:$this
.... occurredPeriod Period
.... occurredDateTime dateTime
.... occurred[x]:occurredDateTime S 0..1 dateTime When the activity occurred
... recorded SΣ 1..1 instant Time when the event was recorded
... outcome SΣ 0..1 BackboneElement Whether the event succeeded or failed
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... code Σ 1..1 Coding Whether the event succeeded or failed
Привязка: AuditEventOutcomeVS (0.10.0) (required)
... patient S 0..1 Reference(Patient) The patient is the subject of the data used/created/updated/deleted during the activity
... agent SΣ 1..* BackboneElement Actor involved in the event
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... type S 0..1 CodeableConcept How agent participated
Привязка: AuditParticipationRoleTypeVS (0.10.0) (required)
.... role S 0..* CodeableConcept Agent role in the event
Привязка: SecurityRoleTypeVS (0.10.0) (required)
.... who SΣ 1..1 Reference(UZ Core PractitionerRole(0.10.0) | UZ Core Practitioner(0.10.0) | UZ Core Patient(0.10.0) | UZ Core RelatedPerson(0.10.0)) Identifier of who
.... authorization S 0..* CodeableConcept Allowable authorization for this agent
Привязка: AuditPurposeOfUseVS (0.10.0) (required)
... source Σ 1..1 BackboneElement Audit Event Reporter
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... observer Σ 1..1 Reference(Practitioner | PractitionerRole | Organization | CareTeam | Patient | Device | RelatedPerson) The identity of source detecting the event
... entity SΣ 0..* BackboneElement Data or objects used
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... what SΣ 0..1 Reference(Resource) Specific instance of resource
.... role S 0..1 CodeableConcept What role the entity played
Привязка: ObjectRoleVS (0.10.0) (required)
.... securityLabel S 0..* CodeableConcept Security labels on the entity
Привязка: SecurityLabelVS (0.10.0) (required)
.... query SΣ 0..1 base64Binary Query parameters
.... detail S 0..* BackboneElement Additional Information about the entity
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
..... type 1..1 CodeableConcept Name of the property
Привязка: AuditEventDetailTypeVS (0.10.0) (example)
..... value[x] 1..1 Property value
...... valueQuantity Quantity
...... valueCodeableConcept CodeableConcept
...... valueString string
...... valueBoolean boolean
...... valueInteger integer
...... valueRange Range
...... valueRatio Ratio
...... valueTime time
...... valueDateTime dateTime
...... valuePeriod Period
...... valueBase64Binary base64Binary

doco Документация для этого формата

Привязки к терминологии

Путь Статус Использование ValueSet Версия Источник
AuditEvent.category Base example Audit Event ID 📍5.0.0 Стандарт FHIR
AuditEvent.category.​coding:dhpCategory.code Base required Audit event type 📍0.10.0 этот IG
AuditEvent.code Base required Audit event subtype 📍0.10.0 этот IG
AuditEvent.action Base required Audit event action 📍0.10.0 этот IG
AuditEvent.outcome.code Base required Audit event outcome 📍0.10.0 этот IG
AuditEvent.agent.type Base required Audit event role type 📍0.10.0 этот IG
AuditEvent.agent.role Base required Security role type 📍0.10.0 этот IG
AuditEvent.agent.authorization Base required Purpose of use 📍0.10.0 этот IG
AuditEvent.entity.role Base required Object role 📍0.10.0 этот IG
AuditEvent.entity.securityLabel Base required Security label 📍0.10.0 этот IG
AuditEvent.entity.detail.​type Base example Types of Audit Event Details 📍0.10.0 этот IG

Ограничения

Id Градация Путь(и) Описание Выражение

НаименованиеФлагиКарта.ТипОписание и ограничения    Filter: Filtersdoco
.. AuditEvent 0..* AuditEvent(5.0.0) Record of an event
... category S 0..* CodeableConcept Type/identifier of event
.... Разрезы для coding 0..* Coding Code defined by a terminology system
Разрез: Не упорядочено, Открыто от value:system
..... coding:dhpCategory S 0..1 Coding Code defined by a terminology system
...... system S 1..1 uri Identity of the terminology system
Требуемый шаблон: http://dicom.nema.org/resources/ontology/DCM
...... code S 1..1 code Symbol in syntax defined by the system
Привязка: AuditEventTypeVS (0.10.0) (required)
... code S 1..1 CodeableConcept Specific type of event
Привязка: AuditEventSubTypeVS (0.10.0) (required)
... action S 0..1 code Type of action performed during the event
Привязка: AuditEventActionVS (0.10.0) (required)
.... occurred[x]:occurredDateTime S 0..1 dateTime When the activity occurred
... recorded S 1..1 instant Time when the event was recorded
... outcome S 0..1 BackboneElement Whether the event succeeded or failed
.... code 1..1 Coding Whether the event succeeded or failed
Привязка: AuditEventOutcomeVS (0.10.0) (required)
... patient S 0..1 Reference(Patient) The patient is the subject of the data used/created/updated/deleted during the activity
... agent S 1..* BackboneElement Actor involved in the event
.... type S 0..1 CodeableConcept How agent participated
Привязка: AuditParticipationRoleTypeVS (0.10.0) (required)
.... role S 0..* CodeableConcept Agent role in the event
Привязка: SecurityRoleTypeVS (0.10.0) (required)
.... who S 1..1 Reference(UZ Core PractitionerRole(0.10.0) | UZ Core Practitioner(0.10.0) | UZ Core Patient(0.10.0) | UZ Core RelatedPerson(0.10.0)) Identifier of who
.... authorization S 0..* CodeableConcept Allowable authorization for this agent
Привязка: AuditPurposeOfUseVS (0.10.0) (required)
... entity S 0..* BackboneElement Data or objects used
.... what S 0..1 Reference(Resource) Specific instance of resource
.... role S 0..1 CodeableConcept What role the entity played
Привязка: ObjectRoleVS (0.10.0) (required)
.... securityLabel S 0..* CodeableConcept Security labels on the entity
Привязка: SecurityLabelVS (0.10.0) (required)
.... query S 0..1 base64Binary Query parameters
.... detail S 0..* BackboneElement Additional Information about the entity
..... type 1..1 CodeableConcept Name of the property
Привязка: AuditEventDetailTypeVS (0.10.0) (example)

doco Документация для этого формата

Терминологические привязки (дифференциал)

Путь Статус Использование ValueSet Версия Источник
AuditEvent.category.​coding:dhpCategory.code Base required Audit event type 📍0.10.0 этот IG
AuditEvent.code Base required Audit event subtype 📍0.10.0 этот IG
AuditEvent.action Base required Audit event action 📍0.10.0 этот IG
AuditEvent.outcome.code Base required Audit event outcome 📍0.10.0 этот IG
AuditEvent.agent.type Base required Audit event role type 📍0.10.0 этот IG
AuditEvent.agent.role Base required Security role type 📍0.10.0 этот IG
AuditEvent.agent.authorization Base required Purpose of use 📍0.10.0 этот IG
AuditEvent.entity.role Base required Object role 📍0.10.0 этот IG
AuditEvent.entity.securityLabel Base required Security label 📍0.10.0 этот IG
AuditEvent.entity.detail.​type Base example Types of Audit Event Details 📍0.10.0 этот IG
НаименованиеФлагиКарта.ТипОписание и ограничения    Filter: Filtersdoco
.. AuditEvent 0..* AuditEvent(5.0.0) Record of an event
... id Σ 0..1 id Logical id of this artifact
... meta Σ 0..1 Meta Metadata about the resource
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... text 0..1 Narrative Text summary of the resource, for human interpretation
This profile does not constrain the narrative in regard to content, language, or traceability to data elements
... contained 0..* Resource Contained, inline Resources
... extension 0..* Extension Additional content defined by implementations
Constraints: ext-1
... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored
Constraints: ext-1
... category SΣ 0..* CodeableConcept Type/identifier of event
Привязка: AuditEventID (example): Type of event.
.... id 0..1 id Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
Разрез: Не упорядочено, Открыто от value:url
Constraints: ext-1
.... Разрезы для coding Σ 0..* Coding Code defined by a terminology system
Разрез: Не упорядочено, Открыто от value:system
..... coding:dhpCategory SΣ 0..1 Coding Code defined by a terminology system
...... id 0..1 id Unique id for inter-element referencing
...... extension 0..* Extension Additional content defined by implementations
Разрез: Не упорядочено, Открыто от value:url
Constraints: ext-1
...... system SΣ 1..1 uri Identity of the terminology system
Требуемый шаблон: http://dicom.nema.org/resources/ontology/DCM
...... version Σ 0..1 string Version of the system - if relevant
...... code SΣC 1..1 code Symbol in syntax defined by the system
Привязка: AuditEventTypeVS (0.10.0) (required)
...... display ΣC 0..1 string Representation defined by the system
...... userSelected Σ 0..1 boolean If this coding was chosen directly by the user
.... text Σ 0..1 string Plain text representation of the concept
... code SΣ 1..1 CodeableConcept Specific type of event
Привязка: AuditEventSubTypeVS (0.10.0) (required)
... action SΣ 0..1 code Type of action performed during the event
Привязка: AuditEventActionVS (0.10.0) (required)
... severity Σ 0..1 code emergency | alert | critical | error | warning | notice | informational | debug
Привязка: AuditEventSeverity (required): This is in the SysLog header, PRI. http://tools.ietf.org/html/rfc5424#appendix-A.3
... Разрезы для occurred[x] 0..1 When the activity occurred
Разрез: Не упорядочено, Открыто от type:$this
.... occurredPeriod Period
.... occurredDateTime dateTime
.... occurred[x]:occurredDateTime S 0..1 dateTime When the activity occurred
... recorded SΣ 1..1 instant Time when the event was recorded
... outcome SΣ 0..1 BackboneElement Whether the event succeeded or failed
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
Constraints: ext-1
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... code Σ 1..1 Coding Whether the event succeeded or failed
Привязка: AuditEventOutcomeVS (0.10.0) (required)
.... detail Σ 0..* CodeableConcept Additional outcome detail
Привязка: AuditEventOutcomeDetail (example): A code that provides details as the exact issue.
... authorization Σ 0..* CodeableConcept Authorization related to the event
Привязка: PurposeOfUse (3.1.0) (example): The authorized purposeOfUse for the activity.
... basedOn 0..* Reference(CarePlan | DeviceRequest | ImmunizationRecommendation | MedicationRequest | NutritionOrder | ServiceRequest | Task) Workflow authorization within which this event occurred
... patient S 0..1 Reference(Patient) The patient is the subject of the data used/created/updated/deleted during the activity
... encounter 0..1 Reference(Encounter) Encounter within which this event occurred or which the event is tightly associated
... agent SΣ 1..* BackboneElement Actor involved in the event
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
Constraints: ext-1
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... type S 0..1 CodeableConcept How agent participated
Привязка: AuditParticipationRoleTypeVS (0.10.0) (required)
.... role S 0..* CodeableConcept Agent role in the event
Привязка: SecurityRoleTypeVS (0.10.0) (required)
.... who SΣ 1..1 Reference(UZ Core PractitionerRole(0.10.0) | UZ Core Practitioner(0.10.0) | UZ Core Patient(0.10.0) | UZ Core RelatedPerson(0.10.0)) Identifier of who
.... requestor Σ 0..1 boolean Whether user is initiator
.... location 0..1 Reference(Location) The agent location when the event occurred
.... policy 0..* uri Policy that authorized the agent participation in the event
.... network[x] 0..1 This agent network location for the activity
..... networkReference Reference(Endpoint)
..... networkUri uri
..... networkString string
.... authorization S 0..* CodeableConcept Allowable authorization for this agent
Привязка: AuditPurposeOfUseVS (0.10.0) (required)
... source Σ 1..1 BackboneElement Audit Event Reporter
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
Constraints: ext-1
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... site 0..1 Reference(Location) Logical source location within the enterprise
.... observer Σ 1..1 Reference(Practitioner | PractitionerRole | Organization | CareTeam | Patient | Device | RelatedPerson) The identity of source detecting the event
.... type 0..* CodeableConcept The type of source where event originated
Привязка: AuditEventSourceType (preferred): Code specifying the type of system that detected and recorded the event. Use of these codes is not required but is encouraged to maintain translation with DICOM AuditMessage schema.
... entity SΣ 0..* BackboneElement Data or objects used
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
Constraints: ext-1
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... what SΣ 0..1 Reference(Resource) Specific instance of resource
.... role S 0..1 CodeableConcept What role the entity played
Привязка: ObjectRoleVS (0.10.0) (required)
.... securityLabel S 0..* CodeableConcept Security labels on the entity
Привязка: SecurityLabelVS (0.10.0) (required)
.... query SΣ 0..1 base64Binary Query parameters
.... detail S 0..* BackboneElement Additional Information about the entity
..... id 0..1 string Unique id for inter-element referencing
..... extension 0..* Extension Additional content defined by implementations
Constraints: ext-1
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
..... type 1..1 CodeableConcept Name of the property
Привязка: AuditEventDetailTypeVS (0.10.0) (example)
..... value[x] 1..1 Property value
...... valueQuantity Quantity
...... valueCodeableConcept CodeableConcept
...... valueString string
...... valueBoolean boolean
...... valueInteger integer
...... valueRange Range
...... valueRatio Ratio
...... valueTime time
...... valueDateTime dateTime
...... valuePeriod Period
...... valueBase64Binary base64Binary
.... agent 0..* Смотреть agent (AuditEvent) Entity is attributed to this agent

doco Документация для этого формата

Привязки к терминологии

Путь Статус Использование ValueSet Версия Источник
AuditEvent.language Base required All Languages 📍5.0.0 Стандарт FHIR
AuditEvent.category Base example Audit Event ID 📍5.0.0 Стандарт FHIR
AuditEvent.category.​coding:dhpCategory.code Base required Audit event type 📍0.10.0 этот IG
AuditEvent.code Base required Audit event subtype 📍0.10.0 этот IG
AuditEvent.action Base required Audit event action 📍0.10.0 этот IG
AuditEvent.severity Base required Audit Event Severity 📍5.0.0 Стандарт FHIR
AuditEvent.outcome.code Base required Audit event outcome 📍0.10.0 этот IG
AuditEvent.outcome.detail Base example Audit Event Outcome Detail 📍5.0.0 Стандарт FHIR
AuditEvent.authorization Base example PurposeOfUse 📍3.1.0 THO v7.3
AuditEvent.agent.type Base required Audit event role type 📍0.10.0 этот IG
AuditEvent.agent.role Base required Security role type 📍0.10.0 этот IG
AuditEvent.agent.authorization Base required Purpose of use 📍0.10.0 этот IG
AuditEvent.source.type Base preferred Audit Event Source Type 📍5.0.0 Стандарт FHIR
AuditEvent.entity.role Base required Object role 📍0.10.0 этот IG
AuditEvent.entity.securityLabel Base required Security label 📍0.10.0 этот IG
AuditEvent.entity.detail.​type Base example Types of Audit Event Details 📍0.10.0 этот IG

Ограничения

Id Градация Путь(и) Описание Выражение

Summary

Обязательный: 0 элемент(2 вложенные обязательны элементs)
Обязательная поддержка: 21 элементs

Структуры

Эта структура относится к этим другим структурам:

Разрезы

Эта структура определяет следующие Разрезы:

  • Элемент 1 разрешен в зависимости от значения AuditEvent.category.coding
  • Элемент 1 разрешен в зависимости от значения AuditEvent.occurred[x]

Просмотр ключевых элементов

НаименованиеФлагиКарта.ТипОписание и ограничения    Filter: Filtersdoco
.. AuditEvent 0..* AuditEvent(5.0.0) Record of an event
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... contained 0..* Resource Contained, inline Resources
... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored
Constraints: ext-1
.... Разрезы для coding Σ 0..* Coding Code defined by a terminology system
Разрез: Не упорядочено, Открыто от value:system
..... coding:dhpCategory SΣ 0..1 Coding Code defined by a terminology system
...... system SΣ 1..1 uri Identity of the terminology system
Требуемый шаблон: http://dicom.nema.org/resources/ontology/DCM
...... code SΣC 1..1 code Symbol in syntax defined by the system
Привязка: AuditEventTypeVS (0.10.0) (required)
... code SΣ 1..1 CodeableConcept Specific type of event
Привязка: AuditEventSubTypeVS (0.10.0) (required)
... action SΣ 0..1 code Type of action performed during the event
Привязка: AuditEventActionVS (0.10.0) (required)
... Разрезы для occurred[x] 0..1 When the activity occurred
Разрез: Не упорядочено, Открыто от type:$this
.... occurredPeriod Period
.... occurredDateTime dateTime
.... occurred[x]:occurredDateTime S 0..1 dateTime When the activity occurred
... recorded SΣ 1..1 instant Time when the event was recorded
... outcome SΣ 0..1 BackboneElement Whether the event succeeded or failed
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... code Σ 1..1 Coding Whether the event succeeded or failed
Привязка: AuditEventOutcomeVS (0.10.0) (required)
... patient S 0..1 Reference(Patient) The patient is the subject of the data used/created/updated/deleted during the activity
... agent SΣ 1..* BackboneElement Actor involved in the event
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... type S 0..1 CodeableConcept How agent participated
Привязка: AuditParticipationRoleTypeVS (0.10.0) (required)
.... role S 0..* CodeableConcept Agent role in the event
Привязка: SecurityRoleTypeVS (0.10.0) (required)
.... who SΣ 1..1 Reference(UZ Core PractitionerRole(0.10.0) | UZ Core Practitioner(0.10.0) | UZ Core Patient(0.10.0) | UZ Core RelatedPerson(0.10.0)) Identifier of who
.... authorization S 0..* CodeableConcept Allowable authorization for this agent
Привязка: AuditPurposeOfUseVS (0.10.0) (required)
... source Σ 1..1 BackboneElement Audit Event Reporter
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... observer Σ 1..1 Reference(Practitioner | PractitionerRole | Organization | CareTeam | Patient | Device | RelatedPerson) The identity of source detecting the event
... entity SΣ 0..* BackboneElement Data or objects used
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... what SΣ 0..1 Reference(Resource) Specific instance of resource
.... role S 0..1 CodeableConcept What role the entity played
Привязка: ObjectRoleVS (0.10.0) (required)
.... securityLabel S 0..* CodeableConcept Security labels on the entity
Привязка: SecurityLabelVS (0.10.0) (required)
.... query SΣ 0..1 base64Binary Query parameters
.... detail S 0..* BackboneElement Additional Information about the entity
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
..... type 1..1 CodeableConcept Name of the property
Привязка: AuditEventDetailTypeVS (0.10.0) (example)
..... value[x] 1..1 Property value
...... valueQuantity Quantity
...... valueCodeableConcept CodeableConcept
...... valueString string
...... valueBoolean boolean
...... valueInteger integer
...... valueRange Range
...... valueRatio Ratio
...... valueTime time
...... valueDateTime dateTime
...... valuePeriod Period
...... valueBase64Binary base64Binary

doco Документация для этого формата

Привязки к терминологии

Путь Статус Использование ValueSet Версия Источник
AuditEvent.category Base example Audit Event ID 📍5.0.0 Стандарт FHIR
AuditEvent.category.​coding:dhpCategory.code Base required Audit event type 📍0.10.0 этот IG
AuditEvent.code Base required Audit event subtype 📍0.10.0 этот IG
AuditEvent.action Base required Audit event action 📍0.10.0 этот IG
AuditEvent.outcome.code Base required Audit event outcome 📍0.10.0 этот IG
AuditEvent.agent.type Base required Audit event role type 📍0.10.0 этот IG
AuditEvent.agent.role Base required Security role type 📍0.10.0 этот IG
AuditEvent.agent.authorization Base required Purpose of use 📍0.10.0 этот IG
AuditEvent.entity.role Base required Object role 📍0.10.0 этот IG
AuditEvent.entity.securityLabel Base required Security label 📍0.10.0 этот IG
AuditEvent.entity.detail.​type Base example Types of Audit Event Details 📍0.10.0 этот IG

Ограничения

Id Градация Путь(и) Описание Выражение

Дифференциальный вид

НаименованиеФлагиКарта.ТипОписание и ограничения    Filter: Filtersdoco
.. AuditEvent 0..* AuditEvent(5.0.0) Record of an event
... category S 0..* CodeableConcept Type/identifier of event
.... Разрезы для coding 0..* Coding Code defined by a terminology system
Разрез: Не упорядочено, Открыто от value:system
..... coding:dhpCategory S 0..1 Coding Code defined by a terminology system
...... system S 1..1 uri Identity of the terminology system
Требуемый шаблон: http://dicom.nema.org/resources/ontology/DCM
...... code S 1..1 code Symbol in syntax defined by the system
Привязка: AuditEventTypeVS (0.10.0) (required)
... code S 1..1 CodeableConcept Specific type of event
Привязка: AuditEventSubTypeVS (0.10.0) (required)
... action S 0..1 code Type of action performed during the event
Привязка: AuditEventActionVS (0.10.0) (required)
.... occurred[x]:occurredDateTime S 0..1 dateTime When the activity occurred
... recorded S 1..1 instant Time when the event was recorded
... outcome S 0..1 BackboneElement Whether the event succeeded or failed
.... code 1..1 Coding Whether the event succeeded or failed
Привязка: AuditEventOutcomeVS (0.10.0) (required)
... patient S 0..1 Reference(Patient) The patient is the subject of the data used/created/updated/deleted during the activity
... agent S 1..* BackboneElement Actor involved in the event
.... type S 0..1 CodeableConcept How agent participated
Привязка: AuditParticipationRoleTypeVS (0.10.0) (required)
.... role S 0..* CodeableConcept Agent role in the event
Привязка: SecurityRoleTypeVS (0.10.0) (required)
.... who S 1..1 Reference(UZ Core PractitionerRole(0.10.0) | UZ Core Practitioner(0.10.0) | UZ Core Patient(0.10.0) | UZ Core RelatedPerson(0.10.0)) Identifier of who
.... authorization S 0..* CodeableConcept Allowable authorization for this agent
Привязка: AuditPurposeOfUseVS (0.10.0) (required)
... entity S 0..* BackboneElement Data or objects used
.... what S 0..1 Reference(Resource) Specific instance of resource
.... role S 0..1 CodeableConcept What role the entity played
Привязка: ObjectRoleVS (0.10.0) (required)
.... securityLabel S 0..* CodeableConcept Security labels on the entity
Привязка: SecurityLabelVS (0.10.0) (required)
.... query S 0..1 base64Binary Query parameters
.... detail S 0..* BackboneElement Additional Information about the entity
..... type 1..1 CodeableConcept Name of the property
Привязка: AuditEventDetailTypeVS (0.10.0) (example)

doco Документация для этого формата

Терминологические привязки (дифференциал)

Путь Статус Использование ValueSet Версия Источник
AuditEvent.category.​coding:dhpCategory.code Base required Audit event type 📍0.10.0 этот IG
AuditEvent.code Base required Audit event subtype 📍0.10.0 этот IG
AuditEvent.action Base required Audit event action 📍0.10.0 этот IG
AuditEvent.outcome.code Base required Audit event outcome 📍0.10.0 этот IG
AuditEvent.agent.type Base required Audit event role type 📍0.10.0 этот IG
AuditEvent.agent.role Base required Security role type 📍0.10.0 этот IG
AuditEvent.agent.authorization Base required Purpose of use 📍0.10.0 этот IG
AuditEvent.entity.role Base required Object role 📍0.10.0 этот IG
AuditEvent.entity.securityLabel Base required Security label 📍0.10.0 этот IG
AuditEvent.entity.detail.​type Base example Types of Audit Event Details 📍0.10.0 этот IG

Обзор моментальных снимковView

НаименованиеФлагиКарта.ТипОписание и ограничения    Filter: Filtersdoco
.. AuditEvent 0..* AuditEvent(5.0.0) Record of an event
... id Σ 0..1 id Logical id of this artifact
... meta Σ 0..1 Meta Metadata about the resource
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... text 0..1 Narrative Text summary of the resource, for human interpretation
This profile does not constrain the narrative in regard to content, language, or traceability to data elements
... contained 0..* Resource Contained, inline Resources
... extension 0..* Extension Additional content defined by implementations
Constraints: ext-1
... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored
Constraints: ext-1
... category SΣ 0..* CodeableConcept Type/identifier of event
Привязка: AuditEventID (example): Type of event.
.... id 0..1 id Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
Разрез: Не упорядочено, Открыто от value:url
Constraints: ext-1
.... Разрезы для coding Σ 0..* Coding Code defined by a terminology system
Разрез: Не упорядочено, Открыто от value:system
..... coding:dhpCategory SΣ 0..1 Coding Code defined by a terminology system
...... id 0..1 id Unique id for inter-element referencing
...... extension 0..* Extension Additional content defined by implementations
Разрез: Не упорядочено, Открыто от value:url
Constraints: ext-1
...... system SΣ 1..1 uri Identity of the terminology system
Требуемый шаблон: http://dicom.nema.org/resources/ontology/DCM
...... version Σ 0..1 string Version of the system - if relevant
...... code SΣC 1..1 code Symbol in syntax defined by the system
Привязка: AuditEventTypeVS (0.10.0) (required)
...... display ΣC 0..1 string Representation defined by the system
...... userSelected Σ 0..1 boolean If this coding was chosen directly by the user
.... text Σ 0..1 string Plain text representation of the concept
... code SΣ 1..1 CodeableConcept Specific type of event
Привязка: AuditEventSubTypeVS (0.10.0) (required)
... action SΣ 0..1 code Type of action performed during the event
Привязка: AuditEventActionVS (0.10.0) (required)
... severity Σ 0..1 code emergency | alert | critical | error | warning | notice | informational | debug
Привязка: AuditEventSeverity (required): This is in the SysLog header, PRI. http://tools.ietf.org/html/rfc5424#appendix-A.3
... Разрезы для occurred[x] 0..1 When the activity occurred
Разрез: Не упорядочено, Открыто от type:$this
.... occurredPeriod Period
.... occurredDateTime dateTime
.... occurred[x]:occurredDateTime S 0..1 dateTime When the activity occurred
... recorded SΣ 1..1 instant Time when the event was recorded
... outcome SΣ 0..1 BackboneElement Whether the event succeeded or failed
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
Constraints: ext-1
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... code Σ 1..1 Coding Whether the event succeeded or failed
Привязка: AuditEventOutcomeVS (0.10.0) (required)
.... detail Σ 0..* CodeableConcept Additional outcome detail
Привязка: AuditEventOutcomeDetail (example): A code that provides details as the exact issue.
... authorization Σ 0..* CodeableConcept Authorization related to the event
Привязка: PurposeOfUse (3.1.0) (example): The authorized purposeOfUse for the activity.
... basedOn 0..* Reference(CarePlan | DeviceRequest | ImmunizationRecommendation | MedicationRequest | NutritionOrder | ServiceRequest | Task) Workflow authorization within which this event occurred
... patient S 0..1 Reference(Patient) The patient is the subject of the data used/created/updated/deleted during the activity
... encounter 0..1 Reference(Encounter) Encounter within which this event occurred or which the event is tightly associated
... agent SΣ 1..* BackboneElement Actor involved in the event
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
Constraints: ext-1
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... type S 0..1 CodeableConcept How agent participated
Привязка: AuditParticipationRoleTypeVS (0.10.0) (required)
.... role S 0..* CodeableConcept Agent role in the event
Привязка: SecurityRoleTypeVS (0.10.0) (required)
.... who SΣ 1..1 Reference(UZ Core PractitionerRole(0.10.0) | UZ Core Practitioner(0.10.0) | UZ Core Patient(0.10.0) | UZ Core RelatedPerson(0.10.0)) Identifier of who
.... requestor Σ 0..1 boolean Whether user is initiator
.... location 0..1 Reference(Location) The agent location when the event occurred
.... policy 0..* uri Policy that authorized the agent participation in the event
.... network[x] 0..1 This agent network location for the activity
..... networkReference Reference(Endpoint)
..... networkUri uri
..... networkString string
.... authorization S 0..* CodeableConcept Allowable authorization for this agent
Привязка: AuditPurposeOfUseVS (0.10.0) (required)
... source Σ 1..1 BackboneElement Audit Event Reporter
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
Constraints: ext-1
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... site 0..1 Reference(Location) Logical source location within the enterprise
.... observer Σ 1..1 Reference(Practitioner | PractitionerRole | Organization | CareTeam | Patient | Device | RelatedPerson) The identity of source detecting the event
.... type 0..* CodeableConcept The type of source where event originated
Привязка: AuditEventSourceType (preferred): Code specifying the type of system that detected and recorded the event. Use of these codes is not required but is encouraged to maintain translation with DICOM AuditMessage schema.
... entity SΣ 0..* BackboneElement Data or objects used
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
Constraints: ext-1
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
.... what SΣ 0..1 Reference(Resource) Specific instance of resource
.... role S 0..1 CodeableConcept What role the entity played
Привязка: ObjectRoleVS (0.10.0) (required)
.... securityLabel S 0..* CodeableConcept Security labels on the entity
Привязка: SecurityLabelVS (0.10.0) (required)
.... query SΣ 0..1 base64Binary Query parameters
.... detail S 0..* BackboneElement Additional Information about the entity
..... id 0..1 string Unique id for inter-element referencing
..... extension 0..* Extension Additional content defined by implementations
Constraints: ext-1
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
Constraints: ext-1
..... type 1..1 CodeableConcept Name of the property
Привязка: AuditEventDetailTypeVS (0.10.0) (example)
..... value[x] 1..1 Property value
...... valueQuantity Quantity
...... valueCodeableConcept CodeableConcept
...... valueString string
...... valueBoolean boolean
...... valueInteger integer
...... valueRange Range
...... valueRatio Ratio
...... valueTime time
...... valueDateTime dateTime
...... valuePeriod Period
...... valueBase64Binary base64Binary
.... agent 0..* Смотреть agent (AuditEvent) Entity is attributed to this agent

doco Документация для этого формата

Привязки к терминологии

Путь Статус Использование ValueSet Версия Источник
AuditEvent.language Base required All Languages 📍5.0.0 Стандарт FHIR
AuditEvent.category Base example Audit Event ID 📍5.0.0 Стандарт FHIR
AuditEvent.category.​coding:dhpCategory.code Base required Audit event type 📍0.10.0 этот IG
AuditEvent.code Base required Audit event subtype 📍0.10.0 этот IG
AuditEvent.action Base required Audit event action 📍0.10.0 этот IG
AuditEvent.severity Base required Audit Event Severity 📍5.0.0 Стандарт FHIR
AuditEvent.outcome.code Base required Audit event outcome 📍0.10.0 этот IG
AuditEvent.outcome.detail Base example Audit Event Outcome Detail 📍5.0.0 Стандарт FHIR
AuditEvent.authorization Base example PurposeOfUse 📍3.1.0 THO v7.3
AuditEvent.agent.type Base required Audit event role type 📍0.10.0 этот IG
AuditEvent.agent.role Base required Security role type 📍0.10.0 этот IG
AuditEvent.agent.authorization Base required Purpose of use 📍0.10.0 этот IG
AuditEvent.source.type Base preferred Audit Event Source Type 📍5.0.0 Стандарт FHIR
AuditEvent.entity.role Base required Object role 📍0.10.0 этот IG
AuditEvent.entity.securityLabel Base required Security label 📍0.10.0 этот IG
AuditEvent.entity.detail.​type Base example Types of Audit Event Details 📍0.10.0 этот IG

Ограничения

Id Градация Путь(и) Описание Выражение

Summary

Обязательный: 0 элемент(2 вложенные обязательны элементs)
Обязательная поддержка: 21 элементs

Структуры

Эта структура относится к этим другим структурам:

Разрезы

Эта структура определяет следующие Разрезы:

  • Элемент 1 разрешен в зависимости от значения AuditEvent.category.coding
  • Элемент 1 разрешен в зависимости от значения AuditEvent.occurred[x]

 

Другие представления профиля: CSV, Excel, Schematron

Быстрый старт

Типовые операции API для этого профиля. Для запросов требуется токен доступа JWT - см. раздел Безопасность и аутентификация. [base] - базовый URL FHIR-сервера; символ | отделяет систему кодирования от значения и должен быть URL-кодирован как %7C.

Ресурсы AuditEvent создаются платформой и доступны клиентам только для чтения - операций создания и обновления нет. Для работы с журналом аудита используйте чтение и поиск.

Получение по идентификатору сервера

GET [base]/AuditEvent/[id]

Поиск в журнале аудита

GET [base]/AuditEvent?patient=Patient/[id]
GET [base]/AuditEvent?patient=Patient/[id]&date=ge2025-01-01
GET [base]/AuditEvent?agent=PractitionerRole/[id]
GET [base]/AuditEvent?patient=Patient/[id]&action=R
GET [base]/AuditEvent?patient=Patient/[id]&category=http://dicom.nema.org/resources/ontology/DCM%7C110112
GET [base]/AuditEvent?patient=Patient/[id]&entity=Condition/[id]
GET [base]/AuditEvent?patient=Patient/[id]&outcome=http://hl7.org/fhir/issue-severity%7Cerror

В FHIR R5 группировка события ищется по параметру category, а конкретный подтип - по code (в R4 использовались type / subtype). В этом профиле outcome.code привязан к ValueSet issue-severity, поэтому запрещённый или неуспешный доступ следует искать по значению error (или fatal), а не success.

Полный перечень поддерживаемых параметров поиска приведён в CapabilityStatement.

Связанные материалы