Guía de Implementación Core de Costa Rica
0.1.0 - ci-build Costa Rica bandera

Guía de Implementación Core de Costa Rica - Versión en desarrollo (v0.1.0): borrador de trabajo de la Iniciativa HL7® Costa Rica, que puede cambiar sin aviso.

Perfil de los recursos: Evento de auditoría

URL oficial: https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent Versión: 0.1.0
Standards status: Draft Nombre computable: CRAuditEvent

Registro de un acceso u operación sobre datos en el HIE de Costa Rica: quién lo hizo, desde qué sistema, con qué propósito, sobre qué datos de qué paciente y con qué resultado, incluidos los intentos fallidos. Adapta IHE BALP a FHIR R5.

Usos:

También puede consultar los usos en las estadísticas de IG de FHIR

Vistas formales del contenido del perfil

Descripción de perfiles, diferenciales, instantáneas y sus representaciones.

NombreMarcasCard.TipoDescripción y restricciones    Filter: Filtersdoco
.. AuditEvent C 0..* AuditEvent Evento de auditoría: quién accedió a qué y con qué resultado
Constraints: cr-auditoria-rest, cr-auditoria-accion, cr-auditoria-detalle, cr-auditoria-proposito, cr-auditoria-agentes, cr-auditoria-red, cr-auditoria-solicitante, cr-auditoria-paciente, cr-auditoria-entidades, cr-auditoria-fechas
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... contained 0..* Resource Contained, inline Resources
... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored
... code SΣ 1..1 CodeableConcept Qué se hizo: la interacción REST (read, search, create...) o el evento de DICOM
Vinculación: AuditEventSubType (example): Specific type of event.
... action SΣ 1..1 code C | R | U | D | E, coherente con el código
Vinculación: AuditEventAction (required): DICOM Audit Event Action
... occurred[x] SC 0..1 dateTime Cuándo ocurrió el evento (no posterior al registro)
Constraints: cr-documento-fecha-hora
... recorded SΣ 1..1 instant Cuándo se registró el evento
... outcome SΣ 1..1 BackboneElement Resultado del evento, también en los fallos
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... code SΣ 1..1 Coding success | warning | error | fatal
Vinculación: AuditEventOutcome (required)
.... detail SΣ 0..* CodeableConcept Detalle (código HTTP y texto), sin datos clínicos
Vinculación: AuditEventOutcomeDetail (example): A code that provides details as the exact issue.
... authorization SΣ 0..1 CodeableConcept Propósito de uso: TREAT | ETREAT | COC | PATRQT | PUBHLTH | HRESCH | HOPERAT | HSYSADMIN | HLEGAL
Vinculación: Propósito de uso (required)
... patient S 0..1 Reference(Paciente) Paciente de los datos (un evento por paciente)
... agent SΣ 2..* BackboneElement El cliente, el servidor y, si la hace una persona, el usuario
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... type S 1..1 CodeableConcept 110152 (destino) | 110153 (origen) | IRCP (usuario)
Vinculación: Tipo de agente de auditoría (required)
.... who SΣ 1..1 Reference(Sistema de información | Rol del profesional | Profesional de salud | Paciente) El sistema registrado en el HIE, o la persona usuaria
.... requestor SΣ 0..1 boolean true para el usuario o, si no hay usuario, para el cliente
.... policy S 0..1 uri Identificador del token (jti) del usuario
.... network[x] S 0..1 Red: la IP o el subsistema X-Road del cliente, la URL del servidor
..... networkReference Reference(Endpoint)
..... networkUri uri
..... networkString string
... source SΣ 1..1 BackboneElement Quién registró el evento
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... observer Σ 1..1 Reference(Sistema de información) El sistema que registró el evento
.... type S 1..1 CodeableConcept Tipo de la fuente (4: servidor de aplicaciones)
Vinculación: AuditEventSourceType (required)
... entity SΣ 0..* BackboneElement El paciente, los datos, la consulta y la transacción
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... what SΣ 0..1 Reference(Resource) El recurso (la versión concreta si se conoce) o el identificador de la transacción
.... role S 0..1 CodeableConcept 1 (paciente) | 4 (datos) | 24 (consulta); sin role, la transacción
Vinculación: AuditEventEntityRole (required)
.... securityLabel S 0..* CodeableConcept Las etiquetas de seguridad del recurso
Vinculación: SecurityLabelExamples (example): Example Security Labels from the Healthcare Privacy and Security Classification System.
.... query SΣ 0..1 base64Binary La consulta, en base64 (solo en la entidad consulta)

doco Documentación de este formato

Vinculaciones terminológicas

Ruta Estado Uso ValueSet Versión Fuente
AuditEvent.category Base required Categoría del evento de auditoría 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.code Base example Audit Event Sub-Type 📍5.0.0 Estándar FHIR
AuditEvent.action Base required Audit Event Action 📍5.0.0 Estándar FHIR
AuditEvent.outcome.code Base required Audit Event Outcome 📦5.0.0 Estándar FHIR
AuditEvent.outcome.detail Base example Audit Event Outcome Detail 📍5.0.0 Estándar FHIR
AuditEvent.authorization Base required Propósito de uso 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.agent.type Base required Tipo de agente de auditoría 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.source.type Base required Audit Event Source Type 📦5.0.0 Estándar FHIR
AuditEvent.entity.role Base required Audit Event Entity Role 📦5.0.0 Estándar FHIR
AuditEvent.entity.securityLabel Base example Example set of Security Labels 📍5.0.0 Estándar FHIR

Restricciones

Id Nivel Ruta(s) Descripción Expression
cr-auditoria-accion error AuditEvent La acción es coherente con la interacción: las lecturas, búsquedas e historias son R; create es C; update y patch son U; delete es D; las demás son E. code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').all(iif(code in ('read' | 'vread' | 'search' | 'search-type' | 'search-system' | 'history' | 'history-instance' | 'history-type' | 'history-system'), %resource.action = 'R', iif(code = 'create', %resource.action = 'C', iif(code in ('update' | 'patch'), %resource.action = 'U', iif(code = 'delete', %resource.action = 'D', %resource.action = 'E')))))
cr-auditoria-agentes error AuditEvent El evento lleva un agente cliente y un agente servidor (DICOM 110152 y 110153). agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110152').exists()).exists() and agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110153').exists()).exists()
cr-auditoria-detalle error AuditEvent Un resultado que no es success lleva su detalle. outcome.code.code != 'success' implies outcome.detail.exists()
cr-auditoria-entidades error AuditEvent Cada entidad indica el recurso (what), salvo la consulta (role 24), que indica la consulta (query). entity.all(iif(role.coding.where(code = '24').exists(), query.exists(), what.exists()))
cr-auditoria-fechas error AuditEvent La fecha del evento no es posterior a la fecha de registro. occurred.ofType(dateTime).empty() or occurred.ofType(dateTime) <= recorded
cr-auditoria-paciente error AuditEvent El paciente del evento va también como entidad con role 1 (Patient), como en IHE BALP. patient.exists() implies entity.where(role.coding.where(system = 'http://terminology.hl7.org/CodeSystem/object-role' and code = '1').exists()).exists()
cr-auditoria-proposito error AuditEvent Un evento con datos de un paciente indica el propósito de uso. patient.exists() implies authorization.exists()
cr-auditoria-red error AuditEvent El cliente y el servidor indican su red (dirección IP, subsistema X-Road o URL). agent.where(type.coding.where(code = '110153' or code = '110152').exists()).all(network.exists())
cr-auditoria-rest error AuditEvent Un evento rest lleva el código de la interacción REST. category.coding.where(code = 'rest').exists() implies code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').exists()
cr-auditoria-solicitante error AuditEvent Hay un solo solicitante (requestor = true): el usuario o, si no hay usuario, el cliente. agent.where(requestor = true).count() = 1
cr-documento-fecha-hora error AuditEvent.occurred[x] La fecha lleva fecha y hora, no solo la fecha. toString().contains('T')
dom-2 error AuditEvent If the resource is contained in another resource, it SHALL NOT contain nested Resources contained.contained.empty()
dom-3 error AuditEvent If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().ofType(canonical) | %resource.descendants().ofType(uri) | %resource.descendants().ofType(url))) or descendants().where(reference = '#').exists() or descendants().where(ofType(canonical) = '#').exists() or descendants().where(ofType(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
dom-4 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
dom-5 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a security label contained.meta.security.empty()
dom-6 best practice AuditEvent A resource should have narrative for robust management text.`div`.exists()
ele-1 error **TODOS** los elementos All FHIR elements must have a @value or children hasValue() or (children().count() > id.count())
ext-1 error **TODAS** las extensiones Must have either extensions or value[x], not both extension.exists() != value.exists()

Esta estructura se deriva de AuditEvent .

NombreMarcasCard.TipoDescripción y restricciones    Filter: Filtersdoco
.. AuditEvent C 0..* AuditEvent Evento de auditoría: quién accedió a qué y con qué resultado
Constraints: cr-auditoria-rest, cr-auditoria-accion, cr-auditoria-detalle, cr-auditoria-proposito, cr-auditoria-agentes, cr-auditoria-red, cr-auditoria-solicitante, cr-auditoria-paciente, cr-auditoria-entidades, cr-auditoria-fechas
... category S 1..1 CodeableConcept Categoría: rest | 110114 (autenticación) | 110113 (alerta de seguridad)
Vinculación: Categoría del evento de auditoría (required)
... code S 1..1 CodeableConcept Qué se hizo: la interacción REST (read, search, create...) o el evento de DICOM
... action S 1..1 code C | R | U | D | E, coherente con el código
... recorded S 1..1 instant Cuándo se registró el evento
... outcome S 1..1 BackboneElement Resultado del evento, también en los fallos
.... code S 1..1 Coding success | warning | error | fatal
Vinculación: AuditEventOutcome (required)
.... detail S 0..* CodeableConcept Detalle (código HTTP y texto), sin datos clínicos
... authorization S 0..1 CodeableConcept Propósito de uso: TREAT | ETREAT | COC | PATRQT | PUBHLTH | HRESCH | HOPERAT | HSYSADMIN | HLEGAL
Vinculación: Propósito de uso (required)
... patient S 0..1 Reference(Paciente) Paciente de los datos (un evento por paciente)
... agent S 2..* BackboneElement El cliente, el servidor y, si la hace una persona, el usuario
.... type S 1..1 CodeableConcept 110152 (destino) | 110153 (origen) | IRCP (usuario)
Vinculación: Tipo de agente de auditoría (required)
.... who S 1..1 Reference(Sistema de información | Rol del profesional | Profesional de salud | Paciente) El sistema registrado en el HIE, o la persona usuaria
.... requestor S 0..1 boolean true para el usuario o, si no hay usuario, para el cliente
.... policy S 0..1 uri Identificador del token (jti) del usuario
.... network[x] S 0..1 Reference(Endpoint), uri, string Red: la IP o el subsistema X-Road del cliente, la URL del servidor
... source S 1..1 BackboneElement Quién registró el evento
.... observer 1..1 Reference(Sistema de información) El sistema que registró el evento
.... type S 1..1 CodeableConcept Tipo de la fuente (4: servidor de aplicaciones)
Vinculación: AuditEventSourceType (required)
... entity S 0..* BackboneElement El paciente, los datos, la consulta y la transacción
.... what S 0..1 Reference(Resource) El recurso (la versión concreta si se conoce) o el identificador de la transacción
.... role S 0..1 CodeableConcept 1 (paciente) | 4 (datos) | 24 (consulta); sin role, la transacción
Vinculación: AuditEventEntityRole (required)
.... securityLabel S 0..* CodeableConcept Las etiquetas de seguridad del recurso
.... query S 0..1 base64Binary La consulta, en base64 (solo en la entidad consulta)

doco Documentación de este formato

Vinculaciones terminológicas (diferencial)

Ruta Estado Uso ValueSet Versión Fuente
AuditEvent.category Base required Categoría del evento de auditoría 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.outcome.code Base required Audit Event Outcome 📦5.0.0 Estándar FHIR
AuditEvent.authorization Base required Propósito de uso 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.agent.type Base required Tipo de agente de auditoría 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.source.type Base required Audit Event Source Type 📦5.0.0 Estándar FHIR
AuditEvent.entity.role Base required Audit Event Entity Role 📦5.0.0 Estándar FHIR

Restricciones

Id Nivel Ruta(s) Descripción Expression
cr-auditoria-accion error AuditEvent La acción es coherente con la interacción: las lecturas, búsquedas e historias son R; create es C; update y patch son U; delete es D; las demás son E. code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').all(iif(code in ('read' | 'vread' | 'search' | 'search-type' | 'search-system' | 'history' | 'history-instance' | 'history-type' | 'history-system'), %resource.action = 'R', iif(code = 'create', %resource.action = 'C', iif(code in ('update' | 'patch'), %resource.action = 'U', iif(code = 'delete', %resource.action = 'D', %resource.action = 'E')))))
cr-auditoria-agentes error AuditEvent El evento lleva un agente cliente y un agente servidor (DICOM 110152 y 110153). agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110152').exists()).exists() and agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110153').exists()).exists()
cr-auditoria-detalle error AuditEvent Un resultado que no es success lleva su detalle. outcome.code.code != 'success' implies outcome.detail.exists()
cr-auditoria-entidades error AuditEvent Cada entidad indica el recurso (what), salvo la consulta (role 24), que indica la consulta (query). entity.all(iif(role.coding.where(code = '24').exists(), query.exists(), what.exists()))
cr-auditoria-fechas error AuditEvent La fecha del evento no es posterior a la fecha de registro. occurred.ofType(dateTime).empty() or occurred.ofType(dateTime) <= recorded
cr-auditoria-paciente error AuditEvent El paciente del evento va también como entidad con role 1 (Patient), como en IHE BALP. patient.exists() implies entity.where(role.coding.where(system = 'http://terminology.hl7.org/CodeSystem/object-role' and code = '1').exists()).exists()
cr-auditoria-proposito error AuditEvent Un evento con datos de un paciente indica el propósito de uso. patient.exists() implies authorization.exists()
cr-auditoria-red error AuditEvent El cliente y el servidor indican su red (dirección IP, subsistema X-Road o URL). agent.where(type.coding.where(code = '110153' or code = '110152').exists()).all(network.exists())
cr-auditoria-rest error AuditEvent Un evento rest lleva el código de la interacción REST. category.coding.where(code = 'rest').exists() implies code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').exists()
cr-auditoria-solicitante error AuditEvent Hay un solo solicitante (requestor = true): el usuario o, si no hay usuario, el cliente. agent.where(requestor = true).count() = 1
cr-documento-fecha-hora error AuditEvent.occurred[x] La fecha lleva fecha y hora, no solo la fecha. toString().contains('T')
NombreMarcasCard.TipoDescripción y restricciones    Filter: Filtersdoco
.. AuditEvent C 0..* AuditEvent Evento de auditoría: quién accedió a qué y con qué resultado
Constraints: cr-auditoria-rest, cr-auditoria-accion, cr-auditoria-detalle, cr-auditoria-proposito, cr-auditoria-agentes, cr-auditoria-red, cr-auditoria-solicitante, cr-auditoria-paciente, cr-auditoria-entidades, cr-auditoria-fechas
... id Σ 0..1 id Logical id of this artifact
... meta Σ 0..1 Meta Metadata about the resource
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... text 0..1 Narrative Text summary of the resource, for human interpretation
This profile does not constrain the narrative in regard to content, language, or traceability to data elements
... contained 0..* Resource Contained, inline Resources
... extension 0..* Extension Additional content defined by implementations
... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored
... category SΣ 1..1 CodeableConcept Categoría: rest | 110114 (autenticación) | 110113 (alerta de seguridad)
Vinculación: Categoría del evento de auditoría (required)
... code SΣ 1..1 CodeableConcept Qué se hizo: la interacción REST (read, search, create...) o el evento de DICOM
Vinculación: AuditEventSubType (example): Specific type of event.
... action SΣ 1..1 code C | R | U | D | E, coherente con el código
Vinculación: AuditEventAction (required): DICOM Audit Event Action
... severity Σ 0..1 code emergency | alert | critical | error | warning | notice | informational | debug
Vinculación: AuditEventSeverity (required): This is in the SysLog header, PRI. http://tools.ietf.org/html/rfc5424#appendix-A.3
... occurred[x] SC 0..1 dateTime Cuándo ocurrió el evento (no posterior al registro)
Constraints: cr-documento-fecha-hora
... recorded SΣ 1..1 instant Cuándo se registró el evento
... outcome SΣ 1..1 BackboneElement Resultado del evento, también en los fallos
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... code SΣ 1..1 Coding success | warning | error | fatal
Vinculación: AuditEventOutcome (required)
.... detail SΣ 0..* CodeableConcept Detalle (código HTTP y texto), sin datos clínicos
Vinculación: AuditEventOutcomeDetail (example): A code that provides details as the exact issue.
... authorization SΣ 0..1 CodeableConcept Propósito de uso: TREAT | ETREAT | COC | PATRQT | PUBHLTH | HRESCH | HOPERAT | HSYSADMIN | HLEGAL
Vinculación: Propósito de uso (required)
... basedOn 0..* Reference(CarePlan | DeviceRequest | ImmunizationRecommendation | MedicationRequest | NutritionOrder | ServiceRequest | Task) Workflow authorization within which this event occurred
... patient S 0..1 Reference(Paciente) Paciente de los datos (un evento por paciente)
... encounter 0..1 Reference(Encounter) Encounter within which this event occurred or which the event is tightly associated
... agent SΣ 2..* BackboneElement El cliente, el servidor y, si la hace una persona, el usuario
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... type S 1..1 CodeableConcept 110152 (destino) | 110153 (origen) | IRCP (usuario)
Vinculación: Tipo de agente de auditoría (required)
.... role 0..* CodeableConcept Agent role in the event
Vinculación: SecurityRoleType (example): What security role enabled the agent to participate in the event.
.... who SΣ 1..1 Reference(Sistema de información | Rol del profesional | Profesional de salud | Paciente) El sistema registrado en el HIE, o la persona usuaria
.... requestor SΣ 0..1 boolean true para el usuario o, si no hay usuario, para el cliente
.... location 0..1 Reference(Location) The agent location when the event occurred
.... policy S 0..1 uri Identificador del token (jti) del usuario
.... network[x] S 0..1 Red: la IP o el subsistema X-Road del cliente, la URL del servidor
..... networkReference Reference(Endpoint)
..... networkUri uri
..... networkString string
.... authorization 0..* CodeableConcept Allowable authorization for this agent
Vinculación: PurposeOfUse (example): The reason the activity took place.
... source SΣ 1..1 BackboneElement Quién registró el evento
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... site 0..1 Reference(Location) Logical source location within the enterprise
.... observer Σ 1..1 Reference(Sistema de información) El sistema que registró el evento
.... type S 1..1 CodeableConcept Tipo de la fuente (4: servidor de aplicaciones)
Vinculación: AuditEventSourceType (required)
... entity SΣ 0..* BackboneElement El paciente, los datos, la consulta y la transacción
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... what SΣ 0..1 Reference(Resource) El recurso (la versión concreta si se conoce) o el identificador de la transacción
.... role S 0..1 CodeableConcept 1 (paciente) | 4 (datos) | 24 (consulta); sin role, la transacción
Vinculación: AuditEventEntityRole (required)
.... securityLabel S 0..* CodeableConcept Las etiquetas de seguridad del recurso
Vinculación: SecurityLabelExamples (example): Example Security Labels from the Healthcare Privacy and Security Classification System.
.... query SΣ 0..1 base64Binary La consulta, en base64 (solo en la entidad consulta)
.... detail 0..* BackboneElement Additional Information about the entity
..... id 0..1 string Unique id for inter-element referencing
..... extension 0..* Extension Additional content defined by implementations
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... type 1..1 CodeableConcept Name of the property
Vinculación: AuditEventID (example): Additional detail about an entity used in an event.
..... value[x] 1..1 Property value
...... valueQuantity Quantity
...... valueCodeableConcept CodeableConcept
...... valueString string
...... valueBoolean boolean
...... valueInteger integer
...... valueRange Range
...... valueRatio Ratio
...... valueTime time
...... valueDateTime dateTime
...... valuePeriod Period
...... valueBase64Binary base64Binary
.... agent 0..* Vea agent (AuditEvent) Entity is attributed to this agent

doco Documentación de este formato

Vinculaciones terminológicas

Ruta Estado Uso ValueSet Versión Fuente
AuditEvent.language Base required All Languages 📍5.0.0 Estándar FHIR
AuditEvent.category Base required Categoría del evento de auditoría 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.code Base example Audit Event Sub-Type 📍5.0.0 Estándar FHIR
AuditEvent.action Base required Audit Event Action 📍5.0.0 Estándar FHIR
AuditEvent.severity Base required Audit Event Severity 📍5.0.0 Estándar FHIR
AuditEvent.outcome.code Base required Audit Event Outcome 📦5.0.0 Estándar FHIR
AuditEvent.outcome.detail Base example Audit Event Outcome Detail 📍5.0.0 Estándar FHIR
AuditEvent.authorization Base required Propósito de uso 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.agent.type Base required Tipo de agente de auditoría 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.agent.role Base example Security Role Type 📍5.0.0 Estándar FHIR
AuditEvent.agent.authorization Base example PurposeOfUse 📦3.1.0 THO v7.4
AuditEvent.source.type Base required Audit Event Source Type 📦5.0.0 Estándar FHIR
AuditEvent.entity.role Base required Audit Event Entity Role 📦5.0.0 Estándar FHIR
AuditEvent.entity.securityLabel Base example Example set of Security Labels 📍5.0.0 Estándar FHIR
AuditEvent.entity.detail.​type Base example Audit Event ID 📍5.0.0 Estándar FHIR

Restricciones

Id Nivel Ruta(s) Descripción Expression
cr-auditoria-accion error AuditEvent La acción es coherente con la interacción: las lecturas, búsquedas e historias son R; create es C; update y patch son U; delete es D; las demás son E. code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').all(iif(code in ('read' | 'vread' | 'search' | 'search-type' | 'search-system' | 'history' | 'history-instance' | 'history-type' | 'history-system'), %resource.action = 'R', iif(code = 'create', %resource.action = 'C', iif(code in ('update' | 'patch'), %resource.action = 'U', iif(code = 'delete', %resource.action = 'D', %resource.action = 'E')))))
cr-auditoria-agentes error AuditEvent El evento lleva un agente cliente y un agente servidor (DICOM 110152 y 110153). agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110152').exists()).exists() and agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110153').exists()).exists()
cr-auditoria-detalle error AuditEvent Un resultado que no es success lleva su detalle. outcome.code.code != 'success' implies outcome.detail.exists()
cr-auditoria-entidades error AuditEvent Cada entidad indica el recurso (what), salvo la consulta (role 24), que indica la consulta (query). entity.all(iif(role.coding.where(code = '24').exists(), query.exists(), what.exists()))
cr-auditoria-fechas error AuditEvent La fecha del evento no es posterior a la fecha de registro. occurred.ofType(dateTime).empty() or occurred.ofType(dateTime) <= recorded
cr-auditoria-paciente error AuditEvent El paciente del evento va también como entidad con role 1 (Patient), como en IHE BALP. patient.exists() implies entity.where(role.coding.where(system = 'http://terminology.hl7.org/CodeSystem/object-role' and code = '1').exists()).exists()
cr-auditoria-proposito error AuditEvent Un evento con datos de un paciente indica el propósito de uso. patient.exists() implies authorization.exists()
cr-auditoria-red error AuditEvent El cliente y el servidor indican su red (dirección IP, subsistema X-Road o URL). agent.where(type.coding.where(code = '110153' or code = '110152').exists()).all(network.exists())
cr-auditoria-rest error AuditEvent Un evento rest lleva el código de la interacción REST. category.coding.where(code = 'rest').exists() implies code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').exists()
cr-auditoria-solicitante error AuditEvent Hay un solo solicitante (requestor = true): el usuario o, si no hay usuario, el cliente. agent.where(requestor = true).count() = 1
cr-documento-fecha-hora error AuditEvent.occurred[x] La fecha lleva fecha y hora, no solo la fecha. toString().contains('T')
dom-2 error AuditEvent If the resource is contained in another resource, it SHALL NOT contain nested Resources contained.contained.empty()
dom-3 error AuditEvent If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().ofType(canonical) | %resource.descendants().ofType(uri) | %resource.descendants().ofType(url))) or descendants().where(reference = '#').exists() or descendants().where(ofType(canonical) = '#').exists() or descendants().where(ofType(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
dom-4 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
dom-5 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a security label contained.meta.security.empty()
dom-6 best practice AuditEvent A resource should have narrative for robust management text.`div`.exists()
ele-1 error **TODOS** los elementos All FHIR elements must have a @value or children hasValue() or (children().count() > id.count())
ext-1 error **TODAS** las extensiones Must have either extensions or value[x], not both extension.exists() != value.exists()

Vista de elementos clave

NombreMarcasCard.TipoDescripción y restricciones    Filter: Filtersdoco
.. AuditEvent C 0..* AuditEvent Evento de auditoría: quién accedió a qué y con qué resultado
Constraints: cr-auditoria-rest, cr-auditoria-accion, cr-auditoria-detalle, cr-auditoria-proposito, cr-auditoria-agentes, cr-auditoria-red, cr-auditoria-solicitante, cr-auditoria-paciente, cr-auditoria-entidades, cr-auditoria-fechas
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... contained 0..* Resource Contained, inline Resources
... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored
... code SΣ 1..1 CodeableConcept Qué se hizo: la interacción REST (read, search, create...) o el evento de DICOM
Vinculación: AuditEventSubType (example): Specific type of event.
... action SΣ 1..1 code C | R | U | D | E, coherente con el código
Vinculación: AuditEventAction (required): DICOM Audit Event Action
... occurred[x] SC 0..1 dateTime Cuándo ocurrió el evento (no posterior al registro)
Constraints: cr-documento-fecha-hora
... recorded SΣ 1..1 instant Cuándo se registró el evento
... outcome SΣ 1..1 BackboneElement Resultado del evento, también en los fallos
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... code SΣ 1..1 Coding success | warning | error | fatal
Vinculación: AuditEventOutcome (required)
.... detail SΣ 0..* CodeableConcept Detalle (código HTTP y texto), sin datos clínicos
Vinculación: AuditEventOutcomeDetail (example): A code that provides details as the exact issue.
... authorization SΣ 0..1 CodeableConcept Propósito de uso: TREAT | ETREAT | COC | PATRQT | PUBHLTH | HRESCH | HOPERAT | HSYSADMIN | HLEGAL
Vinculación: Propósito de uso (required)
... patient S 0..1 Reference(Paciente) Paciente de los datos (un evento por paciente)
... agent SΣ 2..* BackboneElement El cliente, el servidor y, si la hace una persona, el usuario
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... type S 1..1 CodeableConcept 110152 (destino) | 110153 (origen) | IRCP (usuario)
Vinculación: Tipo de agente de auditoría (required)
.... who SΣ 1..1 Reference(Sistema de información | Rol del profesional | Profesional de salud | Paciente) El sistema registrado en el HIE, o la persona usuaria
.... requestor SΣ 0..1 boolean true para el usuario o, si no hay usuario, para el cliente
.... policy S 0..1 uri Identificador del token (jti) del usuario
.... network[x] S 0..1 Red: la IP o el subsistema X-Road del cliente, la URL del servidor
..... networkReference Reference(Endpoint)
..... networkUri uri
..... networkString string
... source SΣ 1..1 BackboneElement Quién registró el evento
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... observer Σ 1..1 Reference(Sistema de información) El sistema que registró el evento
.... type S 1..1 CodeableConcept Tipo de la fuente (4: servidor de aplicaciones)
Vinculación: AuditEventSourceType (required)
... entity SΣ 0..* BackboneElement El paciente, los datos, la consulta y la transacción
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... what SΣ 0..1 Reference(Resource) El recurso (la versión concreta si se conoce) o el identificador de la transacción
.... role S 0..1 CodeableConcept 1 (paciente) | 4 (datos) | 24 (consulta); sin role, la transacción
Vinculación: AuditEventEntityRole (required)
.... securityLabel S 0..* CodeableConcept Las etiquetas de seguridad del recurso
Vinculación: SecurityLabelExamples (example): Example Security Labels from the Healthcare Privacy and Security Classification System.
.... query SΣ 0..1 base64Binary La consulta, en base64 (solo en la entidad consulta)

doco Documentación de este formato

Vinculaciones terminológicas

Ruta Estado Uso ValueSet Versión Fuente
AuditEvent.category Base required Categoría del evento de auditoría 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.code Base example Audit Event Sub-Type 📍5.0.0 Estándar FHIR
AuditEvent.action Base required Audit Event Action 📍5.0.0 Estándar FHIR
AuditEvent.outcome.code Base required Audit Event Outcome 📦5.0.0 Estándar FHIR
AuditEvent.outcome.detail Base example Audit Event Outcome Detail 📍5.0.0 Estándar FHIR
AuditEvent.authorization Base required Propósito de uso 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.agent.type Base required Tipo de agente de auditoría 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.source.type Base required Audit Event Source Type 📦5.0.0 Estándar FHIR
AuditEvent.entity.role Base required Audit Event Entity Role 📦5.0.0 Estándar FHIR
AuditEvent.entity.securityLabel Base example Example set of Security Labels 📍5.0.0 Estándar FHIR

Restricciones

Id Nivel Ruta(s) Descripción Expression
cr-auditoria-accion error AuditEvent La acción es coherente con la interacción: las lecturas, búsquedas e historias son R; create es C; update y patch son U; delete es D; las demás son E. code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').all(iif(code in ('read' | 'vread' | 'search' | 'search-type' | 'search-system' | 'history' | 'history-instance' | 'history-type' | 'history-system'), %resource.action = 'R', iif(code = 'create', %resource.action = 'C', iif(code in ('update' | 'patch'), %resource.action = 'U', iif(code = 'delete', %resource.action = 'D', %resource.action = 'E')))))
cr-auditoria-agentes error AuditEvent El evento lleva un agente cliente y un agente servidor (DICOM 110152 y 110153). agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110152').exists()).exists() and agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110153').exists()).exists()
cr-auditoria-detalle error AuditEvent Un resultado que no es success lleva su detalle. outcome.code.code != 'success' implies outcome.detail.exists()
cr-auditoria-entidades error AuditEvent Cada entidad indica el recurso (what), salvo la consulta (role 24), que indica la consulta (query). entity.all(iif(role.coding.where(code = '24').exists(), query.exists(), what.exists()))
cr-auditoria-fechas error AuditEvent La fecha del evento no es posterior a la fecha de registro. occurred.ofType(dateTime).empty() or occurred.ofType(dateTime) <= recorded
cr-auditoria-paciente error AuditEvent El paciente del evento va también como entidad con role 1 (Patient), como en IHE BALP. patient.exists() implies entity.where(role.coding.where(system = 'http://terminology.hl7.org/CodeSystem/object-role' and code = '1').exists()).exists()
cr-auditoria-proposito error AuditEvent Un evento con datos de un paciente indica el propósito de uso. patient.exists() implies authorization.exists()
cr-auditoria-red error AuditEvent El cliente y el servidor indican su red (dirección IP, subsistema X-Road o URL). agent.where(type.coding.where(code = '110153' or code = '110152').exists()).all(network.exists())
cr-auditoria-rest error AuditEvent Un evento rest lleva el código de la interacción REST. category.coding.where(code = 'rest').exists() implies code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').exists()
cr-auditoria-solicitante error AuditEvent Hay un solo solicitante (requestor = true): el usuario o, si no hay usuario, el cliente. agent.where(requestor = true).count() = 1
cr-documento-fecha-hora error AuditEvent.occurred[x] La fecha lleva fecha y hora, no solo la fecha. toString().contains('T')
dom-2 error AuditEvent If the resource is contained in another resource, it SHALL NOT contain nested Resources contained.contained.empty()
dom-3 error AuditEvent If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().ofType(canonical) | %resource.descendants().ofType(uri) | %resource.descendants().ofType(url))) or descendants().where(reference = '#').exists() or descendants().where(ofType(canonical) = '#').exists() or descendants().where(ofType(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
dom-4 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
dom-5 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a security label contained.meta.security.empty()
dom-6 best practice AuditEvent A resource should have narrative for robust management text.`div`.exists()
ele-1 error **TODOS** los elementos All FHIR elements must have a @value or children hasValue() or (children().count() > id.count())
ext-1 error **TODAS** las extensiones Must have either extensions or value[x], not both extension.exists() != value.exists()

Vista diferencial

Esta estructura se deriva de AuditEvent .

NombreMarcasCard.TipoDescripción y restricciones    Filter: Filtersdoco
.. AuditEvent C 0..* AuditEvent Evento de auditoría: quién accedió a qué y con qué resultado
Constraints: cr-auditoria-rest, cr-auditoria-accion, cr-auditoria-detalle, cr-auditoria-proposito, cr-auditoria-agentes, cr-auditoria-red, cr-auditoria-solicitante, cr-auditoria-paciente, cr-auditoria-entidades, cr-auditoria-fechas
... category S 1..1 CodeableConcept Categoría: rest | 110114 (autenticación) | 110113 (alerta de seguridad)
Vinculación: Categoría del evento de auditoría (required)
... code S 1..1 CodeableConcept Qué se hizo: la interacción REST (read, search, create...) o el evento de DICOM
... action S 1..1 code C | R | U | D | E, coherente con el código
... recorded S 1..1 instant Cuándo se registró el evento
... outcome S 1..1 BackboneElement Resultado del evento, también en los fallos
.... code S 1..1 Coding success | warning | error | fatal
Vinculación: AuditEventOutcome (required)
.... detail S 0..* CodeableConcept Detalle (código HTTP y texto), sin datos clínicos
... authorization S 0..1 CodeableConcept Propósito de uso: TREAT | ETREAT | COC | PATRQT | PUBHLTH | HRESCH | HOPERAT | HSYSADMIN | HLEGAL
Vinculación: Propósito de uso (required)
... patient S 0..1 Reference(Paciente) Paciente de los datos (un evento por paciente)
... agent S 2..* BackboneElement El cliente, el servidor y, si la hace una persona, el usuario
.... type S 1..1 CodeableConcept 110152 (destino) | 110153 (origen) | IRCP (usuario)
Vinculación: Tipo de agente de auditoría (required)
.... who S 1..1 Reference(Sistema de información | Rol del profesional | Profesional de salud | Paciente) El sistema registrado en el HIE, o la persona usuaria
.... requestor S 0..1 boolean true para el usuario o, si no hay usuario, para el cliente
.... policy S 0..1 uri Identificador del token (jti) del usuario
.... network[x] S 0..1 Reference(Endpoint), uri, string Red: la IP o el subsistema X-Road del cliente, la URL del servidor
... source S 1..1 BackboneElement Quién registró el evento
.... observer 1..1 Reference(Sistema de información) El sistema que registró el evento
.... type S 1..1 CodeableConcept Tipo de la fuente (4: servidor de aplicaciones)
Vinculación: AuditEventSourceType (required)
... entity S 0..* BackboneElement El paciente, los datos, la consulta y la transacción
.... what S 0..1 Reference(Resource) El recurso (la versión concreta si se conoce) o el identificador de la transacción
.... role S 0..1 CodeableConcept 1 (paciente) | 4 (datos) | 24 (consulta); sin role, la transacción
Vinculación: AuditEventEntityRole (required)
.... securityLabel S 0..* CodeableConcept Las etiquetas de seguridad del recurso
.... query S 0..1 base64Binary La consulta, en base64 (solo en la entidad consulta)

doco Documentación de este formato

Vinculaciones terminológicas (diferencial)

Ruta Estado Uso ValueSet Versión Fuente
AuditEvent.category Base required Categoría del evento de auditoría 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.outcome.code Base required Audit Event Outcome 📦5.0.0 Estándar FHIR
AuditEvent.authorization Base required Propósito de uso 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.agent.type Base required Tipo de agente de auditoría 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.source.type Base required Audit Event Source Type 📦5.0.0 Estándar FHIR
AuditEvent.entity.role Base required Audit Event Entity Role 📦5.0.0 Estándar FHIR

Restricciones

Id Nivel Ruta(s) Descripción Expression
cr-auditoria-accion error AuditEvent La acción es coherente con la interacción: las lecturas, búsquedas e historias son R; create es C; update y patch son U; delete es D; las demás son E. code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').all(iif(code in ('read' | 'vread' | 'search' | 'search-type' | 'search-system' | 'history' | 'history-instance' | 'history-type' | 'history-system'), %resource.action = 'R', iif(code = 'create', %resource.action = 'C', iif(code in ('update' | 'patch'), %resource.action = 'U', iif(code = 'delete', %resource.action = 'D', %resource.action = 'E')))))
cr-auditoria-agentes error AuditEvent El evento lleva un agente cliente y un agente servidor (DICOM 110152 y 110153). agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110152').exists()).exists() and agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110153').exists()).exists()
cr-auditoria-detalle error AuditEvent Un resultado que no es success lleva su detalle. outcome.code.code != 'success' implies outcome.detail.exists()
cr-auditoria-entidades error AuditEvent Cada entidad indica el recurso (what), salvo la consulta (role 24), que indica la consulta (query). entity.all(iif(role.coding.where(code = '24').exists(), query.exists(), what.exists()))
cr-auditoria-fechas error AuditEvent La fecha del evento no es posterior a la fecha de registro. occurred.ofType(dateTime).empty() or occurred.ofType(dateTime) <= recorded
cr-auditoria-paciente error AuditEvent El paciente del evento va también como entidad con role 1 (Patient), como en IHE BALP. patient.exists() implies entity.where(role.coding.where(system = 'http://terminology.hl7.org/CodeSystem/object-role' and code = '1').exists()).exists()
cr-auditoria-proposito error AuditEvent Un evento con datos de un paciente indica el propósito de uso. patient.exists() implies authorization.exists()
cr-auditoria-red error AuditEvent El cliente y el servidor indican su red (dirección IP, subsistema X-Road o URL). agent.where(type.coding.where(code = '110153' or code = '110152').exists()).all(network.exists())
cr-auditoria-rest error AuditEvent Un evento rest lleva el código de la interacción REST. category.coding.where(code = 'rest').exists() implies code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').exists()
cr-auditoria-solicitante error AuditEvent Hay un solo solicitante (requestor = true): el usuario o, si no hay usuario, el cliente. agent.where(requestor = true).count() = 1
cr-documento-fecha-hora error AuditEvent.occurred[x] La fecha lleva fecha y hora, no solo la fecha. toString().contains('T')

Vista instantáneaView

NombreMarcasCard.TipoDescripción y restricciones    Filter: Filtersdoco
.. AuditEvent C 0..* AuditEvent Evento de auditoría: quién accedió a qué y con qué resultado
Constraints: cr-auditoria-rest, cr-auditoria-accion, cr-auditoria-detalle, cr-auditoria-proposito, cr-auditoria-agentes, cr-auditoria-red, cr-auditoria-solicitante, cr-auditoria-paciente, cr-auditoria-entidades, cr-auditoria-fechas
... id Σ 0..1 id Logical id of this artifact
... meta Σ 0..1 Meta Metadata about the resource
... implicitRules ?!Σ 0..1 uri A set of rules under which this content was created
... text 0..1 Narrative Text summary of the resource, for human interpretation
This profile does not constrain the narrative in regard to content, language, or traceability to data elements
... contained 0..* Resource Contained, inline Resources
... extension 0..* Extension Additional content defined by implementations
... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored
... category SΣ 1..1 CodeableConcept Categoría: rest | 110114 (autenticación) | 110113 (alerta de seguridad)
Vinculación: Categoría del evento de auditoría (required)
... code SΣ 1..1 CodeableConcept Qué se hizo: la interacción REST (read, search, create...) o el evento de DICOM
Vinculación: AuditEventSubType (example): Specific type of event.
... action SΣ 1..1 code C | R | U | D | E, coherente con el código
Vinculación: AuditEventAction (required): DICOM Audit Event Action
... severity Σ 0..1 code emergency | alert | critical | error | warning | notice | informational | debug
Vinculación: AuditEventSeverity (required): This is in the SysLog header, PRI. http://tools.ietf.org/html/rfc5424#appendix-A.3
... occurred[x] SC 0..1 dateTime Cuándo ocurrió el evento (no posterior al registro)
Constraints: cr-documento-fecha-hora
... recorded SΣ 1..1 instant Cuándo se registró el evento
... outcome SΣ 1..1 BackboneElement Resultado del evento, también en los fallos
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... code SΣ 1..1 Coding success | warning | error | fatal
Vinculación: AuditEventOutcome (required)
.... detail SΣ 0..* CodeableConcept Detalle (código HTTP y texto), sin datos clínicos
Vinculación: AuditEventOutcomeDetail (example): A code that provides details as the exact issue.
... authorization SΣ 0..1 CodeableConcept Propósito de uso: TREAT | ETREAT | COC | PATRQT | PUBHLTH | HRESCH | HOPERAT | HSYSADMIN | HLEGAL
Vinculación: Propósito de uso (required)
... basedOn 0..* Reference(CarePlan | DeviceRequest | ImmunizationRecommendation | MedicationRequest | NutritionOrder | ServiceRequest | Task) Workflow authorization within which this event occurred
... patient S 0..1 Reference(Paciente) Paciente de los datos (un evento por paciente)
... encounter 0..1 Reference(Encounter) Encounter within which this event occurred or which the event is tightly associated
... agent SΣ 2..* BackboneElement El cliente, el servidor y, si la hace una persona, el usuario
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... type S 1..1 CodeableConcept 110152 (destino) | 110153 (origen) | IRCP (usuario)
Vinculación: Tipo de agente de auditoría (required)
.... role 0..* CodeableConcept Agent role in the event
Vinculación: SecurityRoleType (example): What security role enabled the agent to participate in the event.
.... who SΣ 1..1 Reference(Sistema de información | Rol del profesional | Profesional de salud | Paciente) El sistema registrado en el HIE, o la persona usuaria
.... requestor SΣ 0..1 boolean true para el usuario o, si no hay usuario, para el cliente
.... location 0..1 Reference(Location) The agent location when the event occurred
.... policy S 0..1 uri Identificador del token (jti) del usuario
.... network[x] S 0..1 Red: la IP o el subsistema X-Road del cliente, la URL del servidor
..... networkReference Reference(Endpoint)
..... networkUri uri
..... networkString string
.... authorization 0..* CodeableConcept Allowable authorization for this agent
Vinculación: PurposeOfUse (example): The reason the activity took place.
... source SΣ 1..1 BackboneElement Quién registró el evento
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... site 0..1 Reference(Location) Logical source location within the enterprise
.... observer Σ 1..1 Reference(Sistema de información) El sistema que registró el evento
.... type S 1..1 CodeableConcept Tipo de la fuente (4: servidor de aplicaciones)
Vinculación: AuditEventSourceType (required)
... entity SΣ 0..* BackboneElement El paciente, los datos, la consulta y la transacción
.... id 0..1 string Unique id for inter-element referencing
.... extension 0..* Extension Additional content defined by implementations
.... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
.... what SΣ 0..1 Reference(Resource) El recurso (la versión concreta si se conoce) o el identificador de la transacción
.... role S 0..1 CodeableConcept 1 (paciente) | 4 (datos) | 24 (consulta); sin role, la transacción
Vinculación: AuditEventEntityRole (required)
.... securityLabel S 0..* CodeableConcept Las etiquetas de seguridad del recurso
Vinculación: SecurityLabelExamples (example): Example Security Labels from the Healthcare Privacy and Security Classification System.
.... query SΣ 0..1 base64Binary La consulta, en base64 (solo en la entidad consulta)
.... detail 0..* BackboneElement Additional Information about the entity
..... id 0..1 string Unique id for inter-element referencing
..... extension 0..* Extension Additional content defined by implementations
..... modifierExtension ?!Σ 0..* Extension Extensions that cannot be ignored even if unrecognized
..... type 1..1 CodeableConcept Name of the property
Vinculación: AuditEventID (example): Additional detail about an entity used in an event.
..... value[x] 1..1 Property value
...... valueQuantity Quantity
...... valueCodeableConcept CodeableConcept
...... valueString string
...... valueBoolean boolean
...... valueInteger integer
...... valueRange Range
...... valueRatio Ratio
...... valueTime time
...... valueDateTime dateTime
...... valuePeriod Period
...... valueBase64Binary base64Binary
.... agent 0..* Vea agent (AuditEvent) Entity is attributed to this agent

doco Documentación de este formato

Vinculaciones terminológicas

Ruta Estado Uso ValueSet Versión Fuente
AuditEvent.language Base required All Languages 📍5.0.0 Estándar FHIR
AuditEvent.category Base required Categoría del evento de auditoría 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.code Base example Audit Event Sub-Type 📍5.0.0 Estándar FHIR
AuditEvent.action Base required Audit Event Action 📍5.0.0 Estándar FHIR
AuditEvent.severity Base required Audit Event Severity 📍5.0.0 Estándar FHIR
AuditEvent.outcome.code Base required Audit Event Outcome 📦5.0.0 Estándar FHIR
AuditEvent.outcome.detail Base example Audit Event Outcome Detail 📍5.0.0 Estándar FHIR
AuditEvent.authorization Base required Propósito de uso 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.agent.type Base required Tipo de agente de auditoría 📦0.1.0 Guía de Implementación de Terminología de Costa Rica vnull
AuditEvent.agent.role Base example Security Role Type 📍5.0.0 Estándar FHIR
AuditEvent.agent.authorization Base example PurposeOfUse 📦3.1.0 THO v7.4
AuditEvent.source.type Base required Audit Event Source Type 📦5.0.0 Estándar FHIR
AuditEvent.entity.role Base required Audit Event Entity Role 📦5.0.0 Estándar FHIR
AuditEvent.entity.securityLabel Base example Example set of Security Labels 📍5.0.0 Estándar FHIR
AuditEvent.entity.detail.​type Base example Audit Event ID 📍5.0.0 Estándar FHIR

Restricciones

Id Nivel Ruta(s) Descripción Expression
cr-auditoria-accion error AuditEvent La acción es coherente con la interacción: las lecturas, búsquedas e historias son R; create es C; update y patch son U; delete es D; las demás son E. code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').all(iif(code in ('read' | 'vread' | 'search' | 'search-type' | 'search-system' | 'history' | 'history-instance' | 'history-type' | 'history-system'), %resource.action = 'R', iif(code = 'create', %resource.action = 'C', iif(code in ('update' | 'patch'), %resource.action = 'U', iif(code = 'delete', %resource.action = 'D', %resource.action = 'E')))))
cr-auditoria-agentes error AuditEvent El evento lleva un agente cliente y un agente servidor (DICOM 110152 y 110153). agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110152').exists()).exists() and agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110153').exists()).exists()
cr-auditoria-detalle error AuditEvent Un resultado que no es success lleva su detalle. outcome.code.code != 'success' implies outcome.detail.exists()
cr-auditoria-entidades error AuditEvent Cada entidad indica el recurso (what), salvo la consulta (role 24), que indica la consulta (query). entity.all(iif(role.coding.where(code = '24').exists(), query.exists(), what.exists()))
cr-auditoria-fechas error AuditEvent La fecha del evento no es posterior a la fecha de registro. occurred.ofType(dateTime).empty() or occurred.ofType(dateTime) <= recorded
cr-auditoria-paciente error AuditEvent El paciente del evento va también como entidad con role 1 (Patient), como en IHE BALP. patient.exists() implies entity.where(role.coding.where(system = 'http://terminology.hl7.org/CodeSystem/object-role' and code = '1').exists()).exists()
cr-auditoria-proposito error AuditEvent Un evento con datos de un paciente indica el propósito de uso. patient.exists() implies authorization.exists()
cr-auditoria-red error AuditEvent El cliente y el servidor indican su red (dirección IP, subsistema X-Road o URL). agent.where(type.coding.where(code = '110153' or code = '110152').exists()).all(network.exists())
cr-auditoria-rest error AuditEvent Un evento rest lleva el código de la interacción REST. category.coding.where(code = 'rest').exists() implies code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').exists()
cr-auditoria-solicitante error AuditEvent Hay un solo solicitante (requestor = true): el usuario o, si no hay usuario, el cliente. agent.where(requestor = true).count() = 1
cr-documento-fecha-hora error AuditEvent.occurred[x] La fecha lleva fecha y hora, no solo la fecha. toString().contains('T')
dom-2 error AuditEvent If the resource is contained in another resource, it SHALL NOT contain nested Resources contained.contained.empty()
dom-3 error AuditEvent If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().ofType(canonical) | %resource.descendants().ofType(uri) | %resource.descendants().ofType(url))) or descendants().where(reference = '#').exists() or descendants().where(ofType(canonical) = '#').exists() or descendants().where(ofType(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
dom-4 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
dom-5 error AuditEvent If a resource is contained in another resource, it SHALL NOT have a security label contained.meta.security.empty()
dom-6 best practice AuditEvent A resource should have narrative for robust management text.`div`.exists()
ele-1 error **TODOS** los elementos All FHIR elements must have a @value or children hasValue() or (children().count() > id.count())
ext-1 error **TODAS** las extensiones Must have either extensions or value[x], not both extension.exists() != value.exists()

 

Otras representaciones de perfil: CSV, Excel, Schematron

Notas:

Uso en el HIE

Repositorio de auditoría. Eventos de auditoría: cada acceso u operación sobre el HIE, incluidos los fallos.

Ver también Servicios del HIE.

Consultas

Lo que el servidor debe responder para este perfil. En la forma, [base] es la URL base del servidor del servicio y lo que va entre llaves se reemplaza por un valor. Cada solicitud usa valores reales de los ejemplos de esta guía, y la respuesta trae los que coinciden; los cuerpos JSON se expanden al hacer clic. Todas las solicitudes llevan el token de acceso al HIE (Authorization: Bearer [token]). Las búsquedas de texto encuentran los valores que empiezan con el texto, sin distinguir mayúsculas ni tildes; las de fecha admiten los prefijos ge, gt, le y lt. En la URL los valores van codificados (| como %7C, + como %2B, un espacio como %20); aquí se muestran sin codificar para que se lean mejor.

Ir a: Leer · Buscar · Crear

Leer

Leer
Forma: GET [base]/AuditEvent/{id}

Lee un evento de auditoría del repositorio de auditoría por su id, la parte final de su URL. Se usa para resolver una referencia que otro recurso hace a un evento de auditoría. En el ejemplo se lee «Acceso de emergencia a un documento restringido (E2)»; la segunda respuesta es la de un id que no existe.

Solicitud

GET [base]/AuditEvent/ejemplo-auditoria-emergencia HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]

Respuesta si el recurso existe

HTTP/1.1 200 OK
ETag: W/"1"
Last-Modified: 2026-10-01T10:00:00-06:00
Content-Type: application/fhir+json
{
  "resourceType": "AuditEvent",
  "id": "ejemplo-auditoria-emergencia",
  "meta": {
    "versionId": "1",
    "lastUpdated": "2026-10-01T10:00:00-06:00",
    "profile": [
      "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
    ]
  },
  "category": [
    {
      "coding": [
        {
          "code": "rest",
          "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
          "display": "RESTful Operation"
        }
      ]
    }
  ],
  "source": {
    "type": [
      {
        "coding": [
          {
            "code": "4",
            "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
            "display": "Application Server"
          }
        ]
      }
    ],
    "observer": {
      "reference": "Device/ejemplo-sistema-repositorio",
      "display": "Repositorio de documentos del HIE"
    }
  },
  "agent": [
    {
      "type": {
        "coding": [
          {
            "code": "110153",
            "system": "http://dicom.nema.org/resources/ontology/DCM",
            "display": "Source Role ID"
          }
        ]
      },
      "who": {
        "reference": "Device/ejemplo-sistema-repositorio",
        "display": "Repositorio de documentos del HIE"
      },
      "requestor": false,
      "networkUri": "https://hie.example.cr/fhir"
    },
    {
      "type": {
        "coding": [
          {
            "code": "110152",
            "system": "http://dicom.nema.org/resources/ontology/DCM",
            "display": "Destination Role ID"
          }
        ]
      },
      "who": {
        "reference": "Device/ejemplo-sistema-hce-hospital",
        "display": "Expediente electrónico del Hospital Privado de Ejemplo"
      },
      "requestor": false,
      "networkString": "CR/COM/3101123456/hce"
    },
    {
      "policy": [
        "urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
      ],
      "type": {
        "coding": [
          {
            "code": "IRCP",
            "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
            "display": "information recipient"
          }
        ]
      },
      "who": {
        "reference": "PractitionerRole/ejemplo-rol-medicina-interna",
        "display": "Ricardo Castro Brenes"
      },
      "requestor": true
    }
  ],
  "entity": [
    {
      "role": {
        "coding": [
          {
            "code": "1",
            "system": "http://terminology.hl7.org/CodeSystem/object-role",
            "display": "Patient"
          }
        ]
      },
      "what": {
        "reference": "Patient/ejemplo-paciente-nacional",
        "display": "Laura Patricia Solís Araya"
      }
    },
    {
      "what": {
        "identifier": {
          "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
          "value": "EPI-2025-118230"
        },
        "display": "Epicrisis de una hospitalización en salud mental"
      },
      "securityLabel": [
        {
          "coding": [
            {
              "code": "R",
              "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
              "display": "restricted"
            }
          ]
        },
        {
          "coding": [
            {
              "code": "PSY",
              "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
              "display": "psychiatry disorder information sensitivity"
            }
          ]
        }
      ],
      "role": {
        "coding": [
          {
            "code": "4",
            "system": "http://terminology.hl7.org/CodeSystem/object-role",
            "display": "Domain Resource"
          }
        ]
      }
    },
    {
      "what": {
        "identifier": {
          "system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
          "value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
        }
      }
    }
  ],
  "outcome": {
    "code": {
      "code": "success",
      "system": "http://hl7.org/fhir/issue-severity",
      "display": "Operation Successful"
    }
  },
  "authorization": [
    {
      "coding": [
        {
          "code": "ETREAT",
          "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
          "display": "Emergency Treatment"
        }
      ],
      "text": "Tratamiento de emergencia"
    }
  ],
  "code": {
    "coding": [
      {
        "code": "read",
        "system": "http://hl7.org/fhir/restful-interaction",
        "display": "read"
      }
    ]
  },
  "action": "R",
  "recorded": "2026-09-30T23:41:07-06:00",
  "patient": {
    "reference": "Patient/ejemplo-paciente-nacional",
    "display": "Laura Patricia Solís Araya"
  },
  "occurredDateTime": "2026-09-30T23:41:06-06:00"
}

Respuesta si no existe

HTTP/1.1 404 Not Found
Content-Type: application/fhir+json
{
  "resourceType": "OperationOutcome",
  "issue": [
    {
      "severity": "error",
      "code": "not-found",
      "diagnostics": "No existe el recurso AuditEvent/no-existe."
    }
  ]
}
Buscar

Buscar por paciente
Forma: GET [base]/AuditEvent?patient=Patient/{id}

Trae quién accedió a los datos de un paciente. Es la consulta que permite informarle quién vio su información, como pide la Ley 8968. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: patient=Patient/ejemplo-paciente-nacional.

Solicitud

GET [base]/AuditEvent?patient=Patient/ejemplo-paciente-nacional HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]

Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6)

HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
  "resourceType": "Bundle",
  "type": "searchset",
  "total": 2,
  "link": [
    {
      "relation": "self",
      "url": "[base]/AuditEvent?patient=Patient/ejemplo-paciente-nacional"
    }
  ],
  "entry": [
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-emergencia",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-hce-hospital",
              "display": "Expediente electrónico del Hospital Privado de Ejemplo"
            },
            "requestor": false,
            "networkString": "CR/COM/3101123456/hce"
          },
          {
            "policy": [
              "urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
            ],
            "type": {
              "coding": [
                {
                  "code": "IRCP",
                  "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
                  "display": "information recipient"
                }
              ]
            },
            "who": {
              "reference": "PractitionerRole/ejemplo-rol-medicina-interna",
              "display": "Ricardo Castro Brenes"
            },
            "requestor": true
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "EPI-2025-118230"
              },
              "display": "Epicrisis de una hospitalización en salud mental"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "R",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "PSY",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
                    "display": "psychiatry disorder information sensitivity"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
                "value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
              }
            }
          }
        ],
        "outcome": {
          "code": {
            "code": "success",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Operation Successful"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "ETREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "Emergency Treatment"
              }
            ],
            "text": "Tratamiento de emergencia"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-09-30T23:41:07-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        },
        "occurredDateTime": "2026-09-30T23:41:06-06:00"
      },
      "search": {
        "mode": "match"
      }
    },
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-denegado",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-laboratorio",
              "display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
            },
            "requestor": true,
            "networkString": "CR/COM/3101234567/lis-central"
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "NOT-2026-004127"
              },
              "display": "Nota de atención a una víctima de violencia doméstica"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "V",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "very restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "SDV",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          }
        ],
        "outcome": {
          "detail": [
            {
              "coding": [
                {
                  "code": "403",
                  "system": "urn:ietf:rfc:7231",
                  "display": "Forbidden"
                }
              ],
              "text": "Acceso denegado: el documento es de confidencialidad V"
            }
          ],
          "code": {
            "code": "error",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Error"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "TREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "treatment"
              }
            ],
            "text": "Tratamiento"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-10-01T09:12:44-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        }
      },
      "search": {
        "mode": "match"
      }
    }
  ]
}

Buscar por fecha de registro
Forma: GET [base]/AuditEvent?date={fecha}

Trae los eventos registrados en una fecha o un rango, para revisar un periodo. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: date=2026-09-30.

Solicitud

GET [base]/AuditEvent?date=2026-09-30 HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]

Respuesta: 1 resultado: Acceso de emergencia a un documento restringido (E2)

HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
  "resourceType": "Bundle",
  "type": "searchset",
  "total": 1,
  "link": [
    {
      "relation": "self",
      "url": "[base]/AuditEvent?date=2026-09-30"
    }
  ],
  "entry": [
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-emergencia",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-hce-hospital",
              "display": "Expediente electrónico del Hospital Privado de Ejemplo"
            },
            "requestor": false,
            "networkString": "CR/COM/3101123456/hce"
          },
          {
            "policy": [
              "urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
            ],
            "type": {
              "coding": [
                {
                  "code": "IRCP",
                  "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
                  "display": "information recipient"
                }
              ]
            },
            "who": {
              "reference": "PractitionerRole/ejemplo-rol-medicina-interna",
              "display": "Ricardo Castro Brenes"
            },
            "requestor": true
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "EPI-2025-118230"
              },
              "display": "Epicrisis de una hospitalización en salud mental"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "R",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "PSY",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
                    "display": "psychiatry disorder information sensitivity"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
                "value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
              }
            }
          }
        ],
        "outcome": {
          "code": {
            "code": "success",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Operation Successful"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "ETREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "Emergency Treatment"
              }
            ],
            "text": "Tratamiento de emergencia"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-09-30T23:41:07-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        },
        "occurredDateTime": "2026-09-30T23:41:06-06:00"
      },
      "search": {
        "mode": "match"
      }
    }
  ]
}

Buscar por agente
Forma: GET [base]/AuditEvent?agent=Device/{id}

Trae lo que hizo un sistema o una persona. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: agent=Device/ejemplo-sistema-repositorio.

Solicitud

GET [base]/AuditEvent?agent=Device/ejemplo-sistema-repositorio HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]

Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6)

HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
  "resourceType": "Bundle",
  "type": "searchset",
  "total": 2,
  "link": [
    {
      "relation": "self",
      "url": "[base]/AuditEvent?agent=Device/ejemplo-sistema-repositorio"
    }
  ],
  "entry": [
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-emergencia",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-hce-hospital",
              "display": "Expediente electrónico del Hospital Privado de Ejemplo"
            },
            "requestor": false,
            "networkString": "CR/COM/3101123456/hce"
          },
          {
            "policy": [
              "urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
            ],
            "type": {
              "coding": [
                {
                  "code": "IRCP",
                  "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
                  "display": "information recipient"
                }
              ]
            },
            "who": {
              "reference": "PractitionerRole/ejemplo-rol-medicina-interna",
              "display": "Ricardo Castro Brenes"
            },
            "requestor": true
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "EPI-2025-118230"
              },
              "display": "Epicrisis de una hospitalización en salud mental"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "R",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "PSY",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
                    "display": "psychiatry disorder information sensitivity"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
                "value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
              }
            }
          }
        ],
        "outcome": {
          "code": {
            "code": "success",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Operation Successful"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "ETREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "Emergency Treatment"
              }
            ],
            "text": "Tratamiento de emergencia"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-09-30T23:41:07-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        },
        "occurredDateTime": "2026-09-30T23:41:06-06:00"
      },
      "search": {
        "mode": "match"
      }
    },
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-denegado",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-laboratorio",
              "display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
            },
            "requestor": true,
            "networkString": "CR/COM/3101234567/lis-central"
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "NOT-2026-004127"
              },
              "display": "Nota de atención a una víctima de violencia doméstica"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "V",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "very restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "SDV",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          }
        ],
        "outcome": {
          "detail": [
            {
              "coding": [
                {
                  "code": "403",
                  "system": "urn:ietf:rfc:7231",
                  "display": "Forbidden"
                }
              ],
              "text": "Acceso denegado: el documento es de confidencialidad V"
            }
          ],
          "code": {
            "code": "error",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Error"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "TREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "treatment"
              }
            ],
            "text": "Tratamiento"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-10-01T09:12:44-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        }
      },
      "search": {
        "mode": "match"
      }
    }
  ]
}

Buscar por datos accedidos
Forma: GET [base]/AuditEvent?entity=Patient/{id}

Trae los eventos sobre un recurso concreto; por ejemplo, quién leyó un documento. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: entity=Patient/ejemplo-paciente-nacional.

Solicitud

GET [base]/AuditEvent?entity=Patient/ejemplo-paciente-nacional HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]

Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6)

HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
  "resourceType": "Bundle",
  "type": "searchset",
  "total": 2,
  "link": [
    {
      "relation": "self",
      "url": "[base]/AuditEvent?entity=Patient/ejemplo-paciente-nacional"
    }
  ],
  "entry": [
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-emergencia",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-hce-hospital",
              "display": "Expediente electrónico del Hospital Privado de Ejemplo"
            },
            "requestor": false,
            "networkString": "CR/COM/3101123456/hce"
          },
          {
            "policy": [
              "urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
            ],
            "type": {
              "coding": [
                {
                  "code": "IRCP",
                  "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
                  "display": "information recipient"
                }
              ]
            },
            "who": {
              "reference": "PractitionerRole/ejemplo-rol-medicina-interna",
              "display": "Ricardo Castro Brenes"
            },
            "requestor": true
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "EPI-2025-118230"
              },
              "display": "Epicrisis de una hospitalización en salud mental"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "R",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "PSY",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
                    "display": "psychiatry disorder information sensitivity"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
                "value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
              }
            }
          }
        ],
        "outcome": {
          "code": {
            "code": "success",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Operation Successful"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "ETREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "Emergency Treatment"
              }
            ],
            "text": "Tratamiento de emergencia"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-09-30T23:41:07-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        },
        "occurredDateTime": "2026-09-30T23:41:06-06:00"
      },
      "search": {
        "mode": "match"
      }
    },
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-denegado",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-laboratorio",
              "display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
            },
            "requestor": true,
            "networkString": "CR/COM/3101234567/lis-central"
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "NOT-2026-004127"
              },
              "display": "Nota de atención a una víctima de violencia doméstica"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "V",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "very restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "SDV",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          }
        ],
        "outcome": {
          "detail": [
            {
              "coding": [
                {
                  "code": "403",
                  "system": "urn:ietf:rfc:7231",
                  "display": "Forbidden"
                }
              ],
              "text": "Acceso denegado: el documento es de confidencialidad V"
            }
          ],
          "code": {
            "code": "error",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Error"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "TREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "treatment"
              }
            ],
            "text": "Tratamiento"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-10-01T09:12:44-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        }
      },
      "search": {
        "mode": "match"
      }
    }
  ]
}

Buscar por categoría
Forma: GET [base]/AuditEvent?category={sistema}|{código}

Separa los tipos de evento: las llamadas a la API (rest), las autenticaciones y las alertas de seguridad. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: category=http://terminology.hl7.org/CodeSystem/audit-event-type|rest.

Solicitud

GET [base]/AuditEvent?category=http://terminology.hl7.org/CodeSystem/audit-event-type|rest HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]

Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6)

HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
  "resourceType": "Bundle",
  "type": "searchset",
  "total": 2,
  "link": [
    {
      "relation": "self",
      "url": "[base]/AuditEvent?category=http://terminology.hl7.org/CodeSystem/audit-event-type|rest"
    }
  ],
  "entry": [
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-emergencia",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-hce-hospital",
              "display": "Expediente electrónico del Hospital Privado de Ejemplo"
            },
            "requestor": false,
            "networkString": "CR/COM/3101123456/hce"
          },
          {
            "policy": [
              "urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
            ],
            "type": {
              "coding": [
                {
                  "code": "IRCP",
                  "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
                  "display": "information recipient"
                }
              ]
            },
            "who": {
              "reference": "PractitionerRole/ejemplo-rol-medicina-interna",
              "display": "Ricardo Castro Brenes"
            },
            "requestor": true
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "EPI-2025-118230"
              },
              "display": "Epicrisis de una hospitalización en salud mental"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "R",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "PSY",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
                    "display": "psychiatry disorder information sensitivity"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
                "value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
              }
            }
          }
        ],
        "outcome": {
          "code": {
            "code": "success",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Operation Successful"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "ETREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "Emergency Treatment"
              }
            ],
            "text": "Tratamiento de emergencia"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-09-30T23:41:07-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        },
        "occurredDateTime": "2026-09-30T23:41:06-06:00"
      },
      "search": {
        "mode": "match"
      }
    },
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-denegado",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-laboratorio",
              "display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
            },
            "requestor": true,
            "networkString": "CR/COM/3101234567/lis-central"
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "NOT-2026-004127"
              },
              "display": "Nota de atención a una víctima de violencia doméstica"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "V",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "very restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "SDV",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          }
        ],
        "outcome": {
          "detail": [
            {
              "coding": [
                {
                  "code": "403",
                  "system": "urn:ietf:rfc:7231",
                  "display": "Forbidden"
                }
              ],
              "text": "Acceso denegado: el documento es de confidencialidad V"
            }
          ],
          "code": {
            "code": "error",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Error"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "TREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "treatment"
              }
            ],
            "text": "Tratamiento"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-10-01T09:12:44-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        }
      },
      "search": {
        "mode": "match"
      }
    }
  ]
}

Buscar por código
Forma: GET [base]/AuditEvent?code={sistema}|{código}

Busca por la operación que se hizo; por ejemplo, todas las lecturas (read). En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: code=http://hl7.org/fhir/restful-interaction|read.

Solicitud

GET [base]/AuditEvent?code=http://hl7.org/fhir/restful-interaction|read HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]

Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6)

HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
  "resourceType": "Bundle",
  "type": "searchset",
  "total": 2,
  "link": [
    {
      "relation": "self",
      "url": "[base]/AuditEvent?code=http://hl7.org/fhir/restful-interaction|read"
    }
  ],
  "entry": [
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-emergencia",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-hce-hospital",
              "display": "Expediente electrónico del Hospital Privado de Ejemplo"
            },
            "requestor": false,
            "networkString": "CR/COM/3101123456/hce"
          },
          {
            "policy": [
              "urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
            ],
            "type": {
              "coding": [
                {
                  "code": "IRCP",
                  "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
                  "display": "information recipient"
                }
              ]
            },
            "who": {
              "reference": "PractitionerRole/ejemplo-rol-medicina-interna",
              "display": "Ricardo Castro Brenes"
            },
            "requestor": true
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "EPI-2025-118230"
              },
              "display": "Epicrisis de una hospitalización en salud mental"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "R",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "PSY",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
                    "display": "psychiatry disorder information sensitivity"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
                "value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
              }
            }
          }
        ],
        "outcome": {
          "code": {
            "code": "success",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Operation Successful"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "ETREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "Emergency Treatment"
              }
            ],
            "text": "Tratamiento de emergencia"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-09-30T23:41:07-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        },
        "occurredDateTime": "2026-09-30T23:41:06-06:00"
      },
      "search": {
        "mode": "match"
      }
    },
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-denegado",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-laboratorio",
              "display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
            },
            "requestor": true,
            "networkString": "CR/COM/3101234567/lis-central"
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "NOT-2026-004127"
              },
              "display": "Nota de atención a una víctima de violencia doméstica"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "V",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "very restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "SDV",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          }
        ],
        "outcome": {
          "detail": [
            {
              "coding": [
                {
                  "code": "403",
                  "system": "urn:ietf:rfc:7231",
                  "display": "Forbidden"
                }
              ],
              "text": "Acceso denegado: el documento es de confidencialidad V"
            }
          ],
          "code": {
            "code": "error",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Error"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "TREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "treatment"
              }
            ],
            "text": "Tratamiento"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-10-01T09:12:44-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        }
      },
      "search": {
        "mode": "match"
      }
    }
  ]
}

Buscar por acción
Forma: GET [base]/AuditEvent?action={código}

Busca por acción: C (crear), R (leer), U (actualizar), D (borrar) o E (ejecutar). En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: action=R.

Solicitud

GET [base]/AuditEvent?action=R HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]

Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6)

HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
  "resourceType": "Bundle",
  "type": "searchset",
  "total": 2,
  "link": [
    {
      "relation": "self",
      "url": "[base]/AuditEvent?action=R"
    }
  ],
  "entry": [
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-emergencia",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-hce-hospital",
              "display": "Expediente electrónico del Hospital Privado de Ejemplo"
            },
            "requestor": false,
            "networkString": "CR/COM/3101123456/hce"
          },
          {
            "policy": [
              "urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
            ],
            "type": {
              "coding": [
                {
                  "code": "IRCP",
                  "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
                  "display": "information recipient"
                }
              ]
            },
            "who": {
              "reference": "PractitionerRole/ejemplo-rol-medicina-interna",
              "display": "Ricardo Castro Brenes"
            },
            "requestor": true
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "EPI-2025-118230"
              },
              "display": "Epicrisis de una hospitalización en salud mental"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "R",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "PSY",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
                    "display": "psychiatry disorder information sensitivity"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
                "value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
              }
            }
          }
        ],
        "outcome": {
          "code": {
            "code": "success",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Operation Successful"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "ETREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "Emergency Treatment"
              }
            ],
            "text": "Tratamiento de emergencia"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-09-30T23:41:07-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        },
        "occurredDateTime": "2026-09-30T23:41:06-06:00"
      },
      "search": {
        "mode": "match"
      }
    },
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-denegado",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-laboratorio",
              "display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
            },
            "requestor": true,
            "networkString": "CR/COM/3101234567/lis-central"
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "NOT-2026-004127"
              },
              "display": "Nota de atención a una víctima de violencia doméstica"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "V",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "very restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "SDV",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          }
        ],
        "outcome": {
          "detail": [
            {
              "coding": [
                {
                  "code": "403",
                  "system": "urn:ietf:rfc:7231",
                  "display": "Forbidden"
                }
              ],
              "text": "Acceso denegado: el documento es de confidencialidad V"
            }
          ],
          "code": {
            "code": "error",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Error"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "TREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "treatment"
              }
            ],
            "text": "Tratamiento"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-10-01T09:12:44-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        }
      },
      "search": {
        "mode": "match"
      }
    }
  ]
}

Buscar por resultado
Forma: GET [base]/AuditEvent?outcome={sistema}|{código}

Busca por resultado. Los eventos que no son success, como los accesos denegados, son los que más interesan a la seguridad. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: outcome=http://hl7.org/fhir/issue-severity|success.

Solicitud

GET [base]/AuditEvent?outcome=http://hl7.org/fhir/issue-severity|success HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]

Respuesta: 1 resultado: Acceso de emergencia a un documento restringido (E2)

HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
  "resourceType": "Bundle",
  "type": "searchset",
  "total": 1,
  "link": [
    {
      "relation": "self",
      "url": "[base]/AuditEvent?outcome=http://hl7.org/fhir/issue-severity|success"
    }
  ],
  "entry": [
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-emergencia",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-hce-hospital",
              "display": "Expediente electrónico del Hospital Privado de Ejemplo"
            },
            "requestor": false,
            "networkString": "CR/COM/3101123456/hce"
          },
          {
            "policy": [
              "urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
            ],
            "type": {
              "coding": [
                {
                  "code": "IRCP",
                  "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
                  "display": "information recipient"
                }
              ]
            },
            "who": {
              "reference": "PractitionerRole/ejemplo-rol-medicina-interna",
              "display": "Ricardo Castro Brenes"
            },
            "requestor": true
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "EPI-2025-118230"
              },
              "display": "Epicrisis de una hospitalización en salud mental"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "R",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "PSY",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
                    "display": "psychiatry disorder information sensitivity"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
                "value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
              }
            }
          }
        ],
        "outcome": {
          "code": {
            "code": "success",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Operation Successful"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "ETREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "Emergency Treatment"
              }
            ],
            "text": "Tratamiento de emergencia"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-09-30T23:41:07-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        },
        "occurredDateTime": "2026-09-30T23:41:06-06:00"
      },
      "search": {
        "mode": "match"
      }
    }
  ]
}

Buscar por propósito de uso
Forma: GET [base]/AuditEvent?purpose={sistema}|{código}

Busca por propósito de uso. Los accesos de emergencia (ETREAT) a datos restringidos se revisan después. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: purpose=http://terminology.hl7.org/CodeSystem/v3-ActReason|ETREAT.

Solicitud

GET [base]/AuditEvent?purpose=http://terminology.hl7.org/CodeSystem/v3-ActReason|ETREAT HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]

Respuesta: 1 resultado: Acceso de emergencia a un documento restringido (E2)

HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
  "resourceType": "Bundle",
  "type": "searchset",
  "total": 1,
  "link": [
    {
      "relation": "self",
      "url": "[base]/AuditEvent?purpose=http://terminology.hl7.org/CodeSystem/v3-ActReason|ETREAT"
    }
  ],
  "entry": [
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-emergencia",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-hce-hospital",
              "display": "Expediente electrónico del Hospital Privado de Ejemplo"
            },
            "requestor": false,
            "networkString": "CR/COM/3101123456/hce"
          },
          {
            "policy": [
              "urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
            ],
            "type": {
              "coding": [
                {
                  "code": "IRCP",
                  "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
                  "display": "information recipient"
                }
              ]
            },
            "who": {
              "reference": "PractitionerRole/ejemplo-rol-medicina-interna",
              "display": "Ricardo Castro Brenes"
            },
            "requestor": true
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "EPI-2025-118230"
              },
              "display": "Epicrisis de una hospitalización en salud mental"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "R",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "PSY",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
                    "display": "psychiatry disorder information sensitivity"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
                "value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
              }
            }
          }
        ],
        "outcome": {
          "code": {
            "code": "success",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Operation Successful"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "ETREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "Emergency Treatment"
              }
            ],
            "text": "Tratamiento de emergencia"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-09-30T23:41:07-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        },
        "occurredDateTime": "2026-09-30T23:41:06-06:00"
      },
      "search": {
        "mode": "match"
      }
    }
  ]
}

Buscar por fuente
Forma: GET [base]/AuditEvent?source=Device/{id}

Trae los eventos que registró un sistema. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: source=Device/ejemplo-sistema-repositorio.

Solicitud

GET [base]/AuditEvent?source=Device/ejemplo-sistema-repositorio HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]

Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6)

HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
  "resourceType": "Bundle",
  "type": "searchset",
  "total": 2,
  "link": [
    {
      "relation": "self",
      "url": "[base]/AuditEvent?source=Device/ejemplo-sistema-repositorio"
    }
  ],
  "entry": [
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-emergencia",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-hce-hospital",
              "display": "Expediente electrónico del Hospital Privado de Ejemplo"
            },
            "requestor": false,
            "networkString": "CR/COM/3101123456/hce"
          },
          {
            "policy": [
              "urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
            ],
            "type": {
              "coding": [
                {
                  "code": "IRCP",
                  "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
                  "display": "information recipient"
                }
              ]
            },
            "who": {
              "reference": "PractitionerRole/ejemplo-rol-medicina-interna",
              "display": "Ricardo Castro Brenes"
            },
            "requestor": true
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "EPI-2025-118230"
              },
              "display": "Epicrisis de una hospitalización en salud mental"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "R",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "PSY",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
                    "display": "psychiatry disorder information sensitivity"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
                "value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
              }
            }
          }
        ],
        "outcome": {
          "code": {
            "code": "success",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Operation Successful"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "ETREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "Emergency Treatment"
              }
            ],
            "text": "Tratamiento de emergencia"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-09-30T23:41:07-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        },
        "occurredDateTime": "2026-09-30T23:41:06-06:00"
      },
      "search": {
        "mode": "match"
      }
    },
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-denegado",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-laboratorio",
              "display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
            },
            "requestor": true,
            "networkString": "CR/COM/3101234567/lis-central"
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "NOT-2026-004127"
              },
              "display": "Nota de atención a una víctima de violencia doméstica"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "V",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "very restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "SDV",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          }
        ],
        "outcome": {
          "detail": [
            {
              "coding": [
                {
                  "code": "403",
                  "system": "urn:ietf:rfc:7231",
                  "display": "Forbidden"
                }
              ],
              "text": "Acceso denegado: el documento es de confidencialidad V"
            }
          ],
          "code": {
            "code": "error",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Error"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "TREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "treatment"
              }
            ],
            "text": "Tratamiento"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-10-01T09:12:44-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        }
      },
      "search": {
        "mode": "match"
      }
    }
  ]
}

Buscar por paciente, con POST
Forma: POST [base]/AuditEvent/_search
cuerpo: patient=Patient/{id}

Hace cualquier búsqueda con POST: los parámetros van en el cuerpo, como un formulario, en lugar de la URL. Se usa cuando los valores son datos personales, como una cédula, para que no queden en los registros de los servidores ni en el historial; la respuesta es la misma que con GET. En el ejemplo se repite la búsqueda por paciente.

Solicitud

POST [base]/AuditEvent/_search HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Content-Type: application/x-www-form-urlencoded

patient=Patient/ejemplo-paciente-nacional

Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6), igual que con GET

HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
  "resourceType": "Bundle",
  "type": "searchset",
  "total": 2,
  "link": [
    {
      "relation": "self",
      "url": "[base]/AuditEvent?patient=Patient/ejemplo-paciente-nacional"
    }
  ],
  "entry": [
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-emergencia",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-hce-hospital",
              "display": "Expediente electrónico del Hospital Privado de Ejemplo"
            },
            "requestor": false,
            "networkString": "CR/COM/3101123456/hce"
          },
          {
            "policy": [
              "urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
            ],
            "type": {
              "coding": [
                {
                  "code": "IRCP",
                  "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
                  "display": "information recipient"
                }
              ]
            },
            "who": {
              "reference": "PractitionerRole/ejemplo-rol-medicina-interna",
              "display": "Ricardo Castro Brenes"
            },
            "requestor": true
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "EPI-2025-118230"
              },
              "display": "Epicrisis de una hospitalización en salud mental"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "R",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "PSY",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
                    "display": "psychiatry disorder information sensitivity"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
                "value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
              }
            }
          }
        ],
        "outcome": {
          "code": {
            "code": "success",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Operation Successful"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "ETREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "Emergency Treatment"
              }
            ],
            "text": "Tratamiento de emergencia"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-09-30T23:41:07-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        },
        "occurredDateTime": "2026-09-30T23:41:06-06:00"
      },
      "search": {
        "mode": "match"
      }
    },
    {
      "fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
      "resource": {
        "resourceType": "AuditEvent",
        "id": "ejemplo-auditoria-denegado",
        "meta": {
          "versionId": "1",
          "lastUpdated": "2026-10-01T10:00:00-06:00",
          "profile": [
            "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
          ]
        },
        "category": [
          {
            "coding": [
              {
                "code": "rest",
                "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
                "display": "RESTful Operation"
              }
            ]
          }
        ],
        "source": {
          "type": [
            {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
                  "display": "Application Server"
                }
              ]
            }
          ],
          "observer": {
            "reference": "Device/ejemplo-sistema-repositorio",
            "display": "Repositorio de documentos del HIE"
          }
        },
        "agent": [
          {
            "type": {
              "coding": [
                {
                  "code": "110153",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Source Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-repositorio",
              "display": "Repositorio de documentos del HIE"
            },
            "requestor": false,
            "networkUri": "https://hie.example.cr/fhir"
          },
          {
            "type": {
              "coding": [
                {
                  "code": "110152",
                  "system": "http://dicom.nema.org/resources/ontology/DCM",
                  "display": "Destination Role ID"
                }
              ]
            },
            "who": {
              "reference": "Device/ejemplo-sistema-laboratorio",
              "display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
            },
            "requestor": true,
            "networkString": "CR/COM/3101234567/lis-central"
          }
        ],
        "entity": [
          {
            "role": {
              "coding": [
                {
                  "code": "1",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Patient"
                }
              ]
            },
            "what": {
              "reference": "Patient/ejemplo-paciente-nacional",
              "display": "Laura Patricia Solís Araya"
            }
          },
          {
            "what": {
              "identifier": {
                "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
                "value": "NOT-2026-004127"
              },
              "display": "Nota de atención a una víctima de violencia doméstica"
            },
            "securityLabel": [
              {
                "coding": [
                  {
                    "code": "V",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
                    "display": "very restricted"
                  }
                ]
              },
              {
                "coding": [
                  {
                    "code": "SDV",
                    "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
                  }
                ]
              }
            ],
            "role": {
              "coding": [
                {
                  "code": "4",
                  "system": "http://terminology.hl7.org/CodeSystem/object-role",
                  "display": "Domain Resource"
                }
              ]
            }
          }
        ],
        "outcome": {
          "detail": [
            {
              "coding": [
                {
                  "code": "403",
                  "system": "urn:ietf:rfc:7231",
                  "display": "Forbidden"
                }
              ],
              "text": "Acceso denegado: el documento es de confidencialidad V"
            }
          ],
          "code": {
            "code": "error",
            "system": "http://hl7.org/fhir/issue-severity",
            "display": "Error"
          }
        },
        "authorization": [
          {
            "coding": [
              {
                "code": "TREAT",
                "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
                "display": "treatment"
              }
            ],
            "text": "Tratamiento"
          }
        ],
        "code": {
          "coding": [
            {
              "code": "read",
              "system": "http://hl7.org/fhir/restful-interaction",
              "display": "read"
            }
          ]
        },
        "action": "R",
        "recorded": "2026-10-01T09:12:44-06:00",
        "patient": {
          "reference": "Patient/ejemplo-paciente-nacional",
          "display": "Laura Patricia Solís Araya"
        }
      },
      "search": {
        "mode": "match"
      }
    }
  ]
}
Crear

Crear
Forma: POST [base]/AuditEvent

Registra un evento de auditoría en el repositorio de auditoría. El servidor valida el recurso contra el perfil, le asigna su id y devuelve su dirección. Lo hace cada sistema del HIE al terminar una operación sobre datos, también si la operación falló (IHE ATNA ITI-20). En el ejemplo se registra «Acceso de emergencia a un documento restringido (E2)»; la segunda respuesta es el rechazo de un recurso que no cumple la invariante cr-auditoria-rest (Un evento rest lleva el código de la interacción REST).

Solicitud

POST [base]/AuditEvent HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Content-Type: application/fhir+json
{
  "resourceType": "AuditEvent",
  "meta": {
    "profile": [
      "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
    ]
  },
  "category": [
    {
      "coding": [
        {
          "code": "rest",
          "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
          "display": "RESTful Operation"
        }
      ]
    }
  ],
  "source": {
    "type": [
      {
        "coding": [
          {
            "code": "4",
            "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
            "display": "Application Server"
          }
        ]
      }
    ],
    "observer": {
      "reference": "Device/ejemplo-sistema-repositorio",
      "display": "Repositorio de documentos del HIE"
    }
  },
  "agent": [
    {
      "type": {
        "coding": [
          {
            "code": "110153",
            "system": "http://dicom.nema.org/resources/ontology/DCM",
            "display": "Source Role ID"
          }
        ]
      },
      "who": {
        "reference": "Device/ejemplo-sistema-repositorio",
        "display": "Repositorio de documentos del HIE"
      },
      "requestor": false,
      "networkUri": "https://hie.example.cr/fhir"
    },
    {
      "type": {
        "coding": [
          {
            "code": "110152",
            "system": "http://dicom.nema.org/resources/ontology/DCM",
            "display": "Destination Role ID"
          }
        ]
      },
      "who": {
        "reference": "Device/ejemplo-sistema-hce-hospital",
        "display": "Expediente electrónico del Hospital Privado de Ejemplo"
      },
      "requestor": false,
      "networkString": "CR/COM/3101123456/hce"
    },
    {
      "policy": [
        "urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
      ],
      "type": {
        "coding": [
          {
            "code": "IRCP",
            "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
            "display": "information recipient"
          }
        ]
      },
      "who": {
        "reference": "PractitionerRole/ejemplo-rol-medicina-interna",
        "display": "Ricardo Castro Brenes"
      },
      "requestor": true
    }
  ],
  "entity": [
    {
      "role": {
        "coding": [
          {
            "code": "1",
            "system": "http://terminology.hl7.org/CodeSystem/object-role",
            "display": "Patient"
          }
        ]
      },
      "what": {
        "reference": "Patient/ejemplo-paciente-nacional",
        "display": "Laura Patricia Solís Araya"
      }
    },
    {
      "what": {
        "identifier": {
          "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
          "value": "EPI-2025-118230"
        },
        "display": "Epicrisis de una hospitalización en salud mental"
      },
      "securityLabel": [
        {
          "coding": [
            {
              "code": "R",
              "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
              "display": "restricted"
            }
          ]
        },
        {
          "coding": [
            {
              "code": "PSY",
              "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
              "display": "psychiatry disorder information sensitivity"
            }
          ]
        }
      ],
      "role": {
        "coding": [
          {
            "code": "4",
            "system": "http://terminology.hl7.org/CodeSystem/object-role",
            "display": "Domain Resource"
          }
        ]
      }
    },
    {
      "what": {
        "identifier": {
          "system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
          "value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
        }
      }
    }
  ],
  "outcome": {
    "code": {
      "code": "success",
      "system": "http://hl7.org/fhir/issue-severity",
      "display": "Operation Successful"
    }
  },
  "authorization": [
    {
      "coding": [
        {
          "code": "ETREAT",
          "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
          "display": "Emergency Treatment"
        }
      ],
      "text": "Tratamiento de emergencia"
    }
  ],
  "code": {
    "coding": [
      {
        "code": "read",
        "system": "http://hl7.org/fhir/restful-interaction",
        "display": "read"
      }
    ]
  },
  "action": "R",
  "recorded": "2026-09-30T23:41:07-06:00",
  "patient": {
    "reference": "Patient/ejemplo-paciente-nacional",
    "display": "Laura Patricia Solís Araya"
  },
  "occurredDateTime": "2026-09-30T23:41:06-06:00"
}

Respuesta si se crea

HTTP/1.1 201 Created
Location: [base]/AuditEvent/ejemplo-auditoria-emergencia/_history/1
ETag: W/"1"
Last-Modified: 2026-10-01T10:00:00-06:00
Content-Type: application/fhir+json
{
  "resourceType": "AuditEvent",
  "id": "ejemplo-auditoria-emergencia",
  "meta": {
    "versionId": "1",
    "lastUpdated": "2026-10-01T10:00:00-06:00",
    "profile": [
      "https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
    ]
  },
  "category": [
    {
      "coding": [
        {
          "code": "rest",
          "system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
          "display": "RESTful Operation"
        }
      ]
    }
  ],
  "source": {
    "type": [
      {
        "coding": [
          {
            "code": "4",
            "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
            "display": "Application Server"
          }
        ]
      }
    ],
    "observer": {
      "reference": "Device/ejemplo-sistema-repositorio",
      "display": "Repositorio de documentos del HIE"
    }
  },
  "agent": [
    {
      "type": {
        "coding": [
          {
            "code": "110153",
            "system": "http://dicom.nema.org/resources/ontology/DCM",
            "display": "Source Role ID"
          }
        ]
      },
      "who": {
        "reference": "Device/ejemplo-sistema-repositorio",
        "display": "Repositorio de documentos del HIE"
      },
      "requestor": false,
      "networkUri": "https://hie.example.cr/fhir"
    },
    {
      "type": {
        "coding": [
          {
            "code": "110152",
            "system": "http://dicom.nema.org/resources/ontology/DCM",
            "display": "Destination Role ID"
          }
        ]
      },
      "who": {
        "reference": "Device/ejemplo-sistema-hce-hospital",
        "display": "Expediente electrónico del Hospital Privado de Ejemplo"
      },
      "requestor": false,
      "networkString": "CR/COM/3101123456/hce"
    },
    {
      "policy": [
        "urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
      ],
      "type": {
        "coding": [
          {
            "code": "IRCP",
            "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
            "display": "information recipient"
          }
        ]
      },
      "who": {
        "reference": "PractitionerRole/ejemplo-rol-medicina-interna",
        "display": "Ricardo Castro Brenes"
      },
      "requestor": true
    }
  ],
  "entity": [
    {
      "role": {
        "coding": [
          {
            "code": "1",
            "system": "http://terminology.hl7.org/CodeSystem/object-role",
            "display": "Patient"
          }
        ]
      },
      "what": {
        "reference": "Patient/ejemplo-paciente-nacional",
        "display": "Laura Patricia Solís Araya"
      }
    },
    {
      "what": {
        "identifier": {
          "system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
          "value": "EPI-2025-118230"
        },
        "display": "Epicrisis de una hospitalización en salud mental"
      },
      "securityLabel": [
        {
          "coding": [
            {
              "code": "R",
              "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
              "display": "restricted"
            }
          ]
        },
        {
          "coding": [
            {
              "code": "PSY",
              "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
              "display": "psychiatry disorder information sensitivity"
            }
          ]
        }
      ],
      "role": {
        "coding": [
          {
            "code": "4",
            "system": "http://terminology.hl7.org/CodeSystem/object-role",
            "display": "Domain Resource"
          }
        ]
      }
    },
    {
      "what": {
        "identifier": {
          "system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
          "value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
        }
      }
    }
  ],
  "outcome": {
    "code": {
      "code": "success",
      "system": "http://hl7.org/fhir/issue-severity",
      "display": "Operation Successful"
    }
  },
  "authorization": [
    {
      "coding": [
        {
          "code": "ETREAT",
          "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
          "display": "Emergency Treatment"
        }
      ],
      "text": "Tratamiento de emergencia"
    }
  ],
  "code": {
    "coding": [
      {
        "code": "read",
        "system": "http://hl7.org/fhir/restful-interaction",
        "display": "read"
      }
    ]
  },
  "action": "R",
  "recorded": "2026-09-30T23:41:07-06:00",
  "patient": {
    "reference": "Patient/ejemplo-paciente-nacional",
    "display": "Laura Patricia Solís Araya"
  },
  "occurredDateTime": "2026-09-30T23:41:06-06:00"
}

Respuesta si no cumple el perfil (invariante cr-auditoria-rest)

HTTP/1.1 422 Unprocessable Entity
Content-Type: application/fhir+json
{
  "resourceType": "OperationOutcome",
  "issue": [
    {
      "severity": "error",
      "code": "invariant",
      "diagnostics": "cr-auditoria-rest: Un evento rest lleva el código de la interacción REST.",
      "expression": [
        "AuditEvent"
      ]
    }
  ]
}