Guía de Implementación Core de Costa Rica
0.1.0 - ci-build
Guía de Implementación Core de Costa Rica - Versión en desarrollo (v0.1.0): borrador de trabajo de la Iniciativa HL7® Costa Rica, que puede cambiar sin aviso.
| URL oficial: https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent | Versión: 0.1.0 | ||||
| Standards status: Draft | Nombre computable: CRAuditEvent | ||||
Registro de un acceso u operación sobre datos en el HIE de Costa Rica: quién lo hizo, desde qué sistema, con qué propósito, sobre qué datos de qué paciente y con qué resultado, incluidos los intentos fallidos. Adapta IHE BALP a FHIR R5.
Usos:
También puede consultar los usos en las estadísticas de IG de FHIR
Descripción de perfiles, diferenciales, instantáneas y sus representaciones.
| Nombre | Marcas | Card. | Tipo | Descripción y restricciones Filter: ![]() ![]() |
|---|---|---|---|---|
![]() |
C | 0..* | AuditEvent | Evento de auditoría: quién accedió a qué y con qué resultado Constraints: cr-auditoria-rest, cr-auditoria-accion, cr-auditoria-detalle, cr-auditoria-proposito, cr-auditoria-agentes, cr-auditoria-red, cr-auditoria-solicitante, cr-auditoria-paciente, cr-auditoria-entidades, cr-auditoria-fechas |
![]() ![]() |
?!Σ | 0..1 | uri | A set of rules under which this content was created |
![]() ![]() |
0..* | Resource | Contained, inline Resources | |
![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored |
![]() ![]() |
SΣ | 1..1 | CodeableConcept | Categoría: rest | 110114 (autenticación) | 110113 (alerta de seguridad) Vinculación: Categoría del evento de auditoría (required) |
![]() ![]() |
SΣ | 1..1 | CodeableConcept | Qué se hizo: la interacción REST (read, search, create...) o el evento de DICOM Vinculación: AuditEventSubType (example): Specific type of event. |
![]() ![]() |
SΣ | 1..1 | code | C | R | U | D | E, coherente con el código Vinculación: AuditEventAction (required): DICOM Audit Event Action |
![]() ![]() |
SC | 0..1 | dateTime | Cuándo ocurrió el evento (no posterior al registro) Constraints: cr-documento-fecha-hora |
![]() ![]() |
SΣ | 1..1 | instant | Cuándo se registró el evento |
![]() ![]() |
SΣ | 1..1 | BackboneElement | Resultado del evento, también en los fallos |
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized |
![]() ![]() ![]() |
SΣ | 1..1 | Coding | success | warning | error | fatal Vinculación: AuditEventOutcome (required) |
![]() ![]() ![]() |
SΣ | 0..* | CodeableConcept | Detalle (código HTTP y texto), sin datos clínicos Vinculación: AuditEventOutcomeDetail (example): A code that provides details as the exact issue. |
![]() ![]() |
SΣ | 0..1 | CodeableConcept | Propósito de uso: TREAT | ETREAT | COC | PATRQT | PUBHLTH | HRESCH | HOPERAT | HSYSADMIN | HLEGAL Vinculación: Propósito de uso (required) |
![]() ![]() |
S | 0..1 | Reference(Paciente) | Paciente de los datos (un evento por paciente) |
![]() ![]() |
SΣ | 2..* | BackboneElement | El cliente, el servidor y, si la hace una persona, el usuario |
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized |
![]() ![]() ![]() |
S | 1..1 | CodeableConcept | 110152 (destino) | 110153 (origen) | IRCP (usuario) Vinculación: Tipo de agente de auditoría (required) |
![]() ![]() ![]() |
SΣ | 1..1 | Reference(Sistema de información | Rol del profesional | Profesional de salud | Paciente) | El sistema registrado en el HIE, o la persona usuaria |
![]() ![]() ![]() |
SΣ | 0..1 | boolean | true para el usuario o, si no hay usuario, para el cliente |
![]() ![]() ![]() |
S | 0..1 | uri | Identificador del token (jti) del usuario |
![]() ![]() ![]() |
S | 0..1 | Red: la IP o el subsistema X-Road del cliente, la URL del servidor | |
![]() ![]() ![]() ![]() |
Reference(Endpoint) | |||
![]() ![]() ![]() ![]() |
uri | |||
![]() ![]() ![]() ![]() |
string | |||
![]() ![]() |
SΣ | 1..1 | BackboneElement | Quién registró el evento |
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized |
![]() ![]() ![]() |
Σ | 1..1 | Reference(Sistema de información) | El sistema que registró el evento |
![]() ![]() ![]() |
S | 1..1 | CodeableConcept | Tipo de la fuente (4: servidor de aplicaciones) Vinculación: AuditEventSourceType (required) |
![]() ![]() |
SΣ | 0..* | BackboneElement | El paciente, los datos, la consulta y la transacción |
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized |
![]() ![]() ![]() |
SΣ | 0..1 | Reference(Resource) | El recurso (la versión concreta si se conoce) o el identificador de la transacción |
![]() ![]() ![]() |
S | 0..1 | CodeableConcept | 1 (paciente) | 4 (datos) | 24 (consulta); sin role, la transacción Vinculación: AuditEventEntityRole (required) |
![]() ![]() ![]() |
S | 0..* | CodeableConcept | Las etiquetas de seguridad del recurso Vinculación: SecurityLabelExamples (example): Example Security Labels from the Healthcare Privacy and Security Classification System. |
![]() ![]() ![]() |
SΣ | 0..1 | base64Binary | La consulta, en base64 (solo en la entidad consulta) |
Documentación de este formato | ||||
| Ruta | Estado | Uso | ValueSet | Versión | Fuente |
| AuditEvent.category | Base | required | Categoría del evento de auditoría | 📦0.1.0 | Guía de Implementación de Terminología de Costa Rica vnull |
| AuditEvent.code | Base | example | Audit Event Sub-Type | 📍5.0.0 | Estándar FHIR |
| AuditEvent.action | Base | required | Audit Event Action | 📍5.0.0 | Estándar FHIR |
| AuditEvent.outcome.code | Base | required | Audit Event Outcome | 📦5.0.0 | Estándar FHIR |
| AuditEvent.outcome.detail | Base | example | Audit Event Outcome Detail | 📍5.0.0 | Estándar FHIR |
| AuditEvent.authorization | Base | required | Propósito de uso | 📦0.1.0 | Guía de Implementación de Terminología de Costa Rica vnull |
| AuditEvent.agent.type | Base | required | Tipo de agente de auditoría | 📦0.1.0 | Guía de Implementación de Terminología de Costa Rica vnull |
| AuditEvent.source.type | Base | required | Audit Event Source Type | 📦5.0.0 | Estándar FHIR |
| AuditEvent.entity.role | Base | required | Audit Event Entity Role | 📦5.0.0 | Estándar FHIR |
| AuditEvent.entity.securityLabel | Base | example | Example set of Security Labels | 📍5.0.0 | Estándar FHIR |
| Id | Nivel | Ruta(s) | Descripción | Expression |
| cr-auditoria-accion | error | AuditEvent | La acción es coherente con la interacción: las lecturas, búsquedas e historias son R; create es C; update y patch son U; delete es D; las demás son E. |
code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').all(iif(code in ('read' | 'vread' | 'search' | 'search-type' | 'search-system' | 'history' | 'history-instance' | 'history-type' | 'history-system'), %resource.action = 'R', iif(code = 'create', %resource.action = 'C', iif(code in ('update' | 'patch'), %resource.action = 'U', iif(code = 'delete', %resource.action = 'D', %resource.action = 'E')))))
|
| cr-auditoria-agentes | error | AuditEvent | El evento lleva un agente cliente y un agente servidor (DICOM 110152 y 110153). |
agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110152').exists()).exists() and agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110153').exists()).exists()
|
| cr-auditoria-detalle | error | AuditEvent | Un resultado que no es success lleva su detalle. |
outcome.code.code != 'success' implies outcome.detail.exists()
|
| cr-auditoria-entidades | error | AuditEvent | Cada entidad indica el recurso (what), salvo la consulta (role 24), que indica la consulta (query). |
entity.all(iif(role.coding.where(code = '24').exists(), query.exists(), what.exists()))
|
| cr-auditoria-fechas | error | AuditEvent | La fecha del evento no es posterior a la fecha de registro. |
occurred.ofType(dateTime).empty() or occurred.ofType(dateTime) <= recorded
|
| cr-auditoria-paciente | error | AuditEvent | El paciente del evento va también como entidad con role 1 (Patient), como en IHE BALP. |
patient.exists() implies entity.where(role.coding.where(system = 'http://terminology.hl7.org/CodeSystem/object-role' and code = '1').exists()).exists()
|
| cr-auditoria-proposito | error | AuditEvent | Un evento con datos de un paciente indica el propósito de uso. |
patient.exists() implies authorization.exists()
|
| cr-auditoria-red | error | AuditEvent | El cliente y el servidor indican su red (dirección IP, subsistema X-Road o URL). |
agent.where(type.coding.where(code = '110153' or code = '110152').exists()).all(network.exists())
|
| cr-auditoria-rest | error | AuditEvent | Un evento rest lleva el código de la interacción REST. |
category.coding.where(code = 'rest').exists() implies code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').exists()
|
| cr-auditoria-solicitante | error | AuditEvent | Hay un solo solicitante (requestor = true): el usuario o, si no hay usuario, el cliente. |
agent.where(requestor = true).count() = 1
|
| cr-documento-fecha-hora | error | AuditEvent.occurred[x] | La fecha lleva fecha y hora, no solo la fecha. |
toString().contains('T')
|
| dom-2 | error | AuditEvent | If the resource is contained in another resource, it SHALL NOT contain nested Resources |
contained.contained.empty()
|
| dom-3 | error | AuditEvent | If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource |
contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().ofType(canonical) | %resource.descendants().ofType(uri) | %resource.descendants().ofType(url))) or descendants().where(reference = '#').exists() or descendants().where(ofType(canonical) = '#').exists() or descendants().where(ofType(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
|
| dom-4 | error | AuditEvent | If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated |
contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
|
| dom-5 | error | AuditEvent | If a resource is contained in another resource, it SHALL NOT have a security label |
contained.meta.security.empty()
|
| dom-6 | best practice | AuditEvent | A resource should have narrative for robust management |
text.`div`.exists()
|
| ele-1 | error | **TODOS** los elementos | All FHIR elements must have a @value or children |
hasValue() or (children().count() > id.count())
|
| ext-1 | error | **TODAS** las extensiones | Must have either extensions or value[x], not both |
extension.exists() != value.exists()
|
Esta estructura se deriva de AuditEvent .
| Nombre | Marcas | Card. | Tipo | Descripción y restricciones Filter: ![]() ![]() |
|---|---|---|---|---|
![]() |
C | 0..* | AuditEvent | Evento de auditoría: quién accedió a qué y con qué resultado Constraints: cr-auditoria-rest, cr-auditoria-accion, cr-auditoria-detalle, cr-auditoria-proposito, cr-auditoria-agentes, cr-auditoria-red, cr-auditoria-solicitante, cr-auditoria-paciente, cr-auditoria-entidades, cr-auditoria-fechas |
![]() ![]() |
S | 1..1 | CodeableConcept | Categoría: rest | 110114 (autenticación) | 110113 (alerta de seguridad) Vinculación: Categoría del evento de auditoría (required) |
![]() ![]() |
S | 1..1 | CodeableConcept | Qué se hizo: la interacción REST (read, search, create...) o el evento de DICOM |
![]() ![]() |
S | 1..1 | code | C | R | U | D | E, coherente con el código |
![]() ![]() |
SC | 0..1 | dateTime | Cuándo ocurrió el evento (no posterior al registro) Constraints: cr-documento-fecha-hora |
![]() ![]() |
S | 1..1 | instant | Cuándo se registró el evento |
![]() ![]() |
S | 1..1 | BackboneElement | Resultado del evento, también en los fallos |
![]() ![]() ![]() |
S | 1..1 | Coding | success | warning | error | fatal Vinculación: AuditEventOutcome (required) |
![]() ![]() ![]() |
S | 0..* | CodeableConcept | Detalle (código HTTP y texto), sin datos clínicos |
![]() ![]() |
S | 0..1 | CodeableConcept | Propósito de uso: TREAT | ETREAT | COC | PATRQT | PUBHLTH | HRESCH | HOPERAT | HSYSADMIN | HLEGAL Vinculación: Propósito de uso (required) |
![]() ![]() |
S | 0..1 | Reference(Paciente) | Paciente de los datos (un evento por paciente) |
![]() ![]() |
S | 2..* | BackboneElement | El cliente, el servidor y, si la hace una persona, el usuario |
![]() ![]() ![]() |
S | 1..1 | CodeableConcept | 110152 (destino) | 110153 (origen) | IRCP (usuario) Vinculación: Tipo de agente de auditoría (required) |
![]() ![]() ![]() |
S | 1..1 | Reference(Sistema de información | Rol del profesional | Profesional de salud | Paciente) | El sistema registrado en el HIE, o la persona usuaria |
![]() ![]() ![]() |
S | 0..1 | boolean | true para el usuario o, si no hay usuario, para el cliente |
![]() ![]() ![]() |
S | 0..1 | uri | Identificador del token (jti) del usuario |
![]() ![]() ![]() |
S | 0..1 | Reference(Endpoint), uri, string | Red: la IP o el subsistema X-Road del cliente, la URL del servidor |
![]() ![]() |
S | 1..1 | BackboneElement | Quién registró el evento |
![]() ![]() ![]() |
1..1 | Reference(Sistema de información) | El sistema que registró el evento | |
![]() ![]() ![]() |
S | 1..1 | CodeableConcept | Tipo de la fuente (4: servidor de aplicaciones) Vinculación: AuditEventSourceType (required) |
![]() ![]() |
S | 0..* | BackboneElement | El paciente, los datos, la consulta y la transacción |
![]() ![]() ![]() |
S | 0..1 | Reference(Resource) | El recurso (la versión concreta si se conoce) o el identificador de la transacción |
![]() ![]() ![]() |
S | 0..1 | CodeableConcept | 1 (paciente) | 4 (datos) | 24 (consulta); sin role, la transacción Vinculación: AuditEventEntityRole (required) |
![]() ![]() ![]() |
S | 0..* | CodeableConcept | Las etiquetas de seguridad del recurso |
![]() ![]() ![]() |
S | 0..1 | base64Binary | La consulta, en base64 (solo en la entidad consulta) |
Documentación de este formato | ||||
| Ruta | Estado | Uso | ValueSet | Versión | Fuente |
| AuditEvent.category | Base | required | Categoría del evento de auditoría | 📦0.1.0 | Guía de Implementación de Terminología de Costa Rica vnull |
| AuditEvent.outcome.code | Base | required | Audit Event Outcome | 📦5.0.0 | Estándar FHIR |
| AuditEvent.authorization | Base | required | Propósito de uso | 📦0.1.0 | Guía de Implementación de Terminología de Costa Rica vnull |
| AuditEvent.agent.type | Base | required | Tipo de agente de auditoría | 📦0.1.0 | Guía de Implementación de Terminología de Costa Rica vnull |
| AuditEvent.source.type | Base | required | Audit Event Source Type | 📦5.0.0 | Estándar FHIR |
| AuditEvent.entity.role | Base | required | Audit Event Entity Role | 📦5.0.0 | Estándar FHIR |
| Id | Nivel | Ruta(s) | Descripción | Expression |
| cr-auditoria-accion | error | AuditEvent | La acción es coherente con la interacción: las lecturas, búsquedas e historias son R; create es C; update y patch son U; delete es D; las demás son E. |
code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').all(iif(code in ('read' | 'vread' | 'search' | 'search-type' | 'search-system' | 'history' | 'history-instance' | 'history-type' | 'history-system'), %resource.action = 'R', iif(code = 'create', %resource.action = 'C', iif(code in ('update' | 'patch'), %resource.action = 'U', iif(code = 'delete', %resource.action = 'D', %resource.action = 'E')))))
|
| cr-auditoria-agentes | error | AuditEvent | El evento lleva un agente cliente y un agente servidor (DICOM 110152 y 110153). |
agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110152').exists()).exists() and agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110153').exists()).exists()
|
| cr-auditoria-detalle | error | AuditEvent | Un resultado que no es success lleva su detalle. |
outcome.code.code != 'success' implies outcome.detail.exists()
|
| cr-auditoria-entidades | error | AuditEvent | Cada entidad indica el recurso (what), salvo la consulta (role 24), que indica la consulta (query). |
entity.all(iif(role.coding.where(code = '24').exists(), query.exists(), what.exists()))
|
| cr-auditoria-fechas | error | AuditEvent | La fecha del evento no es posterior a la fecha de registro. |
occurred.ofType(dateTime).empty() or occurred.ofType(dateTime) <= recorded
|
| cr-auditoria-paciente | error | AuditEvent | El paciente del evento va también como entidad con role 1 (Patient), como en IHE BALP. |
patient.exists() implies entity.where(role.coding.where(system = 'http://terminology.hl7.org/CodeSystem/object-role' and code = '1').exists()).exists()
|
| cr-auditoria-proposito | error | AuditEvent | Un evento con datos de un paciente indica el propósito de uso. |
patient.exists() implies authorization.exists()
|
| cr-auditoria-red | error | AuditEvent | El cliente y el servidor indican su red (dirección IP, subsistema X-Road o URL). |
agent.where(type.coding.where(code = '110153' or code = '110152').exists()).all(network.exists())
|
| cr-auditoria-rest | error | AuditEvent | Un evento rest lleva el código de la interacción REST. |
category.coding.where(code = 'rest').exists() implies code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').exists()
|
| cr-auditoria-solicitante | error | AuditEvent | Hay un solo solicitante (requestor = true): el usuario o, si no hay usuario, el cliente. |
agent.where(requestor = true).count() = 1
|
| cr-documento-fecha-hora | error | AuditEvent.occurred[x] | La fecha lleva fecha y hora, no solo la fecha. |
toString().contains('T')
|
| Nombre | Marcas | Card. | Tipo | Descripción y restricciones Filter: ![]() ![]() | ||||
|---|---|---|---|---|---|---|---|---|
![]() |
C | 0..* | AuditEvent | Evento de auditoría: quién accedió a qué y con qué resultado Constraints: cr-auditoria-rest, cr-auditoria-accion, cr-auditoria-detalle, cr-auditoria-proposito, cr-auditoria-agentes, cr-auditoria-red, cr-auditoria-solicitante, cr-auditoria-paciente, cr-auditoria-entidades, cr-auditoria-fechas | ||||
![]() ![]() |
Σ | 0..1 | id | Logical id of this artifact | ||||
![]() ![]() |
Σ | 0..1 | Meta | Metadata about the resource | ||||
![]() ![]() |
?!Σ | 0..1 | uri | A set of rules under which this content was created | ||||
![]() ![]() |
0..1 | code | Language of the resource content Vinculación: AllLanguages (required): IETF language tag for a human language
| |||||
![]() ![]() |
0..1 | Narrative | Text summary of the resource, for human interpretation This profile does not constrain the narrative in regard to content, language, or traceability to data elements | |||||
![]() ![]() |
0..* | Resource | Contained, inline Resources | |||||
![]() ![]() |
0..* | Extension | Additional content defined by implementations | |||||
![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored | ||||
![]() ![]() |
SΣ | 1..1 | CodeableConcept | Categoría: rest | 110114 (autenticación) | 110113 (alerta de seguridad) Vinculación: Categoría del evento de auditoría (required) | ||||
![]() ![]() |
SΣ | 1..1 | CodeableConcept | Qué se hizo: la interacción REST (read, search, create...) o el evento de DICOM Vinculación: AuditEventSubType (example): Specific type of event. | ||||
![]() ![]() |
SΣ | 1..1 | code | C | R | U | D | E, coherente con el código Vinculación: AuditEventAction (required): DICOM Audit Event Action | ||||
![]() ![]() |
Σ | 0..1 | code | emergency | alert | critical | error | warning | notice | informational | debug Vinculación: AuditEventSeverity (required): This is in the SysLog header, PRI. http://tools.ietf.org/html/rfc5424#appendix-A.3 | ||||
![]() ![]() |
SC | 0..1 | dateTime | Cuándo ocurrió el evento (no posterior al registro) Constraints: cr-documento-fecha-hora | ||||
![]() ![]() |
SΣ | 1..1 | instant | Cuándo se registró el evento | ||||
![]() ![]() |
SΣ | 1..1 | BackboneElement | Resultado del evento, también en los fallos | ||||
![]() ![]() ![]() |
0..1 | string | Unique id for inter-element referencing | |||||
![]() ![]() ![]() |
0..* | Extension | Additional content defined by implementations | |||||
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized | ||||
![]() ![]() ![]() |
SΣ | 1..1 | Coding | success | warning | error | fatal Vinculación: AuditEventOutcome (required) | ||||
![]() ![]() ![]() |
SΣ | 0..* | CodeableConcept | Detalle (código HTTP y texto), sin datos clínicos Vinculación: AuditEventOutcomeDetail (example): A code that provides details as the exact issue. | ||||
![]() ![]() |
SΣ | 0..1 | CodeableConcept | Propósito de uso: TREAT | ETREAT | COC | PATRQT | PUBHLTH | HRESCH | HOPERAT | HSYSADMIN | HLEGAL Vinculación: Propósito de uso (required) | ||||
![]() ![]() |
0..* | Reference(CarePlan | DeviceRequest | ImmunizationRecommendation | MedicationRequest | NutritionOrder | ServiceRequest | Task) | Workflow authorization within which this event occurred | |||||
![]() ![]() |
S | 0..1 | Reference(Paciente) | Paciente de los datos (un evento por paciente) | ||||
![]() ![]() |
0..1 | Reference(Encounter) | Encounter within which this event occurred or which the event is tightly associated | |||||
![]() ![]() |
SΣ | 2..* | BackboneElement | El cliente, el servidor y, si la hace una persona, el usuario | ||||
![]() ![]() ![]() |
0..1 | string | Unique id for inter-element referencing | |||||
![]() ![]() ![]() |
0..* | Extension | Additional content defined by implementations | |||||
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized | ||||
![]() ![]() ![]() |
S | 1..1 | CodeableConcept | 110152 (destino) | 110153 (origen) | IRCP (usuario) Vinculación: Tipo de agente de auditoría (required) | ||||
![]() ![]() ![]() |
0..* | CodeableConcept | Agent role in the event Vinculación: SecurityRoleType (example): What security role enabled the agent to participate in the event. | |||||
![]() ![]() ![]() |
SΣ | 1..1 | Reference(Sistema de información | Rol del profesional | Profesional de salud | Paciente) | El sistema registrado en el HIE, o la persona usuaria | ||||
![]() ![]() ![]() |
SΣ | 0..1 | boolean | true para el usuario o, si no hay usuario, para el cliente | ||||
![]() ![]() ![]() |
0..1 | Reference(Location) | The agent location when the event occurred | |||||
![]() ![]() ![]() |
S | 0..1 | uri | Identificador del token (jti) del usuario | ||||
![]() ![]() ![]() |
S | 0..1 | Red: la IP o el subsistema X-Road del cliente, la URL del servidor | |||||
![]() ![]() ![]() ![]() |
Reference(Endpoint) | |||||||
![]() ![]() ![]() ![]() |
uri | |||||||
![]() ![]() ![]() ![]() |
string | |||||||
![]() ![]() ![]() |
0..* | CodeableConcept | Allowable authorization for this agent Vinculación: PurposeOfUse (example): The reason the activity took place. | |||||
![]() ![]() |
SΣ | 1..1 | BackboneElement | Quién registró el evento | ||||
![]() ![]() ![]() |
0..1 | string | Unique id for inter-element referencing | |||||
![]() ![]() ![]() |
0..* | Extension | Additional content defined by implementations | |||||
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized | ||||
![]() ![]() ![]() |
0..1 | Reference(Location) | Logical source location within the enterprise | |||||
![]() ![]() ![]() |
Σ | 1..1 | Reference(Sistema de información) | El sistema que registró el evento | ||||
![]() ![]() ![]() |
S | 1..1 | CodeableConcept | Tipo de la fuente (4: servidor de aplicaciones) Vinculación: AuditEventSourceType (required) | ||||
![]() ![]() |
SΣ | 0..* | BackboneElement | El paciente, los datos, la consulta y la transacción | ||||
![]() ![]() ![]() |
0..1 | string | Unique id for inter-element referencing | |||||
![]() ![]() ![]() |
0..* | Extension | Additional content defined by implementations | |||||
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized | ||||
![]() ![]() ![]() |
SΣ | 0..1 | Reference(Resource) | El recurso (la versión concreta si se conoce) o el identificador de la transacción | ||||
![]() ![]() ![]() |
S | 0..1 | CodeableConcept | 1 (paciente) | 4 (datos) | 24 (consulta); sin role, la transacción Vinculación: AuditEventEntityRole (required) | ||||
![]() ![]() ![]() |
S | 0..* | CodeableConcept | Las etiquetas de seguridad del recurso Vinculación: SecurityLabelExamples (example): Example Security Labels from the Healthcare Privacy and Security Classification System. | ||||
![]() ![]() ![]() |
SΣ | 0..1 | base64Binary | La consulta, en base64 (solo en la entidad consulta) | ||||
![]() ![]() ![]() |
0..* | BackboneElement | Additional Information about the entity | |||||
![]() ![]() ![]() ![]() |
0..1 | string | Unique id for inter-element referencing | |||||
![]() ![]() ![]() ![]() |
0..* | Extension | Additional content defined by implementations | |||||
![]() ![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized | ||||
![]() ![]() ![]() ![]() |
1..1 | CodeableConcept | Name of the property Vinculación: AuditEventID (example): Additional detail about an entity used in an event. | |||||
![]() ![]() ![]() ![]() |
1..1 | Property value | ||||||
![]() ![]() ![]() ![]() ![]() |
Quantity | |||||||
![]() ![]() ![]() ![]() ![]() |
CodeableConcept | |||||||
![]() ![]() ![]() ![]() ![]() |
string | |||||||
![]() ![]() ![]() ![]() ![]() |
boolean | |||||||
![]() ![]() ![]() ![]() ![]() |
integer | |||||||
![]() ![]() ![]() ![]() ![]() |
Range | |||||||
![]() ![]() ![]() ![]() ![]() |
Ratio | |||||||
![]() ![]() ![]() ![]() ![]() |
time | |||||||
![]() ![]() ![]() ![]() ![]() |
dateTime | |||||||
![]() ![]() ![]() ![]() ![]() |
Period | |||||||
![]() ![]() ![]() ![]() ![]() |
base64Binary | |||||||
![]() ![]() ![]() |
0..* | Vea agent (AuditEvent) | Entity is attributed to this agent | |||||
Documentación de este formato | ||||||||
| Id | Nivel | Ruta(s) | Descripción | Expression |
| cr-auditoria-accion | error | AuditEvent | La acción es coherente con la interacción: las lecturas, búsquedas e historias son R; create es C; update y patch son U; delete es D; las demás son E. |
code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').all(iif(code in ('read' | 'vread' | 'search' | 'search-type' | 'search-system' | 'history' | 'history-instance' | 'history-type' | 'history-system'), %resource.action = 'R', iif(code = 'create', %resource.action = 'C', iif(code in ('update' | 'patch'), %resource.action = 'U', iif(code = 'delete', %resource.action = 'D', %resource.action = 'E')))))
|
| cr-auditoria-agentes | error | AuditEvent | El evento lleva un agente cliente y un agente servidor (DICOM 110152 y 110153). |
agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110152').exists()).exists() and agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110153').exists()).exists()
|
| cr-auditoria-detalle | error | AuditEvent | Un resultado que no es success lleva su detalle. |
outcome.code.code != 'success' implies outcome.detail.exists()
|
| cr-auditoria-entidades | error | AuditEvent | Cada entidad indica el recurso (what), salvo la consulta (role 24), que indica la consulta (query). |
entity.all(iif(role.coding.where(code = '24').exists(), query.exists(), what.exists()))
|
| cr-auditoria-fechas | error | AuditEvent | La fecha del evento no es posterior a la fecha de registro. |
occurred.ofType(dateTime).empty() or occurred.ofType(dateTime) <= recorded
|
| cr-auditoria-paciente | error | AuditEvent | El paciente del evento va también como entidad con role 1 (Patient), como en IHE BALP. |
patient.exists() implies entity.where(role.coding.where(system = 'http://terminology.hl7.org/CodeSystem/object-role' and code = '1').exists()).exists()
|
| cr-auditoria-proposito | error | AuditEvent | Un evento con datos de un paciente indica el propósito de uso. |
patient.exists() implies authorization.exists()
|
| cr-auditoria-red | error | AuditEvent | El cliente y el servidor indican su red (dirección IP, subsistema X-Road o URL). |
agent.where(type.coding.where(code = '110153' or code = '110152').exists()).all(network.exists())
|
| cr-auditoria-rest | error | AuditEvent | Un evento rest lleva el código de la interacción REST. |
category.coding.where(code = 'rest').exists() implies code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').exists()
|
| cr-auditoria-solicitante | error | AuditEvent | Hay un solo solicitante (requestor = true): el usuario o, si no hay usuario, el cliente. |
agent.where(requestor = true).count() = 1
|
| cr-documento-fecha-hora | error | AuditEvent.occurred[x] | La fecha lleva fecha y hora, no solo la fecha. |
toString().contains('T')
|
| dom-2 | error | AuditEvent | If the resource is contained in another resource, it SHALL NOT contain nested Resources |
contained.contained.empty()
|
| dom-3 | error | AuditEvent | If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource |
contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().ofType(canonical) | %resource.descendants().ofType(uri) | %resource.descendants().ofType(url))) or descendants().where(reference = '#').exists() or descendants().where(ofType(canonical) = '#').exists() or descendants().where(ofType(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
|
| dom-4 | error | AuditEvent | If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated |
contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
|
| dom-5 | error | AuditEvent | If a resource is contained in another resource, it SHALL NOT have a security label |
contained.meta.security.empty()
|
| dom-6 | best practice | AuditEvent | A resource should have narrative for robust management |
text.`div`.exists()
|
| ele-1 | error | **TODOS** los elementos | All FHIR elements must have a @value or children |
hasValue() or (children().count() > id.count())
|
| ext-1 | error | **TODAS** las extensiones | Must have either extensions or value[x], not both |
extension.exists() != value.exists()
|
Esta estructura se deriva de AuditEvent .
Resumen
Obligatorios: 5 elementos
Must-Support: 23 elementos
Estructuras
Esta estructura hace referencia a estas otras estructuras:
Vista de elementos clave
| Nombre | Marcas | Card. | Tipo | Descripción y restricciones Filter: ![]() ![]() |
|---|---|---|---|---|
![]() |
C | 0..* | AuditEvent | Evento de auditoría: quién accedió a qué y con qué resultado Constraints: cr-auditoria-rest, cr-auditoria-accion, cr-auditoria-detalle, cr-auditoria-proposito, cr-auditoria-agentes, cr-auditoria-red, cr-auditoria-solicitante, cr-auditoria-paciente, cr-auditoria-entidades, cr-auditoria-fechas |
![]() ![]() |
?!Σ | 0..1 | uri | A set of rules under which this content was created |
![]() ![]() |
0..* | Resource | Contained, inline Resources | |
![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored |
![]() ![]() |
SΣ | 1..1 | CodeableConcept | Categoría: rest | 110114 (autenticación) | 110113 (alerta de seguridad) Vinculación: Categoría del evento de auditoría (required) |
![]() ![]() |
SΣ | 1..1 | CodeableConcept | Qué se hizo: la interacción REST (read, search, create...) o el evento de DICOM Vinculación: AuditEventSubType (example): Specific type of event. |
![]() ![]() |
SΣ | 1..1 | code | C | R | U | D | E, coherente con el código Vinculación: AuditEventAction (required): DICOM Audit Event Action |
![]() ![]() |
SC | 0..1 | dateTime | Cuándo ocurrió el evento (no posterior al registro) Constraints: cr-documento-fecha-hora |
![]() ![]() |
SΣ | 1..1 | instant | Cuándo se registró el evento |
![]() ![]() |
SΣ | 1..1 | BackboneElement | Resultado del evento, también en los fallos |
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized |
![]() ![]() ![]() |
SΣ | 1..1 | Coding | success | warning | error | fatal Vinculación: AuditEventOutcome (required) |
![]() ![]() ![]() |
SΣ | 0..* | CodeableConcept | Detalle (código HTTP y texto), sin datos clínicos Vinculación: AuditEventOutcomeDetail (example): A code that provides details as the exact issue. |
![]() ![]() |
SΣ | 0..1 | CodeableConcept | Propósito de uso: TREAT | ETREAT | COC | PATRQT | PUBHLTH | HRESCH | HOPERAT | HSYSADMIN | HLEGAL Vinculación: Propósito de uso (required) |
![]() ![]() |
S | 0..1 | Reference(Paciente) | Paciente de los datos (un evento por paciente) |
![]() ![]() |
SΣ | 2..* | BackboneElement | El cliente, el servidor y, si la hace una persona, el usuario |
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized |
![]() ![]() ![]() |
S | 1..1 | CodeableConcept | 110152 (destino) | 110153 (origen) | IRCP (usuario) Vinculación: Tipo de agente de auditoría (required) |
![]() ![]() ![]() |
SΣ | 1..1 | Reference(Sistema de información | Rol del profesional | Profesional de salud | Paciente) | El sistema registrado en el HIE, o la persona usuaria |
![]() ![]() ![]() |
SΣ | 0..1 | boolean | true para el usuario o, si no hay usuario, para el cliente |
![]() ![]() ![]() |
S | 0..1 | uri | Identificador del token (jti) del usuario |
![]() ![]() ![]() |
S | 0..1 | Red: la IP o el subsistema X-Road del cliente, la URL del servidor | |
![]() ![]() ![]() ![]() |
Reference(Endpoint) | |||
![]() ![]() ![]() ![]() |
uri | |||
![]() ![]() ![]() ![]() |
string | |||
![]() ![]() |
SΣ | 1..1 | BackboneElement | Quién registró el evento |
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized |
![]() ![]() ![]() |
Σ | 1..1 | Reference(Sistema de información) | El sistema que registró el evento |
![]() ![]() ![]() |
S | 1..1 | CodeableConcept | Tipo de la fuente (4: servidor de aplicaciones) Vinculación: AuditEventSourceType (required) |
![]() ![]() |
SΣ | 0..* | BackboneElement | El paciente, los datos, la consulta y la transacción |
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized |
![]() ![]() ![]() |
SΣ | 0..1 | Reference(Resource) | El recurso (la versión concreta si se conoce) o el identificador de la transacción |
![]() ![]() ![]() |
S | 0..1 | CodeableConcept | 1 (paciente) | 4 (datos) | 24 (consulta); sin role, la transacción Vinculación: AuditEventEntityRole (required) |
![]() ![]() ![]() |
S | 0..* | CodeableConcept | Las etiquetas de seguridad del recurso Vinculación: SecurityLabelExamples (example): Example Security Labels from the Healthcare Privacy and Security Classification System. |
![]() ![]() ![]() |
SΣ | 0..1 | base64Binary | La consulta, en base64 (solo en la entidad consulta) |
Documentación de este formato | ||||
| Ruta | Estado | Uso | ValueSet | Versión | Fuente |
| AuditEvent.category | Base | required | Categoría del evento de auditoría | 📦0.1.0 | Guía de Implementación de Terminología de Costa Rica vnull |
| AuditEvent.code | Base | example | Audit Event Sub-Type | 📍5.0.0 | Estándar FHIR |
| AuditEvent.action | Base | required | Audit Event Action | 📍5.0.0 | Estándar FHIR |
| AuditEvent.outcome.code | Base | required | Audit Event Outcome | 📦5.0.0 | Estándar FHIR |
| AuditEvent.outcome.detail | Base | example | Audit Event Outcome Detail | 📍5.0.0 | Estándar FHIR |
| AuditEvent.authorization | Base | required | Propósito de uso | 📦0.1.0 | Guía de Implementación de Terminología de Costa Rica vnull |
| AuditEvent.agent.type | Base | required | Tipo de agente de auditoría | 📦0.1.0 | Guía de Implementación de Terminología de Costa Rica vnull |
| AuditEvent.source.type | Base | required | Audit Event Source Type | 📦5.0.0 | Estándar FHIR |
| AuditEvent.entity.role | Base | required | Audit Event Entity Role | 📦5.0.0 | Estándar FHIR |
| AuditEvent.entity.securityLabel | Base | example | Example set of Security Labels | 📍5.0.0 | Estándar FHIR |
| Id | Nivel | Ruta(s) | Descripción | Expression |
| cr-auditoria-accion | error | AuditEvent | La acción es coherente con la interacción: las lecturas, búsquedas e historias son R; create es C; update y patch son U; delete es D; las demás son E. |
code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').all(iif(code in ('read' | 'vread' | 'search' | 'search-type' | 'search-system' | 'history' | 'history-instance' | 'history-type' | 'history-system'), %resource.action = 'R', iif(code = 'create', %resource.action = 'C', iif(code in ('update' | 'patch'), %resource.action = 'U', iif(code = 'delete', %resource.action = 'D', %resource.action = 'E')))))
|
| cr-auditoria-agentes | error | AuditEvent | El evento lleva un agente cliente y un agente servidor (DICOM 110152 y 110153). |
agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110152').exists()).exists() and agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110153').exists()).exists()
|
| cr-auditoria-detalle | error | AuditEvent | Un resultado que no es success lleva su detalle. |
outcome.code.code != 'success' implies outcome.detail.exists()
|
| cr-auditoria-entidades | error | AuditEvent | Cada entidad indica el recurso (what), salvo la consulta (role 24), que indica la consulta (query). |
entity.all(iif(role.coding.where(code = '24').exists(), query.exists(), what.exists()))
|
| cr-auditoria-fechas | error | AuditEvent | La fecha del evento no es posterior a la fecha de registro. |
occurred.ofType(dateTime).empty() or occurred.ofType(dateTime) <= recorded
|
| cr-auditoria-paciente | error | AuditEvent | El paciente del evento va también como entidad con role 1 (Patient), como en IHE BALP. |
patient.exists() implies entity.where(role.coding.where(system = 'http://terminology.hl7.org/CodeSystem/object-role' and code = '1').exists()).exists()
|
| cr-auditoria-proposito | error | AuditEvent | Un evento con datos de un paciente indica el propósito de uso. |
patient.exists() implies authorization.exists()
|
| cr-auditoria-red | error | AuditEvent | El cliente y el servidor indican su red (dirección IP, subsistema X-Road o URL). |
agent.where(type.coding.where(code = '110153' or code = '110152').exists()).all(network.exists())
|
| cr-auditoria-rest | error | AuditEvent | Un evento rest lleva el código de la interacción REST. |
category.coding.where(code = 'rest').exists() implies code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').exists()
|
| cr-auditoria-solicitante | error | AuditEvent | Hay un solo solicitante (requestor = true): el usuario o, si no hay usuario, el cliente. |
agent.where(requestor = true).count() = 1
|
| cr-documento-fecha-hora | error | AuditEvent.occurred[x] | La fecha lleva fecha y hora, no solo la fecha. |
toString().contains('T')
|
| dom-2 | error | AuditEvent | If the resource is contained in another resource, it SHALL NOT contain nested Resources |
contained.contained.empty()
|
| dom-3 | error | AuditEvent | If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource |
contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().ofType(canonical) | %resource.descendants().ofType(uri) | %resource.descendants().ofType(url))) or descendants().where(reference = '#').exists() or descendants().where(ofType(canonical) = '#').exists() or descendants().where(ofType(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
|
| dom-4 | error | AuditEvent | If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated |
contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
|
| dom-5 | error | AuditEvent | If a resource is contained in another resource, it SHALL NOT have a security label |
contained.meta.security.empty()
|
| dom-6 | best practice | AuditEvent | A resource should have narrative for robust management |
text.`div`.exists()
|
| ele-1 | error | **TODOS** los elementos | All FHIR elements must have a @value or children |
hasValue() or (children().count() > id.count())
|
| ext-1 | error | **TODAS** las extensiones | Must have either extensions or value[x], not both |
extension.exists() != value.exists()
|
Vista diferencial
Esta estructura se deriva de AuditEvent .
| Nombre | Marcas | Card. | Tipo | Descripción y restricciones Filter: ![]() ![]() |
|---|---|---|---|---|
![]() |
C | 0..* | AuditEvent | Evento de auditoría: quién accedió a qué y con qué resultado Constraints: cr-auditoria-rest, cr-auditoria-accion, cr-auditoria-detalle, cr-auditoria-proposito, cr-auditoria-agentes, cr-auditoria-red, cr-auditoria-solicitante, cr-auditoria-paciente, cr-auditoria-entidades, cr-auditoria-fechas |
![]() ![]() |
S | 1..1 | CodeableConcept | Categoría: rest | 110114 (autenticación) | 110113 (alerta de seguridad) Vinculación: Categoría del evento de auditoría (required) |
![]() ![]() |
S | 1..1 | CodeableConcept | Qué se hizo: la interacción REST (read, search, create...) o el evento de DICOM |
![]() ![]() |
S | 1..1 | code | C | R | U | D | E, coherente con el código |
![]() ![]() |
SC | 0..1 | dateTime | Cuándo ocurrió el evento (no posterior al registro) Constraints: cr-documento-fecha-hora |
![]() ![]() |
S | 1..1 | instant | Cuándo se registró el evento |
![]() ![]() |
S | 1..1 | BackboneElement | Resultado del evento, también en los fallos |
![]() ![]() ![]() |
S | 1..1 | Coding | success | warning | error | fatal Vinculación: AuditEventOutcome (required) |
![]() ![]() ![]() |
S | 0..* | CodeableConcept | Detalle (código HTTP y texto), sin datos clínicos |
![]() ![]() |
S | 0..1 | CodeableConcept | Propósito de uso: TREAT | ETREAT | COC | PATRQT | PUBHLTH | HRESCH | HOPERAT | HSYSADMIN | HLEGAL Vinculación: Propósito de uso (required) |
![]() ![]() |
S | 0..1 | Reference(Paciente) | Paciente de los datos (un evento por paciente) |
![]() ![]() |
S | 2..* | BackboneElement | El cliente, el servidor y, si la hace una persona, el usuario |
![]() ![]() ![]() |
S | 1..1 | CodeableConcept | 110152 (destino) | 110153 (origen) | IRCP (usuario) Vinculación: Tipo de agente de auditoría (required) |
![]() ![]() ![]() |
S | 1..1 | Reference(Sistema de información | Rol del profesional | Profesional de salud | Paciente) | El sistema registrado en el HIE, o la persona usuaria |
![]() ![]() ![]() |
S | 0..1 | boolean | true para el usuario o, si no hay usuario, para el cliente |
![]() ![]() ![]() |
S | 0..1 | uri | Identificador del token (jti) del usuario |
![]() ![]() ![]() |
S | 0..1 | Reference(Endpoint), uri, string | Red: la IP o el subsistema X-Road del cliente, la URL del servidor |
![]() ![]() |
S | 1..1 | BackboneElement | Quién registró el evento |
![]() ![]() ![]() |
1..1 | Reference(Sistema de información) | El sistema que registró el evento | |
![]() ![]() ![]() |
S | 1..1 | CodeableConcept | Tipo de la fuente (4: servidor de aplicaciones) Vinculación: AuditEventSourceType (required) |
![]() ![]() |
S | 0..* | BackboneElement | El paciente, los datos, la consulta y la transacción |
![]() ![]() ![]() |
S | 0..1 | Reference(Resource) | El recurso (la versión concreta si se conoce) o el identificador de la transacción |
![]() ![]() ![]() |
S | 0..1 | CodeableConcept | 1 (paciente) | 4 (datos) | 24 (consulta); sin role, la transacción Vinculación: AuditEventEntityRole (required) |
![]() ![]() ![]() |
S | 0..* | CodeableConcept | Las etiquetas de seguridad del recurso |
![]() ![]() ![]() |
S | 0..1 | base64Binary | La consulta, en base64 (solo en la entidad consulta) |
Documentación de este formato | ||||
| Ruta | Estado | Uso | ValueSet | Versión | Fuente |
| AuditEvent.category | Base | required | Categoría del evento de auditoría | 📦0.1.0 | Guía de Implementación de Terminología de Costa Rica vnull |
| AuditEvent.outcome.code | Base | required | Audit Event Outcome | 📦5.0.0 | Estándar FHIR |
| AuditEvent.authorization | Base | required | Propósito de uso | 📦0.1.0 | Guía de Implementación de Terminología de Costa Rica vnull |
| AuditEvent.agent.type | Base | required | Tipo de agente de auditoría | 📦0.1.0 | Guía de Implementación de Terminología de Costa Rica vnull |
| AuditEvent.source.type | Base | required | Audit Event Source Type | 📦5.0.0 | Estándar FHIR |
| AuditEvent.entity.role | Base | required | Audit Event Entity Role | 📦5.0.0 | Estándar FHIR |
| Id | Nivel | Ruta(s) | Descripción | Expression |
| cr-auditoria-accion | error | AuditEvent | La acción es coherente con la interacción: las lecturas, búsquedas e historias son R; create es C; update y patch son U; delete es D; las demás son E. |
code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').all(iif(code in ('read' | 'vread' | 'search' | 'search-type' | 'search-system' | 'history' | 'history-instance' | 'history-type' | 'history-system'), %resource.action = 'R', iif(code = 'create', %resource.action = 'C', iif(code in ('update' | 'patch'), %resource.action = 'U', iif(code = 'delete', %resource.action = 'D', %resource.action = 'E')))))
|
| cr-auditoria-agentes | error | AuditEvent | El evento lleva un agente cliente y un agente servidor (DICOM 110152 y 110153). |
agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110152').exists()).exists() and agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110153').exists()).exists()
|
| cr-auditoria-detalle | error | AuditEvent | Un resultado que no es success lleva su detalle. |
outcome.code.code != 'success' implies outcome.detail.exists()
|
| cr-auditoria-entidades | error | AuditEvent | Cada entidad indica el recurso (what), salvo la consulta (role 24), que indica la consulta (query). |
entity.all(iif(role.coding.where(code = '24').exists(), query.exists(), what.exists()))
|
| cr-auditoria-fechas | error | AuditEvent | La fecha del evento no es posterior a la fecha de registro. |
occurred.ofType(dateTime).empty() or occurred.ofType(dateTime) <= recorded
|
| cr-auditoria-paciente | error | AuditEvent | El paciente del evento va también como entidad con role 1 (Patient), como en IHE BALP. |
patient.exists() implies entity.where(role.coding.where(system = 'http://terminology.hl7.org/CodeSystem/object-role' and code = '1').exists()).exists()
|
| cr-auditoria-proposito | error | AuditEvent | Un evento con datos de un paciente indica el propósito de uso. |
patient.exists() implies authorization.exists()
|
| cr-auditoria-red | error | AuditEvent | El cliente y el servidor indican su red (dirección IP, subsistema X-Road o URL). |
agent.where(type.coding.where(code = '110153' or code = '110152').exists()).all(network.exists())
|
| cr-auditoria-rest | error | AuditEvent | Un evento rest lleva el código de la interacción REST. |
category.coding.where(code = 'rest').exists() implies code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').exists()
|
| cr-auditoria-solicitante | error | AuditEvent | Hay un solo solicitante (requestor = true): el usuario o, si no hay usuario, el cliente. |
agent.where(requestor = true).count() = 1
|
| cr-documento-fecha-hora | error | AuditEvent.occurred[x] | La fecha lleva fecha y hora, no solo la fecha. |
toString().contains('T')
|
Vista instantáneaView
| Nombre | Marcas | Card. | Tipo | Descripción y restricciones Filter: ![]() ![]() | ||||
|---|---|---|---|---|---|---|---|---|
![]() |
C | 0..* | AuditEvent | Evento de auditoría: quién accedió a qué y con qué resultado Constraints: cr-auditoria-rest, cr-auditoria-accion, cr-auditoria-detalle, cr-auditoria-proposito, cr-auditoria-agentes, cr-auditoria-red, cr-auditoria-solicitante, cr-auditoria-paciente, cr-auditoria-entidades, cr-auditoria-fechas | ||||
![]() ![]() |
Σ | 0..1 | id | Logical id of this artifact | ||||
![]() ![]() |
Σ | 0..1 | Meta | Metadata about the resource | ||||
![]() ![]() |
?!Σ | 0..1 | uri | A set of rules under which this content was created | ||||
![]() ![]() |
0..1 | code | Language of the resource content Vinculación: AllLanguages (required): IETF language tag for a human language
| |||||
![]() ![]() |
0..1 | Narrative | Text summary of the resource, for human interpretation This profile does not constrain the narrative in regard to content, language, or traceability to data elements | |||||
![]() ![]() |
0..* | Resource | Contained, inline Resources | |||||
![]() ![]() |
0..* | Extension | Additional content defined by implementations | |||||
![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored | ||||
![]() ![]() |
SΣ | 1..1 | CodeableConcept | Categoría: rest | 110114 (autenticación) | 110113 (alerta de seguridad) Vinculación: Categoría del evento de auditoría (required) | ||||
![]() ![]() |
SΣ | 1..1 | CodeableConcept | Qué se hizo: la interacción REST (read, search, create...) o el evento de DICOM Vinculación: AuditEventSubType (example): Specific type of event. | ||||
![]() ![]() |
SΣ | 1..1 | code | C | R | U | D | E, coherente con el código Vinculación: AuditEventAction (required): DICOM Audit Event Action | ||||
![]() ![]() |
Σ | 0..1 | code | emergency | alert | critical | error | warning | notice | informational | debug Vinculación: AuditEventSeverity (required): This is in the SysLog header, PRI. http://tools.ietf.org/html/rfc5424#appendix-A.3 | ||||
![]() ![]() |
SC | 0..1 | dateTime | Cuándo ocurrió el evento (no posterior al registro) Constraints: cr-documento-fecha-hora | ||||
![]() ![]() |
SΣ | 1..1 | instant | Cuándo se registró el evento | ||||
![]() ![]() |
SΣ | 1..1 | BackboneElement | Resultado del evento, también en los fallos | ||||
![]() ![]() ![]() |
0..1 | string | Unique id for inter-element referencing | |||||
![]() ![]() ![]() |
0..* | Extension | Additional content defined by implementations | |||||
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized | ||||
![]() ![]() ![]() |
SΣ | 1..1 | Coding | success | warning | error | fatal Vinculación: AuditEventOutcome (required) | ||||
![]() ![]() ![]() |
SΣ | 0..* | CodeableConcept | Detalle (código HTTP y texto), sin datos clínicos Vinculación: AuditEventOutcomeDetail (example): A code that provides details as the exact issue. | ||||
![]() ![]() |
SΣ | 0..1 | CodeableConcept | Propósito de uso: TREAT | ETREAT | COC | PATRQT | PUBHLTH | HRESCH | HOPERAT | HSYSADMIN | HLEGAL Vinculación: Propósito de uso (required) | ||||
![]() ![]() |
0..* | Reference(CarePlan | DeviceRequest | ImmunizationRecommendation | MedicationRequest | NutritionOrder | ServiceRequest | Task) | Workflow authorization within which this event occurred | |||||
![]() ![]() |
S | 0..1 | Reference(Paciente) | Paciente de los datos (un evento por paciente) | ||||
![]() ![]() |
0..1 | Reference(Encounter) | Encounter within which this event occurred or which the event is tightly associated | |||||
![]() ![]() |
SΣ | 2..* | BackboneElement | El cliente, el servidor y, si la hace una persona, el usuario | ||||
![]() ![]() ![]() |
0..1 | string | Unique id for inter-element referencing | |||||
![]() ![]() ![]() |
0..* | Extension | Additional content defined by implementations | |||||
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized | ||||
![]() ![]() ![]() |
S | 1..1 | CodeableConcept | 110152 (destino) | 110153 (origen) | IRCP (usuario) Vinculación: Tipo de agente de auditoría (required) | ||||
![]() ![]() ![]() |
0..* | CodeableConcept | Agent role in the event Vinculación: SecurityRoleType (example): What security role enabled the agent to participate in the event. | |||||
![]() ![]() ![]() |
SΣ | 1..1 | Reference(Sistema de información | Rol del profesional | Profesional de salud | Paciente) | El sistema registrado en el HIE, o la persona usuaria | ||||
![]() ![]() ![]() |
SΣ | 0..1 | boolean | true para el usuario o, si no hay usuario, para el cliente | ||||
![]() ![]() ![]() |
0..1 | Reference(Location) | The agent location when the event occurred | |||||
![]() ![]() ![]() |
S | 0..1 | uri | Identificador del token (jti) del usuario | ||||
![]() ![]() ![]() |
S | 0..1 | Red: la IP o el subsistema X-Road del cliente, la URL del servidor | |||||
![]() ![]() ![]() ![]() |
Reference(Endpoint) | |||||||
![]() ![]() ![]() ![]() |
uri | |||||||
![]() ![]() ![]() ![]() |
string | |||||||
![]() ![]() ![]() |
0..* | CodeableConcept | Allowable authorization for this agent Vinculación: PurposeOfUse (example): The reason the activity took place. | |||||
![]() ![]() |
SΣ | 1..1 | BackboneElement | Quién registró el evento | ||||
![]() ![]() ![]() |
0..1 | string | Unique id for inter-element referencing | |||||
![]() ![]() ![]() |
0..* | Extension | Additional content defined by implementations | |||||
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized | ||||
![]() ![]() ![]() |
0..1 | Reference(Location) | Logical source location within the enterprise | |||||
![]() ![]() ![]() |
Σ | 1..1 | Reference(Sistema de información) | El sistema que registró el evento | ||||
![]() ![]() ![]() |
S | 1..1 | CodeableConcept | Tipo de la fuente (4: servidor de aplicaciones) Vinculación: AuditEventSourceType (required) | ||||
![]() ![]() |
SΣ | 0..* | BackboneElement | El paciente, los datos, la consulta y la transacción | ||||
![]() ![]() ![]() |
0..1 | string | Unique id for inter-element referencing | |||||
![]() ![]() ![]() |
0..* | Extension | Additional content defined by implementations | |||||
![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized | ||||
![]() ![]() ![]() |
SΣ | 0..1 | Reference(Resource) | El recurso (la versión concreta si se conoce) o el identificador de la transacción | ||||
![]() ![]() ![]() |
S | 0..1 | CodeableConcept | 1 (paciente) | 4 (datos) | 24 (consulta); sin role, la transacción Vinculación: AuditEventEntityRole (required) | ||||
![]() ![]() ![]() |
S | 0..* | CodeableConcept | Las etiquetas de seguridad del recurso Vinculación: SecurityLabelExamples (example): Example Security Labels from the Healthcare Privacy and Security Classification System. | ||||
![]() ![]() ![]() |
SΣ | 0..1 | base64Binary | La consulta, en base64 (solo en la entidad consulta) | ||||
![]() ![]() ![]() |
0..* | BackboneElement | Additional Information about the entity | |||||
![]() ![]() ![]() ![]() |
0..1 | string | Unique id for inter-element referencing | |||||
![]() ![]() ![]() ![]() |
0..* | Extension | Additional content defined by implementations | |||||
![]() ![]() ![]() ![]() |
?!Σ | 0..* | Extension | Extensions that cannot be ignored even if unrecognized | ||||
![]() ![]() ![]() ![]() |
1..1 | CodeableConcept | Name of the property Vinculación: AuditEventID (example): Additional detail about an entity used in an event. | |||||
![]() ![]() ![]() ![]() |
1..1 | Property value | ||||||
![]() ![]() ![]() ![]() ![]() |
Quantity | |||||||
![]() ![]() ![]() ![]() ![]() |
CodeableConcept | |||||||
![]() ![]() ![]() ![]() ![]() |
string | |||||||
![]() ![]() ![]() ![]() ![]() |
boolean | |||||||
![]() ![]() ![]() ![]() ![]() |
integer | |||||||
![]() ![]() ![]() ![]() ![]() |
Range | |||||||
![]() ![]() ![]() ![]() ![]() |
Ratio | |||||||
![]() ![]() ![]() ![]() ![]() |
time | |||||||
![]() ![]() ![]() ![]() ![]() |
dateTime | |||||||
![]() ![]() ![]() ![]() ![]() |
Period | |||||||
![]() ![]() ![]() ![]() ![]() |
base64Binary | |||||||
![]() ![]() ![]() |
0..* | Vea agent (AuditEvent) | Entity is attributed to this agent | |||||
Documentación de este formato | ||||||||
| Id | Nivel | Ruta(s) | Descripción | Expression |
| cr-auditoria-accion | error | AuditEvent | La acción es coherente con la interacción: las lecturas, búsquedas e historias son R; create es C; update y patch son U; delete es D; las demás son E. |
code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').all(iif(code in ('read' | 'vread' | 'search' | 'search-type' | 'search-system' | 'history' | 'history-instance' | 'history-type' | 'history-system'), %resource.action = 'R', iif(code = 'create', %resource.action = 'C', iif(code in ('update' | 'patch'), %resource.action = 'U', iif(code = 'delete', %resource.action = 'D', %resource.action = 'E')))))
|
| cr-auditoria-agentes | error | AuditEvent | El evento lleva un agente cliente y un agente servidor (DICOM 110152 y 110153). |
agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110152').exists()).exists() and agent.where(type.coding.where(system = 'http://dicom.nema.org/resources/ontology/DCM' and code = '110153').exists()).exists()
|
| cr-auditoria-detalle | error | AuditEvent | Un resultado que no es success lleva su detalle. |
outcome.code.code != 'success' implies outcome.detail.exists()
|
| cr-auditoria-entidades | error | AuditEvent | Cada entidad indica el recurso (what), salvo la consulta (role 24), que indica la consulta (query). |
entity.all(iif(role.coding.where(code = '24').exists(), query.exists(), what.exists()))
|
| cr-auditoria-fechas | error | AuditEvent | La fecha del evento no es posterior a la fecha de registro. |
occurred.ofType(dateTime).empty() or occurred.ofType(dateTime) <= recorded
|
| cr-auditoria-paciente | error | AuditEvent | El paciente del evento va también como entidad con role 1 (Patient), como en IHE BALP. |
patient.exists() implies entity.where(role.coding.where(system = 'http://terminology.hl7.org/CodeSystem/object-role' and code = '1').exists()).exists()
|
| cr-auditoria-proposito | error | AuditEvent | Un evento con datos de un paciente indica el propósito de uso. |
patient.exists() implies authorization.exists()
|
| cr-auditoria-red | error | AuditEvent | El cliente y el servidor indican su red (dirección IP, subsistema X-Road o URL). |
agent.where(type.coding.where(code = '110153' or code = '110152').exists()).all(network.exists())
|
| cr-auditoria-rest | error | AuditEvent | Un evento rest lleva el código de la interacción REST. |
category.coding.where(code = 'rest').exists() implies code.coding.where(system = 'http://hl7.org/fhir/restful-interaction').exists()
|
| cr-auditoria-solicitante | error | AuditEvent | Hay un solo solicitante (requestor = true): el usuario o, si no hay usuario, el cliente. |
agent.where(requestor = true).count() = 1
|
| cr-documento-fecha-hora | error | AuditEvent.occurred[x] | La fecha lleva fecha y hora, no solo la fecha. |
toString().contains('T')
|
| dom-2 | error | AuditEvent | If the resource is contained in another resource, it SHALL NOT contain nested Resources |
contained.contained.empty()
|
| dom-3 | error | AuditEvent | If the resource is contained in another resource, it SHALL be referred to from elsewhere in the resource or SHALL refer to the containing resource |
contained.where((('#'+id in (%resource.descendants().reference | %resource.descendants().ofType(canonical) | %resource.descendants().ofType(uri) | %resource.descendants().ofType(url))) or descendants().where(reference = '#').exists() or descendants().where(ofType(canonical) = '#').exists() or descendants().where(ofType(canonical) = '#').exists()).not()).trace('unmatched', id).empty()
|
| dom-4 | error | AuditEvent | If a resource is contained in another resource, it SHALL NOT have a meta.versionId or a meta.lastUpdated |
contained.meta.versionId.empty() and contained.meta.lastUpdated.empty()
|
| dom-5 | error | AuditEvent | If a resource is contained in another resource, it SHALL NOT have a security label |
contained.meta.security.empty()
|
| dom-6 | best practice | AuditEvent | A resource should have narrative for robust management |
text.`div`.exists()
|
| ele-1 | error | **TODOS** los elementos | All FHIR elements must have a @value or children |
hasValue() or (children().count() > id.count())
|
| ext-1 | error | **TODAS** las extensiones | Must have either extensions or value[x], not both |
extension.exists() != value.exists()
|
Esta estructura se deriva de AuditEvent .
Resumen
Obligatorios: 5 elementos
Must-Support: 23 elementos
Estructuras
Esta estructura hace referencia a estas otras estructuras:
Otras representaciones de perfil: CSV, Excel, Schematron
Repositorio de auditoría. Eventos de auditoría: cada acceso u operación sobre el HIE, incluidos los fallos.
Ver también Servicios del HIE.
Lo que el servidor debe responder para este perfil. En la forma, [base] es la URL base del servidor del servicio y lo que va entre llaves se reemplaza por un valor. Cada solicitud usa valores reales de los ejemplos de esta guía, y la respuesta trae los que coinciden; los cuerpos JSON se expanden al hacer clic. Todas las solicitudes llevan el token de acceso al HIE (Authorization: Bearer [token]). Las búsquedas de texto encuentran los valores que empiezan con el texto, sin distinguir mayúsculas ni tildes; las de fecha admiten los prefijos ge, gt, le y lt. En la URL los valores van codificados (| como %7C, + como %2B, un espacio como %20); aquí se muestran sin codificar para que se lean mejor.
Leer
Forma: GET [base]/AuditEvent/{id}
Lee un evento de auditoría del repositorio de auditoría por su id, la parte final de su URL. Se usa para resolver una referencia que otro recurso hace a un evento de auditoría. En el ejemplo se lee «Acceso de emergencia a un documento restringido (E2)»; la segunda respuesta es la de un id que no existe.
Solicitud
GET [base]/AuditEvent/ejemplo-auditoria-emergencia HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Respuesta si el recurso existe
HTTP/1.1 200 OK
ETag: W/"1"
Last-Modified: 2026-10-01T10:00:00-06:00
Content-Type: application/fhir+json
{
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-emergencia",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-hce-hospital",
"display": "Expediente electrónico del Hospital Privado de Ejemplo"
},
"requestor": false,
"networkString": "CR/COM/3101123456/hce"
},
{
"policy": [
"urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
],
"type": {
"coding": [
{
"code": "IRCP",
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"display": "information recipient"
}
]
},
"who": {
"reference": "PractitionerRole/ejemplo-rol-medicina-interna",
"display": "Ricardo Castro Brenes"
},
"requestor": true
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "EPI-2025-118230"
},
"display": "Epicrisis de una hospitalización en salud mental"
},
"securityLabel": [
{
"coding": [
{
"code": "R",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "restricted"
}
]
},
{
"coding": [
{
"code": "PSY",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"display": "psychiatry disorder information sensitivity"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
"value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
}
}
}
],
"outcome": {
"code": {
"code": "success",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Operation Successful"
}
},
"authorization": [
{
"coding": [
{
"code": "ETREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "Emergency Treatment"
}
],
"text": "Tratamiento de emergencia"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-09-30T23:41:07-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
},
"occurredDateTime": "2026-09-30T23:41:06-06:00"
}
Respuesta si no existe
HTTP/1.1 404 Not Found
Content-Type: application/fhir+json
{
"resourceType": "OperationOutcome",
"issue": [
{
"severity": "error",
"code": "not-found",
"diagnostics": "No existe el recurso AuditEvent/no-existe."
}
]
}
Buscar por paciente
Forma: GET [base]/AuditEvent?patient=Patient/{id}
Trae quién accedió a los datos de un paciente. Es la consulta que permite informarle quién vio su información, como pide la Ley 8968. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: patient=Patient/ejemplo-paciente-nacional.
Solicitud
GET [base]/AuditEvent?patient=Patient/ejemplo-paciente-nacional HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6)
HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
"resourceType": "Bundle",
"type": "searchset",
"total": 2,
"link": [
{
"relation": "self",
"url": "[base]/AuditEvent?patient=Patient/ejemplo-paciente-nacional"
}
],
"entry": [
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-emergencia",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-hce-hospital",
"display": "Expediente electrónico del Hospital Privado de Ejemplo"
},
"requestor": false,
"networkString": "CR/COM/3101123456/hce"
},
{
"policy": [
"urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
],
"type": {
"coding": [
{
"code": "IRCP",
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"display": "information recipient"
}
]
},
"who": {
"reference": "PractitionerRole/ejemplo-rol-medicina-interna",
"display": "Ricardo Castro Brenes"
},
"requestor": true
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "EPI-2025-118230"
},
"display": "Epicrisis de una hospitalización en salud mental"
},
"securityLabel": [
{
"coding": [
{
"code": "R",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "restricted"
}
]
},
{
"coding": [
{
"code": "PSY",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"display": "psychiatry disorder information sensitivity"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
"value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
}
}
}
],
"outcome": {
"code": {
"code": "success",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Operation Successful"
}
},
"authorization": [
{
"coding": [
{
"code": "ETREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "Emergency Treatment"
}
],
"text": "Tratamiento de emergencia"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-09-30T23:41:07-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
},
"occurredDateTime": "2026-09-30T23:41:06-06:00"
},
"search": {
"mode": "match"
}
},
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-denegado",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-laboratorio",
"display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
},
"requestor": true,
"networkString": "CR/COM/3101234567/lis-central"
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "NOT-2026-004127"
},
"display": "Nota de atención a una víctima de violencia doméstica"
},
"securityLabel": [
{
"coding": [
{
"code": "V",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "very restricted"
}
]
},
{
"coding": [
{
"code": "SDV",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
}
],
"outcome": {
"detail": [
{
"coding": [
{
"code": "403",
"system": "urn:ietf:rfc:7231",
"display": "Forbidden"
}
],
"text": "Acceso denegado: el documento es de confidencialidad V"
}
],
"code": {
"code": "error",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Error"
}
},
"authorization": [
{
"coding": [
{
"code": "TREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "treatment"
}
],
"text": "Tratamiento"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-10-01T09:12:44-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
"search": {
"mode": "match"
}
}
]
}
Buscar por fecha de registro
Forma: GET [base]/AuditEvent?date={fecha}
Trae los eventos registrados en una fecha o un rango, para revisar un periodo. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: date=2026-09-30.
Solicitud
GET [base]/AuditEvent?date=2026-09-30 HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Respuesta: 1 resultado: Acceso de emergencia a un documento restringido (E2)
HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
"resourceType": "Bundle",
"type": "searchset",
"total": 1,
"link": [
{
"relation": "self",
"url": "[base]/AuditEvent?date=2026-09-30"
}
],
"entry": [
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-emergencia",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-hce-hospital",
"display": "Expediente electrónico del Hospital Privado de Ejemplo"
},
"requestor": false,
"networkString": "CR/COM/3101123456/hce"
},
{
"policy": [
"urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
],
"type": {
"coding": [
{
"code": "IRCP",
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"display": "information recipient"
}
]
},
"who": {
"reference": "PractitionerRole/ejemplo-rol-medicina-interna",
"display": "Ricardo Castro Brenes"
},
"requestor": true
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "EPI-2025-118230"
},
"display": "Epicrisis de una hospitalización en salud mental"
},
"securityLabel": [
{
"coding": [
{
"code": "R",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "restricted"
}
]
},
{
"coding": [
{
"code": "PSY",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"display": "psychiatry disorder information sensitivity"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
"value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
}
}
}
],
"outcome": {
"code": {
"code": "success",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Operation Successful"
}
},
"authorization": [
{
"coding": [
{
"code": "ETREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "Emergency Treatment"
}
],
"text": "Tratamiento de emergencia"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-09-30T23:41:07-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
},
"occurredDateTime": "2026-09-30T23:41:06-06:00"
},
"search": {
"mode": "match"
}
}
]
}
Buscar por agente
Forma: GET [base]/AuditEvent?agent=Device/{id}
Trae lo que hizo un sistema o una persona. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: agent=Device/ejemplo-sistema-repositorio.
Solicitud
GET [base]/AuditEvent?agent=Device/ejemplo-sistema-repositorio HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6)
HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
"resourceType": "Bundle",
"type": "searchset",
"total": 2,
"link": [
{
"relation": "self",
"url": "[base]/AuditEvent?agent=Device/ejemplo-sistema-repositorio"
}
],
"entry": [
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-emergencia",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-hce-hospital",
"display": "Expediente electrónico del Hospital Privado de Ejemplo"
},
"requestor": false,
"networkString": "CR/COM/3101123456/hce"
},
{
"policy": [
"urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
],
"type": {
"coding": [
{
"code": "IRCP",
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"display": "information recipient"
}
]
},
"who": {
"reference": "PractitionerRole/ejemplo-rol-medicina-interna",
"display": "Ricardo Castro Brenes"
},
"requestor": true
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "EPI-2025-118230"
},
"display": "Epicrisis de una hospitalización en salud mental"
},
"securityLabel": [
{
"coding": [
{
"code": "R",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "restricted"
}
]
},
{
"coding": [
{
"code": "PSY",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"display": "psychiatry disorder information sensitivity"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
"value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
}
}
}
],
"outcome": {
"code": {
"code": "success",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Operation Successful"
}
},
"authorization": [
{
"coding": [
{
"code": "ETREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "Emergency Treatment"
}
],
"text": "Tratamiento de emergencia"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-09-30T23:41:07-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
},
"occurredDateTime": "2026-09-30T23:41:06-06:00"
},
"search": {
"mode": "match"
}
},
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-denegado",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-laboratorio",
"display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
},
"requestor": true,
"networkString": "CR/COM/3101234567/lis-central"
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "NOT-2026-004127"
},
"display": "Nota de atención a una víctima de violencia doméstica"
},
"securityLabel": [
{
"coding": [
{
"code": "V",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "very restricted"
}
]
},
{
"coding": [
{
"code": "SDV",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
}
],
"outcome": {
"detail": [
{
"coding": [
{
"code": "403",
"system": "urn:ietf:rfc:7231",
"display": "Forbidden"
}
],
"text": "Acceso denegado: el documento es de confidencialidad V"
}
],
"code": {
"code": "error",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Error"
}
},
"authorization": [
{
"coding": [
{
"code": "TREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "treatment"
}
],
"text": "Tratamiento"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-10-01T09:12:44-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
"search": {
"mode": "match"
}
}
]
}
Buscar por datos accedidos
Forma: GET [base]/AuditEvent?entity=Patient/{id}
Trae los eventos sobre un recurso concreto; por ejemplo, quién leyó un documento. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: entity=Patient/ejemplo-paciente-nacional.
Solicitud
GET [base]/AuditEvent?entity=Patient/ejemplo-paciente-nacional HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6)
HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
"resourceType": "Bundle",
"type": "searchset",
"total": 2,
"link": [
{
"relation": "self",
"url": "[base]/AuditEvent?entity=Patient/ejemplo-paciente-nacional"
}
],
"entry": [
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-emergencia",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-hce-hospital",
"display": "Expediente electrónico del Hospital Privado de Ejemplo"
},
"requestor": false,
"networkString": "CR/COM/3101123456/hce"
},
{
"policy": [
"urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
],
"type": {
"coding": [
{
"code": "IRCP",
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"display": "information recipient"
}
]
},
"who": {
"reference": "PractitionerRole/ejemplo-rol-medicina-interna",
"display": "Ricardo Castro Brenes"
},
"requestor": true
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "EPI-2025-118230"
},
"display": "Epicrisis de una hospitalización en salud mental"
},
"securityLabel": [
{
"coding": [
{
"code": "R",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "restricted"
}
]
},
{
"coding": [
{
"code": "PSY",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"display": "psychiatry disorder information sensitivity"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
"value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
}
}
}
],
"outcome": {
"code": {
"code": "success",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Operation Successful"
}
},
"authorization": [
{
"coding": [
{
"code": "ETREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "Emergency Treatment"
}
],
"text": "Tratamiento de emergencia"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-09-30T23:41:07-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
},
"occurredDateTime": "2026-09-30T23:41:06-06:00"
},
"search": {
"mode": "match"
}
},
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-denegado",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-laboratorio",
"display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
},
"requestor": true,
"networkString": "CR/COM/3101234567/lis-central"
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "NOT-2026-004127"
},
"display": "Nota de atención a una víctima de violencia doméstica"
},
"securityLabel": [
{
"coding": [
{
"code": "V",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "very restricted"
}
]
},
{
"coding": [
{
"code": "SDV",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
}
],
"outcome": {
"detail": [
{
"coding": [
{
"code": "403",
"system": "urn:ietf:rfc:7231",
"display": "Forbidden"
}
],
"text": "Acceso denegado: el documento es de confidencialidad V"
}
],
"code": {
"code": "error",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Error"
}
},
"authorization": [
{
"coding": [
{
"code": "TREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "treatment"
}
],
"text": "Tratamiento"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-10-01T09:12:44-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
"search": {
"mode": "match"
}
}
]
}
Buscar por categoría
Forma: GET [base]/AuditEvent?category={sistema}|{código}
Separa los tipos de evento: las llamadas a la API (rest), las autenticaciones y las alertas de seguridad. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: category=http://terminology.hl7.org/CodeSystem/audit-event-type|rest.
Solicitud
GET [base]/AuditEvent?category=http://terminology.hl7.org/CodeSystem/audit-event-type|rest HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6)
HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
"resourceType": "Bundle",
"type": "searchset",
"total": 2,
"link": [
{
"relation": "self",
"url": "[base]/AuditEvent?category=http://terminology.hl7.org/CodeSystem/audit-event-type|rest"
}
],
"entry": [
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-emergencia",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-hce-hospital",
"display": "Expediente electrónico del Hospital Privado de Ejemplo"
},
"requestor": false,
"networkString": "CR/COM/3101123456/hce"
},
{
"policy": [
"urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
],
"type": {
"coding": [
{
"code": "IRCP",
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"display": "information recipient"
}
]
},
"who": {
"reference": "PractitionerRole/ejemplo-rol-medicina-interna",
"display": "Ricardo Castro Brenes"
},
"requestor": true
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "EPI-2025-118230"
},
"display": "Epicrisis de una hospitalización en salud mental"
},
"securityLabel": [
{
"coding": [
{
"code": "R",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "restricted"
}
]
},
{
"coding": [
{
"code": "PSY",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"display": "psychiatry disorder information sensitivity"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
"value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
}
}
}
],
"outcome": {
"code": {
"code": "success",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Operation Successful"
}
},
"authorization": [
{
"coding": [
{
"code": "ETREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "Emergency Treatment"
}
],
"text": "Tratamiento de emergencia"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-09-30T23:41:07-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
},
"occurredDateTime": "2026-09-30T23:41:06-06:00"
},
"search": {
"mode": "match"
}
},
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-denegado",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-laboratorio",
"display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
},
"requestor": true,
"networkString": "CR/COM/3101234567/lis-central"
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "NOT-2026-004127"
},
"display": "Nota de atención a una víctima de violencia doméstica"
},
"securityLabel": [
{
"coding": [
{
"code": "V",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "very restricted"
}
]
},
{
"coding": [
{
"code": "SDV",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
}
],
"outcome": {
"detail": [
{
"coding": [
{
"code": "403",
"system": "urn:ietf:rfc:7231",
"display": "Forbidden"
}
],
"text": "Acceso denegado: el documento es de confidencialidad V"
}
],
"code": {
"code": "error",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Error"
}
},
"authorization": [
{
"coding": [
{
"code": "TREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "treatment"
}
],
"text": "Tratamiento"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-10-01T09:12:44-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
"search": {
"mode": "match"
}
}
]
}
Buscar por código
Forma: GET [base]/AuditEvent?code={sistema}|{código}
Busca por la operación que se hizo; por ejemplo, todas las lecturas (read). En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: code=http://hl7.org/fhir/restful-interaction|read.
Solicitud
GET [base]/AuditEvent?code=http://hl7.org/fhir/restful-interaction|read HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6)
HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
"resourceType": "Bundle",
"type": "searchset",
"total": 2,
"link": [
{
"relation": "self",
"url": "[base]/AuditEvent?code=http://hl7.org/fhir/restful-interaction|read"
}
],
"entry": [
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-emergencia",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-hce-hospital",
"display": "Expediente electrónico del Hospital Privado de Ejemplo"
},
"requestor": false,
"networkString": "CR/COM/3101123456/hce"
},
{
"policy": [
"urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
],
"type": {
"coding": [
{
"code": "IRCP",
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"display": "information recipient"
}
]
},
"who": {
"reference": "PractitionerRole/ejemplo-rol-medicina-interna",
"display": "Ricardo Castro Brenes"
},
"requestor": true
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "EPI-2025-118230"
},
"display": "Epicrisis de una hospitalización en salud mental"
},
"securityLabel": [
{
"coding": [
{
"code": "R",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "restricted"
}
]
},
{
"coding": [
{
"code": "PSY",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"display": "psychiatry disorder information sensitivity"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
"value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
}
}
}
],
"outcome": {
"code": {
"code": "success",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Operation Successful"
}
},
"authorization": [
{
"coding": [
{
"code": "ETREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "Emergency Treatment"
}
],
"text": "Tratamiento de emergencia"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-09-30T23:41:07-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
},
"occurredDateTime": "2026-09-30T23:41:06-06:00"
},
"search": {
"mode": "match"
}
},
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-denegado",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-laboratorio",
"display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
},
"requestor": true,
"networkString": "CR/COM/3101234567/lis-central"
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "NOT-2026-004127"
},
"display": "Nota de atención a una víctima de violencia doméstica"
},
"securityLabel": [
{
"coding": [
{
"code": "V",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "very restricted"
}
]
},
{
"coding": [
{
"code": "SDV",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
}
],
"outcome": {
"detail": [
{
"coding": [
{
"code": "403",
"system": "urn:ietf:rfc:7231",
"display": "Forbidden"
}
],
"text": "Acceso denegado: el documento es de confidencialidad V"
}
],
"code": {
"code": "error",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Error"
}
},
"authorization": [
{
"coding": [
{
"code": "TREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "treatment"
}
],
"text": "Tratamiento"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-10-01T09:12:44-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
"search": {
"mode": "match"
}
}
]
}
Buscar por acción
Forma: GET [base]/AuditEvent?action={código}
Busca por acción: C (crear), R (leer), U (actualizar), D (borrar) o E (ejecutar). En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: action=R.
Solicitud
GET [base]/AuditEvent?action=R HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6)
HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
"resourceType": "Bundle",
"type": "searchset",
"total": 2,
"link": [
{
"relation": "self",
"url": "[base]/AuditEvent?action=R"
}
],
"entry": [
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-emergencia",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-hce-hospital",
"display": "Expediente electrónico del Hospital Privado de Ejemplo"
},
"requestor": false,
"networkString": "CR/COM/3101123456/hce"
},
{
"policy": [
"urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
],
"type": {
"coding": [
{
"code": "IRCP",
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"display": "information recipient"
}
]
},
"who": {
"reference": "PractitionerRole/ejemplo-rol-medicina-interna",
"display": "Ricardo Castro Brenes"
},
"requestor": true
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "EPI-2025-118230"
},
"display": "Epicrisis de una hospitalización en salud mental"
},
"securityLabel": [
{
"coding": [
{
"code": "R",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "restricted"
}
]
},
{
"coding": [
{
"code": "PSY",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"display": "psychiatry disorder information sensitivity"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
"value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
}
}
}
],
"outcome": {
"code": {
"code": "success",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Operation Successful"
}
},
"authorization": [
{
"coding": [
{
"code": "ETREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "Emergency Treatment"
}
],
"text": "Tratamiento de emergencia"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-09-30T23:41:07-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
},
"occurredDateTime": "2026-09-30T23:41:06-06:00"
},
"search": {
"mode": "match"
}
},
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-denegado",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-laboratorio",
"display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
},
"requestor": true,
"networkString": "CR/COM/3101234567/lis-central"
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "NOT-2026-004127"
},
"display": "Nota de atención a una víctima de violencia doméstica"
},
"securityLabel": [
{
"coding": [
{
"code": "V",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "very restricted"
}
]
},
{
"coding": [
{
"code": "SDV",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
}
],
"outcome": {
"detail": [
{
"coding": [
{
"code": "403",
"system": "urn:ietf:rfc:7231",
"display": "Forbidden"
}
],
"text": "Acceso denegado: el documento es de confidencialidad V"
}
],
"code": {
"code": "error",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Error"
}
},
"authorization": [
{
"coding": [
{
"code": "TREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "treatment"
}
],
"text": "Tratamiento"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-10-01T09:12:44-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
"search": {
"mode": "match"
}
}
]
}
Buscar por resultado
Forma: GET [base]/AuditEvent?outcome={sistema}|{código}
Busca por resultado. Los eventos que no son success, como los accesos denegados, son los que más interesan a la seguridad. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: outcome=http://hl7.org/fhir/issue-severity|success.
Solicitud
GET [base]/AuditEvent?outcome=http://hl7.org/fhir/issue-severity|success HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Respuesta: 1 resultado: Acceso de emergencia a un documento restringido (E2)
HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
"resourceType": "Bundle",
"type": "searchset",
"total": 1,
"link": [
{
"relation": "self",
"url": "[base]/AuditEvent?outcome=http://hl7.org/fhir/issue-severity|success"
}
],
"entry": [
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-emergencia",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-hce-hospital",
"display": "Expediente electrónico del Hospital Privado de Ejemplo"
},
"requestor": false,
"networkString": "CR/COM/3101123456/hce"
},
{
"policy": [
"urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
],
"type": {
"coding": [
{
"code": "IRCP",
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"display": "information recipient"
}
]
},
"who": {
"reference": "PractitionerRole/ejemplo-rol-medicina-interna",
"display": "Ricardo Castro Brenes"
},
"requestor": true
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "EPI-2025-118230"
},
"display": "Epicrisis de una hospitalización en salud mental"
},
"securityLabel": [
{
"coding": [
{
"code": "R",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "restricted"
}
]
},
{
"coding": [
{
"code": "PSY",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"display": "psychiatry disorder information sensitivity"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
"value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
}
}
}
],
"outcome": {
"code": {
"code": "success",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Operation Successful"
}
},
"authorization": [
{
"coding": [
{
"code": "ETREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "Emergency Treatment"
}
],
"text": "Tratamiento de emergencia"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-09-30T23:41:07-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
},
"occurredDateTime": "2026-09-30T23:41:06-06:00"
},
"search": {
"mode": "match"
}
}
]
}
Buscar por propósito de uso
Forma: GET [base]/AuditEvent?purpose={sistema}|{código}
Busca por propósito de uso. Los accesos de emergencia (ETREAT) a datos restringidos se revisan después. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: purpose=http://terminology.hl7.org/CodeSystem/v3-ActReason|ETREAT.
Solicitud
GET [base]/AuditEvent?purpose=http://terminology.hl7.org/CodeSystem/v3-ActReason|ETREAT HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Respuesta: 1 resultado: Acceso de emergencia a un documento restringido (E2)
HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
"resourceType": "Bundle",
"type": "searchset",
"total": 1,
"link": [
{
"relation": "self",
"url": "[base]/AuditEvent?purpose=http://terminology.hl7.org/CodeSystem/v3-ActReason|ETREAT"
}
],
"entry": [
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-emergencia",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-hce-hospital",
"display": "Expediente electrónico del Hospital Privado de Ejemplo"
},
"requestor": false,
"networkString": "CR/COM/3101123456/hce"
},
{
"policy": [
"urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
],
"type": {
"coding": [
{
"code": "IRCP",
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"display": "information recipient"
}
]
},
"who": {
"reference": "PractitionerRole/ejemplo-rol-medicina-interna",
"display": "Ricardo Castro Brenes"
},
"requestor": true
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "EPI-2025-118230"
},
"display": "Epicrisis de una hospitalización en salud mental"
},
"securityLabel": [
{
"coding": [
{
"code": "R",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "restricted"
}
]
},
{
"coding": [
{
"code": "PSY",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"display": "psychiatry disorder information sensitivity"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
"value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
}
}
}
],
"outcome": {
"code": {
"code": "success",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Operation Successful"
}
},
"authorization": [
{
"coding": [
{
"code": "ETREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "Emergency Treatment"
}
],
"text": "Tratamiento de emergencia"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-09-30T23:41:07-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
},
"occurredDateTime": "2026-09-30T23:41:06-06:00"
},
"search": {
"mode": "match"
}
}
]
}
Buscar por fuente
Forma: GET [base]/AuditEvent?source=Device/{id}
Trae los eventos que registró un sistema. En el ejemplo se usa el dato de «Acceso de emergencia a un documento restringido (E2)»: source=Device/ejemplo-sistema-repositorio.
Solicitud
GET [base]/AuditEvent?source=Device/ejemplo-sistema-repositorio HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6)
HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
"resourceType": "Bundle",
"type": "searchset",
"total": 2,
"link": [
{
"relation": "self",
"url": "[base]/AuditEvent?source=Device/ejemplo-sistema-repositorio"
}
],
"entry": [
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-emergencia",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-hce-hospital",
"display": "Expediente electrónico del Hospital Privado de Ejemplo"
},
"requestor": false,
"networkString": "CR/COM/3101123456/hce"
},
{
"policy": [
"urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
],
"type": {
"coding": [
{
"code": "IRCP",
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"display": "information recipient"
}
]
},
"who": {
"reference": "PractitionerRole/ejemplo-rol-medicina-interna",
"display": "Ricardo Castro Brenes"
},
"requestor": true
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "EPI-2025-118230"
},
"display": "Epicrisis de una hospitalización en salud mental"
},
"securityLabel": [
{
"coding": [
{
"code": "R",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "restricted"
}
]
},
{
"coding": [
{
"code": "PSY",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"display": "psychiatry disorder information sensitivity"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
"value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
}
}
}
],
"outcome": {
"code": {
"code": "success",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Operation Successful"
}
},
"authorization": [
{
"coding": [
{
"code": "ETREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "Emergency Treatment"
}
],
"text": "Tratamiento de emergencia"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-09-30T23:41:07-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
},
"occurredDateTime": "2026-09-30T23:41:06-06:00"
},
"search": {
"mode": "match"
}
},
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-denegado",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-laboratorio",
"display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
},
"requestor": true,
"networkString": "CR/COM/3101234567/lis-central"
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "NOT-2026-004127"
},
"display": "Nota de atención a una víctima de violencia doméstica"
},
"securityLabel": [
{
"coding": [
{
"code": "V",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "very restricted"
}
]
},
{
"coding": [
{
"code": "SDV",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
}
],
"outcome": {
"detail": [
{
"coding": [
{
"code": "403",
"system": "urn:ietf:rfc:7231",
"display": "Forbidden"
}
],
"text": "Acceso denegado: el documento es de confidencialidad V"
}
],
"code": {
"code": "error",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Error"
}
},
"authorization": [
{
"coding": [
{
"code": "TREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "treatment"
}
],
"text": "Tratamiento"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-10-01T09:12:44-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
"search": {
"mode": "match"
}
}
]
}
Buscar por paciente, con POST
Forma: POST [base]/AuditEvent/_searchcuerpo: patient=Patient/{id}
Hace cualquier búsqueda con POST: los parámetros van en el cuerpo, como un formulario, en lugar de la URL. Se usa cuando los valores son datos personales, como una cédula, para que no queden en los registros de los servidores ni en el historial; la respuesta es la misma que con GET. En el ejemplo se repite la búsqueda por paciente.
Solicitud
POST [base]/AuditEvent/_search HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Content-Type: application/x-www-form-urlencoded
patient=Patient/ejemplo-paciente-nacional
Respuesta: 2 resultados: Acceso de emergencia a un documento restringido (E2); Acceso denegado (E6), igual que con GET
HTTP/1.1 200 OK
Content-Type: application/fhir+json
{
"resourceType": "Bundle",
"type": "searchset",
"total": 2,
"link": [
{
"relation": "self",
"url": "[base]/AuditEvent?patient=Patient/ejemplo-paciente-nacional"
}
],
"entry": [
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-emergencia",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-emergencia",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-hce-hospital",
"display": "Expediente electrónico del Hospital Privado de Ejemplo"
},
"requestor": false,
"networkString": "CR/COM/3101123456/hce"
},
{
"policy": [
"urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
],
"type": {
"coding": [
{
"code": "IRCP",
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"display": "information recipient"
}
]
},
"who": {
"reference": "PractitionerRole/ejemplo-rol-medicina-interna",
"display": "Ricardo Castro Brenes"
},
"requestor": true
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "EPI-2025-118230"
},
"display": "Epicrisis de una hospitalización en salud mental"
},
"securityLabel": [
{
"coding": [
{
"code": "R",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "restricted"
}
]
},
{
"coding": [
{
"code": "PSY",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"display": "psychiatry disorder information sensitivity"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
"value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
}
}
}
],
"outcome": {
"code": {
"code": "success",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Operation Successful"
}
},
"authorization": [
{
"coding": [
{
"code": "ETREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "Emergency Treatment"
}
],
"text": "Tratamiento de emergencia"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-09-30T23:41:07-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
},
"occurredDateTime": "2026-09-30T23:41:06-06:00"
},
"search": {
"mode": "match"
}
},
{
"fullUrl": "[base]/AuditEvent/ejemplo-auditoria-denegado",
"resource": {
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-denegado",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-laboratorio",
"display": "Sistema de laboratorio del Laboratorio Clínico de Ejemplo"
},
"requestor": true,
"networkString": "CR/COM/3101234567/lis-central"
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "NOT-2026-004127"
},
"display": "Nota de atención a una víctima de violencia doméstica"
},
"securityLabel": [
{
"coding": [
{
"code": "V",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "very restricted"
}
]
},
{
"coding": [
{
"code": "SDV",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
}
],
"outcome": {
"detail": [
{
"coding": [
{
"code": "403",
"system": "urn:ietf:rfc:7231",
"display": "Forbidden"
}
],
"text": "Acceso denegado: el documento es de confidencialidad V"
}
],
"code": {
"code": "error",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Error"
}
},
"authorization": [
{
"coding": [
{
"code": "TREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "treatment"
}
],
"text": "Tratamiento"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-10-01T09:12:44-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
"search": {
"mode": "match"
}
}
]
}
Crear
Forma: POST [base]/AuditEvent
Registra un evento de auditoría en el repositorio de auditoría. El servidor valida el recurso contra el perfil, le asigna su id y devuelve su dirección. Lo hace cada sistema del HIE al terminar una operación sobre datos, también si la operación falló (IHE ATNA ITI-20). En el ejemplo se registra «Acceso de emergencia a un documento restringido (E2)»; la segunda respuesta es el rechazo de un recurso que no cumple la invariante cr-auditoria-rest (Un evento rest lleva el código de la interacción REST).
Solicitud
POST [base]/AuditEvent HTTP/1.1
Accept: application/fhir+json
Authorization: Bearer [token]
Content-Type: application/fhir+json
{
"resourceType": "AuditEvent",
"meta": {
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-hce-hospital",
"display": "Expediente electrónico del Hospital Privado de Ejemplo"
},
"requestor": false,
"networkString": "CR/COM/3101123456/hce"
},
{
"policy": [
"urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
],
"type": {
"coding": [
{
"code": "IRCP",
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"display": "information recipient"
}
]
},
"who": {
"reference": "PractitionerRole/ejemplo-rol-medicina-interna",
"display": "Ricardo Castro Brenes"
},
"requestor": true
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "EPI-2025-118230"
},
"display": "Epicrisis de una hospitalización en salud mental"
},
"securityLabel": [
{
"coding": [
{
"code": "R",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "restricted"
}
]
},
{
"coding": [
{
"code": "PSY",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"display": "psychiatry disorder information sensitivity"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
"value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
}
}
}
],
"outcome": {
"code": {
"code": "success",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Operation Successful"
}
},
"authorization": [
{
"coding": [
{
"code": "ETREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "Emergency Treatment"
}
],
"text": "Tratamiento de emergencia"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-09-30T23:41:07-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
},
"occurredDateTime": "2026-09-30T23:41:06-06:00"
}
Respuesta si se crea
HTTP/1.1 201 Created
Location: [base]/AuditEvent/ejemplo-auditoria-emergencia/_history/1
ETag: W/"1"
Last-Modified: 2026-10-01T10:00:00-06:00
Content-Type: application/fhir+json
{
"resourceType": "AuditEvent",
"id": "ejemplo-auditoria-emergencia",
"meta": {
"versionId": "1",
"lastUpdated": "2026-10-01T10:00:00-06:00",
"profile": [
"https://hl7.or.cr/fhir/core/StructureDefinition/cr-auditevent"
]
},
"category": [
{
"coding": [
{
"code": "rest",
"system": "http://terminology.hl7.org/CodeSystem/audit-event-type",
"display": "RESTful Operation"
}
]
}
],
"source": {
"type": [
{
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"display": "Application Server"
}
]
}
],
"observer": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
}
},
"agent": [
{
"type": {
"coding": [
{
"code": "110153",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-repositorio",
"display": "Repositorio de documentos del HIE"
},
"requestor": false,
"networkUri": "https://hie.example.cr/fhir"
},
{
"type": {
"coding": [
{
"code": "110152",
"system": "http://dicom.nema.org/resources/ontology/DCM",
"display": "Destination Role ID"
}
]
},
"who": {
"reference": "Device/ejemplo-sistema-hce-hospital",
"display": "Expediente electrónico del Hospital Privado de Ejemplo"
},
"requestor": false,
"networkString": "CR/COM/3101123456/hce"
},
{
"policy": [
"urn:uuid:7c1e2d3f-4a5b-4c6d-8e7f-9a0b1c2d3e4f"
],
"type": {
"coding": [
{
"code": "IRCP",
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"display": "information recipient"
}
]
},
"who": {
"reference": "PractitionerRole/ejemplo-rol-medicina-interna",
"display": "Ricardo Castro Brenes"
},
"requestor": true
}
],
"entity": [
{
"role": {
"coding": [
{
"code": "1",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Patient"
}
]
},
"what": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/documento/cj-4000042147",
"value": "EPI-2025-118230"
},
"display": "Epicrisis de una hospitalización en salud mental"
},
"securityLabel": [
{
"coding": [
{
"code": "R",
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"display": "restricted"
}
]
},
{
"coding": [
{
"code": "PSY",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"display": "psychiatry disorder information sensitivity"
}
]
}
],
"role": {
"coding": [
{
"code": "4",
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"display": "Domain Resource"
}
]
}
},
{
"what": {
"identifier": {
"system": "https://hl7.or.cr/fhir/sid/xroad-mensaje",
"value": "a1b2c3d4-e5f6-4789-90ab-cdef01234567"
}
}
}
],
"outcome": {
"code": {
"code": "success",
"system": "http://hl7.org/fhir/issue-severity",
"display": "Operation Successful"
}
},
"authorization": [
{
"coding": [
{
"code": "ETREAT",
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"display": "Emergency Treatment"
}
],
"text": "Tratamiento de emergencia"
}
],
"code": {
"coding": [
{
"code": "read",
"system": "http://hl7.org/fhir/restful-interaction",
"display": "read"
}
]
},
"action": "R",
"recorded": "2026-09-30T23:41:07-06:00",
"patient": {
"reference": "Patient/ejemplo-paciente-nacional",
"display": "Laura Patricia Solís Araya"
},
"occurredDateTime": "2026-09-30T23:41:06-06:00"
}
Respuesta si no cumple el perfil (invariante cr-auditoria-rest)
HTTP/1.1 422 Unprocessable Entity
Content-Type: application/fhir+json
{
"resourceType": "OperationOutcome",
"issue": [
{
"severity": "error",
"code": "invariant",
"diagnostics": "cr-auditoria-rest: Un evento rest lleva el código de la interacción REST.",
"expression": [
"AuditEvent"
]
}
]
}