# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-06T01:59:02Z", "synthesisSha256": "e77af3ff667fd1c78c3e6e5a56fedf35ce007e409cca8cbe0583ab201fa06c9f", "providerMode": "single-provider-waiver", "providers": [ "Codex" ], "waivedProviders": [ "Claude", "Grok" ] }, "metaModel": { "id": "WM-PER-007", "registryId": "vr.wm-per-007", "name": "Personal Health", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Society, people and institutions", "industry": [ "Cross-industry" ], "domain": [ "SOC.PER.HLTH" ], "tags": [ "personal", "health", "soc.per.hlth" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-per-007-personal-health/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-per-007", "model": { "registry_id": "vr.wm-per-007", "model_id": "WM-PER-007", "name": "Personal Health", "entry_kind": "entity", "purpose": "Represent one person's longitudinal health states, observations, risks, interventions, care intentions and evidence with strict identity, provenance, clinical-safety and privacy controls independent of storage or interface format.", "scope_statement": "Owns the person-grain health context, subject and source bindings, assertion kinds and time, conditions, risks, function, observations, diagnostic interpretations, allergies, medications, immunizations, procedures, encounter and plan references, provenance, consent, access, correction, retention and summary projections. External systems own people, providers, organizations, devices, products, appointments, encounters, specimens, images, claims, research studies, public-health reports, genomics, consents and source evidence records.", "in_scope": [ "Verified subject and context identity, source mastering, assertion status, longitudinal time, provenance and reconciliation", "Conditions, risks, function, observations, diagnostic evidence, allergies, medicines, immunizations, procedures, devices, encounters, teams, plans and goals", "Consent, privacy, emergency access, correction, retention, terminology, interoperable summaries, validation and safe agent operations" ], "out_of_scope": [ "Provider operations, scheduling, billing, insurance claims, population surveillance, research-study management, raw genomics, raw imaging and medical-device implementation", "Universal clinical guidelines, diagnosis or treatment recommendations, professional licensure decisions and claims of medical correctness without accountable review", "Universal legal ownership, consent, access, retention or emergency rules and any silent replacement of source-system records" ], "boundary_notes": [ { "neighbor": "Person and Identity Register", "distinction": "The person model owns identity and demographics; Personal Health stores verified subject references, match evidence and corrections but never remasters the person.", "source_refs": [ "SRC-001" ] }, { "neighbor": "Health-care Delivery, Encounter and Appointment", "distinction": "Care delivery owns services, resources, workflow and scheduling; Personal Health retains clinically relevant references and resulting assertions at person grain.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "Public Health and Research", "distinction": "Population surveillance and studies own cohort, protocol and reporting semantics; only authorized person-grain participation or disclosure references live here.", "source_refs": [ "SRC-002", "SRC-010" ] }, { "neighbor": "Device, Imaging, Specimen and Genomics", "distinction": "Native payloads and lifecycles remain in specialist masters; this model holds identifiers, clinically relevant summaries, provenance and access references.", "source_refs": [ "SRC-001", "SRC-006" ] }, { "neighbor": "Insurance, Coverage and Claim", "distinction": "Financial eligibility and adjudication are external; they may reference health evidence but never define clinical truth.", "source_refs": [ "SRC-001" ] }, { "neighbor": "Consent, Access and Legal Policy", "distinction": "This model records health-specific policy and consent bindings and their effects, while authorization engines and jurisdictional legal determinations remain external.", "source_refs": [ "SRC-001", "SRC-010" ] } ] }, "sources": [ { "id": "SRC-001", "title": "FHIR Release 5", "organization": "Health Level Seven International", "url": "https://hl7.org/fhir/R5/", "version_or_date": "FHIR 5.0.0, published 26 March 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:56:00Z", "relevance": "Defines interoperable clinical resources including Patient, Condition, Observation, AllergyIntolerance, Medication, Immunization, Procedure, Encounter, CarePlan, Consent, Provenance and DiagnosticReport with common identity, status, terminology and reference patterns." }, { "id": "SRC-002", "title": "International Patient Summary Implementation Guide", "organization": "Health Level Seven International", "url": "https://hl7.org/fhir/uv/ips/", "version_or_date": "Current published FHIR IPS guide, accessed 6 September 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:56:00Z", "relevance": "Defines a minimal, clinically relevant patient summary with required and recommended sections for cross-border and unscheduled care while remaining a projection of source records." }, { "id": "SRC-003", "title": "ICD-11 for Mortality and Morbidity Statistics", "organization": "World Health Organization", "url": "https://icd.who.int/en", "version_or_date": "Current ICD-11 release service, accessed 6 September 2026", "source_type": "classifier", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:56:00Z", "relevance": "Provides a versioned international classification for diseases, health conditions and related concepts; classification references require release and code identity." }, { "id": "SRC-004", "title": "SNOMED CT Release File Specification", "organization": "SNOMED International", "url": "https://docs.snomed.org/snomed-ct-specifications/snomed-ct-release-file-specification", "version_or_date": "Current specification, accessed 6 September 2026", "source_type": "classifier", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:56:00Z", "relevance": "Defines versioned concept, description and relationship release components for detailed clinical terminology and supports edition, module and effective-time pinning." }, { "id": "SRC-005", "title": "LOINC Users' Guide", "organization": "Regenstrief Institute", "url": "https://loinc.org/kb/users-guide/", "version_or_date": "Current LOINC guidance, accessed 6 September 2026", "source_type": "classifier", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:56:00Z", "relevance": "Provides identifiers and semantic axes for observations, measurements and documents; local tests and units still require explicit mappings and version context." }, { "id": "SRC-006", "title": "DICOM Standard Current Edition", "organization": "DICOM Standards Committee", "url": "https://www.dicomstandard.org/current", "version_or_date": "Current edition, accessed 6 September 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:56:00Z", "relevance": "Defines medical imaging information objects, services, identifiers and metadata for referenced imaging studies and reports without embedding image payloads in this model." }, { "id": "SRC-007", "title": "Unified Code for Units of Measure", "organization": "Regenstrief Institute", "url": "https://ucum.org/ucum", "version_or_date": "UCUM specification, accessed 6 September 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:56:00Z", "relevance": "Provides unambiguous computable unit expressions for quantitative clinical observations while original displayed units and conversion provenance remain preserved." }, { "id": "SRC-008", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:56:00Z", "relevance": "Provides entities, activities, agents, attribution, derivation, delegation, revision and qualified influence for clinical and personal-source provenance." }, { "id": "SRC-009", "title": "International Classification of Functioning, Disability and Health", "organization": "World Health Organization", "url": "https://www.who.int/standards/classifications/international-classification-of-functioning-disability-and-health", "version_or_date": "WHO ICF reference, accessed 6 September 2026", "source_type": "classifier", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:56:00Z", "relevance": "Provides a biopsychosocial classification for body functions, activities, participation and environmental factors, preventing Personal Health from being reduced to diagnoses alone." }, { "id": "SRC-010", "title": "General Data Protection Regulation", "organization": "European Union", "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj", "version_or_date": "Regulation (EU) 2016/679, 27 April 2016", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:56:00Z", "relevance": "Supplies an EU health-data privacy profile covering special-category data, purpose limitation, minimization, accuracy, access, rectification, restriction, security, retention and legal bases." }, { "id": "SRC-011", "title": "Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "RFC 3339, July 2002", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-06T01:56:00Z", "relevance": "Defines interoperable event timestamps with seconds and explicit UTC relation for clinical occurrence, recording, observation, issuance and knowledge times." } ], "structure": { "bundles": [ { "id": "subject-record-and-longitudinal-boundary", "name": "Subject, record and longitudinal boundary", "description": "Identifies whose health context is represented and how distributed source records join without identity collapse.", "rationale": "Health data can cause direct harm when assigned to the wrong person, silently merged or stripped of source and time.", "source_refs": [ "SRC-001", "SRC-008", "SRC-011" ], "layers": [ { "id": "subject-and-record-identity", "name": "Subject and record identity", "description": "Stable subject linkage and the identity of this longitudinal context.", "source_refs": [ "SRC-001", "SRC-008" ], "findings": [ { "id": "subject-reference-identity-assurance-and-match-basis", "name": "Subject reference, identity assurance and match basis", "description": "Authoritative person reference, identifiers, assigners, match method, assurance, conflicts and manual-review state.", "source_refs": [ "SRC-001" ], "questions": [ { "id": "subject-reference-identity-assurance-and-match-basis-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for subject reference, identity assurance and match basis?", "kind": "identity", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "subject-reference-identity-assurance-and-match-basis-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes subject reference, identity assurance and match basis, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "subject-reference-identity-assurance-and-match-basis-q03", "text": "How may subject reference, identity assurance and match basis be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "subject-reference-identity-assurance-and-match-basis-data", "name": "Subject reference, identity assurance and match basis data", "description": "Structured, source-qualified answer data for subject reference, identity assurance and match basis.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "subject-reference-identity-assurance-and-match-basis-record", "name": "Subject reference, identity assurance and match basis record", "description": "Versioned evidence-bearing record for subject reference, identity assurance and match basis with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus subject-reference-identity-assurance-and-match-basis assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "health-context-identifier-custodian-controller-and-master-bindings", "name": "Health-context identifier, custodian, controller and master bindings", "description": "Identity of the federated context plus source-system, custodian, controller, repository and portability bindings without universal ownership inference.", "source_refs": [ "SRC-001", "SRC-010" ], "questions": [ { "id": "health-context-identifier-custodian-controller-and-master-bindings-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for health-context identifier, custodian, controller and master bindings?", "kind": "ownership", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "health-context-identifier-custodian-controller-and-master-bindings-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes health-context identifier, custodian, controller and master bindings, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "health-context-identifier-custodian-controller-and-master-bindings-q03", "text": "How may health-context identifier, custodian, controller and master bindings be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "health-context-identifier-custodian-controller-and-master-bindings-data", "name": "Health-context identifier, custodian, controller and master bindings data", "description": "Structured, source-qualified answer data for health-context identifier, custodian, controller and master bindings.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-010" ] } ], "artifacts": [ { "id": "health-context-identifier-custodian-controller-and-master-bindings-record", "name": "Health-context identifier, custodian, controller and master bindings record", "description": "Versioned evidence-bearing record for health-context identifier, custodian, controller and master bindings with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus health-context-identifier-custodian-controller-and-master-bindings assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "assertion-status-and-longitudinal-time", "name": "Assertion status and longitudinal time", "description": "How claims from different sources coexist, change and form a time-aware view.", "source_refs": [ "SRC-001", "SRC-008", "SRC-011" ], "findings": [ { "id": "assertion-kind-source-status-verification-and-contestation", "name": "Assertion kind, source, status, verification and contestation", "description": "Separates self-report, clinical assertion, direct observation, device output and algorithmic inference with verification, refutation and entered-in-error states.", "source_refs": [ "SRC-001", "SRC-008" ], "questions": [ { "id": "assertion-kind-source-status-verification-and-contestation-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for assertion kind, source, status, verification and contestation?", "kind": "provenance", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "assertion-kind-source-status-verification-and-contestation-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes assertion kind, source, status, verification and contestation, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "assertion-kind-source-status-verification-and-contestation-q03", "text": "How may assertion kind, source, status, verification and contestation be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "assertion-kind-source-status-verification-and-contestation-data", "name": "Assertion kind, source, status, verification and contestation data", "description": "Structured, source-qualified answer data for assertion kind, source, status, verification and contestation.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-008" ] } ], "artifacts": [ { "id": "assertion-kind-source-status-verification-and-contestation-record", "name": "Assertion kind, source, status, verification and contestation record", "description": "Versioned evidence-bearing record for assertion kind, source, status, verification and contestation with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus assertion-kind-source-status-verification-and-contestation assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "clinical-event-effective-recorded-issued-observed-and-knowledge-time", "name": "Clinical event, effective, recorded, issued, observed and knowledge time", "description": "Distinct instants and intervals, precision, timezone, uncertainty, retrospective entry and correction lineage.", "source_refs": [ "SRC-001", "SRC-011" ], "questions": [ { "id": "clinical-event-effective-recorded-issued-observed-and-knowledge-time-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for clinical event, effective, recorded, issued, observed and knowledge time?", "kind": "temporal", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "clinical-event-effective-recorded-issued-observed-and-knowledge-time-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes clinical event, effective, recorded, issued, observed and knowledge time, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "clinical-event-effective-recorded-issued-observed-and-knowledge-time-q03", "text": "How may clinical event, effective, recorded, issued, observed and knowledge time be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "clinical-event-effective-recorded-issued-observed-and-knowledge-time-data", "name": "Clinical event, effective, recorded, issued, observed and knowledge time data", "description": "Structured, source-qualified answer data for clinical event, effective, recorded, issued, observed and knowledge time.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-011" ] } ], "artifacts": [ { "id": "clinical-event-effective-recorded-issued-observed-and-knowledge-time-record", "name": "Clinical event, effective, recorded, issued, observed and knowledge time record", "description": "Versioned evidence-bearing record for clinical event, effective, recorded, issued, observed and knowledge time with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus clinical-event-effective-recorded-issued-observed-and-knowledge-time assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-011" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "health-state-risk-and-function", "name": "Health state, risk and function", "description": "Represents conditions, health concerns, risks and the person's functional state.", "rationale": "A useful personal health context includes course, impact and functioning, not only diagnosis codes or a current problem-list snapshot.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-009" ], "layers": [ { "id": "conditions-and-problem-list", "name": "Conditions and problem list", "description": "Clinically asserted and self-reported health problems with course and evidence.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ], "findings": [ { "id": "condition-concern-diagnosis-code-and-verification", "name": "Condition, concern, diagnosis code and verification", "description": "Condition identity, category, terminology, evidence, clinical and verification status, onset and recorder or asserter.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ], "questions": [ { "id": "condition-concern-diagnosis-code-and-verification-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for condition, concern, diagnosis code and verification?", "kind": "state", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "condition-concern-diagnosis-code-and-verification-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes condition, concern, diagnosis code and verification, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "condition-concern-diagnosis-code-and-verification-q03", "text": "How may condition, concern, diagnosis code and verification be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "condition-concern-diagnosis-code-and-verification-data", "name": "Condition, concern, diagnosis code and verification data", "description": "Structured, source-qualified answer data for condition, concern, diagnosis code and verification.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "condition-concern-diagnosis-code-and-verification-record", "name": "Condition, concern, diagnosis code and verification record", "description": "Versioned evidence-bearing record for condition, concern, diagnosis code and verification with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus condition-concern-diagnosis-code-and-verification assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "severity-stage-course-remission-resolution-and-recurrence", "name": "Severity, stage, course, remission, resolution and recurrence", "description": "Time-qualified course assertions, stages, body sites, episodes, remission, relapse and resolved state with explicit source.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ], "questions": [ { "id": "severity-stage-course-remission-resolution-and-recurrence-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for severity, stage, course, remission, resolution and recurrence?", "kind": "lifecycle", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "severity-stage-course-remission-resolution-and-recurrence-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes severity, stage, course, remission, resolution and recurrence, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "severity-stage-course-remission-resolution-and-recurrence-q03", "text": "How may severity, stage, course, remission, resolution and recurrence be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "severity-stage-course-remission-resolution-and-recurrence-data", "name": "Severity, stage, course, remission, resolution and recurrence data", "description": "Structured, source-qualified answer data for severity, stage, course, remission, resolution and recurrence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] } ], "artifacts": [ { "id": "severity-stage-course-remission-resolution-and-recurrence-record", "name": "Severity, stage, course, remission, resolution and recurrence record", "description": "Versioned evidence-bearing record for severity, stage, course, remission, resolution and recurrence with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus severity-stage-course-remission-resolution-and-recurrence assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null } ] }, { "id": "risk-function-and-lived-health", "name": "Risk, function and lived health", "description": "Risk estimates and physical, cognitive, mental and social functioning.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ], "findings": [ { "id": "risk-factor-family-history-prediction-and-prevention-context", "name": "Risk factor, family history, prediction and prevention context", "description": "Observed and asserted factors, model or guideline references, probability horizon, uncertainty and prevention links without deterministic diagnosis.", "source_refs": [ "SRC-001", "SRC-003" ], "questions": [ { "id": "risk-factor-family-history-prediction-and-prevention-context-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for risk factor, family history, prediction and prevention context?", "kind": "measurement", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "risk-factor-family-history-prediction-and-prevention-context-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes risk factor, family history, prediction and prevention context, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "risk-factor-family-history-prediction-and-prevention-context-q03", "text": "How may risk factor, family history, prediction and prevention context be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "risk-factor-family-history-prediction-and-prevention-context-data", "name": "Risk factor, family history, prediction and prevention context data", "description": "Structured, source-qualified answer data for risk factor, family history, prediction and prevention context.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] } ], "artifacts": [ { "id": "risk-factor-family-history-prediction-and-prevention-context-record", "name": "Risk factor, family history, prediction and prevention context record", "description": "Versioned evidence-bearing record for risk factor, family history, prediction and prevention context with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus risk-factor-family-history-prediction-and-prevention-context assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "functional-cognitive-mental-social-and-quality-of-life-status", "name": "Functional, cognitive, mental, social and quality-of-life status", "description": "Activities, participation, body functions, limitations, supports, instruments, self-report and clinician observation with ICF alignment.", "source_refs": [ "SRC-001", "SRC-009" ], "questions": [ { "id": "functional-cognitive-mental-social-and-quality-of-life-status-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for functional, cognitive, mental, social and quality-of-life status?", "kind": "state", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "functional-cognitive-mental-social-and-quality-of-life-status-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes functional, cognitive, mental, social and quality-of-life status, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "functional-cognitive-mental-social-and-quality-of-life-status-q03", "text": "How may functional, cognitive, mental, social and quality-of-life status be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "functional-cognitive-mental-social-and-quality-of-life-status-data", "name": "Functional, cognitive, mental, social and quality-of-life status data", "description": "Structured, source-qualified answer data for functional, cognitive, mental, social and quality-of-life status.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-009" ] } ], "artifacts": [ { "id": "functional-cognitive-mental-social-and-quality-of-life-status-record", "name": "Functional, cognitive, mental, social and quality-of-life status record", "description": "Versioned evidence-bearing record for functional, cognitive, mental, social and quality-of-life status with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus functional-cognitive-mental-social-and-quality-of-life-status assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "observations-diagnostics-and-evidence", "name": "Observations, diagnostics and evidence", "description": "Represents measurements, results and their diagnostic context with sufficient semantics for safe interpretation.", "rationale": "A number or coded result is unsafe without subject, time, method, specimen or body site, units, reference context, interpretation and source.", "source_refs": [ "SRC-001", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008" ], "layers": [ { "id": "measurement-and-observation", "name": "Measurement and observation", "description": "Individual quantitative, qualitative and coded findings.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007" ], "findings": [ { "id": "observation-code-value-unit-component-and-status", "name": "Observation code, value, unit, component and status", "description": "LOINC or other code, value form, UCUM and displayed unit, components, status, performer, device and derived-from references.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007" ], "questions": [ { "id": "observation-code-value-unit-component-and-status-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for observation code, value, unit, component and status?", "kind": "measurement", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "observation-code-value-unit-component-and-status-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes observation code, value, unit, component and status, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "observation-code-value-unit-component-and-status-q03", "text": "How may observation code, value, unit, component and status be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "observation-code-value-unit-component-and-status-data", "name": "Observation code, value, unit, component and status data", "description": "Structured, source-qualified answer data for observation code, value, unit, component and status.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "observation-code-value-unit-component-and-status-record", "name": "Observation code, value, unit, component and status record", "description": "Versioned evidence-bearing record for observation code, value, unit, component and status with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus observation-code-value-unit-component-and-status assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "method-body-site-posture-context-reference-range-and-interpretation", "name": "Method, body site, posture, context, reference range and interpretation", "description": "Collection and measurement conditions, body site, posture, fasting or other context, population-specific ranges, flags and interpretive authority.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007" ], "questions": [ { "id": "method-body-site-posture-context-reference-range-and-interpretation-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for method, body site, posture, context, reference range and interpretation?", "kind": "evidence", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "method-body-site-posture-context-reference-range-and-interpretation-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes method, body site, posture, context, reference range and interpretation, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "method-body-site-posture-context-reference-range-and-interpretation-q03", "text": "How may method, body site, posture, context, reference range and interpretation be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "method-body-site-posture-context-reference-range-and-interpretation-data", "name": "Method, body site, posture, context, reference range and interpretation data", "description": "Structured, source-qualified answer data for method, body site, posture, context, reference range and interpretation.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005", "SRC-007" ] } ], "artifacts": [ { "id": "method-body-site-posture-context-reference-range-and-interpretation-record", "name": "Method, body site, posture, context, reference range and interpretation record", "description": "Versioned evidence-bearing record for method, body site, posture, context, reference range and interpretation with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus method-body-site-posture-context-reference-range-and-interpretation assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-005", "SRC-007" ] } ], "inline_only_rationale": null } ] }, { "id": "specimen-imaging-and-genomic-references", "name": "Specimen, imaging and genomic references", "description": "Links high-volume diagnostic evidence while leaving its native master external.", "source_refs": [ "SRC-001", "SRC-006", "SRC-008" ], "findings": [ { "id": "specimen-collection-processing-accession-and-chain-of-custody", "name": "Specimen collection, processing, accession and chain of custody", "description": "Specimen reference, type, collection site and time, container, processing, accession, adequacy and custody evidence.", "source_refs": [ "SRC-001", "SRC-008" ], "questions": [ { "id": "specimen-collection-processing-accession-and-chain-of-custody-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for specimen collection, processing, accession and chain of custody?", "kind": "provenance", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "specimen-collection-processing-accession-and-chain-of-custody-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes specimen collection, processing, accession and chain of custody, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "specimen-collection-processing-accession-and-chain-of-custody-q03", "text": "How may specimen collection, processing, accession and chain of custody be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "specimen-collection-processing-accession-and-chain-of-custody-data", "name": "Specimen collection, processing, accession and chain of custody data", "description": "Structured, source-qualified answer data for specimen collection, processing, accession and chain of custody.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-008" ] } ], "artifacts": [ { "id": "specimen-collection-processing-accession-and-chain-of-custody-record", "name": "Specimen collection, processing, accession and chain of custody record", "description": "Versioned evidence-bearing record for specimen collection, processing, accession and chain of custody with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus specimen-collection-processing-accession-and-chain-of-custody assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "imaging-study-series-instance-report-and-genomic-result-reference", "name": "Imaging study, series, instance, report and genomic-result reference", "description": "DICOM study and report identifiers plus external genomic result references, access controls, digests and derived summary links.", "source_refs": [ "SRC-001", "SRC-006" ], "questions": [ { "id": "imaging-study-series-instance-report-and-genomic-result-reference-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for imaging study, series, instance, report and genomic-result reference?", "kind": "relationship", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "imaging-study-series-instance-report-and-genomic-result-reference-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes imaging study, series, instance, report and genomic-result reference, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "imaging-study-series-instance-report-and-genomic-result-reference-q03", "text": "How may imaging study, series, instance, report and genomic-result reference be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "imaging-study-series-instance-report-and-genomic-result-reference-data", "name": "Imaging study, series, instance, report and genomic-result reference data", "description": "Structured, source-qualified answer data for imaging study, series, instance, report and genomic-result reference.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] } ], "artifacts": [ { "id": "imaging-study-series-instance-report-and-genomic-result-reference-record", "name": "Imaging study, series, instance, report and genomic-result reference record", "description": "Versioned evidence-bearing record for imaging study, series, instance, report and genomic-result reference with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus imaging-study-series-instance-report-and-genomic-result-reference assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "diagnostic-interpretation-and-uncertainty", "name": "Diagnostic interpretation and uncertainty", "description": "Panels, reports, evidence links and explicit limits on meaning.", "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-005" ], "findings": [ { "id": "diagnostic-report-panel-conclusion-performer-and-finality", "name": "Diagnostic report, panel, conclusion, performer and finality", "description": "Report identity, grouped results, conclusion, interpreter, status, issued time, amendment and superseded versions.", "source_refs": [ "SRC-001", "SRC-005" ], "questions": [ { "id": "diagnostic-report-panel-conclusion-performer-and-finality-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for diagnostic report, panel, conclusion, performer and finality?", "kind": "evidence", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "diagnostic-report-panel-conclusion-performer-and-finality-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes diagnostic report, panel, conclusion, performer and finality, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "diagnostic-report-panel-conclusion-performer-and-finality-q03", "text": "How may diagnostic report, panel, conclusion, performer and finality be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "diagnostic-report-panel-conclusion-performer-and-finality-data", "name": "Diagnostic report, panel, conclusion, performer and finality data", "description": "Structured, source-qualified answer data for diagnostic report, panel, conclusion, performer and finality.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-005" ] } ], "artifacts": [ { "id": "diagnostic-report-panel-conclusion-performer-and-finality-record", "name": "Diagnostic report, panel, conclusion, performer and finality record", "description": "Versioned evidence-bearing record for diagnostic report, panel, conclusion, performer and finality with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus diagnostic-report-panel-conclusion-performer-and-finality assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "evidence-link-uncertainty-detection-limit-data-absent-and-disagreement", "name": "Evidence link, uncertainty, detection limit, data absent and disagreement", "description": "Supporting and contradicting evidence, measurement uncertainty, detection bounds, absence reason, conflicting interpretation and unresolved state.", "source_refs": [ "SRC-001", "SRC-008" ], "questions": [ { "id": "evidence-link-uncertainty-detection-limit-data-absent-and-disagreement-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for evidence link, uncertainty, detection limit, data absent and disagreement?", "kind": "quality", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "evidence-link-uncertainty-detection-limit-data-absent-and-disagreement-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes evidence link, uncertainty, detection limit, data absent and disagreement, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "evidence-link-uncertainty-detection-limit-data-absent-and-disagreement-q03", "text": "How may evidence link, uncertainty, detection limit, data absent and disagreement be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "evidence-link-uncertainty-detection-limit-data-absent-and-disagreement-data", "name": "Evidence link, uncertainty, detection limit, data absent and disagreement data", "description": "Structured, source-qualified answer data for evidence link, uncertainty, detection limit, data absent and disagreement.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-008" ] } ], "artifacts": [ { "id": "evidence-link-uncertainty-detection-limit-data-absent-and-disagreement-record", "name": "Evidence link, uncertainty, detection limit, data absent and disagreement record", "description": "Versioned evidence-bearing record for evidence link, uncertainty, detection limit, data absent and disagreement with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus evidence-link-uncertainty-detection-limit-data-absent-and-disagreement assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "safety-medication-immunization-and-procedures", "name": "Safety, medication, immunization and procedures", "description": "Captures standing safety risks and clinically relevant interventions.", "rationale": "Medication intent, dispensing, administration and patient report can disagree, and allergy, procedure and immunization assertions require their own verification and lifecycle.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004" ], "layers": [ { "id": "allergy-intolerance-and-adverse-reaction", "name": "Allergy, intolerance and adverse reaction", "description": "Substances, manifestations, exposure and confidence needed for safety decisions.", "source_refs": [ "SRC-001", "SRC-004" ], "findings": [ { "id": "allergy-intolerance-substance-category-and-reaction", "name": "Allergy or intolerance substance, category and reaction", "description": "Coded agent or substance, allergy versus intolerance category, manifestations, exposure route, onset, severity and evidence.", "source_refs": [ "SRC-001", "SRC-004" ], "questions": [ { "id": "allergy-intolerance-substance-category-and-reaction-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for allergy or intolerance substance, category and reaction?", "kind": "state", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "allergy-intolerance-substance-category-and-reaction-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes allergy or intolerance substance, category and reaction, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "allergy-intolerance-substance-category-and-reaction-q03", "text": "How may allergy or intolerance substance, category and reaction be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "allergy-intolerance-substance-category-and-reaction-data", "name": "Allergy or intolerance substance, category and reaction data", "description": "Structured, source-qualified answer data for allergy or intolerance substance, category and reaction.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004" ] } ], "artifacts": [ { "id": "allergy-intolerance-substance-category-and-reaction-record", "name": "Allergy or intolerance substance, category and reaction record", "description": "Versioned evidence-bearing record for allergy or intolerance substance, category and reaction with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus allergy-intolerance-substance-category-and-reaction assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "allergy-verification-criticality-last-occurrence-and-refutation", "name": "Allergy verification, criticality, last occurrence and refutation", "description": "Clinical and verification status, criticality, recorder, confirmer, last exposure or reaction and refuted or entered-in-error history.", "source_refs": [ "SRC-001" ], "questions": [ { "id": "allergy-verification-criticality-last-occurrence-and-refutation-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for allergy verification, criticality, last occurrence and refutation?", "kind": "validation", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "allergy-verification-criticality-last-occurrence-and-refutation-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes allergy verification, criticality, last occurrence and refutation, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "allergy-verification-criticality-last-occurrence-and-refutation-q03", "text": "How may allergy verification, criticality, last occurrence and refutation be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "allergy-verification-criticality-last-occurrence-and-refutation-data", "name": "Allergy verification, criticality, last occurrence and refutation data", "description": "Structured, source-qualified answer data for allergy verification, criticality, last occurrence and refutation.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "allergy-verification-criticality-last-occurrence-and-refutation-record", "name": "Allergy verification, criticality, last occurrence and refutation record", "description": "Versioned evidence-bearing record for allergy verification, criticality, last occurrence and refutation with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus allergy-verification-criticality-last-occurrence-and-refutation assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "medication-and-immunization", "name": "Medication and immunization", "description": "Intent, supply, use and administration history for medicines and vaccines.", "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ], "findings": [ { "id": "medication-request-dispense-administration-and-statement-reconciliation", "name": "Medication request, dispense, administration and statement reconciliation", "description": "Product code, intent, dose, route, schedule, indication, prescriber, supply, actual use, adherence and source discrepancies.", "source_refs": [ "SRC-001", "SRC-004" ], "questions": [ { "id": "medication-request-dispense-administration-and-statement-reconciliation-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for medication request, dispense, administration and statement reconciliation?", "kind": "process", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "medication-request-dispense-administration-and-statement-reconciliation-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes medication request, dispense, administration and statement reconciliation, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "medication-request-dispense-administration-and-statement-reconciliation-q03", "text": "How may medication request, dispense, administration and statement reconciliation be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "medication-request-dispense-administration-and-statement-reconciliation-data", "name": "Medication request, dispense, administration and statement reconciliation data", "description": "Structured, source-qualified answer data for medication request, dispense, administration and statement reconciliation.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-004" ] } ], "artifacts": [ { "id": "medication-request-dispense-administration-and-statement-reconciliation-record", "name": "Medication request, dispense, administration and statement reconciliation record", "description": "Versioned evidence-bearing record for medication request, dispense, administration and statement reconciliation with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus medication-request-dispense-administration-and-statement-reconciliation assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "immunization-dose-product-lot-site-reaction-and-validity", "name": "Immunization dose, product, lot, site, reaction and validity", "description": "Vaccine, disease target, dose number, lot, site, route, performer, reaction, status, source and schedule or validity interpretation.", "source_refs": [ "SRC-001", "SRC-002" ], "questions": [ { "id": "immunization-dose-product-lot-site-reaction-and-validity-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for immunization dose, product, lot, site, reaction and validity?", "kind": "event", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "immunization-dose-product-lot-site-reaction-and-validity-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes immunization dose, product, lot, site, reaction and validity, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "immunization-dose-product-lot-site-reaction-and-validity-q03", "text": "How may immunization dose, product, lot, site, reaction and validity be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "immunization-dose-product-lot-site-reaction-and-validity-data", "name": "Immunization dose, product, lot, site, reaction and validity data", "description": "Structured, source-qualified answer data for immunization dose, product, lot, site, reaction and validity.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "immunization-dose-product-lot-site-reaction-and-validity-record", "name": "Immunization dose, product, lot, site, reaction and validity record", "description": "Versioned evidence-bearing record for immunization dose, product, lot, site, reaction and validity with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus immunization-dose-product-lot-site-reaction-and-validity assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null } ] }, { "id": "procedures-devices-and-outcomes", "name": "Procedures, devices and outcomes", "description": "Performed or planned interventions and implanted or assistive devices.", "source_refs": [ "SRC-001", "SRC-006" ], "findings": [ { "id": "procedure-treatment-status-performer-body-site-reason-and-outcome", "name": "Procedure or treatment status, performer, body site, reason and outcome", "description": "Procedure identity, code, occurrence, status, indication, performer, body site, complications, outcome and report reference.", "source_refs": [ "SRC-001" ], "questions": [ { "id": "procedure-treatment-status-performer-body-site-reason-and-outcome-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for procedure or treatment status, performer, body site, reason and outcome?", "kind": "event", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "procedure-treatment-status-performer-body-site-reason-and-outcome-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes procedure or treatment status, performer, body site, reason and outcome, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "procedure-treatment-status-performer-body-site-reason-and-outcome-q03", "text": "How may procedure or treatment status, performer, body site, reason and outcome be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "procedure-treatment-status-performer-body-site-reason-and-outcome-data", "name": "Procedure or treatment status, performer, body site, reason and outcome data", "description": "Structured, source-qualified answer data for procedure or treatment status, performer, body site, reason and outcome.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "procedure-treatment-status-performer-body-site-reason-and-outcome-record", "name": "Procedure or treatment status, performer, body site, reason and outcome record", "description": "Versioned evidence-bearing record for procedure or treatment status, performer, body site, reason and outcome with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus procedure-treatment-status-performer-body-site-reason-and-outcome assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "implant-assistive-device-udi-use-period-and-safety-reference", "name": "Implant or assistive device, UDI, use period and safety reference", "description": "External device identity, unique device identifier, implant or use interval, status, owner, safety notice and removal reference.", "source_refs": [ "SRC-001", "SRC-006" ], "questions": [ { "id": "implant-assistive-device-udi-use-period-and-safety-reference-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for implant or assistive device, udi, use period and safety reference?", "kind": "relationship", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "implant-assistive-device-udi-use-period-and-safety-reference-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes implant or assistive device, udi, use period and safety reference, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "implant-assistive-device-udi-use-period-and-safety-reference-q03", "text": "How may implant or assistive device, udi, use period and safety reference be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "implant-assistive-device-udi-use-period-and-safety-reference-data", "name": "Implant or assistive device, UDI, use period and safety reference data", "description": "Structured, source-qualified answer data for implant or assistive device, udi, use period and safety reference.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-006" ] } ], "artifacts": [ { "id": "implant-assistive-device-udi-use-period-and-safety-reference-record", "name": "Implant or assistive device, UDI, use period and safety reference record", "description": "Versioned evidence-bearing record for implant or assistive device, udi, use period and safety reference with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus implant-assistive-device-udi-use-period-and-safety-reference assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "encounters-care-plans-and-coordination", "name": "Encounters, care plans and coordination", "description": "Links health assertions to care contacts, responsible teams, intentions, goals and follow-up.", "rationale": "A personal context needs the care narrative but does not own provider operations, scheduling, billing or service-delivery execution.", "source_refs": [ "SRC-001", "SRC-002", "SRC-008" ], "layers": [ { "id": "encounters-participants-and-context", "name": "Encounters, participants and context", "description": "Contacts with care settings and the actors and reasons that frame them.", "source_refs": [ "SRC-001", "SRC-002" ], "findings": [ { "id": "encounter-class-type-reason-period-location-and-disposition", "name": "Encounter class, type, reason, period, location and disposition", "description": "External encounter reference, class, care setting, reason, priority, start and end, location, hospitalization context and disposition.", "source_refs": [ "SRC-001" ], "questions": [ { "id": "encounter-class-type-reason-period-location-and-disposition-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for encounter class, type, reason, period, location and disposition?", "kind": "event", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "encounter-class-type-reason-period-location-and-disposition-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes encounter class, type, reason, period, location and disposition, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "encounter-class-type-reason-period-location-and-disposition-q03", "text": "How may encounter class, type, reason, period, location and disposition be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "encounter-class-type-reason-period-location-and-disposition-data", "name": "Encounter class, type, reason, period, location and disposition data", "description": "Structured, source-qualified answer data for encounter class, type, reason, period, location and disposition.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "encounter-class-type-reason-period-location-and-disposition-record", "name": "Encounter class, type, reason, period, location and disposition record", "description": "Versioned evidence-bearing record for encounter class, type, reason, period, location and disposition with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus encounter-class-type-reason-period-location-and-disposition assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "practitioner-organization-care-team-role-and-responsibility", "name": "Practitioner, organization, care-team role and responsibility", "description": "External provider and team identities, encounter or plan role, responsibility interval, communication route and source.", "source_refs": [ "SRC-001", "SRC-002" ], "questions": [ { "id": "practitioner-organization-care-team-role-and-responsibility-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for practitioner, organization, care-team role and responsibility?", "kind": "relationship", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "practitioner-organization-care-team-role-and-responsibility-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes practitioner, organization, care-team role and responsibility, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "practitioner-organization-care-team-role-and-responsibility-q03", "text": "How may practitioner, organization, care-team role and responsibility be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "practitioner-organization-care-team-role-and-responsibility-data", "name": "Practitioner, organization, care-team role and responsibility data", "description": "Structured, source-qualified answer data for practitioner, organization, care-team role and responsibility.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "practitioner-organization-care-team-role-and-responsibility-record", "name": "Practitioner, organization, care-team role and responsibility record", "description": "Versioned evidence-bearing record for practitioner, organization, care-team role and responsibility with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus practitioner-organization-care-team-role-and-responsibility assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null } ] }, { "id": "plans-goals-referrals-and-followup", "name": "Plans, goals, referrals and follow-up", "description": "Agreed or proposed future care and its responsible actors.", "source_refs": [ "SRC-001", "SRC-002" ], "findings": [ { "id": "care-plan-goal-activity-priority-owner-and-progress", "name": "Care plan, goal, activity, priority, owner and progress", "description": "Plan and goal identities, intent, status, targets, activities, responsible parties, progress evidence, review and replacement lineage.", "source_refs": [ "SRC-001" ], "questions": [ { "id": "care-plan-goal-activity-priority-owner-and-progress-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for care plan, goal, activity, priority, owner and progress?", "kind": "process", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "care-plan-goal-activity-priority-owner-and-progress-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes care plan, goal, activity, priority, owner and progress, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "care-plan-goal-activity-priority-owner-and-progress-q03", "text": "How may care plan, goal, activity, priority, owner and progress be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "care-plan-goal-activity-priority-owner-and-progress-data", "name": "Care plan, goal, activity, priority, owner and progress data", "description": "Structured, source-qualified answer data for care plan, goal, activity, priority, owner and progress.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "care-plan-goal-activity-priority-owner-and-progress-record", "name": "Care plan, goal, activity, priority, owner and progress record", "description": "Versioned evidence-bearing record for care plan, goal, activity, priority, owner and progress with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus care-plan-goal-activity-priority-owner-and-progress assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "appointment-referral-service-request-followup-and-patient-instruction", "name": "Appointment, referral, service request, follow-up and patient instruction", "description": "External request and appointment references, recipient, urgency, reason, due time, completion status and versioned instructions.", "source_refs": [ "SRC-001", "SRC-002" ], "questions": [ { "id": "appointment-referral-service-request-followup-and-patient-instruction-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for appointment, referral, service request, follow-up and patient instruction?", "kind": "relationship", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "appointment-referral-service-request-followup-and-patient-instruction-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes appointment, referral, service request, follow-up and patient instruction, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "appointment-referral-service-request-followup-and-patient-instruction-q03", "text": "How may appointment, referral, service request, follow-up and patient instruction be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "appointment-referral-service-request-followup-and-patient-instruction-data", "name": "Appointment, referral, service request, follow-up and patient instruction data", "description": "Structured, source-qualified answer data for appointment, referral, service request, follow-up and patient instruction.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "appointment-referral-service-request-followup-and-patient-instruction-record", "name": "Appointment, referral, service request, follow-up and patient instruction record", "description": "Versioned evidence-bearing record for appointment, referral, service request, follow-up and patient instruction with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus appointment-referral-service-request-followup-and-patient-instruction assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "provenance-consent-privacy-and-retention", "name": "Provenance, consent, privacy and retention", "description": "Makes every material assertion attributable and governs highly sensitive access and lifecycle.", "rationale": "Personal Health must support person agency and lawful portability without pretending one ownership rule applies in every jurisdiction or emergency.", "source_refs": [ "SRC-001", "SRC-008", "SRC-010", "SRC-011" ], "layers": [ { "id": "provenance-consent-and-directives", "name": "Provenance, consent and directives", "description": "Source lineage and the person's or lawful representative's choices.", "source_refs": [ "SRC-001", "SRC-008", "SRC-010" ], "findings": [ { "id": "author-recorder-asserter-performer-source-derivation-and-signature", "name": "Author, recorder, asserter, performer, source, derivation and signature", "description": "Attributable roles, source record, import path, transformations, signatures, digests and revision lineage for each assertion.", "source_refs": [ "SRC-001", "SRC-008" ], "questions": [ { "id": "author-recorder-asserter-performer-source-derivation-and-signature-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for author, recorder, asserter, performer, source, derivation and signature?", "kind": "provenance", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "author-recorder-asserter-performer-source-derivation-and-signature-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes author, recorder, asserter, performer, source, derivation and signature, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "author-recorder-asserter-performer-source-derivation-and-signature-q03", "text": "How may author, recorder, asserter, performer, source, derivation and signature be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "author-recorder-asserter-performer-source-derivation-and-signature-data", "name": "Author, recorder, asserter, performer, source, derivation and signature data", "description": "Structured, source-qualified answer data for author, recorder, asserter, performer, source, derivation and signature.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-008" ] } ], "artifacts": [ { "id": "author-recorder-asserter-performer-source-derivation-and-signature-record", "name": "Author, recorder, asserter, performer, source, derivation and signature record", "description": "Versioned evidence-bearing record for author, recorder, asserter, performer, source, derivation and signature with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus author-recorder-asserter-performer-source-derivation-and-signature assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "consent-directive-purpose-recipient-data-scope-validity-and-revocation", "name": "Consent or directive purpose, recipient, data scope, validity and revocation", "description": "Legal-basis and consent references, represented party, purposes, recipients, permitted data, exclusions, interval and withdrawal effect.", "source_refs": [ "SRC-001", "SRC-010" ], "questions": [ { "id": "consent-directive-purpose-recipient-data-scope-validity-and-revocation-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for consent or directive purpose, recipient, data scope, validity and revocation?", "kind": "authority", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "consent-directive-purpose-recipient-data-scope-validity-and-revocation-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes consent or directive purpose, recipient, data scope, validity and revocation, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "consent-directive-purpose-recipient-data-scope-validity-and-revocation-q03", "text": "How may consent or directive purpose, recipient, data scope, validity and revocation be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "consent-directive-purpose-recipient-data-scope-validity-and-revocation-data", "name": "Consent or directive purpose, recipient, data scope, validity and revocation data", "description": "Structured, source-qualified answer data for consent or directive purpose, recipient, data scope, validity and revocation.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-010" ] } ], "artifacts": [ { "id": "consent-directive-purpose-recipient-data-scope-validity-and-revocation-record", "name": "Consent or directive purpose, recipient, data scope, validity and revocation record", "description": "Versioned evidence-bearing record for consent or directive purpose, recipient, data scope, validity and revocation with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus consent-directive-purpose-recipient-data-scope-validity-and-revocation assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "access-correction-emergency-and-retention", "name": "Access, correction, emergency and retention", "description": "Field-sensitive disclosure, person rights, break-glass use and durable evidence.", "source_refs": [ "SRC-001", "SRC-008", "SRC-010", "SRC-011" ], "findings": [ { "id": "confidentiality-access-minimum-disclosure-emergency-use-and-audit", "name": "Confidentiality, access, minimum disclosure, emergency use and audit", "description": "Sensitivity labels, audience, purpose, minimum view, emergency authority, expiry, notification, post-review and immutable access log.", "source_refs": [ "SRC-001", "SRC-010" ], "questions": [ { "id": "confidentiality-access-minimum-disclosure-emergency-use-and-audit-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for confidentiality, access, minimum disclosure, emergency use and audit?", "kind": "access", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "confidentiality-access-minimum-disclosure-emergency-use-and-audit-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes confidentiality, access, minimum disclosure, emergency use and audit, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "confidentiality-access-minimum-disclosure-emergency-use-and-audit-q03", "text": "How may confidentiality, access, minimum disclosure, emergency use and audit be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "confidentiality-access-minimum-disclosure-emergency-use-and-audit-data", "name": "Confidentiality, access, minimum disclosure, emergency use and audit data", "description": "Structured, source-qualified answer data for confidentiality, access, minimum disclosure, emergency use and audit.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-010" ] } ], "artifacts": [ { "id": "confidentiality-access-minimum-disclosure-emergency-use-and-audit-record", "name": "Confidentiality, access, minimum disclosure, emergency use and audit record", "description": "Versioned evidence-bearing record for confidentiality, access, minimum disclosure, emergency use and audit with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus confidentiality-access-minimum-disclosure-emergency-use-and-audit assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "access-right-correction-amendment-restriction-retention-hold-and-deletion", "name": "Access right, correction, amendment, restriction, retention, hold and deletion", "description": "Request and decision history, contested data, source correction, appended amendment, retention class, legal hold, disposition and tombstone.", "source_refs": [ "SRC-001", "SRC-008", "SRC-010" ], "questions": [ { "id": "access-right-correction-amendment-restriction-retention-hold-and-deletion-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for access right, correction, amendment, restriction, retention, hold and deletion?", "kind": "retention", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "access-right-correction-amendment-restriction-retention-hold-and-deletion-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes access right, correction, amendment, restriction, retention, hold and deletion, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "access-right-correction-amendment-restriction-retention-hold-and-deletion-q03", "text": "How may access right, correction, amendment, restriction, retention, hold and deletion be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "access-right-correction-amendment-restriction-retention-hold-and-deletion-data", "name": "Access right, correction, amendment, restriction, retention, hold and deletion data", "description": "Structured, source-qualified answer data for access right, correction, amendment, restriction, retention, hold and deletion.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-008", "SRC-010" ] } ], "artifacts": [ { "id": "access-right-correction-amendment-restriction-retention-hold-and-deletion-record", "name": "Access right, correction, amendment, restriction, retention, hold and deletion record", "description": "Versioned evidence-bearing record for access right, correction, amendment, restriction, retention, hold and deletion with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus access-right-correction-amendment-restriction-retention-hold-and-deletion assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-008", "SRC-010" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "interoperability-summaries-validation-and-agent-operations", "name": "Interoperability, summaries, validation and agent operations", "description": "Controls terminology, summary projections and safe automated maintenance.", "rationale": "Exchange must preserve identity, status, terminology, units, time, provenance, uncertainty and access semantics and cannot make a summary the source of truth.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-008", "SRC-009", "SRC-011" ], "layers": [ { "id": "terminology-and-summary-projections", "name": "Terminology and summary projections", "description": "Versioned mappings and purpose-specific portable views.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-009" ], "findings": [ { "id": "fhir-resource-ips-emergency-self-and-research-view", "name": "FHIR resource, IPS, emergency, self and research view", "description": "Source and target profile, section inclusion, omissions, confidentiality, expiry, digest and non-round-trip declaration for each projection.", "source_refs": [ "SRC-001", "SRC-002" ], "questions": [ { "id": "fhir-resource-ips-emergency-self-and-research-view-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for fhir resource, ips, emergency, self and research view?", "kind": "interoperability", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "fhir-resource-ips-emergency-self-and-research-view-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes fhir resource, ips, emergency, self and research view, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "fhir-resource-ips-emergency-self-and-research-view-q03", "text": "How may fhir resource, ips, emergency, self and research view be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "fhir-resource-ips-emergency-self-and-research-view-data", "name": "FHIR resource, IPS, emergency, self and research view data", "description": "Structured, source-qualified answer data for fhir resource, ips, emergency, self and research view.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-002" ] } ], "artifacts": [ { "id": "fhir-resource-ips-emergency-self-and-research-view-record", "name": "FHIR resource, IPS, emergency, self and research view record", "description": "Versioned evidence-bearing record for fhir resource, ips, emergency, self and research view with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus fhir-resource-ips-emergency-self-and-research-view assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-002" ] } ], "inline_only_rationale": null }, { "id": "terminology-classification-unit-version-map-and-licence", "name": "Terminology, classification, unit, version, map and licence", "description": "Code system URI, release or edition, code, display, inactive state, map rule, equivalence, UCUM unit and licence constraints.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007", "SRC-009" ], "questions": [ { "id": "terminology-classification-unit-version-map-and-licence-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for terminology, classification, unit, version, map and licence?", "kind": "classification", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "terminology-classification-unit-version-map-and-licence-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes terminology, classification, unit, version, map and licence, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "terminology-classification-unit-version-map-and-licence-q03", "text": "How may terminology, classification, unit, version, map and licence be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "terminology-classification-unit-version-map-and-licence-data", "name": "Terminology, classification, unit, version, map and licence data", "description": "Structured, source-qualified answer data for terminology, classification, unit, version, map and licence.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007", "SRC-009" ] } ], "artifacts": [ { "id": "terminology-classification-unit-version-map-and-licence-record", "name": "Terminology, classification, unit, version, map and licence record", "description": "Versioned evidence-bearing record for terminology, classification, unit, version, map and licence with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus terminology-classification-unit-version-map-and-licence assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-003", "SRC-004", "SRC-005", "SRC-007", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "clinical-safety-and-agent-control", "name": "Clinical safety and agent control", "description": "Authorized operations, clinical review, validation, concurrency and recovery.", "source_refs": [ "SRC-001", "SRC-008", "SRC-010", "SRC-011" ], "findings": [ { "id": "agent-authority-clinical-review-purpose-preconditions-and-nonadvice", "name": "Agent authority, clinical review, purpose, preconditions and non-advice", "description": "Classifies reads, imports, proposals, corrections, disclosures and disposition as autonomous, propose, confirm or forbidden and blocks unsupervised clinical conclusions.", "source_refs": [ "SRC-001", "SRC-010" ], "questions": [ { "id": "agent-authority-clinical-review-purpose-preconditions-and-nonadvice-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for agent authority, clinical review, purpose, preconditions and non-advice?", "kind": "security", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "agent-authority-clinical-review-purpose-preconditions-and-nonadvice-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes agent authority, clinical review, purpose, preconditions and non-advice, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "agent-authority-clinical-review-purpose-preconditions-and-nonadvice-q03", "text": "How may agent authority, clinical review, purpose, preconditions and non-advice be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "agent-authority-clinical-review-purpose-preconditions-and-nonadvice-data", "name": "Agent authority, clinical review, purpose, preconditions and non-advice data", "description": "Structured, source-qualified answer data for agent authority, clinical review, purpose, preconditions and non-advice.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-010" ] } ], "artifacts": [ { "id": "agent-authority-clinical-review-purpose-preconditions-and-nonadvice-record", "name": "Agent authority, clinical review, purpose, preconditions and non-advice record", "description": "Versioned evidence-bearing record for agent authority, clinical review, purpose, preconditions and non-advice with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus agent-authority-clinical-review-purpose-preconditions-and-nonadvice assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "prewrite-postwrite-validation-conflict-concurrency-rollback-and-audit", "name": "Pre-write and post-write validation, conflict, concurrency, rollback and audit", "description": "Identity, terminology, unit, status, temporal, provenance, consent, stale-head and safety checks with immutable before and after evidence.", "source_refs": [ "SRC-001", "SRC-008", "SRC-011" ], "questions": [ { "id": "prewrite-postwrite-validation-conflict-concurrency-rollback-and-audit-q01", "text": "What exact values, codes, references, qualifiers and explicit unknown or data-absent reasons must be recorded for pre-write and post-write validation, conflict, concurrency, rollback and audit?", "kind": "validation", "answer_data": [ "value or typed reference", "code system and version", "status and time", "explicit unknown or absence reason" ] }, { "id": "prewrite-postwrite-validation-conflict-concurrency-rollback-and-audit-q02", "text": "Which person, practitioner, organization, device, source and evidence establishes pre-write and post-write validation, conflict, concurrency, rollback and audit, at what clinical, observation and knowledge time, and with what confidence?", "kind": "evidence", "answer_data": [ "asserting or observing actor", "source and method", "evidence and provenance", "times", "confidence" ] }, { "id": "prewrite-postwrite-validation-conflict-concurrency-rollback-and-audit-q03", "text": "How may pre-write and post-write validation, conflict, concurrency, rollback and audit be clinically validated, contested, corrected, superseded, retained or disclosed without erasing history or importing a neighboring record lifecycle?", "kind": "validation", "answer_data": [ "validation and clinical-review rule", "correction route", "successor or tombstone", "access and retention effect" ] } ], "data_elements": [ { "id": "prewrite-postwrite-validation-conflict-concurrency-rollback-and-audit-data", "name": "Pre-write and post-write validation, conflict, concurrency, rollback and audit data", "description": "Structured, source-qualified answer data for pre-write and post-write validation, conflict, concurrency, rollback and audit.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-008", "SRC-011" ] } ], "artifacts": [ { "id": "prewrite-postwrite-validation-conflict-concurrency-rollback-and-audit-record", "name": "Pre-write and post-write validation, conflict, concurrency, rollback and audit record", "description": "Versioned evidence-bearing record for pre-write and post-write validation, conflict, concurrency, rollback and audit with subject, status, terminology, event and knowledge time, provenance, uncertainty and access marking.", "media_or_form": [ "logical health record", "signed or attributable evidence reference" ], "serial": true, "identity_strategy": "Health-context identifier plus prewrite-postwrite-validation-conflict-concurrency-rollback-and-audit assertion or event identifier; names, dates, codes, file paths and content hashes never identify the person or assertion alone.", "source_refs": [ "SRC-001", "SRC-008", "SRC-011" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-personal-health-context", "name": "Register personal health context", "description": "Create the subject linkage, context identity, custodianship and source-master map.", "inputs": [ "person reference", "identity assurance", "custodian and source bindings" ], "outputs": [ "registered health-context revision" ], "preconditions": [ "subject match is verified", "actor has registration authority" ], "effects": [ "stable person-grain context and provenance are resolvable" ], "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "ingest-health-assertion", "name": "Ingest health assertion", "description": "Append a source-qualified clinical, self-reported, device-observed or inferred assertion without changing its authority class.", "inputs": [ "health context", "source record", "assertion profile", "provenance" ], "outputs": [ "validated assertion revision" ], "preconditions": [ "subject, source and code versions resolve" ], "effects": [ "assertion is queryable with status, time, confidence and access marking" ], "source_refs": [ "SRC-001", "SRC-008", "SRC-011" ] }, { "id": "reconcile-subject-and-source", "name": "Reconcile subject and source", "description": "Compare identifiers, masters and competing source statements and append match, non-match or unresolved evidence.", "inputs": [ "candidate records", "identity evidence", "reconciliation policy" ], "outputs": [ "reconciliation decision" ], "preconditions": [ "no demographic-only automatic merge", "review route exists" ], "effects": [ "sources remain separately attributable and unsafe merges are blocked" ], "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "record-condition-or-health-state", "name": "Record condition or health state", "description": "Append a condition, concern, risk or functional-state assertion with verification and course.", "inputs": [ "health context", "coded or textual assertion", "asserter", "evidence" ], "outputs": [ "health-state revision" ], "preconditions": [ "clinical authority class and terminology are known" ], "effects": [ "problem, course and uncertainty become longitudinally visible" ], "source_refs": [ "SRC-001", "SRC-003", "SRC-004", "SRC-009" ] }, { "id": "record-observation-or-result", "name": "Record observation or result", "description": "Append a measurement, panel or diagnostic report with units, method, context and interpretation.", "inputs": [ "health context", "observation or report", "performer", "specimen or device reference" ], "outputs": [ "observation revision" ], "preconditions": [ "value, unit, time and subject validate" ], "effects": [ "result can be interpreted without stripping source context" ], "source_refs": [ "SRC-001", "SRC-005", "SRC-007" ] }, { "id": "reconcile-medication-and-allergy-safety", "name": "Reconcile medication and allergy safety", "description": "Compare allergy and medication sources and record agreement, discrepancy, verification or refutation.", "inputs": [ "allergy assertions", "medication assertions", "clinical reviewer" ], "outputs": [ "safety reconciliation record" ], "preconditions": [ "sources and statuses are preserved" ], "effects": [ "current safety view exposes unresolved discrepancies instead of hiding them" ], "source_refs": [ "SRC-001", "SRC-004" ] }, { "id": "record-intervention-or-immunization", "name": "Record intervention or immunization", "description": "Append a procedure, treatment, immunization or device-use event with performer, reason and outcome.", "inputs": [ "health context", "intervention record", "source and performer" ], "outputs": [ "intervention revision" ], "preconditions": [ "subject, status and occurrence time validate" ], "effects": [ "care history changes without importing provider workflow" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-006" ] }, { "id": "update-care-plan-and-goal", "name": "Update care plan and goal", "description": "Append a proposed, agreed, active, completed or replaced plan and its goals, activities and progress evidence.", "inputs": [ "health context", "plan or goal", "participants", "progress evidence" ], "outputs": [ "care-plan successor revision" ], "preconditions": [ "responsible parties and plan authority resolve" ], "effects": [ "intent and actual execution remain distinct and prior versions stay citable" ], "source_refs": [ "SRC-001", "SRC-002" ] }, { "id": "issue-purpose-bound-health-summary", "name": "Issue purpose-bound health summary", "description": "Create an IPS, emergency, self or research projection with explicit omissions and expiry.", "inputs": [ "health-context revision", "requester", "purpose", "target profile" ], "outputs": [ "digest-pinned health summary" ], "preconditions": [ "consent or legal basis and minimum disclosure validate" ], "effects": [ "projection is auditable and cannot replace source records" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-010" ] }, { "id": "grant-revoke-or-breakglass-access", "name": "Grant, revoke or exercise emergency access", "description": "Record scoped access authority or one-time emergency use with expiry, notification and post-review.", "inputs": [ "health context", "requester", "purpose", "data scope", "authority" ], "outputs": [ "access decision and audit event" ], "preconditions": [ "identity and authority validate", "emergency threshold is evidenced when used" ], "effects": [ "access is limited, attributable and reviewable" ], "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "correct-or-supersede-health-assertion", "name": "Correct or supersede health assertion", "description": "Append correction, refutation, entered-in-error or source amendment while preserving prior clinical context.", "inputs": [ "assertion", "correction authority", "reason", "replacement" ], "outputs": [ "successor revision and correction event" ], "preconditions": [ "source-system route and affected projections are known" ], "effects": [ "current view changes without erasing history or disagreement" ], "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "retain-restrict-export-or-dispose", "name": "Retain, restrict, export or dispose", "description": "Apply retention, legal hold, portability and disposition decisions per artifact and jurisdiction profile.", "inputs": [ "health context", "policy", "artifact set", "authority" ], "outputs": [ "retention, export or disposition evidence" ], "preconditions": [ "holds, dependencies and source duties are checked" ], "effects": [ "authorized result is recorded with durable tombstones and no cascading source deletion" ], "source_refs": [ "SRC-001", "SRC-010", "SRC-011" ] } ], "composition": [ { "target": "Person, Identity, Provider, Organization, Device, Product, Encounter, Appointment, Specimen, Imaging, Genomics, Claim, Research, Public Health, Consent, Incident and Evidence models", "relation": "REFERENCE", "purpose": "Connect the personal health context to externally mastered subjects, actors, events, artifacts and legal records without lifecycle duplication.", "required": true, "source_refs": [ "SRC-001", "SRC-006", "SRC-008", "SRC-010" ] }, { "target": "HL7 FHIR Release 5", "relation": "ALIGN", "purpose": "Project source-qualified person health assertions to clinical resource profiles while preserving identity, status, time and provenance.", "required": true, "source_refs": [ "SRC-001" ] }, { "target": "HL7 International Patient Summary", "relation": "ALIGN", "purpose": "Produce a minimal clinically relevant cross-border or unscheduled-care summary as a purpose-bound projection.", "required": false, "source_refs": [ "SRC-002" ] }, { "target": "WHO ICD-11, SNOMED CT and LOINC", "relation": "ALIGN", "purpose": "Reference versioned condition, clinical concept, observation and document identifiers without copying terminology masters.", "required": true, "source_refs": [ "SRC-003", "SRC-004", "SRC-005" ] }, { "target": "DICOM, ICF and UCUM", "relation": "ALIGN", "purpose": "Reference imaging objects, functioning classifications and computable measurement units with explicit versions and mapping loss.", "required": false, "source_refs": [ "SRC-006", "SRC-007", "SRC-009" ] }, { "target": "W3C PROV-O", "relation": "ALIGN", "purpose": "Preserve author, performer, source, derivation, transformation and revision provenance across federated health records.", "required": true, "source_refs": [ "SRC-008" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Dimension identity, owner, health-data steward, clinical safety authority, privacy steward and namespace", "Person, provider, organization, device, encounter, specimen, imaging, product, plan, consent, incident and evidence registries", "Master-system mappings for subject, source record, condition, observation, intervention, plan, consent and provenance identifiers", "Identity matching, terminology, clinical review, consent, emergency access, correction, retention, federation and autonomous-agent policies" ], "namespace_guidance": "Mint personal-health context and assertion identifiers in the adopting Dimension only when no authoritative master identifier exists; preserve persons, providers, organizations, devices, products, encounters, specimens, images, appointments, claims, research, consents and evidence as typed references.", "registry_links": [ "https://ver.cy/models/", "https://ver.cy/model-agent-protocol.md", "Dimension-local health-context, assertion, terminology, consent, provenance, projection and lifecycle registries" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonicalize the health context by authoritative person reference plus context issuer, and each assertion by source master identifier; never merge on name, demographic similarity, code, date or hash alone.", "Keep clinical assertion, self-report, observation, device output, algorithmic inference, diagnosis, plan and performed intervention authority and lifecycle distinct." ], "patch_rules": [ "Additive extensions declare target bundle, layer or finding, clinical profile, terminology versions, source, authority, safety, privacy and interoperability impact.", "Subject identity, assertion status, code semantics, unit, time, consent, provenance or clinical-safety changes require a successor version, migration map, rollback plan and continued resolution of prior records." ], "compatibility_rules": [ "Consumers may ignore unknown additive fields only when subject identity, source, status, terminology, unit, time, provenance, uncertainty, consent and safety meaning remain intact.", "FHIR, IPS, ICD, SNOMED CT, LOINC, DICOM, ICF and UCUM projections pin source and target versions and disclose transformed, omitted, generalized or non-round-trippable values." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier for the person-grain health assertion, qualified by source and subject.", "Governed globally resolvable assertion identifier with explicit source-record binding.", "Adopting-Dimension UUID or ULID when no authoritative external identifier exists." ], "timestamp_rule": "Record event timestamps in RFC 3339 with seconds and an explicit UTC offset or Z; keep clinical event, specimen, effective, recorded, issued, observation, knowledge and ingestion times distinct.", "serial_naming_rule": "Name serial artifacts as {health-context-id}--{artifact-kind}--{assertion-or-event-id}; never expose a person name, diagnosis, code, date, filename or hash as identity.", "integrity_rule": "Store digest, media type, byte length, subject, issuer, source and profile versions, terminology and unit versions, valid and knowledge times, provenance, uncertainty, licence and access marking for every retained serial artifact." }, "policies": [ "The adopting Dimension declares who may link subjects, contribute assertions, verify diagnoses, interpret results, reconcile medicines, approve plans, disclose summaries, correct sources and dispose records.", "No agent may diagnose, prescribe, change treatment, suppress a safety alert or represent an inference as clinical fact without current policy and accountable clinical authority.", "The person receives the strongest lawful agency, access, portability and correction controls, but ownership, controller duties, retention and emergency authority remain explicit jurisdiction profiles.", "Provider, device, laboratory, imaging, pharmacy, payer, public-health and research source records remain in their owning systems and are referenced.", "Emergency access is minimum necessary, time-limited, fully logged, notified and reviewed and never becomes a reusable bypass." ], "crud": { "read": [ "Resolve subject, active Dimension, requester, purpose, clinical context, valid and knowledge time, terminology, consent and source freshness; return the minimum permitted view." ], "create": [ "Create stable context identity, verified subject binding, source provenance, status, terminology, time, confidence and explicit unknowns before any health assertion." ], "update": [ "Append an assertion, interpretation, correction, consent or lifecycle event with actor, authority, reason, RFC 3339 time, evidence and before-and-after validation; never overwrite a cited clinical source." ], "delete": [ "Apply source duties, person rights, clinical safety, public-health, legal-hold and retention policy; prefer restriction or tombstone, preserve correction and provenance history and never cascade into external masters." ] }, "roles": [ { "name": "Person or lawful representative", "responsibilities": [ "Exercise lawful access, consent, portability, correction and preference rights and contribute self-reported facts." ] }, { "name": "Clinical professional", "responsibilities": [ "Author and verify clinical assertions, interpret results and approve care changes within professional scope." ] }, { "name": "Health-data steward", "responsibilities": [ "Maintain subject linkage, source maps, terminology pins, provenance and longitudinal reconciliation." ] }, { "name": "Custodian or controller", "responsibilities": [ "Apply legal basis, access, security, retention, breach and disclosure duties for the held records." ] }, { "name": "Laboratory, imaging, pharmacy or device source", "responsibilities": [ "Master its source records, identifiers, status, quality and correction route." ] }, { "name": "Privacy and consent steward", "responsibilities": [ "Evaluate purpose, minimum disclosure, consent or other legal basis, restrictions and emergency use." ] }, { "name": "Clinical safety reviewer", "responsibilities": [ "Review identity, medicine, allergy, result and decision-support hazards and corrective action." ] }, { "name": "Independent auditor", "responsibilities": [ "Review access, provenance, reconciliation, corrections and disposition without changing clinical truth." ] } ], "access": { "default_rule": "Deny disclosure and mutation of health data unless subject, requester, role, purpose, legal basis or consent, scope and time validate; expose the minimum necessary fields and do not reveal hidden record existence through search or counts.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Emergency, statutory, public-health or judicial access must cite authority, be purpose-bound, minimum necessary, attributable, time-limited and reviewable and must preserve the original evidence and person-facing audit where lawful." ], "audit_requirements": [ "Log actor, calling agent, role, purpose, subject and source identities, action, policy and consent, RFC 3339 timestamp with offset, requested and effective scope, emergency basis, evidence and outcome." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "Read the nearest Dimension-owner AGENTS.md, subject-mastering, clinical-safety, consent, privacy, emergency, terminology, correction, retention and federation policies.", "Read this model AGENTS.md, pinned spec.yaml and required person, provider, device, encounter, specimen, imaging, product, plan, consent, incident and evidence model instructions before mutation or disclosure." ] } }, "coverage": { "claim": "A source-grounded reviewable draft for one person's longitudinal health context across HL7 FHIR R5 and IPS, WHO ICD-11 and ICF, SNOMED CT, LOINC, DICOM, UCUM, W3C provenance, an EU privacy profile and RFC 3339, without a claim of universal clinical, jurisdictional, terminology-licence or certified crosswalk completeness.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Verified subject linkage, health-context identity, source masters, assertion identifiers and merge review are explicit." }, { "dimension": "classification and definition", "status": "covered", "notes": "Health assertions are typed as clinical, self-reported, observed, device-produced or inferred with versioned terminology." }, { "dimension": "direct properties", "status": "covered", "notes": "Conditions, observations, risks, function, allergies, medicines, immunizations, procedures and care intentions are first-class." }, { "dimension": "recognition and observation", "status": "covered", "notes": "Method, device, specimen, body site, unit, range, interpretation, confidence and data-absent reason are covered." }, { "dimension": "capabilities and possible actions", "status": "covered", "notes": "Import, reconcile, record, summarize, grant, correct, restrict, export and dispose operations have authority and safety gates." }, { "dimension": "composition", "status": "covered", "notes": "Persons, providers, devices, products, encounters, specimens, images, plans, consents and evidence retain external masters." }, { "dimension": "lifecycle", "status": "covered", "notes": "Assertions, conditions, medications, allergies, plans, consents and projections preserve status, correction and successor history." }, { "dimension": "relationships", "status": "covered", "notes": "Subject, source, author, asserter, performer, provider, care team and custodian relationships are typed and time-qualified." }, { "dimension": "temporal", "status": "covered", "notes": "Clinical event, specimen, effective, recorded, issued, observed, knowledge and ingestion times remain distinct and use RFC 3339 for events." }, { "dimension": "spatial", "status": "covered", "notes": "Body site, care location, jurisdiction and residency are recorded or referenced when material, without exposing them by default." }, { "dimension": "provenance", "status": "covered", "notes": "Authorship, performance, source, import, derivation, signature, transformation, revision and disagreement are attributable." }, { "dimension": "ownership and stewardship", "status": "covered", "notes": "Person agency, custodian and controller duties, source mastership and jurisdiction-specific ownership claims are separate." }, { "dimension": "validation and quality", "status": "covered", "notes": "Subject match, terminology, units, ranges, status, stale evidence, conflicts, safety and projection loss are checked." }, { "dimension": "access and privacy", "status": "covered", "notes": "Special-category sensitivity, consent or legal basis, minimum disclosure, emergency use, audit and hidden existence are covered." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Source retention, person rights, restriction, legal hold, correction history, disposition and tombstone are explicit." }, { "dimension": "interoperability", "status": "covered", "notes": "FHIR R5, IPS, ICD-11, SNOMED CT, LOINC, DICOM, ICF and UCUM mappings are versioned and loss-aware." } ], "known_omissions": [ "No independent Claude or Grok result was available; this source-grounded Codex fallback requires later clinical and external review before canonical promotion.", "National clinical, privacy, retention, consent, emergency, public-health, paediatric, reproductive-health, mental-health, genetic and incapacity rules require jurisdiction-specific profiles.", "Insurance, claims, provider operations, public health, research, genomics, medical-device payloads and care-delivery workflows remain external.", "The frozen relation ledger contains no approved WM-PER-007 dependency rows; composition targets remain draft until registry review.", "Certified FHIR, IPS, ICD-11, SNOMED CT, LOINC, DICOM, ICF and UCUM crosswalks, licence review and clinical conformance fixtures remain future work." ], "conflicts": [ "The previous card says the person owns the record outright, while legal ownership, controller and custodian duties vary by jurisdiction; this model instead gives the person strongest lawful agency and records each legal basis explicitly.", "A longitudinal personal view may reconcile several sources, but it cannot silently override the source EHR, laboratory, pharmacy, imaging or device master.", "FHIR resource status, clinical verification, terminology inactivation and local workflow status are not interchangeable and may conflict." ], "regional_assumptions": [ "The GDPR supplies an EU privacy profile and does not create universal global health-record ownership, consent, retention or emergency-access rules.", "FHIR and IPS are interoperability standards and do not by themselves determine clinical truth, medical necessity, legal authority or record custody.", "ICD, SNOMED CT, LOINC, DICOM, ICF and UCUM have separate governance, release and licence conditions that adopting Dimensions must verify." ], "adversarial_checks": [ "Reject subject merge based only on name, birth date, address or demographic similarity without authoritative identifiers and review evidence.", "Reject a self-report, algorithmic inference, device result or imported code represented as a verified diagnosis without source and authority.", "Reject a numeric result without unit, method or context when needed, time, status, subject, provenance and uncertainty or absence semantics.", "Reject hidden emergency access, reusable break-glass privileges, or research views whose rare combinations permit re-identification.", "Reject agent diagnosis, prescription, treatment change, safety-alert suppression, disclosure or deletion beyond current policy and accountable authority." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "codex" ], "waivedProviders": [ "claude", "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-06T00:00:00Z", "scope": "Canonical single-stream subject-model research after the six-workstream consolidation", "active_providers": [ "codex" ], "waived_providers": [ { "provider": "claude", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "Claude produced no result on prior 1800-second and 900-second attempts and again timed out on bounded 600-second Sonnet and 300-second Haiku passes. The owner prioritized completion over provider availability." }, { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-06T00:00:00Z", "reason": "The repository owner authorized completion without Grok when Grok is unavailable, slow or schema-invalid. Grok may still be attempted as a bounded supplemental reviewer, but its failure never blocks a valid Claude plus no-tools result." } ], "review_rule": "Codex may complete source-grounded fallback research after bounded Claude and Grok attempts fail. It requires a separate no-tools adversarial audit and remains reviewable-draft with a visible absence-of-external-review hold.", "supplemental_provider_attempts": [ { "provider": "claude", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." }, { "provider": "grok", "required": false, "maximum_attempts": 1, "failure_policy": "record-and-continue", "admission_rule": "Use only a locally schema-valid result whose sources and boundaries survive adjudication." } ] }, "boundaryDecision": { "entry_kind": "entity", "status": "accepted as a federated person-grain health context", "rationale": "The model owns person-grain health assertions, their source and longitudinal reconciliation, not the identities or lifecycles of people, providers, devices, products, encounters, specimens, images, claims, research, public-health reports, consent instruments or source evidence. It supports personal agency without making a universal legal-ownership claim." }, "decisions": [ { "concept": "Subject identity and record matching", "disposition": "accepted with fail-closed merge rules", "rationale": "Health assertions may join only through authoritative person references and documented match evidence; demographic similarity alone is insufficient." }, { "concept": "Personal context versus source masters", "disposition": "accepted as federated longitudinal projection", "rationale": "EHR, laboratory, pharmacy, imaging, device and other records remain separately mastered and correctable while the personal context preserves source-qualified assertions and reconciliation." }, { "concept": "Record ownership and person agency", "disposition": "reframed from universal ownership to explicit rights and custody", "rationale": "The previous card's statement that the person owns the record outright is not universal; person rights, custodian, controller, source master, legal basis and jurisdiction are recorded separately." }, { "concept": "Assertion authority", "disposition": "accepted as typed and non-equivalent", "rationale": "Self-report, clinical assertion, direct observation, device result and algorithmic inference retain distinct source, verification, confidence and correction semantics." }, { "concept": "Longitudinal and bitemporal time", "disposition": "accepted with separate clinical and knowledge axes", "rationale": "Clinical event, specimen, effective, recorded, issued, observed, knowledge and ingestion times can differ and must survive retrospective entry and correction." }, { "concept": "Terminology and units", "disposition": "accepted as versioned external references", "rationale": "ICD-11, SNOMED CT, LOINC, ICF and UCUM remain governed external systems whose release, edition, code, unit, inactive state, map equivalence and licence constraints are pinned." }, { "concept": "Conditions and functioning", "disposition": "accepted as complementary health views", "rationale": "Condition and risk records do not replace physical, cognitive, mental, social and participation functioning, and neither a code nor a prediction is automatically a diagnosis." }, { "concept": "Medication and allergy safety", "disposition": "accepted with source reconciliation", "rationale": "Medication intent, dispensing, administration, patient report and allergy verification can conflict, so current safety views preserve discrepancies and accountable review." }, { "concept": "FHIR and IPS", "disposition": "accepted as interoperability projections", "rationale": "FHIR resources and IPS summaries preserve structured clinical exchange but do not determine truth, record ownership, clinical correctness, consent or legal authority." }, { "concept": "Privacy and emergency access", "disposition": "accepted as purpose-bound jurisdiction profiles", "rationale": "Health data and even record existence are highly sensitive; emergency access must be minimum necessary, time-limited, attributable, notified and reviewed where lawful." }, { "concept": "Agent clinical authority", "disposition": "restricted to evidence handling and authorized proposals", "rationale": "An agent may index, validate and summarize within policy but may not diagnose, prescribe, change treatment, suppress safety evidence or present inference as clinical fact without accountable authority." }, { "concept": "Approved registry composition", "disposition": "held pending relation governance", "rationale": "The approved relation ledger contains no WM-PER-007 rows, so proposed links to person, provider, device, encounter, consent, evidence and other models remain draft." } ], "publicationHolds": [ "Claude and Grok timed out during their bounded attempts, so independent external review is absent and explicitly waived for this published reviewable draft.", "The prior card's universal personal-ownership claim is replaced by explicit person rights, custody, controller duties, source mastership and jurisdiction profiles and requires owner review before canonical promotion.", "The approved relationship ledger contains no WM-PER-007 rows, so all proposed sibling composition remains draft.", "National clinical, privacy, retention, consent, emergency, public-health, paediatric, reproductive-health, mental-health, genetic and incapacity profiles require specialist legal and clinical review.", "Certified FHIR, IPS, ICD-11, SNOMED CT, LOINC, DICOM, ICF and UCUM crosswalks, terminology licences, conformance fixtures and clinical-safety tests remain unverified.", "Independent external review was explicitly waived by the repository owner; this codex-only result remains a reviewable draft." ], "deferredResearch": [ "Develop jurisdiction profiles for consent, incapacity, guardian authority, emergency access, retention, source correction and public-health disclosure.", "Approve model identifiers and relation cardinalities for persons, providers, organizations, encounters, devices, products, specimens, imaging, genomics, claims, research, consent, incidents and evidence.", "Create specialist profiles for paediatric, reproductive, mental, genetic, disability, occupational, travel, dental, veterinary-adjacent household and remote-monitoring contexts where appropriate.", "Create deterministic fixtures for wrong-patient prevention, source disagreement, unit conversion, terminology inactivation, allergy refutation, medication reconciliation, corrected reports and emergency access.", "Validate certified FHIR and IPS projections plus terminology, imaging, function and unit mappings with explicit disclosure, licence, loss and round-trip tests." ] }, "statistics": { "sources": 11, "bundles": 7, "layers": 16, "findings": 32, "questions": 96, "artifacts": 32, "functions": 12 } }