For a full list of available versions, see the Directory of published versions
2.4. Business Rules
2.4.1. Business Rules Overview
Business Rules define how patient demographic and identifier information is contributed to the Provincial Client Registry (PCR), how patient identities are created and maintained, and how submitted information is validated, processed, reconciled, audited, and governed. These rules support the Patient Add, Patient Update, Patient Merge, and Patient Unmerge contribution operations and ensure that patient identity information is consistently managed across authorized contributing organizations.
PCR contribution processing is governed by approved FHIR profiles, mandatory data elements, cardinality constraints, identifier requirements, operation-specific validation rules, and processing outcomes.
2.4.2. Contribution Rules
2.4.2.1. Supported Contribution Operations
PCR supports the following contribution operations:
- Patient Add
- Patient Update
- Patient Merge
- Patient Unmerge
Each contribution request SHALL conform to the applicable PCR FHIR profiles, business rules, validation requirements, and operation-specific processing requirements.
2.4.2.2. Record Submission Requirements
Contributors SHALL submit patient demographic and identifier information in accordance with approved PCR contribution requirements.
Supported contribution information MAY include:
- Patient identifiers
- Patient names
- Date of birth
- Administrative sex
- Address information
- Telephone information
- Record relationships
- Other approved patient identity attributes
All submitted information SHALL be subject to PCR validation, identity management, reconciliation, and business rule processing.
2.4.2.3. Contributor Responsibilities
Contributors SHALL:
- Submit complete and accurate patient information.
- Ensure submitted information complies with PCR FHIR profiles and contribution requirements.
- Submit mandatory data elements required for the contribution operation.
- Provide identifiers consistent with approved identifier policies and naming systems.
- Maintain local data quality and correct known errors.
- Submit updates, merges, and unmerges in accordance with approved PCR business processes.
- Ensure contribution activities are performed only by authorized users, systems, or service accounts.
- Comply with applicable privacy, security, onboarding, governance, and audit requirements.
2.4.3. Identifier Rules
Identifiers are fundamental to patient identity management and reconciliation within PCR.
- Contributing systems SHALL submit identifiers using the approved identifier systems and namespaces defined by PCR.
- Identifier systems SHALL be represented using Uniform Resource Identifiers (URIs).
- Submitted identifiers SHALL uniquely identify the patient record within the contributing source.
- Contributing systems SHALL not include leading or trailing whitespace in identifier values.
- PCR maintains relationships between contributing source identifiers and provincial patient identities.
- PCR preserves identifier history and cross-reference information required to support identity management activities.
2.4.3.1. Enterprise Client Identifier (ECID)
- PCR assigns and maintain an Enterprise Client Identifier (ECID) representing the provincial patient identity.
- A provincial patient identity MAY be associated with identifiers received from one or more contributing organizations.
- PCR maintains identifier relationships required to support reconciliation and identity lineage.
2.4.4. Data Quality and Validation Rules
PCR validates all contribution requests before processing.
Validation MAY include:
- FHIR profile conformance validation
- Mandatory data element verification
- Cardinality validation
- Identifier validation
- Data type validation
- Business rule validation
- Operation-specific validation
Contributors SHALL submit requests that are syntactically valid, well formed, and conformant to the PCR FHIR contribution specification.
PCR MAY reject a contribution request when:
- Mandatory information is missing.
- Identifier requirements are not satisfied.
- Data formats are invalid.
- Business validation rules fail.
- Operation-specific requirements are not met.
Date values SHALL be submitted using the YYYY-MM-DD format.
DateTime values SHALL include appropriate precision and time zone context where required. See FHIR dateTime formatting.
Time values submitted by pharmacies, hospitals, or other contributing organizations should reflect the local time zone applicable to the source system when local time is used.
Telephone information SHOULD be submitted in a consistent and meaningful format - (999) 999-9999 [X99999]
UUIDs SHALL be represented in lower-case format where used, for example: urn:uuid:53fefa32-fcbb-4ff8-8a92-55ee120877b7
2.4.5. Identity Reconciliation Rules
PCR maintains a provincial patient identity through the reconciliation of information received from multiple contributing sources.
- PCR validates contributed information before processing.
- PCR evaluates patient identity information to determine whether it should be associated with an existing provincial identity.
- PCR applies approved duplicate prevention and identity management policies.
- PCR maintains cross-references between provincial identities and contributing source identifiers.
- PCR preserves identity lineage and historical relationships as patient identities evolve.
- PCR maintains record relationships submitted through approved contribution processes.
2.4.6. Source Authority Rules
PCR MAY apply source authority and governance policies when determining how contributed demographic information is maintained.
- Contributors SHALL only submit information they are authorized to contribute.
- Contributors SHALL only submit changes for demographic and identifier information under their authority.
- PCR MAY reject, restrict, or review updates that violate applicable governance policies.
- Source authority considerations MAY be applied during patient creation, update, merge, and unmerge processing.
- PCR preserves source attribution associated with contributed information.
2.4.7. Merge and Unmerge Rules
2.4.7.1. Patient Merge
Patient Merge is used to reconcile duplicate patient identities representing the same individual.
- Merge requests SHALL identify the patient records involved in the merge.
- Merge requests SHALL satisfy applicable governance, stewardship, and validation requirements.
- PCR preserves source attribution and audit history.
- PCR maintains identity lineage and record relationships following the merge.
- PCR MAY reject merge requests that do not satisfy PCR validation requirements.
2.4.7.2. Patient Unmerge
Patient Unmerge is used to reverse a prior merge when records have been incorrectly consolidated.
- Unmerge requests SHALL satisfy applicable governance, authorization, and validation requirements.
- PCR restores affected patient identities and record relationships where appropriate.
- PCR preserves historical lineage information associated with both the original merge and subsequent unmerge.
- PCR preserves audit information associated with all merge and unmerge activities.
- PCR MAY reject unmerge requests that do not satisfy PCR validation requirements.
2.4.8. Privacy and Security Rules
Contribution information is considered Personal Information (PI) and Personal Health Information (PHI).
- Contributors SHALL submit, access, use, retain, and protect information in accordance with applicable legislation, agreements, and interoperability specifications.
- Contribution activities SHALL be performed by authorized users, service accounts, or approved system processes.
- Contributing organizations SHALL remain responsible for authentication and authorization of users and systems initiating contribution activity.
- User and system identities SHALL be traceable to authenticated accounts.
- Access to contribution functionality SHALL be restricted to authorized personnel and approved system processes.
2.4.9. Audit and Traceability Rules
PCR contribution activities SHALL support auditing and operational traceability.
The following activities SHALL be auditable where applicable:
- Patient Add
- Patient Update
- Patient Merge
- Patient Unmerge
- Contribution Transaction Processing
Contributing systems SHALL maintain audit and operational records sufficient to support privacy investigations, operational tracing, and compliance activities.
Audit and traceability information SHOULD include:
- Initiating user, service account, or system process
- Transaction type
- Request and response identifiers
- Date and time of submission
- Processing outcome
- Client and organization identifiers where applicable
PCR and contributing systems SHALL preserve source attribution, transaction history, identity lineage information, and outcome details in accordance with applicable governance, regulatory, and operational requirements.
2.4.10. Processing Outcome Rules
PCR will return an appropriate processing outcome for contribution requests.
Processing outcomes MAY include:
- Created
- Updated
- Accepted for Processing
- Validation Error
- Rejected
- Other operation-specific outcomes
Contributing systems SHALL process response information meaningfully, including:
- Successful acknowledgements
- Validation errors
- Rejected requests
- Accepted-for-processing outcomes
- OperationOutcome responses where applicable
Response identifiers and processing outcomes SHOULD be retained to support auditing, troubleshooting, operational support, and transaction traceability.