visit the hl7 website
Provincial Client Registry (PCR) HL7 FHIR® Contribution Implementation Guide v1.0.0-draft1
fhir-logo
  • Index
  • Home
    • Home
    • Introduction
    • Relationship to other Specifications
    • Scope
    • Glossary
  • Business Context
    • Business Context
    • Business Model
    • Business Data
    • Use Cases
    • Business Rules
    • Contribution Models
  • Technical Context
    • Technical Context
    • Implementer Responsibility
    • Conformance Rules
    • Connectivity Summary
  • FHIR Artifacts
    • FHIR Artifacts
    • Interactions
    • Operations
    • Profiles
    • Terminology
    • System URIs
    • Examples
    • Capability Statement
    • Response Handling
    • Downloads
  • Change Log
    • Change Log
    • Known Issues & Future Developments
    • Revision History
    1. Index
    2. Technical Context
    3. Implementer Responsibility

For a full list of available versions, see the Directory of published versions

3.1. Implementer Responsibility

3.1.1. Privacy and Security

The information contributed to PCR is considered Personal Information (PI) and Personal Health Information (PHI). Contributing organizations must ensure that PHI is submitted, accessed, used, retained, and protected only in accordance with applicable legislation, Ontario Health agreements, approved onboarding processes, and PCR interoperability specifications.

Under PHIPA, Ontario Health is a Prescribed Organization with the power and duty to develop and maintain the electronic health record. In this role, Ontario Health manages and integrates PHI received from Health Information Custodians and enables authorized HICs to collect, use, and disclose PHI by means of the EHR.

HICs that contribute records of PHI to Ontario Health as a Prescribed Organization are responsible for completing required onboarding activities, complying with Ontario Health privacy and security policies, procedures, and standards, and contributing PHI in accordance with interoperability specifications established by Ontario Health. These and related obligations are set out in the EHR Contributor Agreement and other applicable Ontario Health agreements executed with contributing HICs.

This interoperability specification establishes the business and technical requirements applicable to PCR FHIR contribution by specified HICs and specified digital health assets. It does not, by itself, mandate contribution to the EHR; rather, it defines the requirements that apply when contribution is undertaken. This information must be read together with the EHR Contributor Agreement, the EHR Access Services Schedule of the Ontario Health Services Agreement where applicable, and any other applicable agreements. Nothing in this specification relieves a HIC of its obligations under PHIPA or its regulations.


3.1.2. User Credentials

For PCR FHIR contribution, the submitting system must identify the authorized system, organization, and, where applicable, the user or service account responsible for initiating the contribution transaction. This supports privacy inquiries, operational traceability, and investigation of submitted PHI where required.

PCR FHIR implementers shall satisfy credential and identity requirements through the approved authentication and authorization mechanism, including OAuth2 token information in the request message header where required. Implementers should refer to the Connectivity section and Ontario Health onboarding materials for detailed token, endpoint, and access requirements.


3.1.3. Message Conformance

Contributing systems shall implement PCR FHIR contribution request messages that are well formed, syntactically valid, and conformant with this specification. Contribution submissions must comply with PCR-defined FHIR profiles, mandatory data elements, cardinality constraints, business validation rules, and operation-specific requirements for Patient Add, Patient Update, Patient Merge, and Patient Unmerge.


3.1.4. System Responsibility for User Authorization and Authentication

Where PCR FHIR contribution is performed by a system-level integration, the contributing Health Information Custodian remains responsible for authenticating and authorizing individual users, service accounts, or system processes that initiate contribution activity. User and system identities must be tied to authenticated accounts and must be managed in accordance with Ontario Health privacy and security requirements.

The contributing HIC is responsible for ensuring the accuracy of the organization, system, user, or service identity represented in the contribution message and related security context. Access to contribution functionality must be limited to appropriately authorized personnel or approved system processes.


3.1.5. Auditing

The contributing system must audit user-initiated and system-initiated PCR FHIR contribution activities, including HTTP POST or other applicable transaction requests. Audit records must support traceability of PHI contributed to PCR, including the initiating user or system process, timestamp, transaction type, target operation, and outcome where applicable.


3.1.6. Logging

The contributing system must log user-initiated and system-initiated PCR contribution activities such as API requests, response codes, operational outcomes, and processing errors. At minimum, the client-side log must capture the Message Request ID sent to PCR, request date and time, Response ID, HTTP response code, Client ID, and Payload ID. These identifiers should support end-to-end correlation across the contributing system, ONE Access Provider Gateway, and PCR where corresponding identifiers are available. Application logs must not store PHI. Access logs may contain PI only where permitted and necessary for access management, security monitoring, or audit support.

The following examples illustrate the minimum client-side information that should be captured for PCR contribution transactions. The sample values are illustrative only and must not include PHI.

Transaction Type Message Request ID Request Date/Time Response ID HTTP Code Client ID Payload ID Outcome
Patient Add MSG-REQ-20260825-0001 2026-08-25T12:10:45-04:00 RSP-20260825-0001 201 CLIENT-HOSP-001 PAYLOAD-ADD-0001 Created
Patient Update MSG-REQ-20260825-0002 2026-08-25T12:14:12-04:00 RSP-20260825-0002 200 CLIENT-HOSP-001 PAYLOAD-UPD-0002 Updated
Patient Merge MSG-REQ-20260825-0003 2026-08-25T12:20:08-04:00 RSP-20260825-0003 202 CLIENT-HOSP-001 PAYLOAD-MRG-0003 Accepted for processing
Patient Unmerge MSG-REQ-20260825-0004 2026-08-25T12:26:30-04:00 RSP-20260825-0004 400 CLIENT-HOSP-001 PAYLOAD-UNM-0004 Rejected — validation error

All audit and log records must be retained in accordance with the contributing HIC’s obligations under PHIPA, Ontario Health agreements, and applicable organizational retention policies. Where requested by Ontario Health, the HIC must provide compliance information or records that do not contain PHI and must cooperate with Ontario Health monitoring activities related to compliance with this interoperability specification.

-

Version: 1.0.0 FHIR Version: R4.0.1

Powered by SIMPLIFIER.NET

HL7® and FHIR® are the registered trademarks of Health Level Seven International