German Practice Management FHIR Profiles (R4)
0.90.0 - STU1 Germany

German Practice Management FHIR Profiles (R4) - Local Development build (v0.90.0) built by the FHIR (HL7® FHIR® Standard) Build Tools. See the Directory of published versions

AI Provenance

AI Provenance

This guide depends on the official HL7 AI Transparency Implementation Guide package, pinned to hl7.fhir.uv.aitransparency#1.0.0-ballot. Consumers use its AI-Device, AI-data prompt/input, AI-ModelCard, and terminology artifacts unchanged.

The ballot's AI-Provenance profile cannot be used by the deployed validator for the accepted-resource flow because its required Provenance.agent slice is classified through the nested Reference-profile discriminator who. The separate https://fhir.cognovis.de/praxis/StructureDefinition/ai-provenance-compatibility profile provides the same required AI-agent, reason, and AI-Device target contract used by that flow, but classifies the AI agent through a direct agent.role pattern. It derives directly from base FHIR R4 Provenance; it does not modify, shadow, or claim conformance to the official AI-Provenance canonical.

This is a bounded Aidbox 2606.2 compatibility contract, not a general replacement for every representation allowed by the official profile. The profile and role semantics remain product- and source-system-neutral; the runtime limitation is the reason this additional conformance surface exists.

The marker is https://fhir.cognovis.de/praxis/CodeSystem/ai-provenance-agent-role#ai-model. It states that the agent is an AI model. It is independent of the ordinary participant type, so an emitter can retain agent.type = author without using authorship to classify the AI agent.

Accepted-resource boundary

AI Provenance describes the lineage of an accepted clinical or administrative FHIR resource. Its Provenance.target points to the resource that was actually accepted and persisted. The compatibility profile records the AI system through the unchanged official AI-Device target profile. Optional AIInputData entity slicing is not part of this bounded profile and no compatibility claim is made for it.

Application proposal state before acceptance is not represented as FHIR. A candidate suggested by an application remains in that application's proposal store until a user accepts it. Acceptance creates or updates the final FHIR resource; AI Provenance is written only when AI actually contributed to that accepted result.

Non-AI audit events

Ordinary authorship, import, update, and other audit events that do not involve AI use the base FHIR R4 Provenance resource. They do not use the AI Transparency profile or the compatibility profile.

Upstream lock and removal condition

The dependency is intentionally pinned to a ballot version. The reviewed package archive SHA-1 is e800eef274236ce8c9f5c63d20c8dff360558fe4; the published StructureDefinition-AI-Provenance.json SHA-256 is 705815dfb54af0874f373595f4728a7de2b59384386e7ba75d12a2564564de7e. The repository drift gate also checks the complete differential and the exact known AIModelAgent slice.

The compatibility profile is removed when both conditions are true:

  1. a reviewed upstream package corrects the Reference-target discriminator; and
  2. the deployed validator passes the unmodified upstream positive and non-AI-Device negative conformance tests.

An upstream version, checksum, or differential change fails the drift gate so that this decision is revisited instead of silently retaining the overlay.