{"xsrfToken":"09b8cb2692b434e62e3465587847487e19fa6141_lout","branding":{"id":"3","key":"in","name":"Health New Zealand Onboarding portal","portalBaseUrl":"/servicedesk/customer/portal/3"},"helpCenterBranding":{"logoUrl":"https://api.media.atlassian.com/file/d7d6a7bf-41c8-48b5-8fc0-6cd18d548643/image?token=eyJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJhY2UxZGE1Ny02NWQ5LTRlOGYtYjkyYS01YWU1YTFiZTQyNjIiLCJhY2Nlc3MiOnsidXJuOmZpbGVzdG9yZTpmaWxlOmQ3ZDZhN2JmLTQxYzgtNDhiNS04ZmMwLTZjZDE4ZDU0ODY0MyI6WyJyZWFkIl19LCJleHAiOjE3MTQzNjc4MjcsIm5iZiI6MTcxNDM2NzIyN30.prsdEeQOYsCwKKHsi0mEc_52sb9IeP20L5BjUilerOw&client=ace1da57-65d9-4e8f-b92a-5ae5a1be4262&mode=fit","logoId":"d7d6a7bf-41c8-48b5-8fc0-6cd18d548643","isLogoAvailable":true,"helpCenterTitle":"Te Whatu Ora - Health New Zealand","sharedPortalName":"Te Whatu Ora Services","userInitialAnnouncementHeader":"Welcome to the Te Whatu Ora API Portal","userInitialAnnouncementMessageWiki":"<p>Te Whatu Ora is making a number of APIs and services available to other health organisations, industry bodies and relevant general groups looking to access or share health-related data for approved purposes.</p>\n<p>Some data available via these APIs and services can only be made available to organisations specified in <a href=\"https://www.privacy.org.nz/assets/New-order/Privacy-Act-2020/Codes-of-practice/Health-information-privacy-code-2020/HIPC-Amendment-No-1/Consolidated-Code-incorporating-Amendment-No-1.pdf\" class=\"external-link\" rel=\"nofollow noreferrer\" target=\"_blank\">Schedule 2 </a> of the Health Information Privacy Code 2020. If you’re not sure if your organisation qualifies you can <a href=\"https://mohapis.atlassian.net/servicedesk/customer/portal/3/group/11/create/36\" class=\"external-link\" rel=\"nofollow noreferrer\" target=\"_blank\">check with us</a>.</p>\n<p>All integrators will need to go through an Onboarding and Certification process to show they can meet the required security and privacy standards. There are some General Integration Requirements for integrating with Te Whatu Ora APIs and services, that all integrators must meet. Depending on your service or us there could be further specific requirements you will need to meet. Security and privacy of sensitive information is a high priority meaning there are stricter controls in place around gaining access.</p>\n<p>Useful links:</p>\n<ul class=\"alternate\" type=\"square\">\n <li><a href=\"https://mohapis.atlassian.net/servicedesk/customer/portal/3/article/294925\" class=\"external-link\" rel=\"nofollow noreferrer\" target=\"_blank\">Requirements for integrating with the Te Whatu Ora APIs </a></li>\n <li><a href=\"https://mohapis.atlassian.net/servicedesk/customer/portal/3/article/294950\" class=\"external-link\" rel=\"nofollow noreferrer\" target=\"_blank\">How to integrate with the Te Whatu Ora's APIs </a></li>\n</ul>\n<p>We recommend that you read the above articles, before using the forms below to submit your request.</p>","translations":{"en-US":{"helpCenterTitle":"Te Whatu Ora - Health New Zealand","sharedPortalName":"Te Whatu Ora Services","announcementHeader":"Welcome to the Te Whatu Ora API Portal","announcementMessage":"Te Whatu Ora is making a number of APIs and services available to other health organisations, industry bodies and relevant general groups looking to access or share health-related data for approved purposes.\n\nSome data available via these APIs and services can only be made available to organisations specified in [Schedule 2 | https://www.privacy.org.nz/assets/New-order/Privacy-Act-2020/Codes-of-practice/Health-information-privacy-code-2020/HIPC-Amendment-No-1/Consolidated-Code-incorporating-Amendment-No-1.pdf] of the Health Information Privacy Code 2020. If you’re not sure if your organisation qualifies you can [check with us| https://mohapis.atlassian.net/servicedesk/customer/portal/3/group/11/create/36].\n\nAll integrators will need to go through an Onboarding and Certification process to show they can meet the required security and privacy standards. There are some General Integration Requirements for integrating with Te Whatu Ora APIs and services, that all integrators must meet. Depending on your service or us there could be further specific requirements you will need to meet. Security and privacy of sensitive information is a high priority meaning there are stricter controls in place around gaining access.\n\nUseful links:\n- [Requirements for integrating with the Te Whatu Ora APIs | https://mohapis.atlassian.net/servicedesk/customer/portal/3/article/294925]\n- [How to integrate with the Te Whatu Ora's APIs | https://mohapis.atlassian.net/servicedesk/customer/portal/3/article/294950]\n\nWe recommend that you read the above articles, before using the forms below to submit your request.\n","localeDisplayName":"English (United States)"},"en-GB":{"localeDisplayName":"English (United Kingdom)"}},"canEditAnnouncement":false,"siteDefaultLanguageTag":"en-US","userLanguageTag":"en-US","portalThemeColor":"#15284c","helpCenterTitleColor":"#ffffff","bannerMediaApiUrl":"https://api.media.atlassian.com/file/5b843e3c-6095-4d8d-8d0d-3b4acab87021/image?token=eyJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJhY2UxZGE1Ny02NWQ5LTRlOGYtYjkyYS01YWU1YTFiZTQyNjIiLCJhY2Nlc3MiOnsidXJuOmZpbGVzdG9yZTpmaWxlOjViODQzZTNjLTYwOTUtNGQ4ZC04ZDBkLTNiNGFjYWI4NzAyMSI6WyJyZWFkIl19LCJleHAiOjE3MTQzNjc4MjcsIm5iZiI6MTcxNDM2NzIyN30.5sJlz9V0zB-dj73kf3SX-ZHBDL3IPBINMp7qGXMVGQQ&client=ace1da57-65d9-4e8f-b92a-5ae5a1be4262&height=300&mode=fit","bannerMediaApiFileId":"5b843e3c-6095-4d8d-8d0d-3b4acab87021","useDefaultBanner":false,"isBannerAvailable":true},"portal":{"id":"3","key":"in","projectId":10002,"serviceDeskId":3,"name":"Health New Zealand Onboarding portal","description":"","portalBaseUrl":"/servicedesk/customer/portal/3","onlyPortal":false,"reqTypes":[{"id":"112","name":"Digital Services Hub Support & Feedback form","descriptionHtml":"","callToAction":"Digital Services Hub Support & Feedback form","introHtml":"<p>Digital Services Hub Support & Feedback form</p>","icon":10503,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10503","groups":[35],"key":""},{"id":"120","name":"DSH Provider Onboarding","descriptionHtml":"","callToAction":"DSH Provider Onboarding","introHtml":"<p>DSH Provider Onboarding</p>","icon":10565,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10565","groups":[35],"key":""},{"id":"36","name":"Make a general enquiry","descriptionHtml":"","callToAction":"Make a general enquiry","introHtml":"<p>If you have an enquiry about an API, digital service or application, require support with onboarding or would like to raise a concern, provide us with as much information as you can to let us know how we can help.</p>","icon":10549,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10549","groups":[11],"key":""},{"id":"67","name":"Request to onboard","descriptionHtml":"","callToAction":"Request to onboard","introHtml":"<p>Complete this form to request access to our APIs or digital services.</p>","icon":10550,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10550","groups":[11],"key":""},{"id":"71","name":"Zero Data","descriptionHtml":"","callToAction":"Zero Data","introHtml":"<p>Onboard to Zero Data</p>","icon":10522,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10522","groups":[11],"key":""},{"id":"64","name":"1. Register your Interest / Apply for Test Access","descriptionHtml":"","callToAction":"1. Register your Interest / Apply for Test Access","introHtml":"<p>Want to access an API/Digital Service test environment? Start the process to get access here.</p>","icon":10550,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10550","groups":[],"key":""},{"id":"65","name":"2. Apply for Product Certification","descriptionHtml":"","callToAction":"2. Apply for Product Certification","introHtml":"<p>Have a product that is ready for production? Start the process to become certified here.</p>","icon":10487,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10487","groups":[],"key":""},{"id":"37","name":"Emailed request","descriptionHtml":"","callToAction":"Emailed request","introHtml":"<p>Request received from your email support channel.</p>","icon":10527,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10527","groups":[],"key":""},{"id":"44","name":"Onboarding - Baseline Security Questionnaire","descriptionHtml":"","callToAction":"Onboarding - Baseline Security Questionnaire","introHtml":"<p>When requested, use this form to provide supporting security information for your test environment access request.</p>","icon":10513,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10513","groups":[],"key":""},{"id":"42","name":"Onboarding - Intermediate Security Questionnaire","descriptionHtml":"","callToAction":"Onboarding - Intermediate Security Questionnaire","introHtml":"<p>When requested, use this form to provide supporting security information for your test environment access request.</p>","icon":10504,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10504","groups":[],"key":""},{"id":"122","name":"Prod Credential Request","descriptionHtml":"","callToAction":"Prod Credential Request","introHtml":"","icon":10513,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10513","groups":[],"key":""},{"id":"38","name":"Report a bug","descriptionHtml":"","callToAction":"Report a bug","introHtml":"<p>Tell us the problems you're experiencing.</p>","icon":10545,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10545","groups":[],"key":""},{"id":"63","name":"Request access to an application or digital service","descriptionHtml":"","callToAction":"Request access to an application or digital service","introHtml":"<p>Complete this form to request access to production for an application or digital service.</p>","icon":10499,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10499","groups":[],"key":""},{"id":"45","name":"Request API Access - Internal Te Whatu Ora","descriptionHtml":"","callToAction":"Request API Access - Internal Te Whatu Ora","introHtml":"<p>This form is to be used for requesting API Test Credentials for Testing your Product using Te Whatu Ora's API(s) in a Test Environment.</p>","icon":10550,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10550","groups":[],"key":""},{"id":"95","name":"Request for support","descriptionHtml":"","callToAction":"Request for support","introHtml":"<p>If you have an enquiry about an API, digital service or application, require support with onboarding or would like to raise a concern, provide us with as much information as you can to let us know how we can help.</p>","icon":10549,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10549","groups":[],"key":""},{"id":"39","name":"Suggest a new feature","descriptionHtml":"","callToAction":"Suggest a new feature","introHtml":"<p>Let us know your idea for a new feature.</p>","icon":10535,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10535","groups":[],"key":""},{"id":"40","name":"Suggest improvement","descriptionHtml":"","callToAction":"Suggest improvement","introHtml":"<p>See a place where we can do better? We're all ears.</p>","icon":10539,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10539","groups":[],"key":""},{"id":"33","name":"Technical support","descriptionHtml":"","callToAction":"Technical support","introHtml":"<p>Need help installing, configuring, or troubleshooting? Select this to request assistance.</p>","icon":10520,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10520","groups":[],"key":""},{"id":"124","name":"Test Credential Request","descriptionHtml":"","callToAction":"Test Credential Request","introHtml":"","icon":10513,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10513","groups":[],"key":""}],"reqGroups":[{"id":11,"name":"General"},{"id":35,"name":"Digital Services Hub"}],"orderMapping":{"35":[120,112],"13":[44,42],"28":[95,36],"11":[67,36,71]},"kbs":{"kbEnabled":true,"kbLink":{"appLinkId":"d899a6d3-5302-3fb3-8a5a-ff87c6886650","appLinkName":"System Confluence","appLinkUrl":"https://mohapis.atlassian.net/wiki","spaceKey":"IN","spaceName":"IntegrationTeam","spaceUrl":"https://mohapis.atlassian.net/wiki/spaces/IN","isServer":false},"labels":[],"projectKey":"IN","serviceDeskId":3,"kbLinkDomainURLs":["https://mohapis.atlassian.net"]},"createPermission":true,"portalAnnouncement":{"portalId":3,"canEditAnnouncement":false,"canAdministerProject":false,"portalProjectKey":"IN","userLanguageHeader":"","userLanguageMessageWiki":"","defaultLanguageHeader":"","defaultLanguageMessage":"","defaultLanguageDisplayName":"English (United States)","isUsingLanguageSupport":true,"translations":{}},"canViewCreateRequestForm":true,"isProjectSimplified":false,"mediaApiUploadInformation":{"token":"eyJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJhY2UxZGE1Ny02NWQ5LTRlOGYtYjkyYS01YWU1YTFiZTQyNjIiLCJhY2Nlc3MiOnsidXJuOmZpbGVzdG9yZTpjb2xsZWN0aW9uOnVwbG9hZC1wcm9qZWN0LTEwMDAyIjpbInJlYWQiLCJjcmVhdGUiLCJ1cGRhdGUiXSwidXJuOmZpbGVzdG9yZTp1cGxvYWQ6KiI6WyJyZWFkIiwiY3JlYXRlIiwidXBkYXRlIl0sInVybjpmaWxlc3RvcmU6Y2h1bms6KiI6WyJyZWFkIiwiY3JlYXRlIl19LCJleHAiOjE3MTQzNjg0MjcsIm5iZiI6MTcxNDM2NzIyN30.ouh0GdcieqKKxGBmN2ejZD4CNXDvbMQEMNOJjqRigVs","targetCollection":"upload-project-10002","endpointUrl":"https://api.media.atlassian.com","clientId":"ace1da57-65d9-4e8f-b92a-5ae5a1be4262","tokenDurationInMins":20}},"reqCreate":{"id":67,"projectId":10002,"form":{"name":"Request to onboard","descriptionHtml":"","callToAction":"Request to onboard","intro":"<p>Complete this form to request access to our APIs or digital services.</p>","instructions":"","icon":10550,"iconUrl":"https://mohapis.atlassian.net/rest/servicedeskapi/requesttype/icon/type/SD_REQTYPE/id/10550","key":""},"fields":[{"fieldType":"text","fieldId":"email","fieldConfigId":"","label":"Email confirmation to","description":"","descriptionHtml":"","required":true,"displayed":true,"presetValues":[]},{"fieldType":"attachment","fieldId":"attachment","fieldConfigId":"","label":"Attachment","description":"For example, Privacy Impact Assessment or security validation documents","descriptionHtml":"<p>For example, Privacy Impact Assessment or security validation documents</p>","required":false,"displayed":true,"presetValues":[]},{"fieldType":"text","fieldId":"summary","fieldConfigId":"","label":"Summary","description":"","descriptionHtml":"","required":true,"displayed":false,"presetValues":["Onboarding registration"]}],"userOrganisations":[],"canBrowseUsers":false,"requestCreateBaseUrl":"/servicedesk/customer/portal/3/create/67","requestValidateBaseUrl":"/servicedesk/customer/portal/3/validate/67","calendarParams":{"firstDay":0,"date":"2024-04-29T17:07:07+1200","useISO8601WeekNumbers":false,"dateIfFormat":"%e/%b/%y","dateTimeIfFormat":"%e/%b/%y %I:%M %p","timeFormat":"12"},"kbs":{"kbEnabled":false,"serviceDeskId":-1},"canRaiseOnBehalf":false,"canSignupCustomers":false,"canCreateAttachments":true,"attachmentRequiredField":false,"hasGroups":true,"canSubmitWithEmailAddress":false,"showRecaptcha":true,"siteKey":"6LePXLkdAAAAAF4gCNalrL1IvZcqbNbZf_Zakudd","mediaApiUploadInformation":{"token":"eyJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJhY2UxZGE1Ny02NWQ5LTRlOGYtYjkyYS01YWU1YTFiZTQyNjIiLCJhY2Nlc3MiOnsidXJuOmZpbGVzdG9yZTpjb2xsZWN0aW9uOnVwbG9hZC1wcm9qZWN0LTEwMDAyIjpbInJlYWQiLCJjcmVhdGUiLCJ1cGRhdGUiXSwidXJuOmZpbGVzdG9yZTp1cGxvYWQ6KiI6WyJyZWFkIiwiY3JlYXRlIiwidXBkYXRlIl0sInVybjpmaWxlc3RvcmU6Y2h1bms6KiI6WyJyZWFkIiwiY3JlYXRlIl19LCJleHAiOjE3MTQzNjg0MjcsIm5iZiI6MTcxNDM2NzIyN30.ouh0GdcieqKKxGBmN2ejZD4CNXDvbMQEMNOJjqRigVs","targetCollection":"upload-project-10002","endpointUrl":"https://api.media.atlassian.com","clientId":"ace1da57-65d9-4e8f-b92a-5ae5a1be4262","tokenDurationInMins":20},"hasProformaForm":true,"proformaTemplateForm":{"id":30,"updated":"2024-02-08T23:39:41.916162Z","publish":{"jira":{"submitOnCreate":true,"validateOnCreate":true},"portal":{"portalRequestTypeIds":[67],"submitOnCreate":true,"validateOnCreate":true}},"design":{"settings":{"templateId":30,"name":"Request to onboard to an API or digital service","submit":{"lock":false,"pdf":true},"language":"en-GB","templateFormUuid":"022dc5e8-5b86-4c6c-8603-20d2261bdfef"},"layout":[{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"info"},"content":[{"type":"paragraph","content":[{"type":"text","text":"Complete this form to help the approval process to integrate with an API or digital service for our external test and integration environment. The questions should be answered by an integrator or software vendor that can give details around the intended integration. "}]},{"type":"paragraph","content":[{"type":"text","text":"Before filling in this form, make sure you have information about:"}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"your organisation so we can use to verify you, "}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"your application or the service you would like to integrate with"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"how you want to use the information "}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"your anticipated go-live date."}]}]}]},{"type":"paragraph","content":[{"type":"text","text":"The approval process to get compliance credentials can take up to 5 business days. This may take longer if we need more information specific to your application. "}]}]},{"type":"panel","attrs":{"panelType":"note"},"content":[{"type":"paragraph","content":[{"type":"text","text":"Your privacy is important to us. The information you provide will be kept confidential. Once you have submitted the request form to us, you can view it in the portal but you cannot edit the original form."}]},{"type":"paragraph","content":[{"type":"text","text":"Our full privacy statement can be viewed at the end of this form."}]}]},{"type":"heading","attrs":{"level":2},"content":[{"type":"text","text":"Your details "}]},{"type":"paragraph","content":[{"type":"text","text":"Tell us who to contact during the process of gaining accreditation for your application."}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":31},"localId":"69bde932-ed7d-413d-a41a-f208a5071070"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":144},"localId":"649c1074-6bbe-4dc3-8013-00e34853d44a"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":159},"localId":"c9beddd5-4323-4bd8-a73b-c931c33d4860"}},{"type":"rule"},{"type":"heading","attrs":{"level":2},"content":[{"type":"text","text":"Your organisation details "}]},{"type":"paragraph","content":[{"type":"text","text":"Provide details of the organisation requesting access to the API, application or digital service. "}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":168},"localId":"d2287510-0d24-4643-bf46-a28f0dc198a4"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":169},"localId":"a339ec99-e48f-4df5-8bbe-45d39f5efe52"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":170},"localId":"3c65628b-ecb4-40ed-8b18-afba01dfb65a"}},{"type":"layoutSection","content":[{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":172},"localId":"c73dc3a4-6e22-4faf-bf2f-e4b73d69b1b9"}}]},{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"paragraph","content":[]},{"type":"paragraph","content":[{"type":"text","text":"Find your NZBN on the NZBN website","marks":[{"type":"link","attrs":{"href":"https://www.nzbn.govt.nz/mynzbn/search/"}},{"type":"subsup","attrs":{"type":"sup"}}]}]}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":4},"localId":"cf88bd27-6fd6-46ac-b019-b508ccd4faed"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":7},"localId":"85e37093-b616-4c16-8d82-7271f0fde9a0"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":102},"localId":"2acdb1d0-ed4a-4dbd-ae7a-d5c119cf3c55"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":71},"localId":"3636c64f-f956-4a75-b8c8-9bacd21e3a93"}}]},{"version":1,"type":"doc","content":[{"type":"rule"},{"type":"heading","attrs":{"level":2},"content":[{"type":"text","text":"About your software product or application"}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":247},"localId":"ce44cc08-1e38-4538-855c-a349b8592180"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":248},"localId":"e64630ab-e306-4310-885f-235da589ef8d"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":250},"localId":"64c4c2c9-d214-469a-9d7c-486261873c11"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":" When a digital service supplier organisation requests access to one of our services via a proxy, the integrating applications will still need to be issued their own credential. The proxy will need to pass through the client credentials when calling the external service."}]},{"type":"paragraph","content":[{"type":"text","text":"The proxy may maintain the application’s credentials on behalf of the application, as long as each application is issued its own credentials, and the client secrets are subject to appropriate security controls."}]}]},{"type":"heading","attrs":{"level":2},"content":[{"type":"text","text":"Rationale"}]},{"type":"table","attrs":{"isNumberColumnEnabled":false,"layout":"default","localId":"0943c658-efa8-4255-811a-a6fbcfa7c93b"},"content":[{"type":"tableRow","content":[{"type":"tableHeader","attrs":{"colwidth":[152]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Category","marks":[{"type":"strong"}]}]}]},{"type":"tableHeader","attrs":{"colwidth":[608]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Description","marks":[{"type":"strong"}]}]}]}]},{"type":"tableRow","content":[{"type":"tableCell","attrs":{"colwidth":[152]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Regulation"}]}]},{"type":"tableCell","attrs":{"colwidth":[608]},"content":[{"type":"paragraph","content":[{"type":"text","text":"The Health Information Privacy Code (HIPC) stipulates which health organisations may assign NHI numbers. In order to comply with HIPC we need to know the identity of the calling organisation before agreeing to share NHI information."}]}]}]},{"type":"tableRow","content":[{"type":"tableCell","attrs":{"colwidth":[152]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Data Quality"}]}]},{"type":"tableCell","attrs":{"colwidth":[608]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Te Whatu Ora has a need to be able to review a client application's use of our services in order to assess the quality of the user experience, mainly to ensure that the user experience supports our data quality needs."}]}]}]},{"type":"tableRow","content":[{"type":"tableCell","attrs":{"colwidth":[152]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Authorisation"}]}]},{"type":"tableCell","attrs":{"colwidth":[608]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Coarse grained authorization in FHIR services is implemented in SMART scopes which are assigned to client identities. We need to be able to allocate these scopes at an application level rather than delegating that responsibility to a third-party proxy."}]}]}]},{"type":"tableRow","content":[{"type":"tableCell","attrs":{"colwidth":[152]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Auditability"}]}]},{"type":"tableCell","attrs":{"colwidth":[608]},"content":[{"type":"paragraph","content":[{"type":"text","text":"We need to be able to audit the activity the users of an individual application in meet our legislative requirements under the Privacy Act and the Official Information Act."}]}]}]},{"type":"tableRow","content":[{"type":"tableCell","attrs":{"colwidth":[152]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Observability"}]}]},{"type":"tableCell","attrs":{"colwidth":[608]},"content":[{"type":"paragraph","content":[{"type":"text","text":"We need to be able to monitor individual applications API usage in order to be able to troubleshoot effectively and to identify unusual patterns."}]}]}]}]}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":252},"localId":"afd184c5-a450-4ea5-a9ba-31e14a19928a"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":253},"localId":"e5fa8d7a-0109-44a7-8d10-7b1bc146fed8"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":254},"localId":"8fbd5cb4-34ae-4cef-976f-2d7758b25dba"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":256},"localId":"3da592b2-7dee-4a8e-85bc-c870de35c9ce"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":257},"localId":"09baa150-5ddf-4052-af69-0d9d6204c7dd"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":258},"localId":"f3510b1f-ebaf-45de-b946-ca710eab7f7a"}}]},{"version":1,"type":"doc","content":[{"type":"rule"},{"type":"heading","attrs":{"level":2},"content":[{"type":"text","text":"APIs and digital services"}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":8},"localId":"2df22ab6-be72-4789-a76e-22af592d5e53"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"info"},"content":[{"type":"paragraph","content":[{"type":"text","text":"Please note, Health Identity policy requires that the identity of the end user of the API is securely established. This means that the API must be able to authenticate the organisation / application making the API call and that every differing organisation / branch will require their own Production credentials to access the data through these APIs."}]}]},{"type":"paragraph","content":[]}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"note"},"content":[{"type":"paragraph","content":[{"type":"text","text":"By using Te Whatu Ora APIs you are accessing personally identifiable information from the NHI which is not directly from the individual concerned. You need to consider your obligations under Health Information Privacy Code 2020, principle 2. Te Whatu Ora may request to see your privacy impact assessment prior to access to production."}]}]},{"type":"rule"}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":236},"localId":"7a5b4af3-61d6-4614-8ea6-13aef0a8d810"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":108},"localId":"0c820258-f0dc-4229-89df-1961a9c429f3"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":237},"localId":"a28a85fe-82f8-41ef-a42c-bfcebce3a70f"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":148},"localId":"ae8747b4-81e1-49f7-afad-28b5724bf8c4"}},{"type":"paragraph","content":[{"type":"text","text":"OpenID Connect (OIDC) Redirect URL","marks":[{"type":"strong"}]}]},{"type":"paragraph","content":[{"type":"text","text":"Provide the redirect URLs for your non-production environments."}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":327},"localId":"d22c5b39-37ad-42c7-b415-cc05661594b0"}},{"type":"paragraph","content":[{"type":"text","text":"Post logout redirect URLs","marks":[{"type":"strong"}]}]},{"type":"paragraph","content":[{"type":"text","text":"Provide the post logout redirect URLs for your non-production environments."}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":328},"localId":"19ad937b-6a49-4aac-9ea8-5e7368866433"}},{"type":"rule"}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":326},"localId":"cb848d1d-be2c-4e99-b2d1-7401a39ed510"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"info"},"content":[{"type":"heading","attrs":{"level":5},"content":[{"type":"text","text":"More information on organisaiton and facility business functions can be found "},{"type":"text","text":"here","marks":[{"type":"link","attrs":{"href":"https://hpi-ig.hip-uat.digital.health.nz/Onboarding.html#business-functions"}},{"type":"underline"}]},{"type":"text","text":"."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":223},"localId":"58986442-a920-4bc3-bb4b-6a5e94a6cf5c"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"info"},"content":[{"type":"heading","attrs":{"level":5},"content":[{"type":"text","text":"More information on practitioner business functions can be found "},{"type":"text","text":"here","marks":[{"type":"link","attrs":{"href":"https://hpi-ig.hip-uat.digital.health.nz/Onboarding.html#business-functions"}},{"type":"underline"}]},{"type":"text","text":"."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":225},"localId":"42ce67ee-d905-4fd6-b97d-eaf040a8d875"}},{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"Access to any of the above Practitioner business functions in Production may require business teams to have completed a Privacy Impact Assessment which has been assessed and approved by the Te Whatu Ora privacy team. Business Owners should progress this in parallel with any application development. Production access to contact details will not be granted unless this step has been completed."}]}]}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"info"},"content":[{"type":"heading","attrs":{"level":5},"content":[{"type":"text","text":"More information on PractitionerRole business functions can be found "},{"type":"text","text":"here","marks":[{"type":"link","attrs":{"href":"https://hpi-ig.hip-uat.digital.health.nz/Onboarding.html#business-functions"}},{"type":"underline"}]},{"type":"text","text":"."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":227},"localId":"b4d6c557-8feb-4c7f-b65c-0fb5f5a95fce"}},{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"Access to any of the above PractitionerRole business functions in Production may require business teams to have completed a Privacy Impact Assessment which has been assessed and approved by the Te Whatu Ora privacy team. Business Owners should progress this in parallel with any application development. Production access to contact details will not be granted unless this step has been completed."}]}]},{"type":"panel","attrs":{"panelType":"info"},"content":[{"type":"paragraph","content":[{"type":"text","text":"Currently there is no data in Production for this business function."}]}]},{"type":"paragraph","content":[]}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":220},"localId":"ea130e11-807e-4b0e-9424-70d68e0fffa0"}},{"type":"rule"}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"info"},"content":[{"type":"heading","attrs":{"level":5},"content":[{"type":"text","text":"More information on patient functions can be found "},{"type":"text","text":"here","marks":[{"type":"link","attrs":{"href":"https://nhi-ig.hip-uat.digital.health.nz/Onboarding.html#business-functions"}},{"type":"underline"}]},{"type":"text","text":"."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":234},"localId":"c69a3283-9f6d-4a56-a50b-b4cf61f01847"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"Access to a ‘Get Patient - Enrolled GP’ and ‘Get Patient - Contact details' in Production will only be granted to Te Whatu Ora business teams that have completed a Privacy Impact Assessment which has been assessed and approved by the Te Whatu Ora privacy team. Business Owners should progress this in parallel with any application development. Production access to contact details will not be granted unless this step has been completed."}]}]},{"type":"paragraph","content":[]}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"‘Maintain Patient’ and ‘Create Patient’ are provided on a limited basis. For those without access, this may be achieved by phoning the Te Whatu Ora contact centre (0800 855 066)."}]}]},{"type":"paragraph","content":[]}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":184},"localId":"c8bc2c31-c4f9-42f5-a953-9a2c44585b49"}},{"type":"rule"}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"error"},"content":[{"type":"paragraph","content":[{"type":"text","text":"The National Enrolment Service is used to update the practice/organisation a patient is enrolled with. For this reason, permission to onboard to this API is limited to organisations that are involved in the enrolment of patients to practices/organisations."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":292},"localId":"9bf9b144-65fa-4862-b734-aea933f6faa6"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"For Enrolment Nomination - Access will only be given to the Te Whatu Ora Whaihua platform users, the Te Whatu Ora Enrolment nomination subscriber and HealthLink in the initial implementation. If you are interested in this business function, please contact "},{"type":"text","text":"integration@health.govt.nz","marks":[{"type":"link","attrs":{"href":"mailto:integration@health.govt.nz"}}]},{"type":"text","text":"."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":293},"localId":"66de4458-d967-43f7-8b14-02a04ed534a4"}}]},{"version":1,"type":"doc","content":[{"type":"rule"}]},{"version":1,"type":"doc","content":[{"type":"heading","attrs":{"level":2},"content":[{"type":"text","text":"Delivery Details"}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":262},"localId":"32afa680-4b88-41a3-b5d7-7354056b51eb"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":264},"localId":"9a528ca2-09e2-40a3-a380-bd7a6cdd8151"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":49},"localId":"25d4be8b-2d3e-4a19-b423-7da775d82033"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":152},"localId":"e0b91f31-f749-4ed5-9c46-5c6a01cb2ebd"}}]},{"version":1,"type":"doc","content":[{"type":"layoutSection","content":[{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":154},"localId":"dccec400-9564-4416-b12b-71a87345d0f6"}}]},{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"paragraph","content":[]}]}]}]},{"version":1,"type":"doc","content":[{"type":"layoutSection","content":[{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":157},"localId":"86733ecb-e6cb-4813-95db-28480a9585ad"}}]},{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"paragraph","content":[]}]}]}]},{"version":1,"type":"doc","content":[{"type":"layoutSection","content":[{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":158},"localId":"83ceca63-f89b-4da3-8b4a-a8a6dc700ec7"}}]},{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"paragraph","content":[]}]}]},{"type":"paragraph","content":[]},{"type":"rule"}]},{"version":1,"type":"doc","content":[{"type":"paragraph","content":[]}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":303},"localId":"3b13126c-a4e0-4d0b-b5ae-01aa7f344ec8"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"By providing these contact details you confirm that the individual has authorised you to share their details for the purpose of communications regarding your information security."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":305},"localId":"91c4daf9-6fe7-42ed-b627-db71c754908f"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":306},"localId":"5e278546-181c-4a80-8bdf-6323cb0b457f"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":307},"localId":"0e5de8e4-9dc6-4b51-8258-a173701e4bb6"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":308},"localId":"fb4fdcef-a704-4c30-915b-ad95bba26c09"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"By providing your contact details you agree that you are authorised to receive the API credentials for the external test and integration environment on behalf of your organisation."}]}]},{"type":"paragraph","content":[]}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"By providing the contact details you confirm that:"}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"the individual has authorised you to share their details for the purpose of receiving the API credentials "}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"the individual is authorised to receive the credentials for the external test and integration environment on behalf of your organisation "}]}]}]}]},{"type":"paragraph","content":[{"type":"text","text":"Who do we send the compliance environment credentials to?"}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":311},"localId":"92f73759-2f6d-4d72-b006-103d980fe7b5"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":312},"localId":"3ff664c8-268f-4dbc-8794-2de5ea96c028"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":313},"localId":"64ee8250-a4ed-4170-be53-0ef504b0fcc0"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":314},"localId":"621d8fab-e619-4f60-95d8-85c81d4a2f83"}},{"type":"panel","attrs":{"panelType":"note"},"content":[{"type":"paragraph","content":[{"type":"text","text":"You must provide an email address for us to send your client ID to. You must provide a mobile number for us to send client secret to."}]}]},{"type":"paragraph","content":[]}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":315},"localId":"a5827e7c-739b-447f-aef1-2513f518fa2d"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"By providing the contact details you confirm the individual has authorised you to share their details for the purpose of ongoing communications with us about support."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":317},"localId":"f3ec0196-5b4d-4502-a749-b10de4ff65fe"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":318},"localId":"0eba8e28-705b-4712-b325-a19ef0d292f5"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":319},"localId":"b65f584d-c6d8-4e0d-b094-8c7015747f8e"}}]},{"version":1,"type":"doc","content":[{"type":"rule"},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":323},"localId":"aad567ba-495b-4a54-a68e-e99945eec63d"}},{"type":"rule"}]},{"version":1,"type":"doc","content":[{"type":"heading","attrs":{"level":2},"content":[{"type":"text","text":"Onboarding & Certification Process Privacy Statement "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Introduction "}]},{"type":"paragraph","content":[{"type":"text","text":"Te Whatu Ora – Health New Zealand manages the process of onboarding developers and users of systems that integrate with digital health information services. "}]},{"type":"paragraph","content":[{"type":"text","text":" This process involves the collection and use of personal information about you and others from your organisation who are involved in applying for, accessing, and maintaining use of these services. "}]},{"type":"paragraph","content":[{"type":"text","text":" This privacy statement explains how we ensure the privacy of this information is protected in accordance with the Privacy Act 2020. "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Last updated "}]},{"type":"paragraph","content":[{"type":"text","text":"We may update this privacy statement from time to time. Please check this privacy statement regularly for modifications and updates. This privacy statement was last updated on "},{"type":"text","text":"27 February 2023. ","marks":[{"type":"strong"}]},{"type":"text","text":" "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Collection of personal information"}]},{"type":"paragraph","content":[{"type":"text","text":"When an API/ Service Onboarding Request is submitted we may:"}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Collect personal information from you directly "}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Collect personal information from a third party."}]}]}]},{"type":"heading","attrs":{"level":4},"content":[{"type":"text","text":"Information we collect directly from you ","marks":[{"type":"em"}]}]},{"type":"paragraph","content":[{"type":"text","text":"When you complete the API/Service Onboarding Request we collect the following personal information about you: "}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Full name "}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Email address "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Mobile phone number "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Your role"}]}]}]},{"type":"heading","attrs":{"level":4},"content":[{"type":"text","text":"Information we collect directly from third party","marks":[{"type":"em"}]}]},{"type":"paragraph","content":[{"type":"text","text":"The person completing the API/Service Onboarding Request may nominate another individual from their organisation to be a point of contact for:"}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Sending onboarding credential information to; and/or"}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"ongoing service support."}]}]}]},{"type":"paragraph","content":[{"type":"text","text":" If you have been nominated as the point of contact, we may collect your name, email address and mobile phone number. The person completing the Request form confirms to Te Whatu Ora (at the time they submit the form) that they have your authorisation to share your details with us. "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Choice"}]},{"type":"paragraph","content":[{"type":"text","text":"If you do not provide us with the personal information outlined above, you may not be able to submit an API/Service Onboarding Request, be onboarded to our services and/or receive ongoing service support."}]},{"type":"paragraph","content":[{"type":"text","text":" The information is held by Te Whatu Ora – Health New Zealand. "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"How we use your personal information "}]},{"type":"paragraph","content":[{"type":"text","text":"We may use your personal information for the following: "}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"To identify you in connection with your application, your organisation and our communications with you "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"To correspond with you regarding your onboarding request "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"To provide access credentials to you "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"To correspond with you for the purposes of technical support "}]}]}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Sharing the information "}]},{"type":"paragraph","content":[{"type":"text","text":"We may share your personal information internally with those directly involved with the process of onboarding your organisation as an integration developer or integrated product user. "}]},{"type":"paragraph","content":[{"type":"text","text":"We may share your information with organisations contracted by Te Whatu Ora to provide supporting services for application requests, compliance assessment or technical support. Attributes will only be shared with others as necessary for that service. If the details are not necessary for a service, they will not be supplied. "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"How long we hold information "}]},{"type":"paragraph","content":[{"type":"text","text":"We only keep your personal information for as long as required for the purposes outlined in this privacy statement and in accordance with the law. "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Storing information securely "}]},{"type":"paragraph","content":[{"type":"text","text":"We take reasonable steps to ensure your personal information is protected against loss, unauthorised access, use, modification, disclosure, or other misuse. "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Access to and requests to correct the information "}]},{"type":"paragraph","content":[{"type":"text","text":"You have the right to access any information we hold about you and ask us to correct it if you think it is wrong. "}]},{"type":"paragraph","content":[{"type":"text","text":" To access any personal information held by us, or if you wish to correct your information, please email "},{"type":"text","text":"integration@health.govt.nz","marks":[{"type":"link","attrs":{"href":"mailto:integration@health.govt.nz"}},{"type":"underline"}]},{"type":"text","text":". "}]},{"type":"paragraph","content":[{"type":"text","text":" When making a request to access or change your information, please include: "}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"your name "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"contact address (email or postal) "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"contact phone number "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"details of the information you want or want to correct - this needs to be as clear and specific as you can make it. "}]}]}]},{"type":"paragraph","content":[{"type":"text","text":" Please note that before we can provide you with your information or make any changes we need to be satisfied about your identity. To do so, we may need to ask you further questions or to view identification which establishes your identity. "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Queries and concerns "}]},{"type":"paragraph","content":[{"type":"text","text":"If you have any queries or concerns about how your personal information has been managed, please contact us to see if we can resolve the problem. You can:"}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Email us at "},{"type":"text","text":"hnzprivacy@health.govt.nz","marks":[{"type":"link","attrs":{"href":"mailto:hnzprivacy@health.govt.nz"}},{"type":"underline"}]},{"type":"text","text":" "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Write to us at Privacy Officer - Te Whatu Ora, PO Box 793, Wellington 6140, New Zealand "}]}]}]},{"type":"paragraph","content":[{"type":"text","text":" If you’re not satisfied with our response to your concerns, you can contact the Office of the Privacy Commissioner. For more information see the "},{"type":"text","text":"Office of the Privacy Commissioner website","marks":[{"type":"link","attrs":{"href":"https://www.privacy.org.nz/your-rights/making-a-complaint/"}}]},{"type":"text","text":". "}]},{"type":"paragraph","content":[{"type":"text","text":" "}]}]}],"conditions":{"263":{"t":"sh","i":{"co":{"cIds":{"262":["1"]}}},"o":{"sIds":["28"]}},"185":{"t":"sh","i":{"co":{"cIds":{"8":["10061"]}}},"o":{"sIds":["20"]}},"297":{"t":"sh","i":{"co":{"cIds":{"234":["10119","10120"]}}},"o":{"sIds":["21"]}},"156":{"t":"sh","i":{"co":{"cIds":{"152":["0"]}}},"o":{"sIds":["33"]}},"235":{"t":"sh","i":{"co":{"cIds":{"8":["10036"]}}},"o":{"sIds":["14"]}},"251":{"t":"sh","i":{"co":{"cIds":{"250":["1"]}}},"o":{"sIds":["4"]}},"232":{"t":"sh","i":{"co":{"cIds":{"326":["6"]}}},"o":{"sIds":["16"]}},"316":{"t":"sh","i":{"co":{"cIds":{"315":["2"]}}},"o":{"sIds":["41"]}},"229":{"t":"sh","i":{"co":{"cIds":{"8":["10060"]}}},"o":{"sIds":["19"]}},"310":{"t":"sh","i":{"co":{"cIds":{"308":["10112"]}}},"o":{"sIds":["39"]}},"302":{"t":"sh","i":{"co":{"cIds":{"159":["7","2","1","3","4","5","0"]}}},"o":{"sIds":["35"]}},"153":{"t":"sh","i":{"co":{"cIds":{"152":["2"]}}},"o":{"sIds":["31"]}},"291":{"t":"sh","i":{"co":{"cIds":{"8":["10065"]}}},"o":{"sIds":["24"]}},"298":{"t":"sh","i":{"co":{"cIds":{"234":["10122","10123"]}}},"o":{"sIds":["22"]}},"217":{"t":"sh","i":{"co":{"cIds":{"8":["10036"]}}},"o":{"sIds":["11"]}},"255":{"t":"sh","i":{"co":{"cIds":{"254":["1"]}}},"o":{"sIds":["6"]}},"325":{"t":"sh","i":{"co":{"cIds":{"8":["10061"]}}},"o":{"sIds":["10"]}},"155":{"t":"sh","i":{"co":{"cIds":{"152":["1"]}}},"o":{"sIds":["32"]}},"233":{"t":"sh","i":{"co":{"cIds":{"8":["10060"]}}},"o":{"sIds":["15"]}},"231":{"t":"sh","i":{"co":{"cIds":{"326":["2"]}}},"o":{"sIds":["17"]}},"72":{"t":"sh","i":{"co":{"cIds":{"102":["1"]}}},"o":{"sIds":["1"]}},"230":{"t":"sh","i":{"co":{"cIds":{"326":["5"]}}},"o":{"sIds":["18"]}},"309":{"t":"sh","i":{"co":{"cIds":{"308":["10111"]}}},"o":{"sIds":["38"]}},"322":{"t":"sh","i":{"co":{"cIds":{"8":["10061","10060"]}}},"o":{"sIds":["9"]}},"214":{"t":"sh","i":{"co":{"cIds":{"323":["1"]}}},"o":{"sIds":["43"]}},"238":{"t":"sh","i":{"co":{"cIds":{"236":["10165"]}}},"o":{"sIds":["12"]}},"304":{"t":"sh","i":{"co":{"cIds":{"303":["1"]}}},"o":{"sIds":["36"]}},"301":{"t":"sh","i":{"co":{"cIds":{"292":["10248"]}}},"o":{"sIds":["25"]}},"239":{"t":"sh","i":{"co":{"cIds":{"236":["10164"]}}},"o":{"sIds":["13"]}}},"sections":{"34":{"conditions":[]},"12":{"name":"If My Health Account is selected","conditions":["238","217"]},"8":{"conditions":[]},"33":{"name":"Other date selected","conditions":["156"]},"22":{"name":"Call Centre contact for access","conditions":["298","185"]},"13":{"name":"If My Health Account Workforce is selected","conditions":["239","217"]},"5":{"conditions":[]},"10":{"name":"If NHI selected","conditions":["325"]},"21":{"name":"PIA warning","conditions":["297","185"]},"43":{"name":"Privacy Statement","conditions":["214"]},"32":{"name":"Full end-to-end date selected","conditions":["155"]},"31":{"name":"Integration for development date selected","conditions":["153"]},"42":{"conditions":[]},"18":{"name":"If Practitioner role selected","conditions":["230","233"]},"3":{"name":"If HPI or NHI","conditions":[]},"28":{"name":"Display if there is a Project as part of this work","conditions":["263"]},"19":{"name":"HPI selected","conditions":["229"]},"23":{"conditions":[]},"4":{"name":"Brokering or proxy API","conditions":["251"]},"40":{"conditions":[]},"15":{"name":"Display if HPI selected","conditions":["233"]},"11":{"name":"Display if MHA selected","conditions":["217"]},"9":{"name":"HPI or NHI","conditions":["322"]},"26":{"conditions":[]},"37":{"conditions":[]},"24":{"name":"Enrolment Nomination","conditions":["291"]},"35":{"name":"If NOT a security person","conditions":["302"]},"16":{"name":"Organisation / Facility selected","conditions":["232","233"]},"6":{"name":"If yes","conditions":["255"]},"36":{"name":"If someone else","conditions":["304","302"]},"1":{"name":"* Existing Access","conditions":["72"]},"39":{"name":"* Send Credentials to someone else","conditions":["310"]},"17":{"name":"If Practitioner selected","conditions":["231","233"]},"25":{"name":"Enrolment Warning ","conditions":["301","291"]},"14":{"name":"Display if MHA selected","conditions":["235"]},"20":{"name":"Display if NHI selected","conditions":["185"]},"27":{"conditions":[]},"2":{"conditions":[]},"38":{"name":"* Send credentials to me","conditions":["309"]},"30":{"conditions":[]},"7":{"conditions":[]},"29":{"conditions":[]},"41":{"conditions":["316"]}},"questions":{"223":{"type":"cm","label":"What organisation / facility function do you require access to?","description":"","validation":{"rq":true},"jiraField":"customfield_10092","defaultAnswer":{"choices":["1"]},"questionKey":""},"313":{"type":"te","label":"Email address","description":"","validation":{"rq":true},"questionKey":""},"236":{"type":"cs","label":"What instance of My Health Account are you interested in?","description":"","validation":{"rq":true},"jiraField":"customfield_10121","questionKey":""},"303":{"type":"cs","label":"Who is the person within your organisation responsible for your information security?","description":"","validation":{"rq":true},"choices":[{"id":"2","label":"Me","other":false},{"id":"1","label":"Someone else","other":false}],"questionKey":""},"328":{"type":"rt","label":"Post logout redirect URLs","description":"","validation":{"rq":false},"jiraField":"customfield_10156","questionKey":""},"152":{"type":"cm","label":"Are there any other important dates we should know about?","description":"For example, dates you need us to work towards before you go-live","validation":{"rq":false},"choices":[{"id":"2","label":"Integration for development date","other":false},{"id":"1","label":"Full end-to-end testing date","other":false},{"id":"0","label":"Other...","other":true}],"questionKey":""},"148":{"type":"pg","label":"How will you use these attributes?'","description":"Your Privacy Impact Assessment must justify the use of each attribute selected above.","validation":{"rq":true},"choices":[],"questionKey":""},"49":{"type":"da","label":"When is the planned go-live date of your product or application?","description":"This is the date your users will be able to access the information surfaced by this API or digital service.","validation":{"rq":true},"jiraField":"customfield_10135","questionKey":""},"308":{"type":"cs","label":"Who will be the person responsible for receiving the compliance environment API credentials? ","description":"If your application is approved, this will be the person we send client ID and client secret to.","validation":{"rq":true},"jiraField":"customfield_10079","questionKey":""},"327":{"type":"rt","label":"OpenID Connect (OIDC) Redirect URLs","description":"","validation":{"rq":false},"jiraField":"customfield_10155","questionKey":""},"169":{"type":"tl","label":"Organisation trading name","description":"","validation":{"rq":false},"choices":[],"questionKey":""},"158":{"type":"da","label":"Another important date","description":"","validation":{"rq":false},"choices":[],"questionKey":""},"8":{"type":"cm","label":"Which APIs and digital services do you want access to?","description":"","validation":{"rq":true},"jiraField":"components","questionKey":""},"307":{"type":"ts","label":"Mobile number","description":"","validation":{"rq":true},"choices":[],"questionKey":""},"170":{"type":"tl","label":"Health Provider Index (HPI) Organisation ID or Vendor ID","description":"Health Provider Index format is GXXnnnn-C where \"X\" is alphanumeric, \"n\" is numberic and \"C\" is a check character. Vendor ID (If it has been issued by Te Whatu Ora) is HSVNnnnn where \"n\" represents a number)","validation":{"rq":false},"jiraField":"customfield_10066","defaultAnswer":{"text":"G0"},"questionKey":""},"4":{"type":"pg","label":"Organisation registered address","description":"Where is your organisation located? ","validation":{"rq":true},"choices":[],"questionKey":""},"318":{"type":"cd","label":"Role","description":"","validation":{"rq":true},"choices":[{"id":"7","label":"Architect","other":false},{"id":"1","label":"Developer","other":false},{"id":"2","label":"Business Owner ","other":false},{"id":"3","label":"Business Manager","other":false},{"id":"4","label":"Administrator","other":false},{"id":"5","label":"Project Manager","other":false},{"id":"6","label":"Security Officer","other":false},{"id":"0","label":"Other...","other":true}],"questionKey":""},"262":{"type":"cs","label":"Is this integration activity part of a project? ","description":"","validation":{"rq":false},"choices":[{"id":"1","label":"Yes","other":false},{"id":"2","label":"No","other":false}],"questionKey":""},"227":{"type":"cm","label":"What practitioner role function do you require access to?","description":"","validation":{"rq":true},"jiraField":"customfield_10090","defaultAnswer":{"choices":["1"]},"questionKey":""},"250":{"type":"cs","label":"Does your application employ any kind of proxy API or brokering service?","description":"","validation":{"rq":false},"choices":[{"id":"1","label":"Yes","other":false},{"id":"2","label":"No","other":false}],"questionKey":""},"253":{"type":"pg","label":"What are the business processes performed within your product or application?","description":"Provide a high level flow of your business process and how you plan to use this digital service or API to help your business process.","validation":{"rq":true},"choices":[],"questionKey":""},"314":{"type":"ts","label":"Mobile number","description":"","validation":{"rq":true},"jiraField":"customfield_10085","questionKey":""},"306":{"type":"te","label":"Email address","description":"","validation":{"rq":true},"questionKey":""},"159":{"type":"cd","label":"Role","description":"","validation":{"rq":true},"choices":[{"id":"7","label":"Architect","other":false},{"id":"1","label":"Developer","other":false},{"id":"2","label":"Business Owner ","other":false},{"id":"3","label":"Business Manager","other":false},{"id":"4","label":"Administrator","other":false},{"id":"5","label":"Project Manager","other":false},{"id":"6","label":"Security Officer","other":false},{"id":"0","label":"Other...","other":true}],"questionKey":""},"144":{"type":"ts","label":"Mobile number","description":"","validation":{"rq":true},"jiraField":"customfield_10084","questionKey":""},"237":{"type":"cm","label":"Identity Attributes you are interested in","description":"","validation":{"rq":true},"jiraField":"customfield_10131","defaultAnswer":{"choices":["10173","10223"]},"questionKey":""},"256":{"type":"pg","label":"Can you provide us more information regarding who you are working with and how you fit into the solution.","description":"","validation":{"rq":true},"choices":[],"questionKey":""},"317":{"type":"tl","label":"Name","description":"","validation":{"rq":true},"jiraField":"customfield_10126","questionKey":""},"71":{"type":"cm","label":"Select the APIs your organisation has access to.","description":"","validation":{"rq":true},"choices":[{"id":"1","label":"My Health Account (MHA)","other":false},{"id":"2","label":"Health Provider Index API (HPI FHIR API)","other":false},{"id":"3","label":"National Health Index API (NHI FHIR API)","other":false}],"questionKey":""},"248":{"type":"cs","label":"What type of software product or application is the above?","description":"","validation":{"rq":false},"jiraField":"customfield_10129","questionKey":""},"292":{"type":"cm","label":"What Function to NES do you want access to?","description":"","validation":{"rq":false},"jiraField":"customfield_10145","questionKey":""},"108":{"type":"cm","label":"Identity Attributes you are interested in","description":"","validation":{"rq":true,"ch":"10213"},"jiraField":"customfield_10130","defaultAnswer":{"choices":["10213"]},"questionKey":""},"234":{"type":"cm","label":"What patient function do you require access to?","description":"","validation":{"rq":true},"jiraField":"customfield_10091","questionKey":""},"252":{"type":"pg","label":"Details of your product or application.","description":"Provide details of the service your product of application provides and how critical it is to your organisation.","validation":{"rq":true},"choices":[],"questionKey":""},"102":{"type":"cs","label":"Does your organisation currently have access to any our APIs?","description":"","validation":{"rq":true},"choices":[{"id":"1","label":"Yes","other":false},{"id":"2","label":"No","other":false},{"id":"3","label":"Not sure","other":false}],"questionKey":""},"31":{"type":"tl","label":"Name","description":"","validation":{"rq":true},"jiraField":"customfield_10076","questionKey":""},"315":{"type":"cs","label":"If your application is approved, who is the best person to contact for production operational support?","description":"We will notify this person of any API or digital service outages, releases and upcoming features.","validation":{"rq":true},"choices":[{"id":"1","label":"Me","other":false},{"id":"2","label":"Someone else","other":false}],"questionKey":""},"184":{"type":"pg","label":"How will you use the information provided in the above functionality?","description":"Your Privacy Impact Assessment must justify the use of each function selected above.","validation":{"rq":true},"choices":[],"questionKey":""},"264":{"type":"ts","label":"What is the name of the Project?","description":"","validation":{"rq":false},"choices":[],"questionKey":""},"257":{"type":"cm","label":"Who are the intended users of your product or application?","description":"Check all that apply.","validation":{"rq":true},"choices":[{"id":"7","label":"Patients: self service","other":false},{"id":"5","label":"Customer-facing staff","other":false},{"id":"1","label":"Health practitioners","other":false},{"id":"9","label":"Hospital administrators","other":false},{"id":"6","label":"IT administrators","other":false},{"id":"8","label":"Practice managers and administrators","other":false},{"id":"0","label":"Other...","other":true}],"questionKey":""},"225":{"type":"cm","label":"What practitioner function do you require access to?","description":"","validation":{"rq":true},"jiraField":"customfield_10093","defaultAnswer":{"choices":["1"]},"questionKey":""},"293":{"type":"rt","label":"Please state the use case for each business function requested?","description":"","validation":{"rq":false},"choices":[],"questionKey":""},"326":{"type":"cm","label":"HPI information you are interested in","description":"","validation":{"rq":true},"choices":[{"id":"6","label":"Organisation / Facility","other":false},{"id":"2","label":"Practitioner ","other":false},{"id":"5","label":"Practioner role (Pracrole)","other":false}],"defaultAnswer":{"choices":["1"]},"questionKey":""},"311":{"type":"tl","label":"Name","description":"","validation":{"rq":true},"jiraField":"customfield_10080","questionKey":""},"258":{"type":"cm","label":"Which category under Schedule 2 of the Health Information Privacy Code 2020 will your users belong to?","description":"This is to provide us further information regarding who is accessing our data or using our digital service.","validation":{"rq":true},"choices":[{"id":"1","label":"Accident Compensation Corporation","other":false},{"id":"2","label":"Department of Corrections Health Service","other":false},{"id":"3","label":"Te Whatu Ora - Health New Zealand","other":false},{"id":"4","label":"Health Practitioner","other":false},{"id":"5","label":"Hospital","other":false},{"id":"6","label":"Independent Practitioners Association of New Zealand","other":false},{"id":"7","label":"MedicAlert Foundation - New Zealand Incorporated","other":false},{"id":"8","label":"Manatu Hauora - Ministry of Health","other":false},{"id":"9","label":"New Zealand Blood and Organ Service","other":false},{"id":"10","label":"New Zealand Defence Force Health Service","other":false},{"id":"11","label":"Pharmaceutical Management Agency New Zealand","other":false},{"id":"12","label":"Primary Health Organisations","other":false},{"id":"14","label":"Te Aka Whai Ora - Maori Health Authority","other":false},{"id":"15","label":"Whaikaha - Ministry of Disabled People","other":false},{"id":"13","label":"Any health agency which has a contract with or is funded by an agency specified in Schedule 2 to provide health or disability services","other":false},{"id":"16","label":"I'm not sure","other":false}],"questionKey":""},"154":{"type":"da","label":"Integration for development date","description":"","validation":{"rq":false},"choices":[],"questionKey":""},"220":{"type":"pg","label":"How will you use the information provided in the above functionality? Please state the use case for each of the business function you requested.","description":"Your Privacy Impact Assessment must justify the use of each function selected above.","validation":{"rq":true},"choices":[],"questionKey":""},"7":{"type":"pg","label":"Purpose of organisation","description":"E.g. products or services it provides, when established etc. This is used to confirm entitlement to access under Health Information Privacy Code 2020 Schedule 2. ","validation":{"rq":true},"choices":[],"questionKey":""},"247":{"type":"tl","label":"Product or application name","description":"","validation":{"rq":true},"jiraField":"customfield_10075","questionKey":""},"319":{"type":"te","label":"Email address","description":"","validation":{"rq":true},"questionKey":""},"168":{"type":"rt","label":"Organisation legal name","description":"","validation":{"rq":true},"jiraField":"customfield_10073","questionKey":""},"254":{"type":"cs","label":"Are you developing this product or application together with a health provider?","description":"","validation":{"rq":false},"choices":[{"id":"1","label":"Yes","other":false},{"id":"2","label":"No","other":false}],"questionKey":""},"323":{"type":"cm","label":"","description":"","validation":{"rq":false},"choices":[{"id":"1","label":"Check to view our Privacy Statement","other":false}],"questionKey":""},"305":{"type":"ts","label":"Full name of person responsible for your organisation's information security.","description":"","validation":{"rq":true},"jiraField":"customfield_10089","questionKey":""},"172":{"type":"ts","label":"New Zealand Business Number (NZBN)","description":"","validation":{"rq":false},"choices":[],"questionKey":""},"157":{"type":"da","label":"Full end-to-end testing date","description":"","validation":{"rq":false},"choices":[],"questionKey":""},"312":{"type":"cd","label":"Role","description":"","validation":{"rq":true},"choices":[{"id":"7","label":"Architect","other":false},{"id":"1","label":"Developer","other":false},{"id":"2","label":"Business Owner ","other":false},{"id":"3","label":"Business Manager","other":false},{"id":"4","label":"Administrator","other":false},{"id":"5","label":"Project Manager","other":false},{"id":"6","label":"Security Officer","other":false},{"id":"0","label":"Other...","other":true}],"questionKey":""}}},"uuid":"022dc5e8-5b86-4c6c-8603-20d2261bdfef"},"proforma":{"formExists":true,"formValid":true,"formTemplateData":{"id":30,"updated":"2024-02-08T23:39:41.916162Z","publish":{"jira":{"submitOnCreate":true,"validateOnCreate":true},"portal":{"portalRequestTypeIds":[67],"submitOnCreate":true,"validateOnCreate":true}},"design":{"settings":{"templateId":30,"name":"Request to onboard to an API or digital service","submit":{"lock":false,"pdf":true},"language":"en-GB","templateFormUuid":"022dc5e8-5b86-4c6c-8603-20d2261bdfef"},"layout":[{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"info"},"content":[{"type":"paragraph","content":[{"type":"text","text":"Complete this form to help the approval process to integrate with an API or digital service for our external test and integration environment. The questions should be answered by an integrator or software vendor that can give details around the intended integration. "}]},{"type":"paragraph","content":[{"type":"text","text":"Before filling in this form, make sure you have information about:"}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"your organisation so we can use to verify you, "}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"your application or the service you would like to integrate with"}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"how you want to use the information "}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"your anticipated go-live date."}]}]}]},{"type":"paragraph","content":[{"type":"text","text":"The approval process to get compliance credentials can take up to 5 business days. This may take longer if we need more information specific to your application. "}]}]},{"type":"panel","attrs":{"panelType":"note"},"content":[{"type":"paragraph","content":[{"type":"text","text":"Your privacy is important to us. The information you provide will be kept confidential. Once you have submitted the request form to us, you can view it in the portal but you cannot edit the original form."}]},{"type":"paragraph","content":[{"type":"text","text":"Our full privacy statement can be viewed at the end of this form."}]}]},{"type":"heading","attrs":{"level":2},"content":[{"type":"text","text":"Your details "}]},{"type":"paragraph","content":[{"type":"text","text":"Tell us who to contact during the process of gaining accreditation for your application."}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":31},"localId":"69bde932-ed7d-413d-a41a-f208a5071070"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":144},"localId":"649c1074-6bbe-4dc3-8013-00e34853d44a"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":159},"localId":"c9beddd5-4323-4bd8-a73b-c931c33d4860"}},{"type":"rule"},{"type":"heading","attrs":{"level":2},"content":[{"type":"text","text":"Your organisation details "}]},{"type":"paragraph","content":[{"type":"text","text":"Provide details of the organisation requesting access to the API, application or digital service. "}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":168},"localId":"d2287510-0d24-4643-bf46-a28f0dc198a4"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":169},"localId":"a339ec99-e48f-4df5-8bbe-45d39f5efe52"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":170},"localId":"3c65628b-ecb4-40ed-8b18-afba01dfb65a"}},{"type":"layoutSection","content":[{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":172},"localId":"c73dc3a4-6e22-4faf-bf2f-e4b73d69b1b9"}}]},{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"paragraph","content":[]},{"type":"paragraph","content":[{"type":"text","text":"Find your NZBN on the NZBN website","marks":[{"type":"link","attrs":{"href":"https://www.nzbn.govt.nz/mynzbn/search/"}},{"type":"subsup","attrs":{"type":"sup"}}]}]}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":4},"localId":"cf88bd27-6fd6-46ac-b019-b508ccd4faed"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":7},"localId":"85e37093-b616-4c16-8d82-7271f0fde9a0"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":102},"localId":"2acdb1d0-ed4a-4dbd-ae7a-d5c119cf3c55"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":71},"localId":"3636c64f-f956-4a75-b8c8-9bacd21e3a93"}}]},{"version":1,"type":"doc","content":[{"type":"rule"},{"type":"heading","attrs":{"level":2},"content":[{"type":"text","text":"About your software product or application"}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":247},"localId":"ce44cc08-1e38-4538-855c-a349b8592180"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":248},"localId":"e64630ab-e306-4310-885f-235da589ef8d"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":250},"localId":"64c4c2c9-d214-469a-9d7c-486261873c11"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":" When a digital service supplier organisation requests access to one of our services via a proxy, the integrating applications will still need to be issued their own credential. The proxy will need to pass through the client credentials when calling the external service."}]},{"type":"paragraph","content":[{"type":"text","text":"The proxy may maintain the application’s credentials on behalf of the application, as long as each application is issued its own credentials, and the client secrets are subject to appropriate security controls."}]}]},{"type":"heading","attrs":{"level":2},"content":[{"type":"text","text":"Rationale"}]},{"type":"table","attrs":{"isNumberColumnEnabled":false,"layout":"default","localId":"0943c658-efa8-4255-811a-a6fbcfa7c93b"},"content":[{"type":"tableRow","content":[{"type":"tableHeader","attrs":{"colwidth":[152]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Category","marks":[{"type":"strong"}]}]}]},{"type":"tableHeader","attrs":{"colwidth":[608]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Description","marks":[{"type":"strong"}]}]}]}]},{"type":"tableRow","content":[{"type":"tableCell","attrs":{"colwidth":[152]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Regulation"}]}]},{"type":"tableCell","attrs":{"colwidth":[608]},"content":[{"type":"paragraph","content":[{"type":"text","text":"The Health Information Privacy Code (HIPC) stipulates which health organisations may assign NHI numbers. In order to comply with HIPC we need to know the identity of the calling organisation before agreeing to share NHI information."}]}]}]},{"type":"tableRow","content":[{"type":"tableCell","attrs":{"colwidth":[152]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Data Quality"}]}]},{"type":"tableCell","attrs":{"colwidth":[608]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Te Whatu Ora has a need to be able to review a client application's use of our services in order to assess the quality of the user experience, mainly to ensure that the user experience supports our data quality needs."}]}]}]},{"type":"tableRow","content":[{"type":"tableCell","attrs":{"colwidth":[152]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Authorisation"}]}]},{"type":"tableCell","attrs":{"colwidth":[608]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Coarse grained authorization in FHIR services is implemented in SMART scopes which are assigned to client identities. We need to be able to allocate these scopes at an application level rather than delegating that responsibility to a third-party proxy."}]}]}]},{"type":"tableRow","content":[{"type":"tableCell","attrs":{"colwidth":[152]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Auditability"}]}]},{"type":"tableCell","attrs":{"colwidth":[608]},"content":[{"type":"paragraph","content":[{"type":"text","text":"We need to be able to audit the activity the users of an individual application in meet our legislative requirements under the Privacy Act and the Official Information Act."}]}]}]},{"type":"tableRow","content":[{"type":"tableCell","attrs":{"colwidth":[152]},"content":[{"type":"paragraph","content":[{"type":"text","text":"Observability"}]}]},{"type":"tableCell","attrs":{"colwidth":[608]},"content":[{"type":"paragraph","content":[{"type":"text","text":"We need to be able to monitor individual applications API usage in order to be able to troubleshoot effectively and to identify unusual patterns."}]}]}]}]}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":252},"localId":"afd184c5-a450-4ea5-a9ba-31e14a19928a"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":253},"localId":"e5fa8d7a-0109-44a7-8d10-7b1bc146fed8"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":254},"localId":"8fbd5cb4-34ae-4cef-976f-2d7758b25dba"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":256},"localId":"3da592b2-7dee-4a8e-85bc-c870de35c9ce"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":257},"localId":"09baa150-5ddf-4052-af69-0d9d6204c7dd"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":258},"localId":"f3510b1f-ebaf-45de-b946-ca710eab7f7a"}}]},{"version":1,"type":"doc","content":[{"type":"rule"},{"type":"heading","attrs":{"level":2},"content":[{"type":"text","text":"APIs and digital services"}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":8},"localId":"2df22ab6-be72-4789-a76e-22af592d5e53"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"info"},"content":[{"type":"paragraph","content":[{"type":"text","text":"Please note, Health Identity policy requires that the identity of the end user of the API is securely established. This means that the API must be able to authenticate the organisation / application making the API call and that every differing organisation / branch will require their own Production credentials to access the data through these APIs."}]}]},{"type":"paragraph","content":[]}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"note"},"content":[{"type":"paragraph","content":[{"type":"text","text":"By using Te Whatu Ora APIs you are accessing personally identifiable information from the NHI which is not directly from the individual concerned. You need to consider your obligations under Health Information Privacy Code 2020, principle 2. Te Whatu Ora may request to see your privacy impact assessment prior to access to production."}]}]},{"type":"rule"}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":236},"localId":"7a5b4af3-61d6-4614-8ea6-13aef0a8d810"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":108},"localId":"0c820258-f0dc-4229-89df-1961a9c429f3"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":237},"localId":"a28a85fe-82f8-41ef-a42c-bfcebce3a70f"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":148},"localId":"ae8747b4-81e1-49f7-afad-28b5724bf8c4"}},{"type":"paragraph","content":[{"type":"text","text":"OpenID Connect (OIDC) Redirect URL","marks":[{"type":"strong"}]}]},{"type":"paragraph","content":[{"type":"text","text":"Provide the redirect URLs for your non-production environments."}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":327},"localId":"d22c5b39-37ad-42c7-b415-cc05661594b0"}},{"type":"paragraph","content":[{"type":"text","text":"Post logout redirect URLs","marks":[{"type":"strong"}]}]},{"type":"paragraph","content":[{"type":"text","text":"Provide the post logout redirect URLs for your non-production environments."}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":328},"localId":"19ad937b-6a49-4aac-9ea8-5e7368866433"}},{"type":"rule"}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":326},"localId":"cb848d1d-be2c-4e99-b2d1-7401a39ed510"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"info"},"content":[{"type":"heading","attrs":{"level":5},"content":[{"type":"text","text":"More information on organisaiton and facility business functions can be found "},{"type":"text","text":"here","marks":[{"type":"link","attrs":{"href":"https://hpi-ig.hip-uat.digital.health.nz/Onboarding.html#business-functions"}},{"type":"underline"}]},{"type":"text","text":"."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":223},"localId":"58986442-a920-4bc3-bb4b-6a5e94a6cf5c"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"info"},"content":[{"type":"heading","attrs":{"level":5},"content":[{"type":"text","text":"More information on practitioner business functions can be found "},{"type":"text","text":"here","marks":[{"type":"link","attrs":{"href":"https://hpi-ig.hip-uat.digital.health.nz/Onboarding.html#business-functions"}},{"type":"underline"}]},{"type":"text","text":"."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":225},"localId":"42ce67ee-d905-4fd6-b97d-eaf040a8d875"}},{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"Access to any of the above Practitioner business functions in Production may require business teams to have completed a Privacy Impact Assessment which has been assessed and approved by the Te Whatu Ora privacy team. Business Owners should progress this in parallel with any application development. Production access to contact details will not be granted unless this step has been completed."}]}]}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"info"},"content":[{"type":"heading","attrs":{"level":5},"content":[{"type":"text","text":"More information on PractitionerRole business functions can be found "},{"type":"text","text":"here","marks":[{"type":"link","attrs":{"href":"https://hpi-ig.hip-uat.digital.health.nz/Onboarding.html#business-functions"}},{"type":"underline"}]},{"type":"text","text":"."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":227},"localId":"b4d6c557-8feb-4c7f-b65c-0fb5f5a95fce"}},{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"Access to any of the above PractitionerRole business functions in Production may require business teams to have completed a Privacy Impact Assessment which has been assessed and approved by the Te Whatu Ora privacy team. Business Owners should progress this in parallel with any application development. Production access to contact details will not be granted unless this step has been completed."}]}]},{"type":"panel","attrs":{"panelType":"info"},"content":[{"type":"paragraph","content":[{"type":"text","text":"Currently there is no data in Production for this business function."}]}]},{"type":"paragraph","content":[]}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":220},"localId":"ea130e11-807e-4b0e-9424-70d68e0fffa0"}},{"type":"rule"}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"info"},"content":[{"type":"heading","attrs":{"level":5},"content":[{"type":"text","text":"More information on patient functions can be found "},{"type":"text","text":"here","marks":[{"type":"link","attrs":{"href":"https://nhi-ig.hip-uat.digital.health.nz/Onboarding.html#business-functions"}},{"type":"underline"}]},{"type":"text","text":"."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":234},"localId":"c69a3283-9f6d-4a56-a50b-b4cf61f01847"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"Access to a ‘Get Patient - Enrolled GP’ and ‘Get Patient - Contact details' in Production will only be granted to Te Whatu Ora business teams that have completed a Privacy Impact Assessment which has been assessed and approved by the Te Whatu Ora privacy team. Business Owners should progress this in parallel with any application development. Production access to contact details will not be granted unless this step has been completed."}]}]},{"type":"paragraph","content":[]}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"‘Maintain Patient’ and ‘Create Patient’ are provided on a limited basis. For those without access, this may be achieved by phoning the Te Whatu Ora contact centre (0800 855 066)."}]}]},{"type":"paragraph","content":[]}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":184},"localId":"c8bc2c31-c4f9-42f5-a953-9a2c44585b49"}},{"type":"rule"}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"error"},"content":[{"type":"paragraph","content":[{"type":"text","text":"The National Enrolment Service is used to update the practice/organisation a patient is enrolled with. For this reason, permission to onboard to this API is limited to organisations that are involved in the enrolment of patients to practices/organisations."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":292},"localId":"9bf9b144-65fa-4862-b734-aea933f6faa6"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"For Enrolment Nomination - Access will only be given to the Te Whatu Ora Whaihua platform users, the Te Whatu Ora Enrolment nomination subscriber and HealthLink in the initial implementation. If you are interested in this business function, please contact "},{"type":"text","text":"integration@health.govt.nz","marks":[{"type":"link","attrs":{"href":"mailto:integration@health.govt.nz"}}]},{"type":"text","text":"."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":293},"localId":"66de4458-d967-43f7-8b14-02a04ed534a4"}}]},{"version":1,"type":"doc","content":[{"type":"rule"}]},{"version":1,"type":"doc","content":[{"type":"heading","attrs":{"level":2},"content":[{"type":"text","text":"Delivery Details"}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":262},"localId":"32afa680-4b88-41a3-b5d7-7354056b51eb"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":264},"localId":"9a528ca2-09e2-40a3-a380-bd7a6cdd8151"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":49},"localId":"25d4be8b-2d3e-4a19-b423-7da775d82033"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":152},"localId":"e0b91f31-f749-4ed5-9c46-5c6a01cb2ebd"}}]},{"version":1,"type":"doc","content":[{"type":"layoutSection","content":[{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":154},"localId":"dccec400-9564-4416-b12b-71a87345d0f6"}}]},{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"paragraph","content":[]}]}]}]},{"version":1,"type":"doc","content":[{"type":"layoutSection","content":[{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":157},"localId":"86733ecb-e6cb-4813-95db-28480a9585ad"}}]},{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"paragraph","content":[]}]}]}]},{"version":1,"type":"doc","content":[{"type":"layoutSection","content":[{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":158},"localId":"83ceca63-f89b-4da3-8b4a-a8a6dc700ec7"}}]},{"type":"layoutColumn","attrs":{"width":50},"content":[{"type":"paragraph","content":[]}]}]},{"type":"paragraph","content":[]},{"type":"rule"}]},{"version":1,"type":"doc","content":[{"type":"paragraph","content":[]}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":303},"localId":"3b13126c-a4e0-4d0b-b5ae-01aa7f344ec8"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"By providing these contact details you confirm that the individual has authorised you to share their details for the purpose of communications regarding your information security."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":305},"localId":"91c4daf9-6fe7-42ed-b627-db71c754908f"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":306},"localId":"5e278546-181c-4a80-8bdf-6323cb0b457f"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":307},"localId":"0e5de8e4-9dc6-4b51-8258-a173701e4bb6"}}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":308},"localId":"fb4fdcef-a704-4c30-915b-ad95bba26c09"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"By providing your contact details you agree that you are authorised to receive the API credentials for the external test and integration environment on behalf of your organisation."}]}]},{"type":"paragraph","content":[]}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"By providing the contact details you confirm that:"}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"the individual has authorised you to share their details for the purpose of receiving the API credentials "}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"the individual is authorised to receive the credentials for the external test and integration environment on behalf of your organisation "}]}]}]}]},{"type":"paragraph","content":[{"type":"text","text":"Who do we send the compliance environment credentials to?"}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":311},"localId":"92f73759-2f6d-4d72-b006-103d980fe7b5"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":312},"localId":"3ff664c8-268f-4dbc-8794-2de5ea96c028"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":313},"localId":"64ee8250-a4ed-4170-be53-0ef504b0fcc0"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":314},"localId":"621d8fab-e619-4f60-95d8-85c81d4a2f83"}},{"type":"panel","attrs":{"panelType":"note"},"content":[{"type":"paragraph","content":[{"type":"text","text":"You must provide an email address for us to send your client ID to. You must provide a mobile number for us to send client secret to."}]}]},{"type":"paragraph","content":[]}]},{"version":1,"type":"doc","content":[{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":315},"localId":"a5827e7c-739b-447f-aef1-2513f518fa2d"}}]},{"version":1,"type":"doc","content":[{"type":"panel","attrs":{"panelType":"warning"},"content":[{"type":"paragraph","content":[{"type":"text","text":"By providing the contact details you confirm the individual has authorised you to share their details for the purpose of ongoing communications with us about support."}]}]},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":317},"localId":"f3ec0196-5b4d-4502-a749-b10de4ff65fe"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":318},"localId":"0eba8e28-705b-4712-b325-a19ef0d292f5"}},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":319},"localId":"b65f584d-c6d8-4e0d-b094-8c7015747f8e"}}]},{"version":1,"type":"doc","content":[{"type":"rule"},{"type":"extension","attrs":{"extensionKey":"question","extensionType":"com.thinktilt.proforma","layout":"default","parameters":{"id":323},"localId":"aad567ba-495b-4a54-a68e-e99945eec63d"}},{"type":"rule"}]},{"version":1,"type":"doc","content":[{"type":"heading","attrs":{"level":2},"content":[{"type":"text","text":"Onboarding & Certification Process Privacy Statement "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Introduction "}]},{"type":"paragraph","content":[{"type":"text","text":"Te Whatu Ora – Health New Zealand manages the process of onboarding developers and users of systems that integrate with digital health information services. "}]},{"type":"paragraph","content":[{"type":"text","text":" This process involves the collection and use of personal information about you and others from your organisation who are involved in applying for, accessing, and maintaining use of these services. "}]},{"type":"paragraph","content":[{"type":"text","text":" This privacy statement explains how we ensure the privacy of this information is protected in accordance with the Privacy Act 2020. "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Last updated "}]},{"type":"paragraph","content":[{"type":"text","text":"We may update this privacy statement from time to time. Please check this privacy statement regularly for modifications and updates. This privacy statement was last updated on "},{"type":"text","text":"27 February 2023. ","marks":[{"type":"strong"}]},{"type":"text","text":" "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Collection of personal information"}]},{"type":"paragraph","content":[{"type":"text","text":"When an API/ Service Onboarding Request is submitted we may:"}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Collect personal information from you directly "}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Collect personal information from a third party."}]}]}]},{"type":"heading","attrs":{"level":4},"content":[{"type":"text","text":"Information we collect directly from you ","marks":[{"type":"em"}]}]},{"type":"paragraph","content":[{"type":"text","text":"When you complete the API/Service Onboarding Request we collect the following personal information about you: "}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Full name "}]}]},{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Email address "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Mobile phone number "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Your role"}]}]}]},{"type":"heading","attrs":{"level":4},"content":[{"type":"text","text":"Information we collect directly from third party","marks":[{"type":"em"}]}]},{"type":"paragraph","content":[{"type":"text","text":"The person completing the API/Service Onboarding Request may nominate another individual from their organisation to be a point of contact for:"}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Sending onboarding credential information to; and/or"}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"ongoing service support."}]}]}]},{"type":"paragraph","content":[{"type":"text","text":" If you have been nominated as the point of contact, we may collect your name, email address and mobile phone number. The person completing the Request form confirms to Te Whatu Ora (at the time they submit the form) that they have your authorisation to share your details with us. "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Choice"}]},{"type":"paragraph","content":[{"type":"text","text":"If you do not provide us with the personal information outlined above, you may not be able to submit an API/Service Onboarding Request, be onboarded to our services and/or receive ongoing service support."}]},{"type":"paragraph","content":[{"type":"text","text":" The information is held by Te Whatu Ora – Health New Zealand. "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"How we use your personal information "}]},{"type":"paragraph","content":[{"type":"text","text":"We may use your personal information for the following: "}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"To identify you in connection with your application, your organisation and our communications with you "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"To correspond with you regarding your onboarding request "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"To provide access credentials to you "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"To correspond with you for the purposes of technical support "}]}]}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Sharing the information "}]},{"type":"paragraph","content":[{"type":"text","text":"We may share your personal information internally with those directly involved with the process of onboarding your organisation as an integration developer or integrated product user. "}]},{"type":"paragraph","content":[{"type":"text","text":"We may share your information with organisations contracted by Te Whatu Ora to provide supporting services for application requests, compliance assessment or technical support. Attributes will only be shared with others as necessary for that service. If the details are not necessary for a service, they will not be supplied. "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"How long we hold information "}]},{"type":"paragraph","content":[{"type":"text","text":"We only keep your personal information for as long as required for the purposes outlined in this privacy statement and in accordance with the law. "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Storing information securely "}]},{"type":"paragraph","content":[{"type":"text","text":"We take reasonable steps to ensure your personal information is protected against loss, unauthorised access, use, modification, disclosure, or other misuse. "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Access to and requests to correct the information "}]},{"type":"paragraph","content":[{"type":"text","text":"You have the right to access any information we hold about you and ask us to correct it if you think it is wrong. "}]},{"type":"paragraph","content":[{"type":"text","text":" To access any personal information held by us, or if you wish to correct your information, please email "},{"type":"text","text":"integration@health.govt.nz","marks":[{"type":"link","attrs":{"href":"mailto:integration@health.govt.nz"}},{"type":"underline"}]},{"type":"text","text":". "}]},{"type":"paragraph","content":[{"type":"text","text":" When making a request to access or change your information, please include: "}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"your name "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"contact address (email or postal) "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"contact phone number "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"details of the information you want or want to correct - this needs to be as clear and specific as you can make it. "}]}]}]},{"type":"paragraph","content":[{"type":"text","text":" Please note that before we can provide you with your information or make any changes we need to be satisfied about your identity. To do so, we may need to ask you further questions or to view identification which establishes your identity. "}]},{"type":"heading","attrs":{"level":3},"content":[{"type":"text","text":"Queries and concerns "}]},{"type":"paragraph","content":[{"type":"text","text":"If you have any queries or concerns about how your personal information has been managed, please contact us to see if we can resolve the problem. You can:"}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Email us at "},{"type":"text","text":"hnzprivacy@health.govt.nz","marks":[{"type":"link","attrs":{"href":"mailto:hnzprivacy@health.govt.nz"}},{"type":"underline"}]},{"type":"text","text":" "}]}]}]},{"type":"bulletList","content":[{"type":"listItem","content":[{"type":"paragraph","content":[{"type":"text","text":"Write to us at Privacy Officer - Te Whatu Ora, PO Box 793, Wellington 6140, New Zealand "}]}]}]},{"type":"paragraph","content":[{"type":"text","text":" If you’re not satisfied with our response to your concerns, you can contact the Office of the Privacy Commissioner. For more information see the "},{"type":"text","text":"Office of the Privacy Commissioner website","marks":[{"type":"link","attrs":{"href":"https://www.privacy.org.nz/your-rights/making-a-complaint/"}}]},{"type":"text","text":". "}]},{"type":"paragraph","content":[{"type":"text","text":" "}]}]}],"conditions":{"263":{"t":"sh","i":{"co":{"cIds":{"262":["1"]}}},"o":{"sIds":["28"]}},"185":{"t":"sh","i":{"co":{"cIds":{"8":["10061"]}}},"o":{"sIds":["20"]}},"297":{"t":"sh","i":{"co":{"cIds":{"234":["10119","10120"]}}},"o":{"sIds":["21"]}},"156":{"t":"sh","i":{"co":{"cIds":{"152":["0"]}}},"o":{"sIds":["33"]}},"235":{"t":"sh","i":{"co":{"cIds":{"8":["10036"]}}},"o":{"sIds":["14"]}},"251":{"t":"sh","i":{"co":{"cIds":{"250":["1"]}}},"o":{"sIds":["4"]}},"232":{"t":"sh","i":{"co":{"cIds":{"326":["6"]}}},"o":{"sIds":["16"]}},"316":{"t":"sh","i":{"co":{"cIds":{"315":["2"]}}},"o":{"sIds":["41"]}},"229":{"t":"sh","i":{"co":{"cIds":{"8":["10060"]}}},"o":{"sIds":["19"]}},"310":{"t":"sh","i":{"co":{"cIds":{"308":["10112"]}}},"o":{"sIds":["39"]}},"302":{"t":"sh","i":{"co":{"cIds":{"159":["7","2","1","3","4","5","0"]}}},"o":{"sIds":["35"]}},"153":{"t":"sh","i":{"co":{"cIds":{"152":["2"]}}},"o":{"sIds":["31"]}},"291":{"t":"sh","i":{"co":{"cIds":{"8":["10065"]}}},"o":{"sIds":["24"]}},"298":{"t":"sh","i":{"co":{"cIds":{"234":["10122","10123"]}}},"o":{"sIds":["22"]}},"217":{"t":"sh","i":{"co":{"cIds":{"8":["10036"]}}},"o":{"sIds":["11"]}},"255":{"t":"sh","i":{"co":{"cIds":{"254":["1"]}}},"o":{"sIds":["6"]}},"325":{"t":"sh","i":{"co":{"cIds":{"8":["10061"]}}},"o":{"sIds":["10"]}},"155":{"t":"sh","i":{"co":{"cIds":{"152":["1"]}}},"o":{"sIds":["32"]}},"233":{"t":"sh","i":{"co":{"cIds":{"8":["10060"]}}},"o":{"sIds":["15"]}},"231":{"t":"sh","i":{"co":{"cIds":{"326":["2"]}}},"o":{"sIds":["17"]}},"72":{"t":"sh","i":{"co":{"cIds":{"102":["1"]}}},"o":{"sIds":["1"]}},"230":{"t":"sh","i":{"co":{"cIds":{"326":["5"]}}},"o":{"sIds":["18"]}},"309":{"t":"sh","i":{"co":{"cIds":{"308":["10111"]}}},"o":{"sIds":["38"]}},"322":{"t":"sh","i":{"co":{"cIds":{"8":["10061","10060"]}}},"o":{"sIds":["9"]}},"214":{"t":"sh","i":{"co":{"cIds":{"323":["1"]}}},"o":{"sIds":["43"]}},"238":{"t":"sh","i":{"co":{"cIds":{"236":["10165"]}}},"o":{"sIds":["12"]}},"304":{"t":"sh","i":{"co":{"cIds":{"303":["1"]}}},"o":{"sIds":["36"]}},"301":{"t":"sh","i":{"co":{"cIds":{"292":["10248"]}}},"o":{"sIds":["25"]}},"239":{"t":"sh","i":{"co":{"cIds":{"236":["10164"]}}},"o":{"sIds":["13"]}}},"sections":{"34":{"conditions":[]},"12":{"name":"If My Health Account is selected","conditions":["238","217"]},"8":{"conditions":[]},"33":{"name":"Other date selected","conditions":["156"]},"22":{"name":"Call Centre contact for access","conditions":["298","185"]},"13":{"name":"If My Health Account Workforce is selected","conditions":["239","217"]},"5":{"conditions":[]},"10":{"name":"If NHI selected","conditions":["325"]},"21":{"name":"PIA warning","conditions":["297","185"]},"43":{"name":"Privacy Statement","conditions":["214"]},"32":{"name":"Full end-to-end date selected","conditions":["155"]},"31":{"name":"Integration for development date selected","conditions":["153"]},"42":{"conditions":[]},"18":{"name":"If Practitioner role selected","conditions":["230","233"]},"3":{"name":"If HPI or NHI","conditions":[]},"28":{"name":"Display if there is a Project as part of this work","conditions":["263"]},"19":{"name":"HPI selected","conditions":["229"]},"23":{"conditions":[]},"4":{"name":"Brokering or proxy API","conditions":["251"]},"40":{"conditions":[]},"15":{"name":"Display if HPI selected","conditions":["233"]},"11":{"name":"Display if MHA selected","conditions":["217"]},"9":{"name":"HPI or NHI","conditions":["322"]},"26":{"conditions":[]},"37":{"conditions":[]},"24":{"name":"Enrolment Nomination","conditions":["291"]},"35":{"name":"If NOT a security person","conditions":["302"]},"16":{"name":"Organisation / Facility selected","conditions":["232","233"]},"6":{"name":"If yes","conditions":["255"]},"36":{"name":"If someone else","conditions":["304","302"]},"1":{"name":"* Existing Access","conditions":["72"]},"39":{"name":"* Send Credentials to someone else","conditions":["310"]},"17":{"name":"If Practitioner selected","conditions":["231","233"]},"25":{"name":"Enrolment Warning ","conditions":["301","291"]},"14":{"name":"Display if MHA selected","conditions":["235"]},"20":{"name":"Display if NHI selected","conditions":["185"]},"27":{"conditions":[]},"2":{"conditions":[]},"38":{"name":"* Send credentials to me","conditions":["309"]},"30":{"conditions":[]},"7":{"conditions":[]},"29":{"conditions":[]},"41":{"conditions":["316"]}},"questions":{"223":{"type":"cm","label":"What organisation / facility function do you require access to?","description":"","validation":{"rq":true},"jiraField":"customfield_10092","defaultAnswer":{"choices":["1"]},"questionKey":""},"313":{"type":"te","label":"Email address","description":"","validation":{"rq":true},"questionKey":""},"236":{"type":"cs","label":"What instance of My Health Account are you interested in?","description":"","validation":{"rq":true},"jiraField":"customfield_10121","questionKey":""},"303":{"type":"cs","label":"Who is the person within your organisation responsible for your information security?","description":"","validation":{"rq":true},"choices":[{"id":"2","label":"Me","other":false},{"id":"1","label":"Someone else","other":false}],"questionKey":""},"328":{"type":"rt","label":"Post logout redirect URLs","description":"","validation":{"rq":false},"jiraField":"customfield_10156","questionKey":""},"152":{"type":"cm","label":"Are there any other important dates we should know about?","description":"For example, dates you need us to work towards before you go-live","validation":{"rq":false},"choices":[{"id":"2","label":"Integration for development date","other":false},{"id":"1","label":"Full end-to-end testing date","other":false},{"id":"0","label":"Other...","other":true}],"questionKey":""},"148":{"type":"pg","label":"How will you use these attributes?'","description":"Your Privacy Impact Assessment must justify the use of each attribute selected above.","validation":{"rq":true},"choices":[],"questionKey":""},"49":{"type":"da","label":"When is the planned go-live date of your product or application?","description":"This is the date your users will be able to access the information surfaced by this API or digital service.","validation":{"rq":true},"jiraField":"customfield_10135","questionKey":""},"308":{"type":"cs","label":"Who will be the person responsible for receiving the compliance environment API credentials? ","description":"If your application is approved, this will be the person we send client ID and client secret to.","validation":{"rq":true},"jiraField":"customfield_10079","questionKey":""},"327":{"type":"rt","label":"OpenID Connect (OIDC) Redirect URLs","description":"","validation":{"rq":false},"jiraField":"customfield_10155","questionKey":""},"169":{"type":"tl","label":"Organisation trading name","description":"","validation":{"rq":false},"choices":[],"questionKey":""},"158":{"type":"da","label":"Another important date","description":"","validation":{"rq":false},"choices":[],"questionKey":""},"8":{"type":"cm","label":"Which APIs and digital services do you want access to?","description":"","validation":{"rq":true},"jiraField":"components","questionKey":""},"307":{"type":"ts","label":"Mobile number","description":"","validation":{"rq":true},"choices":[],"questionKey":""},"170":{"type":"tl","label":"Health Provider Index (HPI) Organisation ID or Vendor ID","description":"Health Provider Index format is GXXnnnn-C where \"X\" is alphanumeric, \"n\" is numberic and \"C\" is a check character. Vendor ID (If it has been issued by Te Whatu Ora) is HSVNnnnn where \"n\" represents a number)","validation":{"rq":false},"jiraField":"customfield_10066","defaultAnswer":{"text":"G0"},"questionKey":""},"4":{"type":"pg","label":"Organisation registered address","description":"Where is your organisation located? ","validation":{"rq":true},"choices":[],"questionKey":""},"318":{"type":"cd","label":"Role","description":"","validation":{"rq":true},"choices":[{"id":"7","label":"Architect","other":false},{"id":"1","label":"Developer","other":false},{"id":"2","label":"Business Owner ","other":false},{"id":"3","label":"Business Manager","other":false},{"id":"4","label":"Administrator","other":false},{"id":"5","label":"Project Manager","other":false},{"id":"6","label":"Security Officer","other":false},{"id":"0","label":"Other...","other":true}],"questionKey":""},"262":{"type":"cs","label":"Is this integration activity part of a project? ","description":"","validation":{"rq":false},"choices":[{"id":"1","label":"Yes","other":false},{"id":"2","label":"No","other":false}],"questionKey":""},"227":{"type":"cm","label":"What practitioner role function do you require access to?","description":"","validation":{"rq":true},"jiraField":"customfield_10090","defaultAnswer":{"choices":["1"]},"questionKey":""},"250":{"type":"cs","label":"Does your application employ any kind of proxy API or brokering service?","description":"","validation":{"rq":false},"choices":[{"id":"1","label":"Yes","other":false},{"id":"2","label":"No","other":false}],"questionKey":""},"253":{"type":"pg","label":"What are the business processes performed within your product or application?","description":"Provide a high level flow of your business process and how you plan to use this digital service or API to help your business process.","validation":{"rq":true},"choices":[],"questionKey":""},"314":{"type":"ts","label":"Mobile number","description":"","validation":{"rq":true},"jiraField":"customfield_10085","questionKey":""},"306":{"type":"te","label":"Email address","description":"","validation":{"rq":true},"questionKey":""},"159":{"type":"cd","label":"Role","description":"","validation":{"rq":true},"choices":[{"id":"7","label":"Architect","other":false},{"id":"1","label":"Developer","other":false},{"id":"2","label":"Business Owner ","other":false},{"id":"3","label":"Business Manager","other":false},{"id":"4","label":"Administrator","other":false},{"id":"5","label":"Project Manager","other":false},{"id":"6","label":"Security Officer","other":false},{"id":"0","label":"Other...","other":true}],"questionKey":""},"144":{"type":"ts","label":"Mobile number","description":"","validation":{"rq":true},"jiraField":"customfield_10084","questionKey":""},"237":{"type":"cm","label":"Identity Attributes you are interested in","description":"","validation":{"rq":true},"jiraField":"customfield_10131","defaultAnswer":{"choices":["10173","10223"]},"questionKey":""},"256":{"type":"pg","label":"Can you provide us more information regarding who you are working with and how you fit into the solution.","description":"","validation":{"rq":true},"choices":[],"questionKey":""},"317":{"type":"tl","label":"Name","description":"","validation":{"rq":true},"jiraField":"customfield_10126","questionKey":""},"71":{"type":"cm","label":"Select the APIs your organisation has access to.","description":"","validation":{"rq":true},"choices":[{"id":"1","label":"My Health Account (MHA)","other":false},{"id":"2","label":"Health Provider Index API (HPI FHIR API)","other":false},{"id":"3","label":"National Health Index API (NHI FHIR API)","other":false}],"questionKey":""},"248":{"type":"cs","label":"What type of software product or application is the above?","description":"","validation":{"rq":false},"jiraField":"customfield_10129","questionKey":""},"292":{"type":"cm","label":"What Function to NES do you want access to?","description":"","validation":{"rq":false},"jiraField":"customfield_10145","questionKey":""},"108":{"type":"cm","label":"Identity Attributes you are interested in","description":"","validation":{"rq":true,"ch":"10213"},"jiraField":"customfield_10130","defaultAnswer":{"choices":["10213"]},"questionKey":""},"234":{"type":"cm","label":"What patient function do you require access to?","description":"","validation":{"rq":true},"jiraField":"customfield_10091","questionKey":""},"252":{"type":"pg","label":"Details of your product or application.","description":"Provide details of the service your product of application provides and how critical it is to your organisation.","validation":{"rq":true},"choices":[],"questionKey":""},"102":{"type":"cs","label":"Does your organisation currently have access to any our APIs?","description":"","validation":{"rq":true},"choices":[{"id":"1","label":"Yes","other":false},{"id":"2","label":"No","other":false},{"id":"3","label":"Not sure","other":false}],"questionKey":""},"31":{"type":"tl","label":"Name","description":"","validation":{"rq":true},"jiraField":"customfield_10076","questionKey":""},"315":{"type":"cs","label":"If your application is approved, who is the best person to contact for production operational support?","description":"We will notify this person of any API or digital service outages, releases and upcoming features.","validation":{"rq":true},"choices":[{"id":"1","label":"Me","other":false},{"id":"2","label":"Someone else","other":false}],"questionKey":""},"184":{"type":"pg","label":"How will you use the information provided in the above functionality?","description":"Your Privacy Impact Assessment must justify the use of each function selected above.","validation":{"rq":true},"choices":[],"questionKey":""},"264":{"type":"ts","label":"What is the name of the Project?","description":"","validation":{"rq":false},"choices":[],"questionKey":""},"257":{"type":"cm","label":"Who are the intended users of your product or application?","description":"Check all that apply.","validation":{"rq":true},"choices":[{"id":"7","label":"Patients: self service","other":false},{"id":"5","label":"Customer-facing staff","other":false},{"id":"1","label":"Health practitioners","other":false},{"id":"9","label":"Hospital administrators","other":false},{"id":"6","label":"IT administrators","other":false},{"id":"8","label":"Practice managers and administrators","other":false},{"id":"0","label":"Other...","other":true}],"questionKey":""},"225":{"type":"cm","label":"What practitioner function do you require access to?","description":"","validation":{"rq":true},"jiraField":"customfield_10093","defaultAnswer":{"choices":["1"]},"questionKey":""},"293":{"type":"rt","label":"Please state the use case for each business function requested?","description":"","validation":{"rq":false},"choices":[],"questionKey":""},"326":{"type":"cm","label":"HPI information you are interested in","description":"","validation":{"rq":true},"choices":[{"id":"6","label":"Organisation / Facility","other":false},{"id":"2","label":"Practitioner ","other":false},{"id":"5","label":"Practioner role (Pracrole)","other":false}],"defaultAnswer":{"choices":["1"]},"questionKey":""},"311":{"type":"tl","label":"Name","description":"","validation":{"rq":true},"jiraField":"customfield_10080","questionKey":""},"258":{"type":"cm","label":"Which category under Schedule 2 of the Health Information Privacy Code 2020 will your users belong to?","description":"This is to provide us further information regarding who is accessing our data or using our digital service.","validation":{"rq":true},"choices":[{"id":"1","label":"Accident Compensation Corporation","other":false},{"id":"2","label":"Department of Corrections Health Service","other":false},{"id":"3","label":"Te Whatu Ora - Health New Zealand","other":false},{"id":"4","label":"Health Practitioner","other":false},{"id":"5","label":"Hospital","other":false},{"id":"6","label":"Independent Practitioners Association of New Zealand","other":false},{"id":"7","label":"MedicAlert Foundation - New Zealand Incorporated","other":false},{"id":"8","label":"Manatu Hauora - Ministry of Health","other":false},{"id":"9","label":"New Zealand Blood and Organ Service","other":false},{"id":"10","label":"New Zealand Defence Force Health Service","other":false},{"id":"11","label":"Pharmaceutical Management Agency New Zealand","other":false},{"id":"12","label":"Primary Health Organisations","other":false},{"id":"14","label":"Te Aka Whai Ora - Maori Health Authority","other":false},{"id":"15","label":"Whaikaha - Ministry of Disabled People","other":false},{"id":"13","label":"Any health agency which has a contract with or is funded by an agency specified in Schedule 2 to provide health or disability services","other":false},{"id":"16","label":"I'm not sure","other":false}],"questionKey":""},"154":{"type":"da","label":"Integration for development date","description":"","validation":{"rq":false},"choices":[],"questionKey":""},"220":{"type":"pg","label":"How will you use the information provided in the above functionality? Please state the use case for each of the business function you requested.","description":"Your Privacy Impact Assessment must justify the use of each function selected above.","validation":{"rq":true},"choices":[],"questionKey":""},"7":{"type":"pg","label":"Purpose of organisation","description":"E.g. products or services it provides, when established etc. This is used to confirm entitlement to access under Health Information Privacy Code 2020 Schedule 2. ","validation":{"rq":true},"choices":[],"questionKey":""},"247":{"type":"tl","label":"Product or application name","description":"","validation":{"rq":true},"jiraField":"customfield_10075","questionKey":""},"319":{"type":"te","label":"Email address","description":"","validation":{"rq":true},"questionKey":""},"168":{"type":"rt","label":"Organisation legal name","description":"","validation":{"rq":true},"jiraField":"customfield_10073","questionKey":""},"254":{"type":"cs","label":"Are you developing this product or application together with a health provider?","description":"","validation":{"rq":false},"choices":[{"id":"1","label":"Yes","other":false},{"id":"2","label":"No","other":false}],"questionKey":""},"323":{"type":"cm","label":"","description":"","validation":{"rq":false},"choices":[{"id":"1","label":"Check to view our Privacy Statement","other":false}],"questionKey":""},"305":{"type":"ts","label":"Full name of person responsible for your organisation's information security.","description":"","validation":{"rq":true},"jiraField":"customfield_10089","questionKey":""},"172":{"type":"ts","label":"New Zealand Business Number (NZBN)","description":"","validation":{"rq":false},"choices":[],"questionKey":""},"157":{"type":"da","label":"Full end-to-end testing date","description":"","validation":{"rq":false},"choices":[],"questionKey":""},"312":{"type":"cd","label":"Role","description":"","validation":{"rq":true},"choices":[{"id":"7","label":"Architect","other":false},{"id":"1","label":"Developer","other":false},{"id":"2","label":"Business Owner ","other":false},{"id":"3","label":"Business Manager","other":false},{"id":"4","label":"Administrator","other":false},{"id":"5","label":"Project Manager","other":false},{"id":"6","label":"Security Officer","other":false},{"id":"0","label":"Other...","other":true}],"questionKey":""}}},"uuid":"022dc5e8-5b86-4c6c-8603-20d2261bdfef"},"linkedJiraFields":["customfield_10090","components","customfield_10091","customfield_10080","customfield_10092","customfield_10093","customfield_10073","customfield_10084","customfield_10085","customfield_10075","customfield_10130","customfield_10076","customfield_10131","customfield_10121","customfield_10066","customfield_10089","customfield_10155","customfield_10145","customfield_10156","customfield_10079","customfield_10135","customfield_10126","customfield_10129"]},"key":""},"portalWebFragments":{"headerPanels":[],"subheaderPanels":[],"footerPanels":[],"pagePanels":{"propertyPanels":[],"legacyPropertyPanels":[]}}}