-- in context of your Active Directory integration, is this sAMAccountName, or userPrincipalName?
As a follow-up, is there any form of presumption that a customer must have integrated the electronic health record with an instance of Active Directory to function? Is there a required cardinality between those systems (1:1), or should this function with multiple possible Active Directory domains? In the case of the latter, I presume userPrincipalName must be used?
"a claim for order/test result context" -- are you referring to an Encounter resource, here? Or, something else?