HL7 FHIR Audit + Provenance + Digital Signatures. AUDITEVENT LOGGING (FHIR-SEC-07 + FHIR-SEC-4.1) - FHIR AuditEvent Resource for structured audit logging + IETF RFC 3881 + IHE ATNA + DICOM Audit + comprehensive audit trail of: (a) authentication events; (b) authorization decisions; (c) resource access (read + create + update + delete + search); (d) export + transmit; (e) emergency access (Break the Glass); (f) failed access attempts; (g) administrative actions + configuration changes; (h) authentication failures + lockouts; (i) admin overrides + escalations; (j) consent changes. Each AuditEvent captures: type + subtype + action + recorded + outcome + outcomeDesc + agent (who) + source (where) + entity (what data) + entity.role + entity.lifecycle. AUDIT LOG INTEGRITY AND RETENTION (FHIR-SEC-08 + FHIR-SEC-4.3) - tamper-resistant logging + immutable (write-once or signed/hashed) + retention per HIPAA 6 years + state requirements (e.g. CA 10 years) + sectoral requirements + secure storage + access controls + integrity verification + log review + sectoral SOC + central log management + sectoral CISO + Compliance Officer review. AUDIT LOG REVIEW: regular + risk-based + AI-driven anomaly detection + UEBA + Insider Threat Detection + investigation procedures + escalation; sectoral best practices + HHS OCR Right of Access Initiative + breach response. PROVENANCE TRACKING (FHIR-SEC-11 + FHIR-SEC-4.2) - FHIR Provenance Resource for end-to-end data lineage + chain of custody + agent (who created + modified) + entity (input data + reference) + signature + reason + activity + recorded + occurred; mandatory for many regulated workflows (clinical trials + e-prescribing + claims + sectoral); supports trust verification + dispute resolution + AI training + research. DIGITAL SIGNATURES ON RESOURCES (FHIR-SEC-10) - FHIR Resource + Provenance Resource signature (X.509 + JWS + W3C XML Signature) + non-repudiation + tamper detection + clinical accountability + e-prescribing + Controlled Substances Act DEA EPCS requirements + sectoral signature requirements; cryptographic key management + HSM integration. KEY EVIDENCE: AuditEvent log + Provenance Resource + signature implementation + log retention + integrity verification + audit review procedures + SOC + Compliance reports.
This control maps to 31 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 31 it maps to, and the evidence behind each claim, over MCP and REST.