HL7 FHIR Security Framework
FHIR Security: Audit + Provenance + Digital Signatures + AuditEvent + Resource Integrity

HL7 FHIR Security Framework HL7-FHIR-Audit-Provenance-DigitalSignatures-Integrity: HL7 FHIR Audit + Provenance + Digital Signatures + AuditEvent Resource + Audit Log Integrity + Retention

HL7 FHIR Audit + Provenance + Digital Signatures. AUDITEVENT LOGGING (FHIR-SEC-07 + FHIR-SEC-4.1) - FHIR AuditEvent Resource for structured audit logging + IETF RFC 3881 + IHE ATNA + DICOM Audit + comprehensive audit trail of: (a) authentication events; (b) authorization decisions; (c) resource access (read + create + update + delete + search); (d) export + transmit; (e) emergency access (Break the Glass); (f) failed access attempts; (g) administrative actions + configuration changes; (h) authentication failures + lockouts; (i) admin overrides + escalations; (j) consent changes. Each AuditEvent captures: type + subtype + action + recorded + outcome + outcomeDesc + agent (who) + source (where) + entity (what data) + entity.role + entity.lifecycle. AUDIT LOG INTEGRITY AND RETENTION (FHIR-SEC-08 + FHIR-SEC-4.3) - tamper-resistant logging + immutable (write-once or signed/hashed) + retention per HIPAA 6 years + state requirements (e.g. CA 10 years) + sectoral requirements + secure storage + access controls + integrity verification + log review + sectoral SOC + central log management + sectoral CISO + Compliance Officer review. AUDIT LOG REVIEW: regular + risk-based + AI-driven anomaly detection + UEBA + Insider Threat Detection + investigation procedures + escalation; sectoral best practices + HHS OCR Right of Access Initiative + breach response. PROVENANCE TRACKING (FHIR-SEC-11 + FHIR-SEC-4.2) - FHIR Provenance Resource for end-to-end data lineage + chain of custody + agent (who created + modified) + entity (input data + reference) + signature + reason + activity + recorded + occurred; mandatory for many regulated workflows (clinical trials + e-prescribing + claims + sectoral); supports trust verification + dispute resolution + AI training + research. DIGITAL SIGNATURES ON RESOURCES (FHIR-SEC-10) - FHIR Resource + Provenance Resource signature (X.509 + JWS + W3C XML Signature) + non-repudiation + tamper detection + clinical accountability + e-prescribing + Controlled Substances Act DEA EPCS requirements + sectoral signature requirements; cryptographic key management + HSM integration. KEY EVIDENCE: AuditEvent log + Provenance Resource + signature implementation + log retention + integrity verification + audit review procedures + SOC + Compliance reports.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 31 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 3 controls

  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention
  • IACS-UR-E26-Detect-Logging-Monitoring-Audit-Alerting IACS UR E26 Detect Goal - Logging + Network Monitoring + Audit Trail + Alerting + SIEM
  • IACS-UR-E27-Logging-Forensics-EventCapture IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection
  • CAT-D3-2 Detective controls

FISMA · 1 control

  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

GHG Protocol · 1 control

  • GHG-Suite-Corporate-Principles GHG Protocol Suite, Corporate Standard and 5 Reporting Principles
  • GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics

HITECH Act · 1 control

  • HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC
  • 62351-14 Cyber security event logging

ISO/IEC 27011:2024 · 1 control

  • 27011-8.4 Logging and monitoring

MITRE D3FEND · 1 control

OWASP ASVS · 1 control

  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 31 it maps to, and the evidence behind each claim, over MCP and REST.