Frameworks / HL7 FHIR Security Framework / HL7-FHIR-Auth-SMART-OAuth-OIDC-Backend HL7 FHIR Security Framework
FHIR Security: Authentication + SMART App Launch + OpenID Connect + Backend Services + Token Lifetime
HL7 FHIR Security Framework HL7-FHIR-Auth-SMART-OAuth-OIDC-Backend: HL7 FHIR Authentication - SMART App Launch + OAuth 2.0 + OpenID Connect + Backend Services + Token Lifetime HL7 FHIR Authentication. SMART APP LAUNCH IMPLEMENTATION GUIDE v2.2.0 - foundational FHIR-based OAuth 2.0 / OAuth 2.1 + OpenID Connect framework + standardised app authorization. 3 LAUNCH MODES: (a) EHR-LAUNCH (SMART App in context of EHR with patient + user context); (b) STANDALONE-LAUNCH (SMART App initiated by user/patient); (c) BACKEND SERVICES LAUNCH (server-to-server + asymmetric key + system-level scopes). KEY OAUTH 2.0/2.1 + OPENID CONNECT FLOWS: (1) Authorization Code Grant + PKCE (Proof Key for Code Exchange) - required for public clients; (2) Backend Services - asymmetric key (JWT Bearer Token) for confidential clients + server-to-server; (3) Client Credentials Grant - rare in healthcare; (4) Refresh Tokens - long-lived sessions; (5) Resource Owner Password (DEPRECATED). PKCE: code_verifier + code_challenge_method=S256 (S256 + plain); prevents authorization code interception attacks; MANDATORY for SMART Standalone-Launch. OPENID CONNECT - identity layer on top of OAuth 2.0 + ID token + UserInfo endpoint + JWKS + scopes (openid + profile + email); FHIR-SEC-04. USER AUTHENTICATION (FHIR-SEC-2.1) - OAuth-token based + Multi-factor Authentication (MFA) + biometric + risk-based + adaptive + customer journey + customer protection; coordinates with hospital/EHR user authentication + SSO (SAML + OIDC); ID Token + claims. SYSTEM-TO-SYSTEM AUTHENTICATION (FHIR-SEC-2.3 + FHIR-SEC-05) - Backend Services Authentication + asymmetric key (RS256/ES256) + JWT Bearer Token + JWKS publication + scope-based authorization; SMART Backend Services IG; mTLS optional; ideal for EHR-to-EHR + payer-provider + 3rd-party. TOKEN LIFETIME + REFRESH (FHIR-SEC-18) - short-lived access tokens (typically 5-60 minutes) + refresh tokens (longer-lived + bound to user/client) + secure storage + revocation + token introspection; OAuth 2.0 RFC 7009 + RFC 7662; manage token lifecycle + sliding window + offline-access scope. KEY EVIDENCE: SMART IG compliance + OAuth flows + PKCE implementation + ID token + JWKS + token endpoint security + refresh token storage.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 78 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA OWASPAPI-2 Broken Authentication and Token Management OWASPAPI-3 Broken Object Property Level Authorization (BOPLA) DSOMM-1 Culture, Organization, Education, and Governance DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition OWASPTOP10-6 A06:2025 Vulnerable and Outdated Components OWASPTOP10-7 A07:2025 Identification and Authentication Failures AMLCTF-35 Identity Verification Standard DSO-3 Data Access Management CAT-IRP-4 Organizational characteristics FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) GLI33-PAM-KYC-AML-Payments GLI-33 Player Account Management, KYC, AML, Payment Processing and Account Lifecycle GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment HITECH-SubtitleD-StrengthIndividualRights HITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition) IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access ICAO-ANX17-Chap4-SpecialCategories-Weapons-InFlightSecurity-CockpitDoor ICAO Annex 17 Chapter 4 - Special Categories of Passengers + Weapons + In-Flight Security Officers + Flight Crew Compartment Door 62351-8 Role-based access control (RBAC) 23837-1.7.3 Authentication and classical post-processing 27011-8.1 User Endpoint Devices 27400-6.1 Secure Device Design EHDSREG-6 Phased Application and Enforcement RUSPD-2 Lawful Basis, Consent, Notice TEFCAREC-1 Common Agreement Conformance and Onboarding ACE-CR-4 Cargo Release Authorization CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures USMCADIGITAL-2 Personal Information Protection and Consumer Protection VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 78 it maps to, and the evidence behind each claim, over MCP and REST.