HL7 FHIR Security Framework
FHIR Security: Authentication + SMART App Launch + OpenID Connect + Backend Services + Token Lifetime

HL7 FHIR Security Framework HL7-FHIR-Auth-SMART-OAuth-OIDC-Backend: HL7 FHIR Authentication - SMART App Launch + OAuth 2.0 + OpenID Connect + Backend Services + Token Lifetime

HL7 FHIR Authentication. SMART APP LAUNCH IMPLEMENTATION GUIDE v2.2.0 - foundational FHIR-based OAuth 2.0 / OAuth 2.1 + OpenID Connect framework + standardised app authorization. 3 LAUNCH MODES: (a) EHR-LAUNCH (SMART App in context of EHR with patient + user context); (b) STANDALONE-LAUNCH (SMART App initiated by user/patient); (c) BACKEND SERVICES LAUNCH (server-to-server + asymmetric key + system-level scopes). KEY OAUTH 2.0/2.1 + OPENID CONNECT FLOWS: (1) Authorization Code Grant + PKCE (Proof Key for Code Exchange) - required for public clients; (2) Backend Services - asymmetric key (JWT Bearer Token) for confidential clients + server-to-server; (3) Client Credentials Grant - rare in healthcare; (4) Refresh Tokens - long-lived sessions; (5) Resource Owner Password (DEPRECATED). PKCE: code_verifier + code_challenge_method=S256 (S256 + plain); prevents authorization code interception attacks; MANDATORY for SMART Standalone-Launch. OPENID CONNECT - identity layer on top of OAuth 2.0 + ID token + UserInfo endpoint + JWKS + scopes (openid + profile + email); FHIR-SEC-04. USER AUTHENTICATION (FHIR-SEC-2.1) - OAuth-token based + Multi-factor Authentication (MFA) + biometric + risk-based + adaptive + customer journey + customer protection; coordinates with hospital/EHR user authentication + SSO (SAML + OIDC); ID Token + claims. SYSTEM-TO-SYSTEM AUTHENTICATION (FHIR-SEC-2.3 + FHIR-SEC-05) - Backend Services Authentication + asymmetric key (RS256/ES256) + JWT Bearer Token + JWKS publication + scope-based authorization; SMART Backend Services IG; mTLS optional; ideal for EHR-to-EHR + payer-provider + 3rd-party. TOKEN LIFETIME + REFRESH (FHIR-SEC-18) - short-lived access tokens (typically 5-60 minutes) + refresh tokens (longer-lived + bound to user/client) + secure storage + revocation + token introspection; OAuth 2.0 RFC 7009 + RFC 7662; manage token lifecycle + sliding window + offline-access scope. KEY EVIDENCE: SMART IG compliance + OAuth flows + PKCE implementation + ID token + JWKS + token endpoint security + refresh token storage.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 78 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.2 Authentication Mechanisms
  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-2 Broken Authentication and Token Management
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

BSI IT-Grundschutz · 2 controls

  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements

FIDO2 / WebAuthn · 2 controls

  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition

OWASP ASVS · 2 controls

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-6 A06:2025 Vulnerable and Outdated Components
  • OWASPTOP10-7 A07:2025 Identification and Authentication Failures
  • AMLCTF-35 Identity Verification Standard
  • DSO-3 Data Access Management
  • CAT-IRP-4 Organizational characteristics

FISMA · 1 control

  • FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • GLI33-PAM-KYC-AML-Payments GLI-33 Player Account Management, KYC, AML, Payment Processing and Account Lifecycle
  • GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment

HITECH Act · 1 control

  • HITECH-SubtitleD-StrengthIndividualRights HITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition)
  • IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access
  • ICAO-ANX17-Chap4-SpecialCategories-Weapons-InFlightSecurity-CockpitDoor ICAO Annex 17 Chapter 4 - Special Categories of Passengers + Weapons + In-Flight Security Officers + Flight Crew Compartment Door
  • 62351-8 Role-based access control (RBAC)

ISO/IEC 23837:2023 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27011:2024 · 1 control

  • 27011-8.1 User Endpoint Devices

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

MITRE D3FEND · 1 control

MiFID II / MiFIR · 1 control

  • EHDSREG-6 Phased Application and Enforcement
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • ACE-CR-4 Cargo Release Authorization
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 78 it maps to, and the evidence behind each claim, over MCP and REST.