HL7 FHIR Security Framework
FHIR Security: Authorization + OAuth 2.0 Scopes + Security Labels + Consent + Patient Compartment + Bulk Data + Break the Glass

HL7 FHIR Security Framework HL7-FHIR-Authorization-Scopes-Consent-Bulk-Break-Glass: HL7 FHIR Authorization - OAuth 2.0 Scopes + Security Labels + Consent + Patient Compartment + Bulk Data + Break the Glass

HL7 FHIR Authorization. OAUTH 2.0 SCOPES (FHIR-SEC-02 + FHIR-SEC-06): SMART scope syntax + fine-grained authorization. KEY SCOPE PATTERNS: (a) PATIENT SCOPES - patient/[ResourceType].[CRUDS] + patient/Observation.r (read) + patient/* (all patient data); (b) USER SCOPES - user/[ResourceType].[CRUDS] + user/Patient.r + user/* (all user-accessible data); (c) SYSTEM SCOPES - system/[ResourceType].[CRUDS] + system/Patient.r + system/* (Backend Services); (d) OPENID CONNECT - openid + profile + email + fhirUser (user reference); (e) OFFLINE ACCESS - offline_access (refresh tokens). v2 scope syntax (SMART v2): granular CRUDS (Create + Read + Update + Delete + Search) + fhirContext (multiple patient/system contexts) + parameters (patient/Observation.rs?category=laboratory). LAUNCH CONTEXTS: launch/patient + launch/encounter + launch/episodeofcare + launch/fhirContext - SMART app receives context from EHR. SECURITY LABELS (FHIR-SEC-3.1) - structured labels for sensitivity + handling + jurisdictional regulations + HIPAA + PHI + PII + research + clinical trial + reproductive health + behavioural + substance abuse (42 CFR Part 2 + R + HIPAA) + sectoral disclosure restrictions; FHIR Security Labels IG. CONSENT RESOURCE ENFORCEMENT (FHIR-SEC-09 + FHIR-SEC-3.2) - FHIR Consent Resource + patient authorization + breach disclosure + Privacy by Design + access decisions; consent-based access control + provider-patient consent + cross-organizational consent + research consent. PATIENT COMPARTMENT ENFORCEMENT (FHIR-SEC-13) - logical compartment + isolation per Patient + Practitioner + RelatedPerson + Device + Organization; FHIR Resource compartmentDefinition; cross-patient access prevention. BULK DATA EXPORT AUTHORIZATION (FHIR-SEC-15) - SMART Backend Services + JWT Bearer Token + system scope + asynchronous processing + Group/Patient/Practitioner export + Cures Act Open APIs + payer-data + research; FHIR Bulk Data IG. BREAK THE GLASS (FHIR-SEC-17) - emergency access procedures + override + audit + escalation + post-event review + clinician override + emergency department + sectoral best practice; AuditEvent integration. SCOPE-BASED AUTHORIZATION (FHIR-SEC-3.3) - scope evaluation + decision logic + Policy Decision Point (PDP) + Policy Enforcement Point (PEP) + XACML-style decisions + ABAC + RBAC + sectoral compliance. KEY EVIDENCE: SMART scopes + Security Labels + Consent Resource + Patient Compartment + Bulk Data + Break the Glass procedures + audit + remediation.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.