HL7 FHIR Security Framework
FHIR Security: Resilience + Rate Limiting + CORS + Anti-Abuse + SMART Health Cards + De-identification

HL7 FHIR Security Framework HL7-FHIR-Resilience-RateLimit-CORS-AntiAbuse-SmartHealth: HL7 FHIR Resilience - Rate Limiting + Anti-Abuse + CORS + SMART Health Cards + De-identification + Privacy

HL7 FHIR Resilience + Privacy + SMART Health Cards. RATE LIMITING AND ANTI-ABUSE (FHIR-SEC-14) - API rate limiting + throttling + DDoS protection + abuse detection + IP/Subject + Token-based limits + sliding window + token bucket + sectoral best practices; AWS API Gateway + Azure API Management + Apigee + Kong + sectoral protection from quota abuse + scrapers + bots + automated attack; integration with WAF + bot management (Cloudflare + Akamai + Imperva + DataDome). CROSS ORIGIN RESOURCE SHARING (CORS) (FHIR-SEC-20) - secure CORS configuration for browser-based FHIR clients + Origin allowlisting + credentials handling + Preflight requests + appropriate sectoral best practices; protection from XSRF/CSRF + Same-Origin Policy + Browser security model + PWA + Single-Page Applications; SMART browser-based apps + patient portals. SMART HEALTH CARDS VERIFICATION (FHIR-SEC-16) - SMART Health Cards Framework + verifiable healthcare credentials + JWS-based signed credentials + COVID-19 vaccination + interoperability + verifiable + portable + offline-verifiable + W3C VC alignment; SMART Health Links for sharing + Discord-style links + revocation. DE-IDENTIFICATION FOR RESEARCH (FHIR-SEC-12) - FHIR Resource de-identification + HIPAA Safe Harbor + Expert Determination + Limited Data Set + Pseudonymization + Tokenization + Differential Privacy + secondary use + research + 21 CFR + IRB-approved + sectoral best practices; FHIR Privacy Implementation Guide + Common Rule + GDPR Art. 89. CONSENT-BASED ACCESS CONTROL (FHIR-SEC-3.2 covered in Authorization domain). PATIENT-DIRECTED CONSENT - patient authorization to 3rd-party apps + Cures Act Information Blocking + ONC USCDI + access right + revocation + sectoral best practices.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.