HL7 FHIR Security Framework scope + structure. HL7 FAST HEALTHCARE INTEROPERABILITY RESOURCES (FHIR) is the global standard for healthcare data exchange APIs published by HEALTH LEVEL 7 INTERNATIONAL (HL7). VERSIONS: (a) FHIR DSTU1 (2014); (b) DSTU2 (2015); (c) STU3 (2017); (d) R4 NORMATIVE (October 2019) - first normative version + foundational for ONC Cures Act + USCDI + TEFCA; (e) R4B (2022) - minor enhancements; (f) R5 (2023) - latest normative; (g) R6 (planning) - future + Federated Identity + Verifiable Credentials + AI integration enhancements. SECURITY FRAMEWORK SCOPE: comprehensive API security + privacy + access control framework covering Transport + Authentication + Authorization + Audit + Consent + Digital Signatures + Privacy + Emergency Access + Resilience for all FHIR-based healthcare APIs. KEY COMPONENTS: (a) FHIR R4/R5 SECURITY MODULE (hl7.org/fhir/security.html) - core security guidance + resource model + best practices + OAuth + audit; (b) SMART APP LAUNCH IMPLEMENTATION GUIDE (v2.2.0 current) - EHR-Launch + Standalone-Launch + Backend Services Launch + PKCE + asymmetric key + OAuth 2.1 + OpenID Connect; (c) FHIR BULK DATA IG (v2.0 current) - bulk export + asynchronous processing + Backend Services Authentication + Group + Patient + Practitioner export; (d) FHIR CONSENT RESOURCE - consent modeling + patient authorization + breach disclosure; (e) FHIR AUDITEVENT RESOURCE - structured audit logging; (f) FHIR PROVENANCE RESOURCE - data provenance + chain of custody; (g) FHIR SECURITY LABELS - structured labeling for sensitivity + classification + handling; (h) SMART HEALTH CARDS + SMART HEALTH LINKS - verifiable healthcare credentials + COVID + vaccination + interoperability. SCOPE: covers ALL healthcare data exchange via FHIR APIs including EHRs + payers + patient apps + 3rd-party apps + research + public health + clinical decision support + AI + telehealth + e-prescribing + claims + clinical + administrative + financial domains. HL7 LICENSE: FHIR specification freely available + open standard published under HL7 SPECIFICATIONS license + supports broad adoption + ecosystem development.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.