HL7 FHIR Security Framework
FHIR Security: Transport TLS + Communication + Time Keeping + Server CapabilityStatement

HL7 FHIR Security Framework HL7-FHIR-Transport-TLS-Communication: HL7 FHIR Transport Security - TLS 1.2+, Communication Security, Time Keeping, Server CapabilityStatement

HL7 FHIR Transport Security. TRANSPORT LAYER SECURITY (TLS) - all FHIR APIs MUST use TLS 1.2+ for production + TLS 1.3 recommended; certificate validation + trust chain + certificate pinning where appropriate + HSTS + secure session establishment + cipher suite enforcement (no NULL + no anonymous + no RC4 + no DES/3DES + forward secrecy); FHIR Security Module guidance + sectoral healthcare cybersecurity best practices. COMMUNICATION SECURITY: (a) HTTP/2 + HTTP/3 + QUIC support; (b) WebSocket + Server-Sent Events + REST + GraphQL + FHIRPath for subscriptions + queries; (c) JSON + XML + Turtle serialization; (d) End-to-end encryption + integrity verification; (e) mTLS (mutual TLS) for high-security scenarios + Backend Services + Server-to-Server; (f) Replay attack prevention via nonces + timestamps + Time Keeping. TIME KEEPING - secure time synchronization via NTP + Stratum 1-2 + monotonic counters + Time-of-Day verification + drift detection + replay prevention + audit log time stamps + token expiration + JWT signing time; FHIR resource lastUpdated + createdAt + modifiedAt + audit trails + Provenance recordedAt. SERVER CAPABILITYSTATEMENT SECURITY (FHIR-SEC-19) - FHIR servers MUST publish CapabilityStatement (R4) / Conformance (DSTU2/STU3) Resource declaring (a) security mechanisms supported (cors + service + certificate + description + token endpoint); (b) authorization scheme (OAuth 2.0 + SMART + OpenID Connect + Backend Services); (c) authorization scopes supported + claims; (d) profile + IG compliance; (e) version + supported resources; (f) Operations + Subscriptions supported. CapabilityStatement enables client discovery + auto-configuration + interoperability + trust establishment. KEY EVIDENCE: TLS configuration + certificate management + cipher suite enforcement + CapabilityStatement + time synchronization + audit logs.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 77 controls across 40 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 4 controls

  • BSI-08 Cryptographic protection of data
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • AWWA-4.4 Audit Logging and Monitoring

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

OWASP ASVS · 3 controls

  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics
  • GhCSA-Service-Provider-Licensing-Professional Cybersecurity Service Provider Licensing and Professional Accreditation
  • IACS-UR-E26-Detect-Logging-Monitoring-Audit-Alerting IACS UR E26 Detect Goal - Logging + Network Monitoring + Audit Trail + Alerting + SIEM
  • IACS-UR-E27-Logging-Forensics-EventCapture IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection
  • 62351-14 Cyber security event logging
  • 62351-9 Cyber security key management

ISO/IEC 27011:2024 · 2 controls

  • 27011-8.3 Cryptography and key management
  • 27011-8.4 Logging and monitoring

MITRE D3FEND · 2 controls

OWASP Top 10:2025 · 2 controls

  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • ASD37-17 TLS encryption between email servers (Limited)

Bahrain PDPL · 1 control

  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour
  • CAT-D3-2 Detective controls
  • FFIEC-09 Encryption and key management

FIDO2 / WebAuthn · 1 control

FISMA · 1 control

  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)

GHG Protocol · 1 control

  • GHG-Suite-Corporate-Principles GHG Protocol Suite, Corporate Standard and 5 Reporting Principles

GLBA · 1 control

  • GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines
  • GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety

HITECH Act · 1 control

  • HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC

HKMA SPM · 1 control

  • HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF

ISO/IEC 27010:2015 · 1 control

  • 27010-10.1 Cryptographic Protection

ISO/IEC 27400:2022 · 1 control

  • 27400-6.2 Device Identity and Authentication
  • 29115-7.4 Level of Assurance 4 (LoA4)

India DPDP Act · 1 control

  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 77 it maps to, and the evidence behind each claim, over MCP and REST.