Back to Frameworks

HL7 FHIR Security Framework

International (Healthcare)
vR4/R5 (2023)
7 domains
7 controls

The HL7 FHIR Security Framework is the foundational security + privacy + access control framework for FHIR (Fast Healthcare Interoperability Resources) - the global standard for healthcare data exchange APIs. Developed + maintained by HEALTH LEVEL 7 INTERNATIONAL (HL7), the framework covers all aspects of API-based healthcare data exchange security. KEY HISTORY: FHIR DSTU1 (2014) + DSTU2 (2015) + STU3 (2017) + R4 normative (October 2019) + R4B (2022) + R5 (2023) + R6 (planning). FHIR is now the DEFACTO global standard for healthcare interoperability APIs + foundation for ONC Cures Act Final Rule + USCDI + TEFCA + e-prescribing + telehealth + research + EHR-to-EHR + patient + provider + payer + public health + AI + clinical decision support APIs. SECURITY FRAMEWORK PILLARS: (a) TRANSPORT SECURITY - TLS 1.2+ + certificate pinning + secure communications; (b) AUTHENTICATION - SMART App Launch + OAuth 2.0 + OpenID Connect + Backend Services (asymmetric key) + user + system authentication; (c) AUTHORIZATION - OAuth 2.0 scopes (patient/Resource.* + user/* + system/* + scope granularity) + SMART scope syntax + Security Labels + Consent Resource enforcement; (d) AUDIT + PROVENANCE - AuditEvent Resource logging + Provenance tracking + retention + integrity; (e) CONSENT - Consent Resource modeling + enforcement + patient authorization + breach disclosure; (f) BULK DATA - Bulk Data Export Authorization (Backend Services + SMART Bulk Data); (g) DIGITAL SIGNATURES - Resource-level digital signatures + Provenance signatures; (h) CROSS-ORGANIZATIONAL - Backend services to backend services + JWT Bearer Tokens + Asymmetric keys; (i) PRIVACY - de-identification + research + Security Labels + consent integration; (j) EMERGENCY ACCESS - Break the Glass + override procedures; (k) RESILIENCE - Rate Limiting + Anti-Abuse + Server CapabilityStatement security + CORS + Token lifetime + Refresh. SMART ON FHIR (Substitutable Medical Applications + Reusable Technologies): SMART App Launch IG v2.2.0 (current) + EHR-Launch + Standalone-Launch + Backend Services Launch + PKCE + asymmetric key + OAuth 2.1 + OpenID Connect + scopes + capabilities; SMART Health Cards + SMART Health Links + SMART Cards Framework. KEY HL7 FHIR SECURITY SPECIFICATIONS: hl7.org/fhir/security.html (R4/R5 core) + SMART App Launch Implementation Guide + FHIR Bulk Data IG + FHIR Consent Resource + AuditEvent Resource + Provenance Resource + Security Labels + FHIR Operations + FHIR Subscriptions. COORDINATION: (1) HIPAA Privacy + Security Rules (verified separately) - foundational US healthcare privacy + security law; (2) ONC Information Blocking Final Rule (verified separately as HITECH-coordinated) - mandates FHIR-based APIs + Open APIs + USCDI; (3) 21st Century Cures Act - Section 4002 ONC requirements + FHIR + Open APIs; (4) USCDI United States Core Data for Interoperability v1-v4+ - FHIR-mapped data elements; (5) TEFCA Trusted Exchange Framework + Common Agreement (2022+) - voluntary nationwide interoperability + QHINs + FHIR coordination; (6) FDA UDI + DSCSA + clinical research + drug + device registries + FHIR coordination; (7) ONC EHR Certification 2015 Edition Cures Update + FHIR R4 + USCDI + Open APIs; (8) GLOBAL ADOPTION - UK NHS + Israel + Canada + Australia + India + Singapore + Brazil + many countries adopting FHIR for interoperability. 2024-2025+ DIRECTIONS: (a) AI + ML INTEGRATION - FHIR APIs + AI + clinical decision support + agentic AI + Subscriptions; (b) BULK DATA + ANALYTICS + AI - large-scale data exchange + research; (c) QUANTUM-RESISTANT CRYPTOGRAPHY - transition planning for OAuth + TLS + JWT; (d) PATIENT-DIRECTED EXCHANGE - patient access + Apps + 3rd-party + Open Banking-style consent; (e) RANSOMWARE + CYBERSECURITY - sectoral cybersecurity + Change Healthcare crisis + healthcare-specific threat landscape; (f) FHIR R6 PLANNING + further security enhancements + new IGs + Federated Identity + Verifiable Credentials integration. STATUS: HL7 FHIR is FREELY available + open standard published under HL7 SPECIFICATIONS license; broad sectoral adoption + Fortune 500 healthcare + payers + EHRs + Mainland China + global + ongoing R6 planning + emerging cybersecurity + AI + tokenization features.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

FHIR Security Framework: Scope, FHIR R4/R5/R6 Versions, HL7 Specification + Security/Privacy Module

1 controls
Controls in the FHIR Security Framework: Scope, FHIR R4/R5/R6 Versions, HL7 Specification + Security/Privacy Module domain of HL7 FHIR Security Framework1 controls
CodeTitle
HL7-FHIR-Scope-Versions-HL7-SpecificationHL7 FHIR Security Framework Scope, FHIR Versions (R4/R4B/R5/R6), HL7 Specification + Security/Privacy Module

FHIR Security: Audit + Provenance + Digital Signatures + AuditEvent + Resource Integrity

1 controls
Controls in the FHIR Security: Audit + Provenance + Digital Signatures + AuditEvent + Resource Integrity domain of HL7 FHIR Security Framework1 controls
CodeTitle
HL7-FHIR-Audit-Provenance-DigitalSignatures-IntegrityHL7 FHIR Audit + Provenance + Digital Signatures + AuditEvent Resource + Audit Log Integrity + Retention

FHIR Security: Authentication + SMART App Launch + OpenID Connect + Backend Services + Token Lifetime

1 controls
Controls in the FHIR Security: Authentication + SMART App Launch + OpenID Connect + Backend Services + Token Lifetime domain of HL7 FHIR Security Framework1 controls
CodeTitle
HL7-FHIR-Auth-SMART-OAuth-OIDC-BackendHL7 FHIR Authentication - SMART App Launch + OAuth 2.0 + OpenID Connect + Backend Services + Token Lifetime

FHIR Security: Authorization + OAuth 2.0 Scopes + Security Labels + Consent + Patient Compartment + Bulk Data + Break the Glass

1 controls
Controls in the FHIR Security: Authorization + OAuth 2.0 Scopes + Security Labels + Consent + Patient Compartment + Bulk Data + Break the Glass domain of HL7 FHIR Security Framework1 controls
CodeTitle
HL7-FHIR-Authorization-Scopes-Consent-Bulk-Break-GlassHL7 FHIR Authorization - OAuth 2.0 Scopes + Security Labels + Consent + Patient Compartment + Bulk Data + Break the Glass

FHIR Security: Coordination with HIPAA + ONC + Cures + USCDI + TEFCA, 2024-2025 Pipeline

1 controls
Controls in the FHIR Security: Coordination with HIPAA + ONC + Cures + USCDI + TEFCA, 2024-2025 Pipeline domain of HL7 FHIR Security Framework1 controls
CodeTitle
HL7-FHIR-Coord-HIPAA-ONC-Cures-USCDI-TEFCAHL7 FHIR Coordination with HIPAA, ONC Information Blocking, 21st Century Cures Act, USCDI, TEFCA + 2024-2025 Pipeline

FHIR Security: Resilience + Rate Limiting + CORS + Anti-Abuse + SMART Health Cards + De-identification

1 controls
Controls in the FHIR Security: Resilience + Rate Limiting + CORS + Anti-Abuse + SMART Health Cards + De-identification domain of HL7 FHIR Security Framework1 controls
CodeTitle
HL7-FHIR-Resilience-RateLimit-CORS-AntiAbuse-SmartHealthHL7 FHIR Resilience - Rate Limiting + Anti-Abuse + CORS + SMART Health Cards + De-identification + Privacy

FHIR Security: Transport TLS + Communication + Time Keeping + Server CapabilityStatement

1 controls
Controls in the FHIR Security: Transport TLS + Communication + Time Keeping + Server CapabilityStatement domain of HL7 FHIR Security Framework1 controls
CodeTitle
HL7-FHIR-Transport-TLS-CommunicationHL7 FHIR Transport Security - TLS 1.2+, Communication Security, Time Keeping, Server CapabilityStatement

Maps to 80 other frameworks

7 total controls
MITRE D3FEND
3 source controls mapped|2 target controls covered
43%
BSI IT-Grundschutz
3 source controls mapped|6 target controls covered
43%
OWASP ASVS
3 source controls mapped|6 target controls covered
43%
Azure Security Benchmark
3 source controls mapped|4 target controls covered
43%
AWS Well-Architected Security Pillar
3 source controls mapped|4 target controls covered
43%
FISMA
3 source controls mapped|2 target controls covered
43%
OWASP DevSecOps Maturity Model (DSOMM)
3 source controls mapped|4 target controls covered
43%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|6 target controls covered
43%
OWASP Top 10:2025
3 source controls mapped|4 target controls covered
43%
FFIEC Cybersecurity Assessment Tool (CAT)
3 source controls mapped|2 target controls covered
43%
ISO/IEC 27011:2024
3 source controls mapped|3 target controls covered
43%
HITECH Act
3 source controls mapped|2 target controls covered
43%
IEC 62351 - Power Systems Communication Security
3 source controls mapped|3 target controls covered
43%
Spain ENS
3 source controls mapped|6 target controls covered
43%
FTC GLBA Safeguards Rule (16 CFR Part 314)
3 source controls mapped|1 target controls covered
43%
Ghana Cybersecurity Act
3 source controls mapped|3 target controls covered
43%
ASD Strategies to Mitigate Cyber Security Incidents
2 source controls mapped|4 target controls covered
29%
ISO 19011
2 source controls mapped|3 target controls covered
29%
29%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
2 source controls mapped|4 target controls covered
29%
OWASP API Security Top 10 - 2023
2 source controls mapped|5 target controls covered
29%
ISO/IEC 27400:2022
2 source controls mapped|2 target controls covered
29%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
2 source controls mapped|4 target controls covered
29%
FIDO2 / WebAuthn
2 source controls mapped|2 target controls covered
29%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
2 source controls mapped|5 target controls covered
29%
ICH E6(R3) - Good Clinical Practice
2 source controls mapped|1 target controls covered
29%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
2 source controls mapped|2 target controls covered
29%
Annex 11 to EU GMP - Computerised Systems
2 source controls mapped|1 target controls covered
29%
NIST SP 800-171
2 source controls mapped|1 target controls covered
29%
GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6
2 source controls mapped|1 target controls covered
29%
GHG Protocol
2 source controls mapped|1 target controls covered
29%
MiFID II / MiFIR
1 source controls mapped|1 target controls covered
14%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
14%
US Automated Commercial Environment (ACE) - CBP Trade Data Requirements
1 source controls mapped|1 target controls covered
14%
Regulation on the European Health Data Space (EHDS)
1 source controls mapped|1 target controls covered
14%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|1 target controls covered
14%
Armenia Law on Protection of Personal Data (2015)
1 source controls mapped|1 target controls covered
14%
Wisconsin Data Privacy Act (SB 670)
1 source controls mapped|1 target controls covered
14%
Tennessee Information Protection Act (TIPA)
1 source controls mapped|1 target controls covered
14%
AML/CTF Act 2006 (Australia)
1 source controls mapped|1 target controls covered
14%
SWIFT CSCF
1 source controls mapped|1 target controls covered
14%
ISO 13485
1 source controls mapped|1 target controls covered
14%
SWIFT CSCF v2024
1 source controls mapped|1 target controls covered
14%
Regulation (EU) 2019/1239 on the Maritime Single Window (MSW)
1 source controls mapped|1 target controls covered
14%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
1 source controls mapped|2 target controls covered
14%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|2 target controls covered
14%
NAIC Insurance Data Security Model Law (MDL-668)
1 source controls mapped|2 target controls covered
14%
Florida Digital Bill of Rights (FDBR)
1 source controls mapped|2 target controls covered
14%
Russia Federal Law on Personal Data (152-FZ)
1 source controls mapped|1 target controls covered
14%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
1 source controls mapped|1 target controls covered
14%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
1 source controls mapped|1 target controls covered
14%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|1 target controls covered
14%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|1 target controls covered
14%
Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
1 source controls mapped|1 target controls covered
14%
GLI-33 - Gaming Laboratories International Event Wagering Systems
1 source controls mapped|1 target controls covered
14%
Ley Orgánica de Protección de Datos Personales (LOPDP)
1 source controls mapped|1 target controls covered
14%
Law No. 172-13 on the Protection of Personal Data
1 source controls mapped|1 target controls covered
14%
India DPDP Act
1 source controls mapped|1 target controls covered
14%
ISO/IEC 27010:2015
1 source controls mapped|1 target controls covered
14%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
1 source controls mapped|1 target controls covered
14%
ISO 27005
1 source controls mapped|1 target controls covered
14%
ISO 20000-1
1 source controls mapped|1 target controls covered
14%
FFIEC IT Examination Handbook
1 source controls mapped|1 target controls covered
14%
APPI
1 source controls mapped|1 target controls covered
14%
14%
Privacy Act 1988 (Australia)
1 source controls mapped|1 target controls covered
14%
HKMA SPM
1 source controls mapped|1 target controls covered
14%
FBI CJIS Security Policy
1 source controls mapped|2 target controls covered
14%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|1 target controls covered
14%
GLBA
1 source controls mapped|1 target controls covered
14%
APRA CPS 234
1 source controls mapped|1 target controls covered
14%
Bahrain PDPL
1 source controls mapped|1 target controls covered
14%
ISO 31000:2018
1 source controls mapped|1 target controls covered
14%
Switzerland FADP
1 source controls mapped|1 target controls covered
14%

Frequently Asked Questions

What is HL7 FHIR Security Framework?

HL7 FHIR Security Framework is a compliance framework from International (Healthcare) with 7 domains and 7 controls. The HL7 FHIR Security Framework is the foundational security + privacy + access control framework for FHIR (Fast Healthcare Interoperability Resources) - the global standard for healthcare data exchange APIs. Developed + maintained by HEALTH LEVEL 7 INTERNATIONAL (HL7), the framework covers all aspects of API-based healthcare data exchange security. KEY HISTORY: FHIR DSTU1 (2014) + DSTU2 (2015) + STU3 (2017) + R4 normative (October 2019) + R4B (2022) + R5 (2023) + R6 (planning). FHIR is now the DEFACTO global standard for healthcare interoperability APIs + foundation for ONC Cures Act Final Rule + USCDI + TEFCA + e-prescribing + telehealth + research + EHR-to-EHR + patient + provider + payer + public health + AI + clinical decision support APIs. SECURITY FRAMEWORK PILLARS: (a) TRANSPORT SECURITY - TLS 1.2+ + certificate pinning + secure communications; (b) AUTHENTICATION - SMART App Launch + OAuth 2.0 + OpenID Connect + Backend Services (asymmetric key) + user + system authentication; (c) AUTHORIZATION - OAuth 2.0 scopes (patient/Resource.* + user/* + system/* + scope granularity) + SMART scope syntax + Security Labels + Consent Resource enforcement; (d) AUDIT + PROVENANCE - AuditEvent Resource logging + Provenance tracking + retention + integrity; (e) CONSENT - Consent Resource modeling + enforcement + patient authorization + breach disclosure; (f) BULK DATA - Bulk Data Export Authorization (Backend Services + SMART Bulk Data); (g) DIGITAL SIGNATURES - Resource-level digital signatures + Provenance signatures; (h) CROSS-ORGANIZATIONAL - Backend services to backend services + JWT Bearer Tokens + Asymmetric keys; (i) PRIVACY - de-identification + research + Security Labels + consent integration; (j) EMERGENCY ACCESS - Break the Glass + override procedures; (k) RESILIENCE - Rate Limiting + Anti-Abuse + Server CapabilityStatement security + CORS + Token lifetime + Refresh. SMART ON FHIR (Substitutable Medical Applications + Reusable Technologies): SMART App Launch IG v2.2.0 (current) + EHR-Launch + Standalone-Launch + Backend Services Launch + PKCE + asymmetric key + OAuth 2.1 + OpenID Connect + scopes + capabilities; SMART Health Cards + SMART Health Links + SMART Cards Framework. KEY HL7 FHIR SECURITY SPECIFICATIONS: hl7.org/fhir/security.html (R4/R5 core) + SMART App Launch Implementation Guide + FHIR Bulk Data IG + FHIR Consent Resource + AuditEvent Resource + Provenance Resource + Security Labels + FHIR Operations + FHIR Subscriptions. COORDINATION: (1) HIPAA Privacy + Security Rules (verified separately) - foundational US healthcare privacy + security law; (2) ONC Information Blocking Final Rule (verified separately as HITECH-coordinated) - mandates FHIR-based APIs + Open APIs + USCDI; (3) 21st Century Cures Act - Section 4002 ONC requirements + FHIR + Open APIs; (4) USCDI United States Core Data for Interoperability v1-v4+ - FHIR-mapped data elements; (5) TEFCA Trusted Exchange Framework + Common Agreement (2022+) - voluntary nationwide interoperability + QHINs + FHIR coordination; (6) FDA UDI + DSCSA + clinical research + drug + device registries + FHIR coordination; (7) ONC EHR Certification 2015 Edition Cures Update + FHIR R4 + USCDI + Open APIs; (8) GLOBAL ADOPTION - UK NHS + Israel + Canada + Australia + India + Singapore + Brazil + many countries adopting FHIR for interoperability. 2024-2025+ DIRECTIONS: (a) AI + ML INTEGRATION - FHIR APIs + AI + clinical decision support + agentic AI + Subscriptions; (b) BULK DATA + ANALYTICS + AI - large-scale data exchange + research; (c) QUANTUM-RESISTANT CRYPTOGRAPHY - transition planning for OAuth + TLS + JWT; (d) PATIENT-DIRECTED EXCHANGE - patient access + Apps + 3rd-party + Open Banking-style consent; (e) RANSOMWARE + CYBERSECURITY - sectoral cybersecurity + Change Healthcare crisis + healthcare-specific threat landscape; (f) FHIR R6 PLANNING + further security enhancements + new IGs + Federated Identity + Verifiable Credentials integration. STATUS: HL7 FHIR is FREELY available + open standard published under HL7 SPECIFICATIONS license; broad sectoral adoption + Fortune 500 healthcare + payers + EHRs + Mainland China + global + ongoing R6 planning + emerging cybersecurity + AI + tokenization features. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does HL7 FHIR Security Framework have?

HL7 FHIR Security Framework has 7 controls organised across 7 domains. The largest domains are FHIR Security Framework: Scope, FHIR R4/R5/R6 Versions, HL7 Specification + Security/Privacy Module (1 controls), FHIR Security: Audit + Provenance + Digital Signatures + AuditEvent + Resource Integrity (1 controls), FHIR Security: Authentication + SMART App Launch + OpenID Connect + Backend Services + Token Lifetime (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does HL7 FHIR Security Framework map to?

HL7 FHIR Security Framework maps to 80 other compliance frameworks. The top mapping partners are NIST SP 800-171A - Assessing Security Requirements for Controlled Unclassified Information (CUI) (43% coverage), MITRE D3FEND (43% coverage), IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems (43% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with HL7 FHIR Security Framework compliance?

Start your HL7 FHIR Security Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about HL7 FHIR Security Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 7 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required