1. FHIR Security Overview
Medical data is one of the most sensitive types of data. FHIR provides many built-in security mechanisms.
| Security layer | FHIR mechanism |
|---|---|
| Authentication | SMART on FHIR, OAuth 2.0 |
| Authorization | Clinical scopes, Consent |
| Audit | AuditEvent resource |
| Provenance | Provenance resources |
| Labeling | Security labels (meta.security) |
| Consent | Consent resources |
| Transport | TLS 1.2+ |
2. Security Labels
Security labels attached meta.security to assign security labels to resources.
{
"resourceType": "Observation",
"meta": {
"security": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"code": "R",
"display": "Restricted"
},
{
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"code": "HIV",
"display": "HIV/AIDS information sensitivity"
}
]
}
}
Confidentiality Codes
| Code | Display | Description |
|---|---|---|
| U | Unrestricted | No restrictions |
| L | Low | Low level |
| M | Moderate | Average level |
| N | Normal | Normal |
| R | Restricted | Limitations |
| V | Very Restricted | Very limited (psychiatry, HIV, abuse) |
3. AuditEvent Resource
Note every operation data access — WHO did WHAT to WHICH data, WHEN, WHERE, WHY.
{
"resourceType": "AuditEvent",
"category": [
{
"coding": [
{
"system": "http://dicom.nema.org/resources/ontology/DCM",
"code": "110112",
"display": "Query"
}
]
}
],
"code": {
"coding": [
{
"system": "http://hl7.org/fhir/restful-interaction",
"code": "search-type",
"display": "search"
}
]
},
"action": "E",
"recorded": "2025-01-15T10:30:00+07:00",
"outcome": {
"code": {
"system": "http://terminology.hl7.org/CodeSystem/audit-event-outcome",
"code": "success"
}
},
"agent": [
{
"type": {
"coding": [
{
"system": "http://dicom.nema.org/resources/ontology/DCM",
"code": "110153",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Practitioner/practitioner-001",
"display": "BS. Trần Thị B"
},
"requestor": true,
"networkString": "192.168.1.100"
}
],
"source": {
"observer": {
"reference": "Device/fhir-server-001"
},
"type": [
{
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"code": "4",
"display": "Application Server"
}
]
}
]
},
"entity": [
{
"what": {
"reference": "Patient/patient-001"
},
"role": {
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"code": "1",
"display": "Patient"
}
]
}
}
]
}
4. Provenance Resource
Note origin and history data changes — who created, who edited, from what source.
{
"resourceType": "Provenance",
"target": [
{"reference": "Observation/obs-hba1c-001"}
],
"recorded": "2025-01-15T10:30:00+07:00",
"activity": {
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-DataOperation",
"code": "CREATE"
}
]
},
"agent": [
{
"type": {
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/provenance-participant-type",
"code": "author"
}
]
},
"who": {
"reference": "Practitioner/practitioner-001"
},
"onBehalfOf": {
"reference": "Organization/org-lab-001"
}
}
],
"entity": [
{
"role": "source",
"what": {
"reference": "Device/lab-analyzer-001",
"display": "Máy xét nghiệm huyết học tự động"
}
}
]
}
5. Consent Resource
Consent Record patient consent/refusal for data use.
{
"resourceType": "Consent",
"status": "active",
"category": [
{
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/consentcategorycodes",
"code": "59284-0",
"display": "Patient Consent"
}
]
}
],
"subject": {
"reference": "Patient/patient-001"
},
"date": "2025-01-15",
"grantor": [
{
"reference": "Patient/patient-001"
}
],
"controller": [
{
"reference": "Organization/org-bvdk-001"
}
],
"decision": "permit",
"provision": [
{
"type": "permit",
"actor": [
{
"role": {
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"code": "PRCP",
"display": "Primary information recipient"
}
]
},
"reference": {
"reference": "Organization/org-bvdk-001"
}
}
],
"action": [
{
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/consentaction",
"code": "access"
}
]
}
],
"securityLabel": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"code": "N"
}
],
"purpose": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"code": "TREAT",
"display": "Treatment"
}
],
"provision": [
{
"type": "deny",
"securityLabel": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"code": "PSY",
"display": "Psychiatry"
}
]
}
]
}
]
}
6. RBAC/ABAC in FHIR
| Model | Description | For example |
|---|---|---|
| RBAC | Role-Based Access Control | Cardiology doctors only see Cardiology patients |
| ABAC | Attribute-Based Access Control | Based on security label, location, time |
| PBAC | Purpose-Based Access Control | Access for therapeutic purposes only (TREAT) |
7. Compliance — HIPAA, GDPR, Vietnam
| Regulations | Scope | Main requirements |
|---|---|---|
| HIPAA | United States | PHI protection, minimum necessary, audit trail, BAA |
| GDPR | EU | Consent, right to erasure, DPO, data portability |
| Law on Cyber Security (86/2015) | Vietnam | Protect personal information, notify when breaching |
| Decree 13/2023/ND-CP | Vietnam | Personal data protection, consent, DPO |
| Circular 46/2018/TT-BYT | Vietnam | Electronic medical records, confidential |
8. Best Practices for FHIR Server security
- TLS 1.2+ for all connections
- OAuth 2.0 (SMART on FHIR) for authentication/authorization
- AuditEvent log every visit — retention ≥ 7 years (medical)
- Security labels for sensitive data (HIV, psychiatric, genetic)
- Consent — store and enforce patient consent
- Encryption at rest — database encryption
- Network segmentation — FHIR server in internal network
- Rate limiting — anti-abuse API
- Input validation — validate all FHIR resources
- Minimal exposure — only expose necessary via CapabilityStatement
9. Summary
Security Labels — Label confidentiality and sensitivity on resources
AuditEvent — Audit trail for all data access
Provenance — Traceability of data
Consent — Patient consent management, permit/deny by purpose
Compliance — HIPAA (US), GDPR (EU), Decree 13/2023 (VN)