Chuyển đến nội dung chính

Lesson 17: Security, Privacy and Consent in FHIR

FHIR Security labels, AuditEvent resource, Provenance resource, Consent framework, RBAC/ABAC in FHIR, medical data encryption, HIPAA compliance, GDPR, Vietnam medical security regulations, security best practices for FHIR Server.

🏗️ Architecture — Lesson 17 Lesson 17: Security, Privacy and Consent in FHIR

HL7 FHIR - Basic to Advanced Healthcare Data Standard

Part 5: Integration, Messaging and Security

xdev.asia

1. FHIR Security Overview

Medical data is one of the most sensitive types of data. FHIR provides many built-in security mechanisms.

Security layerFHIR mechanism
AuthenticationSMART on FHIR, OAuth 2.0
AuthorizationClinical scopes, Consent
AuditAuditEvent resource
ProvenanceProvenance resources
LabelingSecurity labels (meta.security)
ConsentConsent resources
TransportTLS 1.2+

2. Security Labels

Security labels attached meta.security to assign security labels to resources.

{
  "resourceType": "Observation",
  "meta": {
    "security": [
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
        "code": "R",
        "display": "Restricted"
      },
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
        "code": "HIV",
        "display": "HIV/AIDS information sensitivity"
      }
    ]
  }
}

Confidentiality Codes

CodeDisplayDescription
UUnrestrictedNo restrictions
LLowLow level
MModerateAverage level
NNormalNormal
RRestrictedLimitations
VVery RestrictedVery limited (psychiatry, HIV, abuse)

3. AuditEvent Resource

Note every operation data access — WHO did WHAT to WHICH data, WHEN, WHERE, WHY.

{
  "resourceType": "AuditEvent",
  "category": [
    {
      "coding": [
        {
          "system": "http://dicom.nema.org/resources/ontology/DCM",
          "code": "110112",
          "display": "Query"
        }
      ]
    }
  ],
  "code": {
    "coding": [
      {
        "system": "http://hl7.org/fhir/restful-interaction",
        "code": "search-type",
        "display": "search"
      }
    ]
  },
  "action": "E",
  "recorded": "2025-01-15T10:30:00+07:00",
  "outcome": {
    "code": {
      "system": "http://terminology.hl7.org/CodeSystem/audit-event-outcome",
      "code": "success"
    }
  },
  "agent": [
    {
      "type": {
        "coding": [
          {
            "system": "http://dicom.nema.org/resources/ontology/DCM",
            "code": "110153",
            "display": "Source Role ID"
          }
        ]
      },
      "who": {
        "reference": "Practitioner/practitioner-001",
        "display": "BS. Trần Thị B"
      },
      "requestor": true,
      "networkString": "192.168.1.100"
    }
  ],
  "source": {
    "observer": {
      "reference": "Device/fhir-server-001"
    },
    "type": [
      {
        "coding": [
          {
            "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
            "code": "4",
            "display": "Application Server"
          }
        ]
      }
    ]
  },
  "entity": [
    {
      "what": {
        "reference": "Patient/patient-001"
      },
      "role": {
        "coding": [
          {
            "system": "http://terminology.hl7.org/CodeSystem/object-role",
            "code": "1",
            "display": "Patient"
          }
        ]
      }
    }
  ]
}

4. Provenance Resource

Note origin and history data changes — who created, who edited, from what source.

{
  "resourceType": "Provenance",
  "target": [
    {"reference": "Observation/obs-hba1c-001"}
  ],
  "recorded": "2025-01-15T10:30:00+07:00",
  "activity": {
    "coding": [
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-DataOperation",
        "code": "CREATE"
      }
    ]
  },
  "agent": [
    {
      "type": {
        "coding": [
          {
            "system": "http://terminology.hl7.org/CodeSystem/provenance-participant-type",
            "code": "author"
          }
        ]
      },
      "who": {
        "reference": "Practitioner/practitioner-001"
      },
      "onBehalfOf": {
        "reference": "Organization/org-lab-001"
      }
    }
  ],
  "entity": [
    {
      "role": "source",
      "what": {
        "reference": "Device/lab-analyzer-001",
        "display": "Máy xét nghiệm huyết học tự động"
      }
    }
  ]
}

Consent Record patient consent/refusal for data use.

{
  "resourceType": "Consent",
  "status": "active",
  "category": [
    {
      "coding": [
        {
          "system": "http://terminology.hl7.org/CodeSystem/consentcategorycodes",
          "code": "59284-0",
          "display": "Patient Consent"
        }
      ]
    }
  ],
  "subject": {
    "reference": "Patient/patient-001"
  },
  "date": "2025-01-15",
  "grantor": [
    {
      "reference": "Patient/patient-001"
    }
  ],
  "controller": [
    {
      "reference": "Organization/org-bvdk-001"
    }
  ],
  "decision": "permit",
  "provision": [
    {
      "type": "permit",
      "actor": [
        {
          "role": {
            "coding": [
              {
                "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
                "code": "PRCP",
                "display": "Primary information recipient"
              }
            ]
          },
          "reference": {
            "reference": "Organization/org-bvdk-001"
          }
        }
      ],
      "action": [
        {
          "coding": [
            {
              "system": "http://terminology.hl7.org/CodeSystem/consentaction",
              "code": "access"
            }
          ]
        }
      ],
      "securityLabel": [
        {
          "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
          "code": "N"
        }
      ],
      "purpose": [
        {
          "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
          "code": "TREAT",
          "display": "Treatment"
        }
      ],
      "provision": [
        {
          "type": "deny",
          "securityLabel": [
            {
              "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
              "code": "PSY",
              "display": "Psychiatry"
            }
          ]
        }
      ]
    }
  ]
}

6. RBAC/ABAC in FHIR

ModelDescriptionFor example
RBACRole-Based Access ControlCardiology doctors only see Cardiology patients
ABACAttribute-Based Access ControlBased on security label, location, time
PBACPurpose-Based Access ControlAccess for therapeutic purposes only (TREAT)

7. Compliance — HIPAA, GDPR, Vietnam

RegulationsScopeMain requirements
HIPAAUnited StatesPHI protection, minimum necessary, audit trail, BAA
GDPREUConsent, right to erasure, DPO, data portability
Law on Cyber Security (86/2015)VietnamProtect personal information, notify when breaching
Decree 13/2023/ND-CPVietnamPersonal data protection, consent, DPO
Circular 46/2018/TT-BYTVietnamElectronic medical records, confidential

8. Best Practices for FHIR Server security

  1. TLS 1.2+ for all connections
  2. OAuth 2.0 (SMART on FHIR) for authentication/authorization
  3. AuditEvent log every visit — retention ≥ 7 years (medical)
  4. Security labels for sensitive data (HIV, psychiatric, genetic)
  5. Consent — store and enforce patient consent
  6. Encryption at rest — database encryption
  7. Network segmentation — FHIR server in internal network
  8. Rate limiting — anti-abuse API
  9. Input validation — validate all FHIR resources
  10. Minimal exposure — only expose necessary via CapabilityStatement

9. Summary

  • Security Labels — Label confidentiality and sensitivity on resources

  • AuditEvent — Audit trail for all data access

  • Provenance — Traceability of data

  • Consent — Patient consent management, permit/deny by purpose

  • Compliance — HIPAA (US), GDPR (EU), Decree 13/2023 (VN)