Chuyển đến nội dung chính

レッスン 16: FHIR の SMART - OAuth2 と医療アプリケーション

SMART アプリ起動フレームワーク、医療における OAuth 2.0、臨床スコープ、起動コンテキスト (EHR 起動、スタンドアロン起動)、SMART バックエンド サービス (システム間)、CDS フック (臨床意思決定支援)。簡単な SMART アプリの作成を練習します。

🏗️ アーキテクチャ — レッスン 16 レッスン 16: FHIR での SMART - OAuth2 とアプリケーション 医療

HL7 FHIR - 基本から高度な医療データ標準

パート 5: 統合、メッセージング、セキュリティ

xdev.asia

1. SMART on FHIR の概要

スマート FHIR の (代替可能な医療アプリケーション、再利用可能なテクノロジー) は、サードパーティの医療アプリケーションが OAuth 2.0 + FHIR を介して EHR/EMR と安全に統合できるようにするフレームワークです。


┌─────────────┐                    ┌─────────────┐
│  SMART App  │   OAuth 2.0 flow   │   EHR/EMR   │
│  (web/      │ ◀────────────────▶ │  (FHIR      │
│  mobile)    │   FHIR API calls   │   Server)   │
└─────────────┘                    └─────────────┘
       │                                  │
       │        ┌──────────────┐          │
       └───────▶│  Auth Server │◀─────────┘
                │  (OAuth 2.0) │
                └──────────────┘

2. 起動タイプ

EHRの発売

アプリが開いています EHR内から — EHR はコンテキスト (患者、遭遇) を送信します。


1. Bác sĩ click "Open App" trong EHR
2. EHR redirect → App với launch parameter
3. App → Authorization Server (authorize endpoint)
4. User đồng ý → Auth Server trả code
5. App đổi code → access_token + id_token
6. App gọi FHIR API với access_token
GET https://smart-app.example.com/launch
  ?iss=https://fhir-server.hospital.vn/fhir/r5
  &launch=xyz123

スタンドアロンの起動

アプリの実行 独立した、自分で FHIR サーバーを見つけて許可を求めます。

GET https://fhir-server.hospital.vn/fhir/r5/.well-known/smart-configuration
{
  "authorization_endpoint": "https://auth.hospital.vn/authorize",
  "token_endpoint": "https://auth.hospital.vn/token",
  "capabilities": [
    "launch-ehr",
    "launch-standalone",
    "client-public",
    "client-confidential-symmetric",
    "sso-openid-connect",
    "context-ehr-patient",
    "permission-v2"
  ],
  "scopes_supported": [
    "openid",
    "fhirUser",
    "launch",
    "launch/patient",
    "patient/*.rs",
    "user/*.cruds"
  ]
}

3. クリニカルスコープ (SMART v2)

SMART スコープは、どのアプリケーションにアクセスを許可するかを制御します。

# Scope format (v2):
# [context]/[resourceType].[cruds]

# Patient-level scopes (data của patient cụ thể)
patient/Patient.rs          # Read Patient + Search
patient/Observation.rs      # Read + Search Observations
patient/MedicationRequest.rs

# User-level scopes (theo quyền của user đang login)
user/Patient.cruds          # Full CRUD + Search on Patient
user/Encounter.rs
user/*.rs                   # Read + Search tất cả resources

# System-level scopes (backend services)
system/Patient.rs
system/*.rs

クラッズ作戦

キャラクター操作
c作成
r読む
あなたアップデート
d削除
s検索

4. OAuth 2.0認可コードフロー

# Step 1: Authorization Request
GET https://auth.hospital.vn/authorize
  ?response_type=code
  &client_id=my-smart-app
  &redirect_uri=https://smart-app.example.com/callback
  &scope=launch/patient openid fhirUser patient/Patient.rs patient/Observation.rs
  &state=random-state-value
  &aud=https://fhir-server.hospital.vn/fhir/r5
  &code_challenge=E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM
  &code_challenge_method=S256
# Step 2: Token Exchange
POST https://auth.hospital.vn/token
Content-Type: application/x-www-form-urlencoded

grant_type=authorization_code
&code=auth-code-from-callback
&redirect_uri=https://smart-app.example.com/callback
&client_id=my-smart-app
&code_verifier=dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk
{
  "access_token": "eyJ...",
  "token_type": "Bearer",
  "expires_in": 3600,
  "scope": "launch/patient openid fhirUser patient/Patient.rs patient/Observation.rs",
  "id_token": "eyJ...",
  "patient": "patient-001",
  "encounter": "encounter-001",
  "fhirUser": "Practitioner/practitioner-001"
}
# Step 3: FHIR API Calls
GET https://fhir-server.hospital.vn/fhir/r5/Patient/patient-001
Authorization: Bearer eyJ...

5. SMART バックエンド サービス (システム間)

ユーザーの操作は必要ありません - を使用してください client_credentials JWT アサーションを使用します。

POST https://auth.hospital.vn/token
Content-Type: application/x-www-form-urlencoded

grant_type=client_credentials
&scope=system/Patient.rs system/Observation.rs
&client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer
&client_assertion=eyJ...signed_jwt...

6. CDS フック — 臨床意思決定のサポート

CDS フックによりアプリケーションがプロビジョニングできるようになります 臨床上の提案 EHR での意思決定時。

{
  "hookInstance": "uuid-001",
  "hook": "patient-view",
  "fhirServer": "https://fhir-server.hospital.vn/fhir/r5",
  "fhirAuthorization": {
    "access_token": "eyJ...",
    "token_type": "Bearer",
    "scope": "patient/Patient.rs patient/Observation.rs"
  },
  "context": {
    "userId": "Practitioner/practitioner-001",
    "patientId": "patient-001"
  }
}

CDS レスポンス (カード)

{
  "cards": [
    {
      "uuid": "card-001",
      "summary": "HbA1c cao — Cần điều chỉnh thuốc tiểu đường",
      "detail": "HbA1c gần nhất: 8.5% (2025-01-10). Mục tiêu: < 7%. Xem xét tăng liều Metformin hoặc thêm thuốc mới.",
      "indicator": "warning",
      "source": {
        "label": "Diabetes Management CDS",
        "url": "https://cds.hospital.vn"
      },
      "suggestions": [
        {
          "label": "Kê đơn Metformin 1000mg",
          "actions": [
            {
              "type": "create",
              "description": "Tạo MedicationRequest Metformin 1000mg",
              "resource": {
                "resourceType": "MedicationRequest",
                "status": "draft",
                "intent": "proposal"
              }
            }
          ]
        }
      ]
    }
  ]
}

7. まとめ

  • FHIR でスマート — OAuth 2.0 + FHIR (サードパーティの健康アプリ用)

  • EHRの発売 — EHR 内からアプリを開き、利用可能なコンテキストを取得します

  • スタンドアロンの起動 — アプリは独立して実行され、独自に権限を要求します

  • 臨床範囲 — 患者/*、ユーザー/*、システム/* (cruds 権限付き)

  • バックエンドサービス — システム間、JWT クライアント アサーション

  • CDS フック — ポイントオブケアでの意思決定支援