Chuyển đến nội dung chính

Bài 17: Security, Privacy và Consent trong FHIR

FHIR Security labels, AuditEvent resource, Provenance resource, Consent framework, RBAC/ABAC trong FHIR, mã hóa dữ liệu y tế, HIPAA compliance, GDPR, quy định bảo mật y tế Việt Nam, best practices bảo mật cho FHIR Server.

🏗️ Kiến trúc — Bài 17 Bài 17: Security, Privacy và Consent trong FHIR

HL7 FHIR - Chuẩn Dữ liệu Y tế từ Cơ bản đến Nâng cao

Phần 5: Tích hợp, Messaging và Security

xdev.asia

Xem bản video

1. FHIR Security Overview

Dữ liệu y tế là một trong những loại dữ liệu nhạy cảm nhất. FHIR cung cấp nhiều cơ chế bảo mật tích hợp.

Lớp bảo mậtCơ chế FHIR
AuthenticationSMART on FHIR, OAuth 2.0
AuthorizationClinical scopes, Consent
AuditAuditEvent resource
ProvenanceProvenance resource
LabelingSecurity labels (meta.security)
ConsentConsent resource
TransportTLS 1.2+

2. Security Labels

Security labels gắn vào meta.security để gán nhãn bảo mật cho resources.

{
  "resourceType": "Observation",
  "meta": {
    "security": [
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
        "code": "R",
        "display": "Restricted"
      },
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
        "code": "HIV",
        "display": "HIV/AIDS information sensitivity"
      }
    ]
  }
}

Confidentiality Codes

CodeDisplayMô tả
UUnrestrictedKhông hạn chế
LLowMức thấp
MModerateMức trung bình
NNormalBình thường
RRestrictedHạn chế
VVery RestrictedRất hạn chế (tâm thần, HIV, lạm dụng)

3. AuditEvent Resource

Ghi nhận mọi thao tác truy cập dữ liệu — WHO did WHAT to WHICH data, WHEN, WHERE, WHY.

{
  "resourceType": "AuditEvent",
  "category": [
    {
      "coding": [
        {
          "system": "http://dicom.nema.org/resources/ontology/DCM",
          "code": "110112",
          "display": "Query"
        }
      ]
    }
  ],
  "code": {
    "coding": [
      {
        "system": "http://hl7.org/fhir/restful-interaction",
        "code": "search-type",
        "display": "search"
      }
    ]
  },
  "action": "E",
  "recorded": "2025-01-15T10:30:00+07:00",
  "outcome": {
    "code": {
      "system": "http://terminology.hl7.org/CodeSystem/audit-event-outcome",
      "code": "success"
    }
  },
  "agent": [
    {
      "type": {
        "coding": [
          {
            "system": "http://dicom.nema.org/resources/ontology/DCM",
            "code": "110153",
            "display": "Source Role ID"
          }
        ]
      },
      "who": {
        "reference": "Practitioner/practitioner-001",
        "display": "BS. Trần Thị B"
      },
      "requestor": true,
      "networkString": "192.168.1.100"
    }
  ],
  "source": {
    "observer": {
      "reference": "Device/fhir-server-001"
    },
    "type": [
      {
        "coding": [
          {
            "system": "http://terminology.hl7.org/CodeSystem/security-source-type",
            "code": "4",
            "display": "Application Server"
          }
        ]
      }
    ]
  },
  "entity": [
    {
      "what": {
        "reference": "Patient/patient-001"
      },
      "role": {
        "coding": [
          {
            "system": "http://terminology.hl7.org/CodeSystem/object-role",
            "code": "1",
            "display": "Patient"
          }
        ]
      }
    }
  ]
}

4. Provenance Resource

Ghi nhận nguồn gốc và lịch sử thay đổi của data — ai tạo, ai sửa, từ nguồn nào.

{
  "resourceType": "Provenance",
  "target": [
    {"reference": "Observation/obs-hba1c-001"}
  ],
  "recorded": "2025-01-15T10:30:00+07:00",
  "activity": {
    "coding": [
      {
        "system": "http://terminology.hl7.org/CodeSystem/v3-DataOperation",
        "code": "CREATE"
      }
    ]
  },
  "agent": [
    {
      "type": {
        "coding": [
          {
            "system": "http://terminology.hl7.org/CodeSystem/provenance-participant-type",
            "code": "author"
          }
        ]
      },
      "who": {
        "reference": "Practitioner/practitioner-001"
      },
      "onBehalfOf": {
        "reference": "Organization/org-lab-001"
      }
    }
  ],
  "entity": [
    {
      "role": "source",
      "what": {
        "reference": "Device/lab-analyzer-001",
        "display": "Máy xét nghiệm huyết học tự động"
      }
    }
  ]
}

Consent ghi nhận sự đồng ý/từ chối của bệnh nhân về việc sử dụng dữ liệu.

{
  "resourceType": "Consent",
  "status": "active",
  "category": [
    {
      "coding": [
        {
          "system": "http://terminology.hl7.org/CodeSystem/consentcategorycodes",
          "code": "59284-0",
          "display": "Patient Consent"
        }
      ]
    }
  ],
  "subject": {
    "reference": "Patient/patient-001"
  },
  "date": "2025-01-15",
  "grantor": [
    {
      "reference": "Patient/patient-001"
    }
  ],
  "controller": [
    {
      "reference": "Organization/org-bvdk-001"
    }
  ],
  "decision": "permit",
  "provision": [
    {
      "type": "permit",
      "actor": [
        {
          "role": {
            "coding": [
              {
                "system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
                "code": "PRCP",
                "display": "Primary information recipient"
              }
            ]
          },
          "reference": {
            "reference": "Organization/org-bvdk-001"
          }
        }
      ],
      "action": [
        {
          "coding": [
            {
              "system": "http://terminology.hl7.org/CodeSystem/consentaction",
              "code": "access"
            }
          ]
        }
      ],
      "securityLabel": [
        {
          "system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
          "code": "N"
        }
      ],
      "purpose": [
        {
          "system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
          "code": "TREAT",
          "display": "Treatment"
        }
      ],
      "provision": [
        {
          "type": "deny",
          "securityLabel": [
            {
              "system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
              "code": "PSY",
              "display": "Psychiatry"
            }
          ]
        }
      ]
    }
  ]
}

6. RBAC/ABAC trong FHIR

ModelMô tảVí dụ
RBACRole-Based Access ControlBác sĩ khoa Tim chỉ xem BN khoa Tim
ABACAttribute-Based Access ControlDựa trên security label, location, time
PBACPurpose-Based Access ControlChỉ truy cập cho mục đích điều trị (TREAT)

7. Compliance — HIPAA, GDPR, Việt Nam

Quy địnhPhạm viYêu cầu chính
HIPAAHoa KỳPHI protection, minimum necessary, audit trail, BAA
GDPREUConsent, right to erasure, DPO, data portability
Luật ATTT mạng (86/2015)Việt NamBảo vệ thông tin cá nhân, thông báo khi breach
NĐ 13/2023/NĐ-CPViệt NamBảo vệ dữ liệu cá nhân, consent, DPO
TT 46/2018/TT-BYTViệt NamHồ sơ bệnh án điện tử, bảo mật

8. Best Practices bảo mật FHIR Server

  1. TLS 1.2+ cho tất cả connections
  2. OAuth 2.0 (SMART on FHIR) cho authentication/authorization
  3. AuditEvent log mọi truy cập — retention ≥ 7 năm (y tế)
  4. Security labels cho dữ liệu nhạy cảm (HIV, tâm thần, di truyền)
  5. Consent — lưu trữ và enforce sự đồng ý của bệnh nhân
  6. Encryption at rest — mã hóa database
  7. Network segmentation — FHIR server trong internal network
  8. Rate limiting — chống abuse API
  9. Input validation — validate tất cả FHIR resources
  10. Minimal exposure — chỉ expose cần thiết qua CapabilityStatement

9. Tổng kết

  • Security Labels — Gắn nhãn confidentiality, sensitivity lên resources

  • AuditEvent — Audit trail cho mọi truy cập dữ liệu

  • Provenance — Truy xuất nguồn gốc data

  • Consent — Quản lý sự đồng ý bệnh nhân, permit/deny by purpose

  • Compliance — HIPAA (US), GDPR (EU), NĐ 13/2023 (VN)