Xem bản video
1. FHIR Security Overview
Dữ liệu y tế là một trong những loại dữ liệu nhạy cảm nhất. FHIR cung cấp nhiều cơ chế bảo mật tích hợp.
| Lớp bảo mật | Cơ chế FHIR |
|---|---|
| Authentication | SMART on FHIR, OAuth 2.0 |
| Authorization | Clinical scopes, Consent |
| Audit | AuditEvent resource |
| Provenance | Provenance resource |
| Labeling | Security labels (meta.security) |
| Consent | Consent resource |
| Transport | TLS 1.2+ |
2. Security Labels
Security labels gắn vào meta.security để gán nhãn bảo mật cho resources.
{
"resourceType": "Observation",
"meta": {
"security": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"code": "R",
"display": "Restricted"
},
{
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"code": "HIV",
"display": "HIV/AIDS information sensitivity"
}
]
}
}
Confidentiality Codes
| Code | Display | Mô tả |
|---|---|---|
| U | Unrestricted | Không hạn chế |
| L | Low | Mức thấp |
| M | Moderate | Mức trung bình |
| N | Normal | Bình thường |
| R | Restricted | Hạn chế |
| V | Very Restricted | Rất hạn chế (tâm thần, HIV, lạm dụng) |
3. AuditEvent Resource
Ghi nhận mọi thao tác truy cập dữ liệu — WHO did WHAT to WHICH data, WHEN, WHERE, WHY.
{
"resourceType": "AuditEvent",
"category": [
{
"coding": [
{
"system": "http://dicom.nema.org/resources/ontology/DCM",
"code": "110112",
"display": "Query"
}
]
}
],
"code": {
"coding": [
{
"system": "http://hl7.org/fhir/restful-interaction",
"code": "search-type",
"display": "search"
}
]
},
"action": "E",
"recorded": "2025-01-15T10:30:00+07:00",
"outcome": {
"code": {
"system": "http://terminology.hl7.org/CodeSystem/audit-event-outcome",
"code": "success"
}
},
"agent": [
{
"type": {
"coding": [
{
"system": "http://dicom.nema.org/resources/ontology/DCM",
"code": "110153",
"display": "Source Role ID"
}
]
},
"who": {
"reference": "Practitioner/practitioner-001",
"display": "BS. Trần Thị B"
},
"requestor": true,
"networkString": "192.168.1.100"
}
],
"source": {
"observer": {
"reference": "Device/fhir-server-001"
},
"type": [
{
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/security-source-type",
"code": "4",
"display": "Application Server"
}
]
}
]
},
"entity": [
{
"what": {
"reference": "Patient/patient-001"
},
"role": {
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/object-role",
"code": "1",
"display": "Patient"
}
]
}
}
]
}
4. Provenance Resource
Ghi nhận nguồn gốc và lịch sử thay đổi của data — ai tạo, ai sửa, từ nguồn nào.
{
"resourceType": "Provenance",
"target": [
{"reference": "Observation/obs-hba1c-001"}
],
"recorded": "2025-01-15T10:30:00+07:00",
"activity": {
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-DataOperation",
"code": "CREATE"
}
]
},
"agent": [
{
"type": {
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/provenance-participant-type",
"code": "author"
}
]
},
"who": {
"reference": "Practitioner/practitioner-001"
},
"onBehalfOf": {
"reference": "Organization/org-lab-001"
}
}
],
"entity": [
{
"role": "source",
"what": {
"reference": "Device/lab-analyzer-001",
"display": "Máy xét nghiệm huyết học tự động"
}
}
]
}
5. Consent Resource
Consent ghi nhận sự đồng ý/từ chối của bệnh nhân về việc sử dụng dữ liệu.
{
"resourceType": "Consent",
"status": "active",
"category": [
{
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/consentcategorycodes",
"code": "59284-0",
"display": "Patient Consent"
}
]
}
],
"subject": {
"reference": "Patient/patient-001"
},
"date": "2025-01-15",
"grantor": [
{
"reference": "Patient/patient-001"
}
],
"controller": [
{
"reference": "Organization/org-bvdk-001"
}
],
"decision": "permit",
"provision": [
{
"type": "permit",
"actor": [
{
"role": {
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-ParticipationType",
"code": "PRCP",
"display": "Primary information recipient"
}
]
},
"reference": {
"reference": "Organization/org-bvdk-001"
}
}
],
"action": [
{
"coding": [
{
"system": "http://terminology.hl7.org/CodeSystem/consentaction",
"code": "access"
}
]
}
],
"securityLabel": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-Confidentiality",
"code": "N"
}
],
"purpose": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-ActReason",
"code": "TREAT",
"display": "Treatment"
}
],
"provision": [
{
"type": "deny",
"securityLabel": [
{
"system": "http://terminology.hl7.org/CodeSystem/v3-ActCode",
"code": "PSY",
"display": "Psychiatry"
}
]
}
]
}
]
}
6. RBAC/ABAC trong FHIR
| Model | Mô tả | Ví dụ |
|---|---|---|
| RBAC | Role-Based Access Control | Bác sĩ khoa Tim chỉ xem BN khoa Tim |
| ABAC | Attribute-Based Access Control | Dựa trên security label, location, time |
| PBAC | Purpose-Based Access Control | Chỉ truy cập cho mục đích điều trị (TREAT) |
7. Compliance — HIPAA, GDPR, Việt Nam
| Quy định | Phạm vi | Yêu cầu chính |
|---|---|---|
| HIPAA | Hoa Kỳ | PHI protection, minimum necessary, audit trail, BAA |
| GDPR | EU | Consent, right to erasure, DPO, data portability |
| Luật ATTT mạng (86/2015) | Việt Nam | Bảo vệ thông tin cá nhân, thông báo khi breach |
| NĐ 13/2023/NĐ-CP | Việt Nam | Bảo vệ dữ liệu cá nhân, consent, DPO |
| TT 46/2018/TT-BYT | Việt Nam | Hồ sơ bệnh án điện tử, bảo mật |
8. Best Practices bảo mật FHIR Server
- TLS 1.2+ cho tất cả connections
- OAuth 2.0 (SMART on FHIR) cho authentication/authorization
- AuditEvent log mọi truy cập — retention ≥ 7 năm (y tế)
- Security labels cho dữ liệu nhạy cảm (HIV, tâm thần, di truyền)
- Consent — lưu trữ và enforce sự đồng ý của bệnh nhân
- Encryption at rest — mã hóa database
- Network segmentation — FHIR server trong internal network
- Rate limiting — chống abuse API
- Input validation — validate tất cả FHIR resources
- Minimal exposure — chỉ expose cần thiết qua CapabilityStatement
9. Tổng kết
Security Labels — Gắn nhãn confidentiality, sensitivity lên resources
AuditEvent — Audit trail cho mọi truy cập dữ liệu
Provenance — Truy xuất nguồn gốc data
Consent — Quản lý sự đồng ý bệnh nhân, permit/deny by purpose
Compliance — HIPAA (US), GDPR (EU), NĐ 13/2023 (VN)