HEALTH INTEROPERABILITYREVIEW

Move data. Preserve meaning. Prove the exchange.

Operating domain

Operating domain: Security, authorization, and trust

Risk that exchange credentials, certificates, clients, users, systems, scopes, directories, and trust relationships are weakly governed, overbroad, stale, or poorly monitored across organizational boundaries.

What this domain asks

Risk that exchange credentials, certificates, clients, users, systems, scopes, directories, and trust relationships are weakly governed, overbroad, stale, or poorly monitored across organizational boundaries.

The domain should retain its own evidence, decision owner, materiality criteria, exception path, and consequence even when it shares organization identity, workflow, or technology with adjacent domains. Aggregation can support oversight; it should not erase the evidence behind different risks or operating outcomes.

Buyer questions

  • Who or what is authenticated at each handoff?
  • How are clients, certificates, scopes, and directories provisioned and revoked?
  • How is least privilege applied to user, system, and bulk access?
  • Which trust framework governs each route?
  • How are anomalous requests, compromised credentials, and downstream incidents detected?
  • Which logs are retained and who can interpret them?

Mapped workflows

SMART On FHIR Authorization

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for SMART on FHIR authorization within this domain.

Direct Secure Messaging

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for Direct secure messaging within this domain.

Query-Based Document Exchange

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for query-based document exchange within this domain.

TEFCA And QHIN Connectivity

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for TEFCA and QHIN connectivity within this domain.

Provider Directory And Endpoint Discovery

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for provider directory and endpoint discovery within this domain.

Consent, Authorization, And Data Segmentation

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for consent, authorization, and data segmentation within this domain.

Operational Monitoring And Exception Management

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for operational monitoring and exception management within this domain.

Authority context

HTI-2 Final Rule

HTI-2 finalizes TEFCA-related definitions, establishes 45 CFR Part 172 provisions supporting TEFCA reliability, privacy, security, trust, and transparency, and leaves the TEFCA Manner Exception unchanged.

QTF v2.1

The QTF defines technical and functional requirements for QHIN-to-QHIN exchange and works with the Common Agreement and operating procedures to support nationwide exchange.

SMART App Launch 2.2.0

SMART App Launch defines discovery, authorization, scopes, token exchange, and app-launch patterns for applications accessing FHIR APIs from within or outside an EHR workflow.

The Direct Standard Version 1.3

The Direct Standard specifies a secure, authenticated, scalable method for sending health information to known recipients using profiled internet messaging, public-key infrastructure, certificate discovery, trust, and delivery notifications.

Relevant operating models

Evidence boundary

Health Interoperability Review provides market, standards, policy, and operating research. It does not provide patient-specific medical advice, determine an individual's rights or coverage, certify product conformity, authorize a disclosure, or replace legal, privacy, security, clinical, or implementation review. A provider's documented capability can identify a research candidate but cannot establish buyer-specific adequacy for this domain.