HEALTH INTEROPERABILITYREVIEW

Move data. Preserve meaning. Prove the exchange.

International with broad U.S. adoption · international FHIR authorization implementation guide

HL7 SMART App Launch Implementation Guide

SMART App Launch defines discovery, authorization, scopes, token exchange, and app-launch patterns for applications accessing FHIR APIs from within or outside an EHR workflow.

What the authority record establishes

SMART App Launch defines discovery, authorization, scopes, token exchange, and app-launch patterns for applications accessing FHIR APIs from within or outside an EHR workflow.

Voluntary unless adopted by certification, program, contract, or implementation requirement

The exact official title, issuing body, jurisdiction, version or application record, and linked source define the scope of this page. Readers should not transfer the authority's status to a commercial product or infer transaction-, patient-, system-, site-, or organization-specific applicability from this summary.

Why it matters to this market

A buyer needs evidence for the exact SMART version, supported launch contexts, scopes, client registration, user and system authorization, and operational token controls.

Affected operating stages

  • Client Registration
  • Capability Discovery
  • Authorization
  • Token Issuance
  • FHIR Access
  • Refresh And Revocation
  • Audit

Capabilities to examine

FHIR API Gateway And Orchestration

Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for FHIR API gateway and orchestration.

FHIR Profile And Implementation-Guide Support

Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for FHIR profile and implementation-guide support.

SMART On FHIR Authorization

Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for SMART on FHIR authorization.

Consent, Authorization, And Data Segmentation

Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for consent, authorization, and data segmentation.

Conformance Testing And Validation

Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for conformance testing and validation.

Operational Monitoring And Exception Management

Ask how the system or service identifies the controlling source and version, applies customer-specific interpretation, handles exceptions, preserves human judgment, and retains evidence for operational monitoring and exception management.

Affected buyer audiences

  • EHR and FHIR server developers
  • application developers
  • health systems
  • health plans
  • security and identity teams

Implementation questions

  • Which entities, products, populations, transactions, systems, sites, or jurisdictions are actually within scope?
  • What is binding, what is guidance, and what is a technical or consensus standard?
  • Which publication, adoption, effective, application, transition, and enforcement dates differ?
  • Who owns legal, clinical, quality, regulatory, policy, or operational interpretation?
  • How will a source revision affect open work and historical decisions?

Interpretation boundary

SMART support does not authorize a particular disclosure or establish the clinical fitness of an app.