onFHIR.io complies with the authorization standards; User Managed Access (UMA) as 'Resource Server' and specifically OAuth 2.0 and Heart WG UMA and OAuth profiles.
It is hard to implement all the standards and technologies required for Healthcare IT applications
You can integrate onFHIR.io with your existing Authorization servers over popular privacy and security standards and onFHIR.io enforce your privacy and security policies accordingly.
onFHIR.io complies with the authorization standards; User Managed Access (UMA) as 'Resource Server' and specifically OAuth 2.0 and Heart WG UMA and OAuth profiles.
Each Rest API call uses HTTPS/TLS to protect the data transfers, while the data persisted (at rest) in onFHIR.io is encrypted by AES-256.
onFHIR.io creates and stores audit records compliant with FHIR AuditEvent Resource definition for all data accesses and operations. You can configure it to store all audit events locally.
onFhir.io enables sensitive patient data to be processed in compliance with GDPR. A configuration tool is provided where data controllers can analyse the data structures to be processed, and selects de-identification method alternatives such as Substitution, Fuzzing, Redaction and Generalization. The tool also support anonymization methods such as k-anonymity.
Use onFHIR.io + onAuth.io together to have a complete healthcare IT architecture; while onFHIR.io storing and protecting health data, onAuth.io protect your user identity data and act as an Authorization Server.
onAuth.io implements OpenID Connect protocol for client and end-user authentication by complying with Heart WG profile for OpenID Connect. You can provide 2-factor or 3-factor strong authentication for your users.
onAuth.io implement OpenID Connect for identity management and provides you administrative panels to register and manage your users.
onAuth.io enables you to define your Enterprise Access Control Policies (represented by OASIS XACML) from a GUI and make authorization decisions based on these policies.
You can further enable patients to define their consents and manage their privacy. onAuth.io implements UMA as "Authorization Server" enables patient managed access control where onFHIR.io is the "Resource Server"
onAuth.io provides an secure audit repository server to store your audit records in compliance with FHIR AuditEvent. It also provides audit view UIs for your users.