Authorization solution for full stack FHIR HAPI access

Zoltán Richárd Jánki, Zoltán Szabó, Vilmos Bilicki, Márta Fidrich · 2017

The Health Level Seven's (HL7) Fast Healthcare Interoperability Resources (FHIR) standard enables the standardized access to the health related data stored in different Electronic Health Record (EHR) backends. A popular open source implementation of FHIR is the Java-based HAPI. It provides generic FHIR-compatible Representational State Transfer (REST) interfaces for data access. One weak point of this solution is the lack of client side support. It supports only Java-based client environments. This is useful in the case of Android-based native client, but for the JavaScript or TypeScript-based full stack environments a JavaScript-based environment is needed. Here, we present our solution which integrates HAPI into a JavaScript-based full stack environment. Another novelty of our solution is that it extends the FHIR's access control model so that it has the best aspects of Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) access control approaches.

Read the paper · More papers on PaperTik