FHIR © HL7.org  |  FHIRsmith 4.0.1  |  Server Home  |  XIG Home  |  XIG Stats  | 

FHIR IG analytics

Packagehl7.ehrs.uv.cmhaffr2
Resource TypeRequirements
IdRequirements-CMHAFFR2-APU.1.json
FHIR VersionR5
Sourcehttps://build.fhir.org/ig/HL7/cmhaff-ig/Requirements-CMHAFFR2-APU.1.html
URLhttp://hl7.org/ehrs/uv/cmhaffr2/Requirements/CMHAFFR2-APU.1
Version2.0.1
Statusactive
Date2026-08-27T10:32:57+00:00
NameAPU_1_Authentication
TitleAPU.1 Authentication (Header)
Realmuv
Authorityhl7
DescriptionThis category is about the system protecting against unauthorized access (e.g., by persons other than the consumer).
PurposeThe functionality of an app, its sponsorship, and linkages to external data sources all affect the security, privacy and data controls which are established to ensure safe and effective use. In this section, conformance criteria point to issues which can be addressed through a range of options, and as such implementers should consider not only the conformance criteria but the discussion regarding applicability to the exemplary use cases.

Resources that use this resource

No resources found


Resources that this resource uses

No resources found


Narrative

Note: links and images are rebased to the (stated) source

Description I: The functionality of an app, its sponsorship, and linkages to external data sources all affect the security, privacy and data controls which are established to ensure safe and effective use. In this section, conformance criteria point to issues which can be addressed through a range of options, and as such implementers should consider not only the conformance criteria but the discussion regarding applicability to the exemplary use cases.
Criteria N:
APU.1#58 SHALL The app SHALL authenticate the identity of an app user prior to any access of PHI or PII.
APU.1#59 SHALL The app SHALL authorize the app user to access a feature of the app before that feature or any associated PHI or PII is displayed, where authorization may be internal to the app or derived from an external source.
APU.1#60 SHALL The app SHALL terminate at the request of an app user such that access to PHI or PII requires a new, successful authentication attempt.
APU.1#61 SHALL conditional IF another external HIT system (e.g., EHR) is a system actor THEN the app SHALL verify a subject's association with their real-world identity, establishing that a subject is who they claim to be (identity proofing).
APU.1#62 SHALL conditional IF app features are supported by data provided by or written to an EHR THEN the app SHALL ensure the EHR authorizes an app user's access to those app features.
APU.1#63 SHALL conditional IF PII or PHI are displayed THEN the app SHALL terminate the app or make PHI or PII invisible after a period of time of user inactivity as described in the app's Terms of Use (e.g., inactivity timeout, session timeout, or automatic logoff, determined as part of overall risk analysis regarding data sensitivity).
APU.1#64 SHALL conditional IF passwords are stored on the device THEN the app SHALL encrypt passwords and SHALL NOT display passwords as plaintext.
APU.1#65 SHALL conditional IF access to an account exposes Protected Health Information (PHI) or PII THEN the app SHALL give the user an option to utilize strong authentication methods (e.g., multi-factor authentication and/or biometrics) in addition to passwords, clearly describing and/or demonstrating the authentication mechanism to the user before selection.

Source1

{
  "resourceType": "Requirements",
  "id": "CMHAFFR2-APU.1",
  "meta": {
    "profile": [
      "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/FMHeader"
    ]
  },
  "text": {
    "status": "extensions",
    "div": "<!-- snip (see above) -->"
  },
  "extension": [
    {
      "url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-wg",
      "valueCode": "mobile"
    }
  ],
  "url": "http://hl7.org/ehrs/uv/cmhaffr2/Requirements/CMHAFFR2-APU.1",
  "version": "2.0.1",
  "name": "APU_1_Authentication",
  "title": "APU.1 Authentication (Header)",
  "status": "active",
  "date": "2026-08-27T10:32:57+00:00",
  "publisher": "HL7 International / Mobile Health",
  "contact": [
    {
      "telecom": [
        {
          "system": "url",
          "value": "http://www.hl7.org/Special/committees/mobile"
        }
      ]
    }
  ],
  "description": "This category is about the system protecting against unauthorized access (e.g., by persons other than the consumer).",
  "jurisdiction": [
    {
      "coding": [
        {
          "system": "http://unstats.un.org/unsd/methods/m49/m49.htm",
          "code": "001",
          "display": "World"
        }
      ]
    }
  ],
  "purpose": "The functionality of an app, its sponsorship, and linkages to external data sources all affect the security, privacy and data controls which are established to ensure safe and effective use. In this section, conformance criteria point to issues which can be addressed through a range of options, and as such implementers should consider not only the conformance criteria but the discussion regarding applicability to the exemplary use cases.",
  "statement": [
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-APU.1-58",
      "label": "APU.1#58",
      "conformance": [
        "SHALL"
      ],
      "conditionality": false,
      "requirement": "The app SHALL authenticate the identity of an app user prior to any access of PHI or PII."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-APU.1-59",
      "label": "APU.1#59",
      "conformance": [
        "SHALL"
      ],
      "conditionality": false,
      "requirement": "The app SHALL authorize the app user to access a feature of the app before that feature or any associated PHI or PII is displayed, where authorization may be internal to the app or derived from an external source."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-APU.1-60",
      "label": "APU.1#60",
      "conformance": [
        "SHALL"
      ],
      "conditionality": false,
      "requirement": "The app SHALL terminate at the request of an app user such that access to PHI or PII requires a new, successful authentication attempt."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-APU.1-61",
      "label": "APU.1#61",
      "conformance": [
        "SHALL"
      ],
      "conditionality": true,
      "requirement": "IF another external HIT system (e.g., EHR) is a system actor THEN the app SHALL verify a subject's association with their real-world identity, establishing that a subject is who they claim to be (identity proofing)."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-APU.1-62",
      "label": "APU.1#62",
      "conformance": [
        "SHALL"
      ],
      "conditionality": true,
      "requirement": "IF app features are supported by data provided by or written to an EHR THEN the app SHALL ensure the EHR authorizes an app user's access to those app features."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-APU.1-63",
      "label": "APU.1#63",
      "conformance": [
        "SHALL"
      ],
      "conditionality": true,
      "requirement": "IF PII or PHI are displayed THEN the app SHALL terminate the app or make PHI or PII invisible after a period of time of user inactivity as described in the app's Terms of Use (e.g., inactivity timeout, session timeout, or automatic logoff, determined as part of overall risk analysis regarding data sensitivity)."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-APU.1-64",
      "label": "APU.1#64",
      "conformance": [
        "SHALL"
      ],
      "conditionality": true,
      "requirement": "IF passwords are stored on the device THEN the app SHALL encrypt passwords and SHALL NOT display passwords as plaintext."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-APU.1-65",
      "label": "APU.1#65",
      "conformance": [
        "SHALL"
      ],
      "conditionality": true,
      "requirement": "IF access to an account exposes Protected Health Information (PHI) or PII THEN the app SHALL give the user an option to utilize strong authentication methods (e.g., multi-factor authentication and/or biometrics) in addition to passwords, clearly describing and/or demonstrating the authentication mechanism to the user before selection."
    }
  ]
}