FHIR IG analytics| Package | hl7.ehrs.uv.cmhaffr2 |
| Resource Type | Requirements |
| Id | Requirements-CMHAFFR2-APU.4.json |
| FHIR Version | R5 |
| Source | https://build.fhir.org/ig/HL7/cmhaff-ig/Requirements-CMHAFFR2-APU.4.html |
| URL | http://hl7.org/ehrs/uv/cmhaffr2/Requirements/CMHAFFR2-APU.4 |
| Version | 2.0.1 |
| Status | active |
| Date | 2026-08-27T10:32:57+00:00 |
| Name | APU_4_Security_for_Data_at_Rest_and_in_Transport |
| Title | APU.4 Security for Data at Rest and in Transport (Header) |
| Realm | uv |
| Authority | hl7 |
| Description | This category is about providing assurance that the consumer’s stored data is secure, regardless of whether it is stored on the consumer’s devices or elsewhere (e.g., in cloud-based servers for an app). It also provides assurance that consumer data is secure when it is moved between the consumer’s device(s) and other locations. |
No resources found
No resources found
Note: links and images are rebased to the (stated) source
| APU.4#83 | SHALL | The app SHALL store PHI and PII on a smartphone as encrypted values. |
| APU.4#84 | SHALL | The app SHALL store PHI and PII on any external server as encrypted values. |
| APU.4#85 | SHALL | The app SHALL permit the account holder to delete information collected through the app, including data generated by an associated device, unless PHI and PII has been transmitted to a data set maintained by a Health Plan or Health Provider. |
| APU.4#86 | SHALL | The app SHALL improve and/or upgrade encryption cipher and suites to match evolving best practices. |
| APU.4#87 | SHALL | The app SHALL transmit PHI and PII between the app and an external data source, including data generated through a device associated with the app, as encrypted values. |
{
"resourceType": "Requirements",
"id": "CMHAFFR2-APU.4",
"meta": {
"profile": [
"http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/FMHeader"
]
},
"text": {
"status": "extensions",
"div": "<!-- snip (see above) -->"
},
"extension": [
{
"url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-wg",
"valueCode": "mobile"
}
],
"url": "http://hl7.org/ehrs/uv/cmhaffr2/Requirements/CMHAFFR2-APU.4",
"version": "2.0.1",
"name": "APU_4_Security_for_Data_at_Rest_and_in_Transport",
"title": "APU.4 Security for Data at Rest and in Transport (Header)",
"status": "active",
"date": "2026-08-27T10:32:57+00:00",
"publisher": "HL7 International / Mobile Health",
"contact": [
{
"telecom": [
{
"system": "url",
"value": "http://www.hl7.org/Special/committees/mobile"
}
]
}
],
"description": "This category is about providing assurance that the consumer’s stored data is secure, regardless of whether it is stored on the consumer’s\ndevices or elsewhere (e.g., in cloud-based servers for an app). It also provides assurance that consumer data is secure when it is moved between the\nconsumer’s device(s) and other locations.",
"jurisdiction": [
{
"coding": [
{
"system": "http://unstats.un.org/unsd/methods/m49/m49.htm",
"code": "001",
"display": "World"
}
]
}
],
"statement": [
{
"extension": [
{
"url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
"valueBoolean": false
}
],
"key": "CMHAFFR2-APU.4-83",
"label": "APU.4#83",
"conformance": [
"SHALL"
],
"conditionality": false,
"requirement": "The app SHALL store PHI and PII on a smartphone as encrypted values."
},
{
"extension": [
{
"url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
"valueBoolean": false
}
],
"key": "CMHAFFR2-APU.4-84",
"label": "APU.4#84",
"conformance": [
"SHALL"
],
"conditionality": false,
"requirement": "The app SHALL store PHI and PII on any external server as encrypted values."
},
{
"extension": [
{
"url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
"valueBoolean": false
}
],
"key": "CMHAFFR2-APU.4-85",
"label": "APU.4#85",
"conformance": [
"SHALL"
],
"conditionality": false,
"requirement": "The app SHALL permit the account holder to delete information collected through the app, including data generated by an associated device, unless PHI and PII has been transmitted to a data set maintained by a Health Plan or Health Provider."
},
{
"extension": [
{
"url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
"valueBoolean": false
}
],
"key": "CMHAFFR2-APU.4-86",
"label": "APU.4#86",
"conformance": [
"SHALL"
],
"conditionality": false,
"requirement": "The app SHALL improve and/or upgrade encryption cipher and suites to match evolving best practices."
},
{
"extension": [
{
"url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
"valueBoolean": false
}
],
"key": "CMHAFFR2-APU.4-87",
"label": "APU.4#87",
"conformance": [
"SHALL"
],
"conditionality": false,
"requirement": "The app SHALL transmit PHI and PII between the app and an external data source, including data generated through a device associated with the app, as encrypted values."
}
]
}