FHIR © HL7.org  |  FHIRsmith 4.0.1  |  Server Home  |  XIG Home  |  XIG Stats  | 

FHIR IG analytics

Packagehl7.ehrs.uv.cmhaffr2
Resource TypeRequirements
IdRequirements-CMHAFFR2-APU.5.json
FHIR VersionR5
Sourcehttps://build.fhir.org/ig/HL7/cmhaff-ig/Requirements-CMHAFFR2-APU.5.html
URLhttp://hl7.org/ehrs/uv/cmhaffr2/Requirements/CMHAFFR2-APU.5
Version2.0.1
Statusactive
Date2026-08-27T10:32:57+00:00
NameAPU_5_Data_Authenticity__Provenance__and_Associated_Metadata
TitleAPU.5 Data Authenticity, Provenance, and Associated Metadata (Header)
Realmuv
Authorityhl7
DescriptionThis category is about providing assurance that consumer data is secure when it is moved between the consumer’s device(s) and other locations. This category is about the attribution of sources of data (provenance) and assurance of data authenticity.

Resources that use this resource

No resources found


Resources that this resource uses

No resources found


Narrative

Note: links and images are rebased to the (stated) source

Criteria N:
APU.5#89 SHALL The app SHALL conform to Best Practices for Data Authenticity, Provenance, and Associated Metadata.
APU.5#90 SHALL conditional IF the app itself originates data (see ISO 21089 definition of "originate") THEN the app SHALL provide the customer a review option which includes the option to irreversibly destroy, reject, or discard data.
APU.5#91 SHALL conditional IF the app itself only receives data as a "pass through" and cannot store data THEN the app SHALL provide the customer a review option to display the data prior to executing the pass-through which includes the option to irreversibly stop and block the pass-through.
APU.5#92 SHALL conditional IF the app itself receives data and stores it THEN the app SHALL provide the customer a review option that permits only appending data and/or free text comments to received data as author while preserving the original received data intact with original provenance, and SHALL NOT allow deleting the original data.

Source1

{
  "resourceType": "Requirements",
  "id": "CMHAFFR2-APU.5",
  "meta": {
    "profile": [
      "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/FMHeader"
    ]
  },
  "text": {
    "status": "extensions",
    "div": "<!-- snip (see above) -->"
  },
  "extension": [
    {
      "url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-wg",
      "valueCode": "mobile"
    }
  ],
  "url": "http://hl7.org/ehrs/uv/cmhaffr2/Requirements/CMHAFFR2-APU.5",
  "version": "2.0.1",
  "name": "APU_5_Data_Authenticity__Provenance__and_Associated_Metadata",
  "title": "APU.5 Data Authenticity, Provenance, and Associated Metadata (Header)",
  "status": "active",
  "date": "2026-08-27T10:32:57+00:00",
  "publisher": "HL7 International / Mobile Health",
  "contact": [
    {
      "telecom": [
        {
          "system": "url",
          "value": "http://www.hl7.org/Special/committees/mobile"
        }
      ]
    }
  ],
  "description": "This category is about providing assurance that consumer data is secure when it is moved between the consumer’s device(s) and other\nlocations. This category is about the attribution of sources of data (provenance) and assurance of data authenticity.",
  "jurisdiction": [
    {
      "coding": [
        {
          "system": "http://unstats.un.org/unsd/methods/m49/m49.htm",
          "code": "001",
          "display": "World"
        }
      ]
    }
  ],
  "statement": [
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-APU.5-89",
      "label": "APU.5#89",
      "conformance": [
        "SHALL"
      ],
      "conditionality": false,
      "requirement": "The app SHALL conform to Best Practices for Data Authenticity, Provenance, and Associated Metadata."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-APU.5-90",
      "label": "APU.5#90",
      "conformance": [
        "SHALL"
      ],
      "conditionality": true,
      "requirement": "IF the app itself originates data (see ISO 21089 definition of \"originate\") THEN the app SHALL provide the customer a review option which includes the option to irreversibly destroy, reject, or discard data."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-APU.5-91",
      "label": "APU.5#91",
      "conformance": [
        "SHALL"
      ],
      "conditionality": true,
      "requirement": "IF the app itself only receives data as a \"pass through\" and cannot store data THEN the app SHALL provide the customer a review option to display the data prior to executing the pass-through which includes the option to irreversibly stop and block the pass-through."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-APU.5-92",
      "label": "APU.5#92",
      "conformance": [
        "SHALL"
      ],
      "conditionality": true,
      "requirement": "IF the app itself receives data and stores it THEN the app SHALL provide the customer a review option that permits only appending data and/or free text comments to received data as author while preserving the original received data intact with original provenance, and SHALL NOT allow deleting the original data."
    }
  ]
}