FHIR IG analytics| Package | hl7.ehrs.uv.cmhaffr2 |
| Resource Type | Requirements |
| Id | Requirements-CMHAFFR2-AST.1.json |
| FHIR Version | R5 |
| Source | https://build.fhir.org/ig/HL7/cmhaff-ig/Requirements-CMHAFFR2-AST.1.html |
| URL | http://hl7.org/ehrs/uv/cmhaffr2/Requirements/CMHAFFR2-AST.1 |
| Version | 2.0.1 |
| Status | active |
| Date | 2026-08-27T10:32:57+00:00 |
| Name | AST_1_App_and_Data_Removal |
| Title | AST.1 App and Data Removal (Header) |
| Realm | uv |
| Authority | hl7 |
No resources found
No resources found
Note: links and images are rebased to the (stated) source
| AST.1#115 | SHALL | The app SHALL permit an app Account Holder to remove the app from a mobile device at any time. |
| AST.1#116 | SHALL | The app SHALL inform an app Account Holder of the consequences of removing the app (e.g., loss of locally-stored data) from a smartphone and SHALL give an opportunity to confirm removal before the app is removed. |
| AST.1#117 | SHALL | The app SHALL permit an app Account Holder to close an associated account or data store associated with the app. |
| AST.1#118 | SHALL | The app SHALL inform an app Account Holder of the consequences of deleting the account and SHALL give an opportunity to confirm closing the account before it is closed. |
| AST.1#119 | SHALL | The app SHALL inform the user that data that was part of the account may have been transmitted to other systems outside of the account itself and may persist (e.g., if the user collects device data in an app and transmits that data to an EHR which stores it as PGHD, deleting the account may not delete data in the EHR). |
| AST.1#120 | SHALL | The app SHALL permit the account holder to download data generated by the account holder or a proxy subject of the account holder to a data set under full control of the account holder (data portability) before closing an app account. |
| AST.1#121 | SHALL conditional | IF the device permits remote or external access to device data THEN the app SHALL allow any PHI or PII stored on a device to be wiped remotely by the account holder without deleting the account related to the wiped data. |
| AST.1#122 | SHALL | The app SHALL set and communicate clear criteria to the user regarding the deletion of data, including automatic deletion if the user has not used the app for a specified period. |
{
"resourceType": "Requirements",
"id": "CMHAFFR2-AST.1",
"meta": {
"profile": [
"http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/FMHeader"
]
},
"text": {
"status": "extensions",
"div": "<!-- snip (see above) -->"
},
"extension": [
{
"url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-wg",
"valueCode": "mobile"
}
],
"url": "http://hl7.org/ehrs/uv/cmhaffr2/Requirements/CMHAFFR2-AST.1",
"version": "2.0.1",
"name": "AST_1_App_and_Data_Removal",
"title": "AST.1 App and Data Removal (Header)",
"status": "active",
"date": "2026-08-27T10:32:57+00:00",
"publisher": "HL7 International / Mobile Health",
"contact": [
{
"telecom": [
{
"system": "url",
"value": "http://www.hl7.org/Special/committees/mobile"
}
]
}
],
"jurisdiction": [
{
"coding": [
{
"system": "http://unstats.un.org/unsd/methods/m49/m49.htm",
"code": "001",
"display": "World"
}
]
}
],
"statement": [
{
"extension": [
{
"url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
"valueBoolean": false
}
],
"key": "CMHAFFR2-AST.1-115",
"label": "AST.1#115",
"conformance": [
"SHALL"
],
"conditionality": false,
"requirement": "The app SHALL permit an app Account Holder to remove the app from a mobile device at any time."
},
{
"extension": [
{
"url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
"valueBoolean": false
}
],
"key": "CMHAFFR2-AST.1-116",
"label": "AST.1#116",
"conformance": [
"SHALL"
],
"conditionality": false,
"requirement": "The app SHALL inform an app Account Holder of the consequences of removing the app (e.g., loss of locally-stored data) from a smartphone and SHALL give an opportunity to confirm removal before the app is removed."
},
{
"extension": [
{
"url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
"valueBoolean": false
}
],
"key": "CMHAFFR2-AST.1-117",
"label": "AST.1#117",
"conformance": [
"SHALL"
],
"conditionality": false,
"requirement": "The app SHALL permit an app Account Holder to close an associated account or data store associated with the app."
},
{
"extension": [
{
"url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
"valueBoolean": false
}
],
"key": "CMHAFFR2-AST.1-118",
"label": "AST.1#118",
"conformance": [
"SHALL"
],
"conditionality": false,
"requirement": "The app SHALL inform an app Account Holder of the consequences of deleting the account and SHALL give an opportunity to confirm closing the account before it is closed."
},
{
"extension": [
{
"url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
"valueBoolean": false
}
],
"key": "CMHAFFR2-AST.1-119",
"label": "AST.1#119",
"conformance": [
"SHALL"
],
"conditionality": false,
"requirement": "The app SHALL inform the user that data that was part of the account may have been transmitted to other systems outside of the account itself and may persist (e.g., if the user collects device data in an app and transmits that data to an EHR which stores it as PGHD, deleting the account may not delete data in the EHR)."
},
{
"extension": [
{
"url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
"valueBoolean": false
}
],
"key": "CMHAFFR2-AST.1-120",
"label": "AST.1#120",
"conformance": [
"SHALL"
],
"conditionality": false,
"requirement": "The app SHALL permit the account holder to download data generated by the account holder or a proxy subject of the account holder to a data set under full control of the account holder (data portability) before closing an app account."
},
{
"extension": [
{
"url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
"valueBoolean": false
}
],
"key": "CMHAFFR2-AST.1-121",
"label": "AST.1#121",
"conformance": [
"SHALL"
],
"conditionality": true,
"requirement": "IF the device permits remote or external access to device data THEN the app SHALL allow any PHI or PII stored on a device to be wiped remotely by the account holder without deleting the account related to the wiped data."
},
{
"extension": [
{
"url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
"valueBoolean": false
}
],
"key": "CMHAFFR2-AST.1-122",
"label": "AST.1#122",
"conformance": [
"SHALL"
],
"conditionality": false,
"requirement": "The app SHALL set and communicate clear criteria to the user regarding the deletion of data, including automatic deletion if the user has not used the app for a specified period."
}
]
}