FHIR © HL7.org  |  FHIRsmith 4.0.1  |  Server Home  |  XIG Home  |  XIG Stats  | 

FHIR IG analytics

Packagehl7.ehrs.uv.cmhaffr2
Resource TypeRequirements
IdRequirements-CMHAFFR2-AST.1.json
FHIR VersionR5
Sourcehttps://build.fhir.org/ig/HL7/cmhaff-ig/Requirements-CMHAFFR2-AST.1.html
URLhttp://hl7.org/ehrs/uv/cmhaffr2/Requirements/CMHAFFR2-AST.1
Version2.0.1
Statusactive
Date2026-08-27T10:32:57+00:00
NameAST_1_App_and_Data_Removal
TitleAST.1 App and Data Removal (Header)
Realmuv
Authorityhl7

Resources that use this resource

No resources found


Resources that this resource uses

No resources found


Narrative

Note: links and images are rebased to the (stated) source

Criteria N:
AST.1#115 SHALL The app SHALL permit an app Account Holder to remove the app from a mobile device at any time.
AST.1#116 SHALL The app SHALL inform an app Account Holder of the consequences of removing the app (e.g., loss of locally-stored data) from a smartphone and SHALL give an opportunity to confirm removal before the app is removed.
AST.1#117 SHALL The app SHALL permit an app Account Holder to close an associated account or data store associated with the app.
AST.1#118 SHALL The app SHALL inform an app Account Holder of the consequences of deleting the account and SHALL give an opportunity to confirm closing the account before it is closed.
AST.1#119 SHALL The app SHALL inform the user that data that was part of the account may have been transmitted to other systems outside of the account itself and may persist (e.g., if the user collects device data in an app and transmits that data to an EHR which stores it as PGHD, deleting the account may not delete data in the EHR).
AST.1#120 SHALL The app SHALL permit the account holder to download data generated by the account holder or a proxy subject of the account holder to a data set under full control of the account holder (data portability) before closing an app account.
AST.1#121 SHALL conditional IF the device permits remote or external access to device data THEN the app SHALL allow any PHI or PII stored on a device to be wiped remotely by the account holder without deleting the account related to the wiped data.
AST.1#122 SHALL The app SHALL set and communicate clear criteria to the user regarding the deletion of data, including automatic deletion if the user has not used the app for a specified period.

Source1

{
  "resourceType": "Requirements",
  "id": "CMHAFFR2-AST.1",
  "meta": {
    "profile": [
      "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/FMHeader"
    ]
  },
  "text": {
    "status": "extensions",
    "div": "<!-- snip (see above) -->"
  },
  "extension": [
    {
      "url": "http://hl7.org/fhir/StructureDefinition/structuredefinition-wg",
      "valueCode": "mobile"
    }
  ],
  "url": "http://hl7.org/ehrs/uv/cmhaffr2/Requirements/CMHAFFR2-AST.1",
  "version": "2.0.1",
  "name": "AST_1_App_and_Data_Removal",
  "title": "AST.1 App and Data Removal (Header)",
  "status": "active",
  "date": "2026-08-27T10:32:57+00:00",
  "publisher": "HL7 International / Mobile Health",
  "contact": [
    {
      "telecom": [
        {
          "system": "url",
          "value": "http://www.hl7.org/Special/committees/mobile"
        }
      ]
    }
  ],
  "jurisdiction": [
    {
      "coding": [
        {
          "system": "http://unstats.un.org/unsd/methods/m49/m49.htm",
          "code": "001",
          "display": "World"
        }
      ]
    }
  ],
  "statement": [
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-AST.1-115",
      "label": "AST.1#115",
      "conformance": [
        "SHALL"
      ],
      "conditionality": false,
      "requirement": "The app SHALL permit an app Account Holder to remove the app from a mobile device at any time."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-AST.1-116",
      "label": "AST.1#116",
      "conformance": [
        "SHALL"
      ],
      "conditionality": false,
      "requirement": "The app SHALL inform an app Account Holder of the consequences of removing the app (e.g., loss of locally-stored data) from a smartphone and SHALL give an opportunity to confirm removal before the app is removed."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-AST.1-117",
      "label": "AST.1#117",
      "conformance": [
        "SHALL"
      ],
      "conditionality": false,
      "requirement": "The app SHALL permit an app Account Holder to close an associated account or data store associated with the app."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-AST.1-118",
      "label": "AST.1#118",
      "conformance": [
        "SHALL"
      ],
      "conditionality": false,
      "requirement": "The app SHALL inform an app Account Holder of the consequences of deleting the account and SHALL give an opportunity to confirm closing the account before it is closed."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-AST.1-119",
      "label": "AST.1#119",
      "conformance": [
        "SHALL"
      ],
      "conditionality": false,
      "requirement": "The app SHALL inform the user that data that was part of the account may have been transmitted to other systems outside of the account itself and may persist (e.g., if the user collects device data in an app and transmits that data to an EHR which stores it as PGHD, deleting the account may not delete data in the EHR)."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-AST.1-120",
      "label": "AST.1#120",
      "conformance": [
        "SHALL"
      ],
      "conditionality": false,
      "requirement": "The app SHALL permit the account holder to download data generated by the account holder or a proxy subject of the account holder to a data set under full control of the account holder (data portability) before closing an app account."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-AST.1-121",
      "label": "AST.1#121",
      "conformance": [
        "SHALL"
      ],
      "conditionality": true,
      "requirement": "IF the device permits remote or external access to device data THEN the app SHALL allow any PHI or PII stored on a device to be wiped remotely by the account holder without deleting the account related to the wiped data."
    },
    {
      "extension": [
        {
          "url": "http://hl7.org/ehrs/uv/cmhaffr2/StructureDefinition/requirements-dependent",
          "valueBoolean": false
        }
      ],
      "key": "CMHAFFR2-AST.1-122",
      "label": "AST.1#122",
      "conformance": [
        "SHALL"
      ],
      "conditionality": false,
      "requirement": "The app SHALL set and communicate clear criteria to the user regarding the deletion of data, including automatic deletion if the user has not used the app for a specified period."
    }
  ]
}