Skip to main content

FHIR Conformance Profile

CONTRACT tier required

The FHIR conformance profile is available on CONTRACT tier accounts only. This profile requires the fhir_conformance entitlement. Contact your account manager to enable it. See plan availability and pricing.

The FHIR (Fast Healthcare Interoperability Resources) conformance profile verifies that your FHIR R4/R4B API meets baseline security and schema requirements. APIContext runs conformance checks against your API responses on every monitor run.

What it checks

The FHIR profile verifies:

CheckDescription
TLS / SMART-on-FHIR transportRequests must use HTTPS; SMART-on-FHIR OAuth flows are verified
Content-TypeResponses must return application/fhir+json or application/fhir+xml
Resource schemaResponse body is a valid FHIR resource (validates resourceType, required fields)
OperationOutcome handlingErrors are returned as OperationOutcome resources, not generic HTTP error bodies
Security labelsResources include required sensitivity labels where mandated by the profile

Enabling the profile

  1. Go to Project Settings → Conformance.
  2. Under Security Profiles, select FHIR.
  3. Save changes. The profile applies to all monitors in the project on the next run.

Interpreting results

Conformance results appear in INVESTIGATE → Conformance. Each failed check shows:

  • The specific rule that was not met
  • The response value that failed the check
  • A reference to the FHIR specification section

See also