Security Guide for SAP Health Data Services for FHIR
Security Guide for SAP Health Data Services for FHIR
Content
Overview
Auditing and Logging Information
Identity and Access Management
Network and Communication Security
Data Storage Security
Data Backup and Restore
Rate Limiting
Client-side Validations
Preventing Cross-Site Scripting Using Output Encoding
Preventing Unvalidated Redirects and Forwards
Malware Scanning
Data Protection and Privacy
Glossary for Data Protection and Privacy
Authorization for Data Protection and Privacy
Designing Configurations for Data Protection and Privacy
Examples for Designing Configurations for Data Protection and Privacy
Define Business Configuration for the Residence Period and Retention Period
Enabling FHIR Resources for Data Protection and Privacy
Maintaining Personal Attributes
Maintaining Data Subject and Usage Purpose for Personal Data
Define Compartment Definition for the Primary Resource of the Data Subject
Define Business Configuration for Mapping Compartment to the Data Subject
Executing Operations for Data Protection and Privacy
Block Personal Data
Erasure of Personal Data
Personal Data Record
Audit Logging
Audit Logging Personal Attributes Examples
Read Access Logging
Data Modification Logging
Instance-Based Authorization
Authorization Check Against the Institution Attribute
Authorization for the Business User Workflow to Perform Check Against Institution Attribute
Authorization for the Technical User Workflow to Perform Check Against Institution Attribute
Instance-Based Authorization for RESTful Interactions on an Institution Level
Authorization Check Against the Department Attribute
Authorization for the Business User Workflow to Perform Check Against the Department Attribute
Authorization for the Technical User Workflow to Perform Check Against the Department Attribute
Instance-Based Authorization for RESTful Interactions on the Department Level
Security Considerations for the SAP Authorization and Trust Management Service