Mobile-ID Digital TrustISO/IEC 27001:2022 · SIS351224I008Published certification scope
View evidence

HEALTH DATA & INTEROPERABILITY

Healthcare Interoperability Center

One integration contract for data, authorization, events and evidence from sandbox to production.

01

REST API

Synchronous business operations with explicit authorization, correlation, idempotency and error semantics.

Configuration-dependent
02

OpenAPI

Machine-readable request, response and error contracts used to align client generation, validation and test evidence.

Configuration-dependent
03

FHIR R4

Profile-governed exchange of healthcare resources, identifiers and terminology; production support remains profile-specific.

Configuration-dependent
04

SMART on FHIR

OAuth-based application launch and scoped access that binds application identity, user context and permitted FHIR data.

Configuration-dependent
05

HL7v2

Message-based integration with mapping, acknowledgement, correlation and replay controls at the legacy-system boundary.

Configuration-dependent
06

DICOM

Imaging objects and metadata organized around study, series and instance context with governed access and retention.

Configuration-dependent
07

DICOMweb

Web-oriented imaging query/retrieve/store integration whose exact operations and deployment support are configuration-dependent.

Configuration-dependent
08

Webhooks

Outbound callbacks with event identity, signature/authentication, retry and duplicate-delivery handling.

Configuration-dependent
09

Events / AsyncAPI

Asynchronous event contracts that define topic, payload, correlation, ordering assumptions and consumer recovery behavior.

Configuration-dependent
10

OAuth 2.1

Authorization boundary for clients and users with scoped access, secure redirect/PKCE patterns where applicable, and token lifecycle controls.

Configuration-dependent
11

OIDC

Federated authentication and identity claims used to establish session/user context without replacing application authorization.

Configuration-dependent
12

mTLS

Certificate-bound transport/client authentication with issuance, trust, rotation, revocation and expiry operations.

Configuration-dependent
13

DeviceKit

Device-facing integration surface for discovery, pairing, measurement sessions, provenance and recoverable device errors.

Configuration-dependent
FHIR R4

Profiles and validation

Resources are paired with identifiers, terminology, scopes and validation outcomes.

CapabilityStatementPatientObservationDiagnosticReportAppointmentConsentIdentifierTerminologyBundleValidation
Screen detail

Search all Trusted Care
TRUSTED CARE

09 applications

Governed application access; no unverified login URL is invented.

Patient AppPatients & familiesRequest accessDoctor PortalDoctors & cliniciansRequest accessNurse & Care CoordinatorNurses & care coordinatorsRequest accessAdmin PortalOrganization administratorsRequest accessHealth KioskReception & service pointsRequest accessPharmacy PortalPharmacistsRequest accessLaboratory PortalLaboratory teamsRequest accessCareGiver AppCaregivers & familiesRequest accessTelehealthPatients & care teamsRequest access