SMART on FHIR
SMART App Launch
SMART on FHIR is the OAuth 2.0 / OpenID Connect authorization framework that lets third-party apps securely launch against a FHIR API with scoped access.
SMART on FHIR (SMART App Launch) is the standard that governs how an application authenticates and is authorized to access a FHIR API. It layers OAuth 2.0 and OpenID Connect on top of FHIR, defining scopes that limit exactly which resources and operations an app may use and on whose behalf.
SMART App Launch 1.0.0 is part of the CMS-0057-F mandated stack and underpins the patient-access and provider-access APIs: it is what allows a patient's chosen third-party app, or a provider-facing app, to connect to a payer or EHR FHIR endpoint securely and with consent.
For implementers, SMART is the difference between a FHIR API that is technically present and one that is safely usable by outside apps at scale, with auditable, scoped access.
How this relates to Health1st
Health1st's Compliance & Consent Agent enforces SMART / OAuth2 / OIDC policy, scope, and consent on the APIs it helps expose, so access to translated FHIR data is authorized, provenance-tracked, and auditable.
Related terms
FHIR is HL7's modern, web-native standard for exchanging healthcare data as modular JSON/XML resources over RESTful APIs.
CMS-0057-F requires impacted US payers to stand up four FHIR APIs — Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization (PARDD) — with API compliance generally due January 1, 2027.
US Core is the HL7 implementation guide that constrains FHIR resources into the specific profiles US regulation requires, binding them to USCDI data elements.
Ready to turn months of interface work into days?
See a live HL7 v2 ↔ FHIR translation on your own message types. No obligation.
