FHIR R4 & HAPI · Chapter 17
Chapter 17 · SMART on FHIR 2.2 · Zero-trust RBAC

Authentication is not authorization. A FHIR server has to prove both.

We built and seeded the server. Now the hardest question - who may read this patient's blood pressure, and who may not. Authentication asks who you are. Authorization asks what you may touch. Confuse the two and you leak protected health information. SMART on FHIR answers both - and it is live regulatory pressure, with the TEFCA FAST security deadline landing in January 2026.

What we will cover

App launch & the OAuth2 / OIDC flow The version-two scope grammar The zero-trust enforcement chain
The app never gets a key to the building - it gets a scoped pass the door re-checks every time