FHIR R4 & HAPI · Chapter 20
Chapter 20 · Compliance & Audit · The hook

The moment the data is real, the law is watching.

Last chapter we built a working telemedicine platform — appointments, clinical documents, a searchable corpus of patient records. Compliance is not a feature you bolt on at the end. It is a property the platform must hold, continuously, on every single request. FHIR hands you two records and one gate.

The promise

AuditEvent — who touched it · Provenance — where it came from · Consent — whether it may be touched at all

Three FHIR primitives, pulled in different directions by three regulatory regimes. The engineer's job is to hold all three at once.

What you will be able to do

The audit trail — AuditEvent & Provenance The three regimes — HIPAA · GDPR · EU AI Act The consent gate — deny-by-default