National Directory of Healthcare Providers & Services (NDH) Implementation Guide, published by HL7 International / Patient Administration. This guide is not an authorized publication; it is the continuous build for version 2.0.0-current built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/fhir-us-ndh/ and changes regularly. See the Directory of published versions
| Page standards status: Informative |
Our vision for NDH is that it will function as a public or semi-public utility, with a substantial amount of its information being made openly available. However, certain data included in NDH may be sensitive, and not accessible to all NDH stakeholders or the public. For instance, an implementer may choose to restrict data related to military personnel, emergency responders/volunteers, or domestic violence shelters from being accessible to anyone who has access to NDH, or to users in a local environment who have obtained data from NDH.
It is our expectation that NDH operational policies and legal agreements will provide a clear understanding of which data stakeholders can access. If necessary, these policies will require stakeholders to maintain the privacy and confidentiality of any sensitive information within downstream local environments.
The NDH Server SHALL be protected using TLS in accordance with BCP 195. The NDH Server SHOULD support OAuth 2.0 for authorization. The NDH Server SHOULD support FAST Security - Security for Scalable Registration, Authentication, and Authorization for dynamic client app discovery and authentication. The NDH Server SHOULD support SMART on FHIR for authorization of client requests to protected server resources. The NDH Server SHOULD support OpenID Connect for user authentication and identity management.