SMART Imaging Access
0.1.0 - ci-build
SMART Imaging Access, published by Argonaut Project. This guide is not an authorized publication; it is the continuous build for version 0.1.0 built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/argonautproject/smart-imaging/ and changes regularly. See the Directory of published versions
| Draft as of 2026-09-23 |
<CapabilityStatement xmlns="http://hl7.org/fhir">
<id value="smart-imaging-server"/>
<text>
<status value="extensions"/>
<div xmlns="http://www.w3.org/1999/xhtml"><p class="res-header-id"><b>Generated Narrative: CapabilityStatement smart-imaging-server</b></p><a name="smart-imaging-server"> </a><a name="hcsmart-imaging-server"> </a><h2 id="title">SMART Imaging Access Server</h2><ul><li>Implementation Guide Version: 0.1.0 </li><li>FHIR Version: 4.0.1 </li><li>Supported Formats: <code>json</code></li><li>Published on: 2026-09-23 </li><li>Published by: Argonaut Project </li></ul><blockquote class="impl-note"><p><strong>Note to Implementers: FHIR Capabilities</strong></p><p>Any FHIR capability may be 'allowed' by the system unless explicitly marked as 'SHALL NOT'. A few items are marked as MAY in the Implementation Guide to highlight their potential relevance to the use case.</p></blockquote><h2 id="rest">FHIR RESTful Capabilities</h2><div class="panel panel-default"><div class="panel-heading"><h3 id="mode1" class="panel-title">Mode: <code>server</code></h3></div><div class="panel-body"><div class="lead"><em>Security</em></div><blockquote><div><p>FHIR requests carry a SMART access token issued by the Authorization Server configured
for the deployment. Deployments SHALL support SMART App Launch, SMART Backend
Services, or both, as defined in <a href="specification.html#authorization">Authorization</a>.
Supported modes are advertised for each imaging endpoint with the corresponding
capability http://fhir.org/argonaut/smart-imaging/capabilities/app-launch or
http://fhir.org/argonaut/smart-imaging/capabilities/backend-services (or both).
The Imaging Server validates the token and enforces granted scopes and underlying
access restrictions. App Launch requests SHALL match the token's patient context.
Backend Services requests SHALL be limited to the client's pre-authorized access;
system/ImagingStudy.rs does not grant access to all patients or studies.
Missing patient context SHALL NOT imply system-level access. Every WADO-RS
request SHALL carry the same SMART access token used for the authorized FHIR
request. A returned Endpoint address may be a capability URL; the DICOMweb
Server then validates the token, the capability, and their binding and enforces
all applicable restrictions. Capability issuance SHALL be limited to the data
and operations authorized by the FHIR request. Each retrieval SHALL enforce the
validation, lifetime, and revocation requirements in
<a href="specification.html#retrieving-images">Retrieving images</a>.</p>
</div></blockquote></div></div><h3 id="resourcesCap1">Capabilities by Resource/Profile</h3><h4 id="resourcesSummary1">Summary</h4><p>The summary table lists the resources that are part of this configuration, and for each resource it lists:</p><ul><li>The relevant profiles (if any)</li><li>The interactions supported by each resource (<b><span class="bg-info">R</span></b>ead, <b><span class="bg-info">S</span></b>earch, <b><span class="bg-info">U</span></b>pdate, and <b><span class="bg-info">C</span></b>reate, are always shown, while <b><span class="bg-info">VR</span></b>ead, <b><span class="bg-info">P</span></b>atch, <b><span class="bg-info">D</span></b>elete, <b><span class="bg-info">H</span></b>istory on <b><span class="bg-info">I</span></b>nstance, or <b><span class="bg-info">H</span></b>istory on <b><span class="bg-info">T</span></b>ype are only present if at least one of the resources has support for them.</li><li><span>The required, recommended, and some optional search parameters (if any). </span></li><li>The linked resources enabled for <code>_include</code></li><li>The other resources enabled for <code>_revinclude</code></li><li>The operations on the resource (if any)</li></ul><div class="table-responsive"><table class="table table-condensed table-hover"><thead><tr><th><b>Resource Type</b></th><th><b>Profile</b></th><th class="text-center"><b title="GET a resource (read interaction)">R</b></th><th class="text-center"><b title="GET all set of resources of the type (search interaction)">S</b></th><th class="text-center"><b title="PUT a new resource version (update interaction)">U</b></th><th class="text-center"><b title="POST a new resource (create interaction)">C</b></th><th><b title="Required and recommended search parameters">Searches</b></th><th><code><b>_include</b></code></th><th><code><b>_revinclude</b></code></th><th><b>Operations</b></th></tr></thead><tbody><tr><td><a href="#ImagingStudy1-1">ImagingStudy</a></td><td>Supported Profiles<br/> <a href="StructureDefinition-smart-imaging-study.html">SMART ImagingStudy</a></td><td class="text-center"/><td class="text-center">y</td><td class="text-center"/><td class="text-center"/><td>patient, identifier, _lastUpdated</td><td><code>ImagingStudy:endpoint</code></td><td/><td/></tr></tbody></table></div><hr/><div class="panel panel-default"><div class="panel-heading"><h4 id="ImagingStudy1-1" class="panel-title"><span style="float: right;">Resource Conformance: unspecified </span>ImagingStudy</h4></div><div class="panel-body"><div class="container"><div class="row"><div class="col-lg-4"><span class="lead">Core FHIR Resource</span><br/><a href="http://hl7.org/fhir/R4/imagingstudy.html">ImagingStudy</a></div><div class="col-lg-4"><span class="lead">Reference Policy</span><br/></div><div class="col-lg-4"><span class="lead">Interaction summary</span><br/><ul><li>Supports <code>search-type</code>.</li></ul></div></div><p/><div class="row"><div class="col-6"><span class="lead">Supported Profiles</span><p><a href="StructureDefinition-smart-imaging-study.html">SMART ImagingStudy</a></p></div></div><p/><div class="row"><div class="col-12"><span class="lead">Documentation</span><blockquote><div><p>The server SHALL support searching ImagingStudy by patient, alone and in
combination with <code>_lastUpdated</code> and <code>identifier</code> (a DICOM Study Instance UID
in <code>urn:oid:...</code> form). The server SHALL support <code>_include=ImagingStudy:endpoint</code>
so apps receive the WADO-RS Endpoint for each study. Apps SHALL resolve Endpoints
provided as response-local Bundle entries, separately addressable resources
included in the Bundle, or contained resources. Response-specific capability
Endpoints SHOULD use urn:uuid fullUrl values; the server SHALL include them on
the same Bundle page as each referencing study, even without an _include request.</p>
<p>Searches SHALL enforce the access rules in <a href="specification.html#finding-studies">Finding studies</a>:
patient-context mismatches and backend requests for unauthorized patients receive
403 Forbidden. Results and included Endpoints SHALL exclude unauthorized studies.
Neither authorization mode requires population-wide search.</p>
<p>If results are not yet available (for example, the server is querying an
underlying PACS), the server MAY respond <code>503</code> with a <code>Retry-After</code> header;
the app retries after the indicated number of seconds.</p>
</div></blockquote></div></div><div class="row"><div class="col-lg-7"><span class="lead">Search Parameters</span><table class="table table-condensed table-hover"><thead><tr><th>Conformance</th><th>Parameter</th><th>Type</th><th>Documentation</th></tr></thead><tbody><tr><td><b>SHALL</b></td><td><a href="http://hl7.org/fhir/R4/imagingstudy.html#search">patient</a></td><td><code>reference</code></td><td><div><p>The patient whose studies are requested. SHALL be supported alone and in combination with <code>_lastUpdated</code> or <code>identifier</code>.</p>
</div></td></tr><tr><td><b>SHALL</b></td><td><a href="http://hl7.org/fhir/R4/imagingstudy.html#search">identifier</a></td><td><code>token</code></td><td><div><p>A DICOM Study Instance UID in <code>urn:oid:...</code> form, used with <code>patient</code> to look up a specific study.</p>
</div></td></tr><tr><td><b>SHALL</b></td><td><a href="http://hl7.org/fhir/R4/resource.html#search">_lastUpdated</a></td><td><code>date</code></td><td><div><p>Used with <code>patient</code> to fetch only studies updated after a given time, e.g. <code>_lastUpdated=gt2023-04-17T04:00:00Z</code>.</p>
</div></td></tr></tbody></table></div><div class="col-lg-5"> </div></div></div></div></div></div>
</text>
<url
value="http://fhir.org/argonaut/smart-imaging/CapabilityStatement/smart-imaging-server"/>
<version value="0.1.0"/>
<name value="SmartImagingAccessServer"/>
<title value="SMART Imaging Access Server"/>
<status value="draft"/>
<date value="2026-09-23"/>
<publisher value="Argonaut Project"/>
<contact>
<name value="Argonaut Project"/>
<telecom>
<system value="url"/>
<value
value="https://confluence.hl7.org/display/AP/Argonaut+Project+Home"/>
</telecom>
</contact>
<description
value="Requirements for the Imaging FHIR Server. WADO-RS retrieval and SMART token
validation are specified in [Retrieving images](specification.html#retrieving-images)
and [Authorization](specification.html#authorization)."/>
<jurisdiction>
<coding>
<system value="http://unstats.un.org/unsd/methods/m49/m49.htm"/>
<code value="001"/>
<display value="World"/>
</coding>
</jurisdiction>
<kind value="requirements"/>
<fhirVersion value="4.0.1"/>
<format value="json"/>
<rest>
<mode value="server"/>
<security>
<description
value="FHIR requests carry a SMART access token issued by the Authorization Server configured
for the deployment. Deployments SHALL support SMART App Launch, SMART Backend
Services, or both, as defined in [Authorization](specification.html#authorization).
Supported modes are advertised for each imaging endpoint with the corresponding
capability http://fhir.org/argonaut/smart-imaging/capabilities/app-launch or
http://fhir.org/argonaut/smart-imaging/capabilities/backend-services (or both).
The Imaging Server validates the token and enforces granted scopes and underlying
access restrictions. App Launch requests SHALL match the token's patient context.
Backend Services requests SHALL be limited to the client's pre-authorized access;
system/ImagingStudy.rs does not grant access to all patients or studies.
Missing patient context SHALL NOT imply system-level access. Every WADO-RS
request SHALL carry the same SMART access token used for the authorized FHIR
request. A returned Endpoint address may be a capability URL; the DICOMweb
Server then validates the token, the capability, and their binding and enforces
all applicable restrictions. Capability issuance SHALL be limited to the data
and operations authorized by the FHIR request. Each retrieval SHALL enforce the
validation, lifetime, and revocation requirements in
[Retrieving images](specification.html#retrieving-images)."/>
</security>
<resource>
<type value="ImagingStudy"/>
<supportedProfile
value="http://fhir.org/argonaut/smart-imaging/StructureDefinition/smart-imaging-study"/>
<documentation
value="The server SHALL support searching ImagingStudy by patient, alone and in
combination with `_lastUpdated` and `identifier` (a DICOM Study Instance UID
in `urn:oid:...` form). The server SHALL support `_include=ImagingStudy:endpoint`
so apps receive the WADO-RS Endpoint for each study. Apps SHALL resolve Endpoints
provided as response-local Bundle entries, separately addressable resources
included in the Bundle, or contained resources. Response-specific capability
Endpoints SHOULD use urn:uuid fullUrl values; the server SHALL include them on
the same Bundle page as each referencing study, even without an _include request.
Searches SHALL enforce the access rules in [Finding studies](specification.html#finding-studies):
patient-context mismatches and backend requests for unauthorized patients receive
403 Forbidden. Results and included Endpoints SHALL exclude unauthorized studies.
Neither authorization mode requires population-wide search.
If results are not yet available (for example, the server is querying an
underlying PACS), the server MAY respond `503` with a `Retry-After` header;
the app retries after the indicated number of seconds."/>
<interaction>
<code value="search-type"/>
</interaction>
<searchInclude value="ImagingStudy:endpoint"/>
<searchParam>
<name value="patient"/>
<definition
value="http://hl7.org/fhir/SearchParameter/clinical-patient"/>
<type value="reference"/>
<documentation
value="The patient whose studies are requested. SHALL be supported alone and in combination with `_lastUpdated` or `identifier`."/>
</searchParam>
<searchParam>
<name value="identifier"/>
<definition
value="http://hl7.org/fhir/SearchParameter/clinical-identifier"/>
<type value="token"/>
<documentation
value="A DICOM Study Instance UID in `urn:oid:...` form, used with `patient` to look up a specific study."/>
</searchParam>
<searchParam>
<name value="_lastUpdated"/>
<definition
value="http://hl7.org/fhir/SearchParameter/Resource-lastUpdated"/>
<type value="date"/>
<documentation
value="Used with `patient` to fetch only studies updated after a given time, e.g. `_lastUpdated=gt2023-04-17T04:00:00Z`."/>
</searchParam>
</resource>
</rest>
</CapabilityStatement>