This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| SMART on FHIR | |
|---|---|
| Name | SMART on FHIR |
| Developer | Health Level Seven International |
| Released | 2012 |
| Latest release | 2017 core profiles / ongoing updates |
| Programming languages | JavaScript, Java, C#, Python, Ruby |
| Platform | Web, mobile, cloud |
| License | Open clinical specification |
SMART on FHIR SMART on FHIR is an open specification that standardizes how third‑party applications connect to electronic health record platforms using the Fast Healthcare Interoperability Resources protocol and modern web authorization. It enables app portability across implementations such as Epic Systems Corporation, Cerner Corporation, Allscripts, Athenahealth, and cloud services from Amazon Web Services, Microsoft Azure, and Google Cloud Platform. The framework combines resources, profiles, and scopes to permit granular data access for applications used by clinicians, researchers, and patients affiliated with institutions like Mayo Clinic, Cleveland Clinic, Johns Hopkins Hospital, and national initiatives such as ONC programs.
SMART on FHIR builds on the HL7 ecosystem by defining standardized APIs, data profiles, and launch sequences that let applications authenticate, authorize, and exchange clinical data with systems including Veterans Health Administration installations and regional health information exchanges such as CommonWell Health Alliance. It aligns with privacy and interoperability efforts exemplified by Meaningful Use and the 21st Century Cures Act, supporting workflows in ambulatory settings at organizations like Kaiser Permanente and academic centers including Massachusetts General Hospital and Stanford Health Care. SMART bridges terminologies used by SNOMED CT, LOINC, and RxNorm to deliver contextually accurate data for apps deployed by vendors such as IBM Watson Health and research platforms developed at Harvard Medical School and Mount Sinai Health System.
SMART originated as a project at Boston Children’s Hospital and Harvard Medical School with stakeholders including Partners HealthCare and contributors from MIT and Brigham and Women’s Hospital. Early collaborations involved OpenMRS, i2b2, and the Sutter Health network, while governance transitioned to Health Level Seven International to harmonize with the FHIR specification developed by HL7 International. Major milestones mirror policy shifts led by Centers for Medicare & Medicaid Services and Office of the National Coordinator for Health Information Technology; pilot programs at Stanford Medicine and demonstrations at conferences like HIMSS accelerated adoption. Subsequent integration work included partnerships with vendors such as Oracle Cerner and initiatives by Google Health and Microsoft HealthVault‑adjacent projects.
The SMART architecture comprises a launch framework, a set of FHIR profiles, and an authorization model based on OAuth 2.0 and OpenID Connect. Core components include the SMART Launch Sequence used by [EHR] platforms like Epic, an authorization server pattern adopted by Cerner, and a resource model mapped to clinical terminologies such as SNOMED CT and LOINC. Implementations often use SDKs and tools from communities around SMART Health IT, libraries implemented in Node.js, Java Spring, .NET Core, and Python Flask, and developer portals operated by vendors including Allscripts and cloud partners like Amazon and Microsoft.
Security in SMART leverages industry standards exemplified by OAuth 2.0 and OpenID Connect plus best practices advocated by NIST and ISO. Authorization scopes enable least‑privilege access to FHIR resources referenced by clinical systems at Johns Hopkins Hospital and regulatory compliance regimes driven by HIPAA and policy work by ONC. Deployments in enterprise settings integrate with identity providers like Okta, Ping Identity, and Active Directory Federation Services used across health systems including Intermountain Healthcare and Geisinger Health System. Auditing and consent management are addressed in implementations interfacing with research infrastructures such as NIH‑funded networks and trial platforms at Fred Hutchinson Cancer Center.
SMART supports clinical decision support apps at institutions like Brigham and Women’s Hospital, patient-facing portals deployed by Kaiser Permanente and Mayo Clinic, research recruitment tools used by All of Us Research Program, and population health dashboards integrated by CDC partners. Use cases include medication management with data from RxNorm mappings, lab result normalization via LOINC, genomic data integration in projects at Broad Institute and Regeneron, and clinical trial eligibility screening used by networks such as PCORI. Commercial and open‑source apps appear in app galleries run by vendors like Epic App Orchard and initiatives hosted by SMART Health IT and HL7 connectathons.
Adoption has been driven by certification programs, vendor marketplaces, and national strategies led by entities such as ONC, CMS, and multinational consortia including IHE International. SMART interoperate with standards and vocabularies from SNOMED International, LOINC Committee, and RxNorm maintainers; it is referenced in guidance from WHO and integration work by corporate collaborators including IBM, Google, Microsoft, and startups incubated at MIT Media Lab and Harvard Innovation Labs. Standards alignment is routinely validated at interoperability events such as IHE Connectathon and conferences like HL7 FHIR DevDays.
Challenges include variation in vendor FHIR implementations across platforms like Epic and Cerner, inconsistent adoption of profiles and terminologies from SNOMED CT and LOINC Committee, and operational hurdles noted by health systems such as Vanderbilt University Medical Center and UC San Diego Health. Regulatory uncertainty at times involves interplay with HIPAA enforcement and policy updates from ONC and CMS, while technical constraints include performance and scalability on infrastructures like AWS and Azure, and the need for robust identity federation using providers like Okta and Ping Identity. Work remains to reconcile semantic interoperability, privacy consent models advocated by Office for Civil Rights and to support longitudinal data use in research consortia including All of Us and NCATS.
Category:Health information technology