FHIR Pilot

Security & data handling

A deliberately narrow boundary for FHIR preflight work.

FHIR Pilot is designed for authorised non-production testing. The current service does not require production access, PHI or secrets in the public intake flow.

The operating boundary

We treat the official test-kit version, selected groups, test scope and data boundary as part of the deliverable, not fine print. Public unauthenticated endpoints may use the connected route; credentialed environments use zero-access unless a separate secure-access gate is approved.

Authorised sandboxConfirmed suiteSanitised evidenceScoped report

Service controls

Controls applied to every accepted scope.

01

Scope before access

The FHIR version, profile, endpoint class, checks and access route are recorded before execution. Unsupported and excluded checks remain visible.

02

Non-production only

FHIR Pilot accepts authorised sandbox or test environments. Production systems and protected health information are prohibited.

03

Least-privilege by scope

Baseline connected checks are read-only. Any additional interaction required by a confirmed official suite must be explicitly authorised, limited to test data and remain inside the recorded boundary.

04

No secrets in intake

The public request form rejects endpoint URLs and common credential patterns. Credentials are never requested by email or stored in the inquiry record.

05

Zero-access alternative

If external access is not acceptable, execution stays in your environment and only sanitised evidence enters the review workflow.

06

Minimal retention

Inquiry and first-party funnel records are automatically pruned after 90 days. Optional Google Analytics event data is set to 14 months. Customer report retention is agreed per scope.

Data map

What enters the system and why.

DataPurposeDefault retentionBoundary
Inquiry detailsScope and respond to a requestAutomatically pruned after 90 daysEmail, company, optional role, route and non-sensitive context; a copy is delivered to the private GPT Work operations group via Telegram
First-party eventsMeasure page and funnel performanceAutomatically pruned after 90 daysNo cookies, advertising identifiers or form contents
Optional Google AnalyticsUnderstand acquisition, engagement and conversion14 months for event-level dataLoaded only after consent; no form contents, Google Signals, ad personalisation, user ID or PHI
Temporary access materialRun an approved connected scopeDefined by the written scopeNot submitted through the website; zero-access is the default for credentialed suites
Customer reportDeliver findings and evidenceAgreed before paid workNo retained FHIR payload bodies unless explicitly required and authorised

Connected-run gate

Every gate must pass before access.

Public unauthenticated sandboxes may use the connected route. Credentialed scopes use zero-access by default and move to connected execution only after a separate secure-access gate is approved in writing.

  • HTTPS endpoint and ownership/authority confirmation
  • Approved non-production host and exact path
  • Public/private network checks and host allowlisting
  • Redirect, port and method restrictions
  • Rate, response-size and timeout limits
  • Purpose-built temporary-secret channel before credentials are ever accepted

Zero-access route

Keep execution inside your boundary.

  • Your team controls execution and secrets
  • Only sanitised output is submitted for review
  • No patient identifiers or payload bodies
  • The same scope, finding and remediation model
  • One shareable stakeholder report

Explicitly outside the current service

Production accessPHI / sensitive patient dataPenetration testingCertification claimsHIPAA BAARegulatory or legal approvalUnapproved third-party endpointsInteractions outside the confirmed suite

Public sample runs use public demo/test environments and are labelled accordingly.

Security question or incident?

Contact support@digitalcognitivesolutions.com. Include a request/report reference, but do not send credentials, endpoint URLs, PHI or FHIR payloads by email.

Request free diagnostic