Fine-Grained Access Control

Rostislav Antonov
April 11, 2025
3 min

Access Control

How can confidentiality of data be ensured and access to these data be controlled among system users, considering different access levels and data sensitivity?

FGAC (Fine-Grained Access Control) lets you manage resource access at varying levels of detail. You can start by controlling access to entire resources, but sometimes you need even finer control. For example, you might allow all users to see a resource but hide certain fields from some of them.

With Aidbox Label-Based Access Control (an implementation of FHIR Security Labels), you can apply security labels not only to an entire resource but also to individual fields within that resource, allowing access management on the resource element level.

To achieve this add security labels to the resource fields you want to protect (using an extension). Then assign security labels to your users. When a request is made, Aidbox FHIR server compares the user’s labels to the resource’s labels and hides any fields that don’t match.
‍

Fine-Grained Access Control

For details: documentation

How did you like the article?
Be the first to know!
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

contact us

Get in touch with us today!

By submitting the form you agree to Privacy Policy and Cookie Policy.
Thank you!
We’ll be in touch soon.

In the meantime, you can:
Oops! Something went wrong while submitting the form.

Never miss a thing
Subscribe for more content!

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
By clicking “Subscribe” you agree to Health Samurai Privacy Policy and consent to Health Samurai using your contact data for newsletter purposes