HealthRecordCommunity
FHIR🌏 GermanyEnriched

Technical Advantages of DiGA-Compliant FHIR Backend 'Fire Arrow'

DiGA-Compliant FHIR Backend (Germany) - Fire Arrow

May 23, 2026

Summary

The FHIR-native backend, Fire Arrow, supports compliance with Germany’s Digital Healthcare Act (DiGA). It excels by meeting strict security and interoperability requirements demanded by the BfArM, particularly regarding authentication, authorization, and adherence to domestic profiles like ISiK/KBV.

Details

This article introduces 'Fire Arrow,' an FHIR backend designed for compliance with Germany's Digital Healthcare Act (DiGA). The system focuses heavily on regulatory compliance and interoperability. Technically, it meets advanced security requirements mandated by DiGAV and BfArM. These include identity management via OAuth/OIDC, deny-by-default authorization, and comprehensive audit logging across REST, GraphQL, and bulk surfaces. For data subject rights, consent resources are stored as standard FHIR, supporting requests like full data export or resource deletion. In terms of interoperability, it adheres to German domestic profile families such as ISiK (for hospital systems) and KBV (for ambulatory care). Fire Arrow handles these profiles not through schema changes but via 'profile validation' configuration, simplifying maintenance as data models evolve. Its key strength is providing technical evidence required for DiGA manufacturers during the BfArM Fast-Track submission or continuous operational review. This allows developers to build a system with compliance built-in from the start.

📰
Read Original Article
firearrow.io

Original content copyright by respective publishers