Technical Advantages of DiGA-Compliant FHIR Backend 'Fire Arrow'
DiGA-Compliant FHIR Backend (Germany) - Fire Arrow
Summary
The FHIR-native backend, Fire Arrow, supports compliance with Germany’s Digital Healthcare Act (DiGA). It excels by meeting strict security and interoperability requirements demanded by the BfArM, particularly regarding authentication, authorization, and adherence to domestic profiles like ISiK/KBV.
Details
This article introduces 'Fire Arrow,' an FHIR backend designed for compliance with Germany's Digital Healthcare Act (DiGA). The system focuses heavily on regulatory compliance and interoperability. Technically, it meets advanced security requirements mandated by DiGAV and BfArM. These include identity management via OAuth/OIDC, deny-by-default authorization, and comprehensive audit logging across REST, GraphQL, and bulk surfaces. For data subject rights, consent resources are stored as standard FHIR, supporting requests like full data export or resource deletion. In terms of interoperability, it adheres to German domestic profile families such as ISiK (for hospital systems) and KBV (for ambulatory care). Fire Arrow handles these profiles not through schema changes but via 'profile validation' configuration, simplifying maintenance as data models evolve. Its key strength is providing technical evidence required for DiGA manufacturers during the BfArM Fast-Track submission or continuous operational review. This allows developers to build a system with compliance built-in from the start.
Original content copyright by respective publishers