Skip to main content

Roadmap

Status: In active development  ·  Target: Q3 2026

PhaseTasksWhat gets built
FoundationT1–T4ConsentRecord JPA, ConsentService, FHIR Consent mapper, AuditService
EnforcementT5–T6ConsentEnforcementInterceptor, SmartConsentCustomizer
OAuth2 screenT7–T8requireAuthorizationConsent(true), Thymeleaf consent screen
Patient portalT9–T11Dashboard, revocation flow, history + audit trail
API + adminT12–T14FHIR REST API, org-level policy engine, integration tests

Regulatory coverage: HIPAA, HTI-1/TEFCA, GDPR/EHDS, DISHA, My Health Record

ATNA Audit

  • IHE ATNA-compliant FHIR AuditEvent logging
  • Async @EventListener — never blocks request path
  • Every auth event, consent decision, and FHIR access logged
  • Queryable via FHIR API

v1.2.0 — Referral Module

Status: Planned  ·  Target: Q4 2026

  • FHIR ServiceRequest + Task workflow
  • Cross-facility referral with status tracking
  • Integrates with Consent Manager for access control

Versioning policy

We track HAPI FHIR stable releases. When HAPI releases a new minor version, we validate and publish a matching platform release within 2–4 weeks. Security patches are released within 24 hours of a confirmed vulnerability for Enterprise and Government customers.

Version format: {hapi-major}.{hapi-minor}.{platform-patch}

Example: Platform 7.4.2 = HAPI FHIR 7.4.x, platform patch 2.


Long-term alignment

FrameworkTarget versionTimeline
SMART App Launch v3.0 (when published)Full supportWithin 90 days of HL7 publication
IHE MHDv4.2v1.3.0
SMART Backend Servicesv2.0v1.3.0
FHIR R5Optional overlayv2.0.0