About This Server

This server provides a complete implementation of the FHIR Specification using a 100% open source software stack.

This server is built from a number of modules of the HAPI FHIR project, which is a 100% open-source (Apache 2.0 Licensed) Java based implementation of the FHIR specification.

Data On This Server

We're excited to introduce our new data storage solution, designed specifically with the security and privacy needs of healthcare institutions like yours in mind. Our system uses what's called a "single-tenant FHIR server" to store your valuable patient data. Here’s what that means for you and why it’s important:

Single-Tenant Architecture: Lumidos FHIR

Think of a single-tenant architecture as having a secure, dedicated storage facility just for your hospital or clinic, unlike a multi-tenant architecture where multiple organizations share the same storage space. This dedicated environment ensures:

  • Enhanced Security: Your data is stored in its own isolated server environment. This minimizes risks from cyber threats that could potentially affect servers shared by multiple organizations.
  • Customized Performance and Reliability: Because the server is solely dedicated to your organization, it can be optimized specifically for your data and usage patterns, ensuring faster access and greater reliability.
  • Exclusive Control and Privacy: You have complete control over the server settings and access, reinforcing privacy and compliance with healthcare regulations such as HIPAA in the US.

Secure Access Through IPSec VPN and mTLS Connections

Access to your dedicated FHIR server is safeguarded by two robust security measures: IPSec VPN and mTLS connections. Here's how they work to protect your data:

  • IPSec VPN (Virtual Private Network): This creates a secure, encrypted tunnel over the internet between your network and our servers. It's as if you have a private, secure line directly to your dedicated server, making it extremely difficult for unauthorized parties to intercept or access your data.
  • mTLS (Mutual Transport Layer Security) Connections: mTLS adds another layer of security by requiring both the client (you) and the server (us) to authenticate each other before any data is exchanged. This ensures that only authorized devices and servers can communicate with each other, significantly reducing the risk of data breaches.

Peace of Mind

By choosing our single-tenant FHIR server secured with IPSec VPN and mTLS connections, you're not just getting a storage solution. You're ensuring that your patients' data is stored in a private, secure environment that's accessible only through the most secure connections. This commitment to security and privacy helps maintain your institution's reputation and trustworthiness, ultimately benefiting both you and the patients you serve.