FHIR for regulators: governance, sandbox, and compliance

Competent authorities set the scope, criteria, and oversight mechanisms for health-data standards. Depending on statutory functions and formal coordination decisions, Vietnam's Ministry of Health (BYT), Vietnam Social Security (BHXH), the Ministry of Science and Technology, the Ministry of Public Security, and other stakeholders may participate in different parts of a program. This page presents a reference FHIR governance framework; it does not assign legal duties to any agency.

Primary audience: leadership at the Ministry of Health, the Department of Medical Service Administration, the Department of Science, Technology and Training, Vietnam Social Security, the Ministry of Science and Technology, the Ministry of Public Security, legal affairs units, and policy advisory teams. The goal: understand the international benchmarks, map out a hybrid model that works for Vietnam, and avoid the common pitfalls of national interoperability programs.

TL;DR

  • A national program may need five governance functions: define scope, govern terminology, operate test environments and multi-party testing, assess conformance, and oversee deployed systems. Ownership must follow legal authority.
  • Three reference models: ONC (United States — top-down via the Cures Act §170.315(g)(10)), JAMI/MHLW (Japan — community-led, JP Core maintained by the JAMI FHIR Working Group), and eHDSI (EU — federation through national contact points).
  • One option for Vietnam is a hybrid model: test the trial-use VN Core through a multi-stakeholder Working Group, then consider recognition or binding requirements only when legal scope, conformance criteria, test infrastructure, and appropriate interoperability evidence exist. No fixed IG version or number of Connectathons automatically establishes readiness.
  • Proposed division of labor: BYT leads clinical scope and health terminology; BHXH participates in the Claim/EOB domain; the science-and-technology and public-security ministries participate within their mandates. Technical stewardship must be established through governance and is not implicitly held by this website.
  • Five common pitfalls: setting deadlines before the sandbox is ready, neglecting terminology governance, publishing standards without a Connectathon, locking the regulator into one vendor, and failing to plan a revision cycle for the IG.

1. Why regulators need to understand FHIR

Vietnam's 2025-2026 digital-health framework addresses electronic medical records, digital health data, and data connection in different scopes. Circular 13/2025/TT-BYT (effective 21/07/2025) sets EMR implementation timelines for hospitals and other healthcare facilities within its scope; Article 1(3) requires EMR information to be linked to the personal identification number of Vietnamese citizens and of foreign nationals who have been issued an electronic identification account. The Circular creates neither two alternative identifiers nor a requirement to use FHIR or a VNeID API. Decree 102/2025/NĐ-CP (effective 01/07/2025) governs digital health data. Decree 278/2025/NĐ-CP (effective 22/10/2025) governs mandatory data connection and sharing among agencies within the political system; it should not be generalized into an automatic FHIR obligation for every health facility.

Legal obligations and technical conformance are related but distinct layers. FHIR is a health-data exchange standard published by HL7 International; an Implementation Guide, test suite, and acceptance criteria can measure conformance for a defined use case. VN Core currently uses FHIR R4 4.0.1 as its trial-use baseline. Passing FHIR tests does not by itself demonstrate legal compliance, and adopting VN Core in Vietnam would require decisions by competent authorities plus the applicable legal, safety, and operational assessments.

If a competent authority selects FHIR for a defined scope, the governance program may include recognizing a canonical, governing Vietnamese code systems, publishing machine-readable releases, operating terminology and sandbox services, multi-party testing, conformance assessment, and change control. Allocation, funding, and recognition of each function require separate decisions. The canonical http://fhir.hl7.org.vn/core/ is currently only an Omi HealthTech-initiated trial-use build for technical comparison.

2. Five governance functions

International programs distribute the functions below in different ways across public authorities, standards bodies, testing organizations, and implementer communities. Vietnam can use this framework to analyze responsibilities; the final allocation must follow governing instruments and competent decisions.

2.1. Publishing a national Implementation Guide

An Implementation Guide (IG) is a packaged set of technical artifacts — profiles, extensions, terminology, and examples — that adapts FHIR to a national context. Vietnam currently has two products called VN Core IG, but with different origins. The first was published by the IT Department of the Ministry of Health (the unit's name at the time of publication) in the hl7vn/vn-core-ig repository, with canonical URL http://fhir.ehealth.gov.vn/core/ and package hl7.fhir.vn.core#1.0.0; it remains a draft CI build last updated in July 2024. The second is a trial-use open contribution initiated by Omi HealthTech at hl7.org.vn with canonical URL http://fhir.hl7.org.vn/core/, and is being built on a transparent roadmap. The important governance task ahead is technical comparison, canonical convergence, and scope approval through a national Working Group and formal Ministry of Health decision process.

Any recognition of an IG would require review of legal basis, authority, issuance procedure, and scope of application. Circular 13/2025/TT-BYT does not imply that FHIR or VN Core has been recognized, and this page cannot determine whether a Circular, Decision, or another instrument would be appropriate before legal review. Participation by BYT, BHXH, the Ministry of Science and Technology, and the Ministry of Public Security is a domain-based coordination proposal, not an approved assignment.

2.2. Terminology governance

FHIR conformance depends heavily on code-system identity, version, and binding rules. The Ministry of Health has issued many catalogs, including Decision 4469/QĐ-BYT (ICD-10 VN, 28/10/2020), Decision 1227/QĐ-BYT (laboratory indicators batch 1, 11/04/2025), Decisions 2427, 2493, and 2805/QĐ-BYT (SNOMED CT VN releases in 2025), Decision 387/QĐ-BYT (ICD-9-CM 2026, 05/02/2026), and Decision 3276/QĐ-BYT (codes for people presenting for care, 17/10/2025). Machine-to-machine use additionally requires confirmation of the authoritative source, licensing, versions, concept status, and distribution mechanism; a terminology server is one infrastructure option for this layer.

If a shared terminology service is implemented, it needs clear data ownership, a release cycle, versioning, and concept-status policy. FHIR operations such as $expand, $lookup, and $validate-code should be advertised only when supported and declared in the server's CapabilityStatement. Shared infrastructure can reduce divergence among local copies, but cost, availability, licensing, and the operating model require separate assessment.

2.3. Running sandboxes and Connectathons

A sandbox is a test environment separated from production, usually using synthetic data or data handled under an appropriate policy. A Connectathon is one form of multi-party testing used to surface different interpretations of a specification. The United States uses Inferno in certain ONC testing programs; Japan and Europe also run interoperability testing within their own program scopes. Each program must publish its frequency, access controls, and pass criteria.

This page has not confirmed a competent-authority publication establishing a national FHIR sandbox or Connectathon in Vietnam. One pilot option is to coordinate with regional testing communities and operate a sandbox for selected VN Core use cases. A FHIR server is only one component; the program also needs test-data governance, access control, terminology, test suites, monitoring, support, and an operating budget.

2.4. Vendor certification

The ONC Health IT Certification Program applies criteria and test procedures to Health IT Modules seeking certification; its legal scope is not identical to every EHR or healthcare facility in the United States. Vietnam could study module- and use-case-specific conformance assessment. FHIR, OAuth, or SMART criteria apply only when the relevant IG and interface contract require them. Passing FHIR tests is not equivalent to compliance with Law 91/2025, cybersecurity, clinical safety, or licensing rules; those layers require independent assessment.

When designing assessment, decision-makers should evaluate proportionality, accessibility for smaller implementers, conflicts of interest, and supplier-concentration risk. Assessment by module or use case is one option, but the level of scrutiny should follow risk and intended use rather than a single label for an entire product.

2.5. Compliance audit

Post-deployment oversight may combine self-assessment, remote testing with synthetic data, and risk-based on-site review. Any mandatory mechanism, response deadline, or linkage to operating licenses requires clear legal authority, due process, appeal rights, and data-protection controls. A test bundle measures only the criteria described in its test plan; it does not establish compliance with every legal obligation.

Remedies or sanctions depend on the applicable instrument, article, actor, conduct, and circumstances. A FHIR conformance error is not automatically an administrative violation, and this technical guidance does not determine penalty amounts. Implementing authorities should obtain legal review for each oversight and enforcement mechanism.

3. Three international reference models

ONC (United States), JAMI/MHLW (Japan), and eHDSI (EU) illustrate three different organizational approaches. The comparison below is analytical only; their legal scope, maturity, and implementation evidence are not directly equivalent.

3.1. ONC (United States) — top-down mandate

The Office of the National Coordinator for Health IT (ONC) sits within the U.S. Department of Health and Human Services (HHS). The 21st Century Cures Act (2016), together with the ONC Cures Act Final Rule (issued in 2020), established a detailed certification framework. Specifically: the §170.315(g)(10) criterion requires certified Health IT Modules and API developers to support a FHIR R4 standardized API for patient and population services, including the USCDI (US Core Data for Interoperability) data set via the US Core IG. The rule applies to certified modules; this indirectly constrains EHRs used by facilities receiving Medicare or Medicaid funding — but not every healthcare system in the country.

Useful features of the ONC approach include scoped criteria, published test procedures, and a defined relationship between specifications and a certification program. API, certification, and information-blocking rules have distinct actors, exceptions, and enforcement mechanisms; they should not be transplanted directly to Vietnam or read as one obligation applying to every U.S. health system.

3.2. JAMI/MHLW (Japan) — community-led, government-supported

Japan takes the consensus path. JP Core IG is developed and maintained by the JAMI FHIR Domestic Implementation Working Group, not issued as a binding standard by Japan's Ministry of Health, Labour and Welfare (MHLW). The current JP Core documentation states explicitly: developed by the JAMI FHIR domestic implementation group, and not yet approved by HL7 Japan. Even so, MHLW has many projects and policies supporting FHIR and health data standards (for example, promoting health information exchange), creating a favorable environment for community-led implementation.

A Working Group model allows hospitals, vendors, industry associations, and research institutions to review specifications together. The main lesson is to publish the issuing body, normative or trial-use status, voting process, and relationship to government policy. Release speed or adoption should not be characterized without comparable evidence.

3.3. eHDSI (EU) — federation

The European Health Data Space (EHDS) and the eHealth Digital Service Infrastructure (eHDSI) are coordinated by the European Commission. Each member state runs a National Contact Point for eHealth (NCPeH) that acts as a gateway. Two core use cases are already in production: Patient Summary (based on HL7's International Patient Summary) and ePrescription/eDispensation for travelers within the EU.

Federation separates national infrastructure from the cross-border exchange interface. It also requires coordinated governance of trust, identity, terminology, translation, conformance, and multi-party operations. Delivery time depends on each country's readiness and participation scope, so it cannot be reduced to a single adoption-speed label.

Criterion ONC (US) JAMI/MHLW (Japan) eHDSI (EU)
Spec author ONC + HL7 (US Core) JAMI FHIR WG (community) EC + member states
Enforcement mechanism Certification §170.315(g)(10) Recommendation + policy support Intergovernmental agreement
Test suite Inferno (official) JP Core test reports Gateway testing
Assessment basis Certification criteria and test procedures Working Group process and published artifacts Gateway conformance and cross-country agreements
Lesson for Vietnam Need a test suite + certification Multi-stakeholder Working Group is the key Separate domestic infrastructure from cross-border

4. A hybrid model for Vietnam

No model can be transferred unchanged to Vietnam. One option for consultation is a hybrid: competent authorities define policy outcomes, scope, and acceptance criteria, while a multi-stakeholder Working Group maintains technical artifacts through a public process. This option is viable only if accountability, decision rights, resources, and conflict-of-interest controls are explicit.

The overall structure could look like this:

Proposed framework — not an authorized assignment

[Authority deciding clinical and legal scope]
   ↓ defines use cases, covered actors, acceptance criteria, and oversight
[Designated data and terminology governance function]
   ↓ publishes authoritative sources, versions, licenses, and validation services
[Designated testing operator]
   ↓ sandbox, test suite, conformance reports, and incident management
[Payer and other bodies within their authority]
   ↓ domain requirements, reconciliation rules, and business evidence
[Technical steward recognized by participating parties]
   ↓ maintains the IG, issue log, versioning, and consensus process
[Healthcare facilities, vendors, academia, and community]
   ↓ implement use cases, test with peers, and submit evidence

If this model is selected, the trial stage needs entry and exit criteria, test infrastructure, and a defect process before binding requirements are considered. A Working Group can draft technical content, but competent authorities still decide scope, recognition, and accountability. This page does not assume a funding or operating assignment.

A potential value of the hybrid is separating policy decisions from detailed authoring while retaining public control. Its risks include unclear accountability and capture by one stakeholder group. Selection should therefore follow a capability assessment, stakeholder consultation, operating-cost analysis, and conflict-of-interest controls rather than assumptions about public-sector expertise or vendor behavior.

5. Proposed roles and technical stewardship

The table below describes potential participants and outputs for consultation. It is not an approved RACI matrix and does not replace instruments governing each body's functions and duties.

Unit Primary role Concrete output
Ministry of Health — Department of Science, Technology and Training; Department of Medical Service Administration May consider clinical scope, health terminology, and a recognition path within its authority If decided: use-case requirements, authoritative terminology sources, conformance criteria, and an appropriate instrument or guidance after legal review
Vietnam Social Security (BHXH) May provide payer-domain requirements and BHYT reconciliation evidence Business requirements, test data, and validation results against data standards issued by competent authorities, including Decisions 3176/QĐ-BYT and 697/QĐ-BYT
Ministry of Science and Technology Participate in standards, digital-transformation, or infrastructure matters within assigned functions Coordination input and technical requirements under current governing instruments; no FHIR-specific duty is inferred from Decree 55/2025/NĐ-CP
Ministry of Public Security + Government — cybersecurity and personal data protection Participate within assigned cybersecurity and personal-data-protection functions Applicable requirements under Law 116/2025, Law 91/2025, Decree 356/2025, and related instruments; a FHIR profile or security label is not treated as complete compliance evidence
A technical steward recognized by the participating parties Coordinate IG maintenance, the multi-stakeholder Working Group, and interoperability testing A transparent change process, issue log, test reports, and versioned releases
EHR and HIS vendors Implement agreed use cases and contribute test evidence Module-level conformance reports, CapabilityStatements, and deviation records; SMART or FHIR operations only where the applicable interface requires them
Hospitals Implement EMRs where Circular 13/2025 applies; join FHIR testing when a use case is selected Process, data-quality, safety, and interoperability evidence for an approved interface; Circular 13 does not itself mandate FHIR
Startups, research institutes, medical universities Innovation, medical AI, workforce development New use cases, FHIR-based clinical research, training programs

Important nuance: Decree 356/2025/NĐ-CP is a Government decree on personal data protection, with the Ministry of Public Security as the lead advising body. From 01/03/2025, the former Ministry of Information and Communications was merged into the Ministry of Science and Technology under Decree 55/2025/NĐ-CP, and network information security duties were transferred to the Ministry of Public Security. This page therefore separates the Ministry of Science and Technology's digital-transformation/standards role from the Ministry of Public Security's cybersecurity, network information security, and PDP role.

No financing model has been decided. Public funding, membership fees, event sponsorship, or public-private arrangements would each require separate review by competent authorities and participants, including conflict-of-interest controls. Omi HealthTech currently contributes the trial-use artifact set and technical dossier only; this website does not represent an Affiliate or an approved public program.

6. Readiness conditions for an HL7 Affiliate model in Vietnam

HL7 International is a non-profit headquartered in the United States and the steward of HL7 v2, v3, CDA, and FHIR. HL7 International runs an Affiliate program for individual countries: each nation can establish a formal member organization (an Affiliate) representing its national community within HL7 International. HL7 Japan, HL7 Korea, HL7 Singapore, HL7 Taiwan, and HL7 Australia already exist. Vietnam does not yet have an Affiliate.

Potential value if one is established

  • A formal coordination point with HL7 International under an approved Affiliate arrangement.
  • A domestic technical community that can review, test, and maintain Implementation Guides.
  • Stronger collaboration with regional Affiliates and participation in relevant standards activities.
  • A transparent mechanism for Connectathons, training, and intellectual-property governance.

Readiness gates, not committed dates

Stage Activity Expected outcome
1. Prepare Form a multi-stakeholder Working Group and publish its charter, voting rules, and conflict-of-interest policy Membership, scope, governance model, and a public issue channel
2. Demonstrate Publish a versioned trial-use IG; operate sandbox, terminology services, and multi-party testing Test reports, issue log, conformance criteria, and interoperability evidence
3. Consult Compare options with competent authorities, existing communities, and HL7 International Canonical matrix, legal-entity options, and formal-recognition prerequisites
4. Decide Submit an application or publish a path only after stakeholder agreement and relevant rules are satisfied A competent decision plus clear operating, funding, and transition plans

There is currently no recognition decision, legal entity, approved budget, or committed establishment date for an HL7 Affiliate in Vietnam. These stages are a readiness framework; specific requirements and privileges must be checked against HL7 International's rules in force when an application is made.

7. Five common pitfalls in national FHIR programs

Interoperability programs repeatedly encounter similar governance risks. Vietnam should control the following five risks through explicit criteria and implementation evidence.

Pitfall 1 — Mandating before infrastructure is ready

Binding requirements issued before there is a sandbox, terminology service, implementation guidance, and test suite can produce paper compliance without demonstrated interoperability. A mandate should follow a readiness assessment and testing evidence, not a fixed lead time assumed to fit every program.

Pitfall 2 — Skipping terminology governance

CodeSystem copies with different URIs, versions, or concept status can produce different validation results across systems. Issuing a catalog, publishing a machine-readable release, and operating a terminology service are separate layers. Their priorities should follow the use case, licensing constraints, and operating model.

Pitfall 3 — Publishing without a Connectathon

A legal instrument or an isolated validator result is not evidence of end-to-end interoperability. Multi-party testing can uncover interpretive, workflow, and operational gaps. A Connectathon is one method; a program may also use continuous test harnesses or supervised pilots. Frequency should follow release cadence, risk, and test capacity rather than a universal minimum.

Pitfall 4 — Vendor lock-in for the regulator

Disproportionate criteria, test suites that cannot be independently inspected, or dependency on one vendor's tooling can reduce participation and system substitutability. Controls may include public test artifacts, module- or use-case-level criteria, an appeal process, and conflict-of-interest disclosure. Effects on price and competition require separate market evidence.

Pitfall 5 — No revision cycle for the IG

FHIR, terminology, and law all evolve. Profiles need review when a new platform release, code-system release, or legal instrument appears. Without a review cadence, defect channel, and compatibility policy, an IG will drift from implementation reality. Governance should set the release cycle from the magnitude of change and the available testing capacity.

8. Frequently asked questions

Should the Ministry of Health issue a Circular making FHIR mandatory right away?

This page does not recommend a particular instrument or issuance date. Before considering binding requirements, competent authorities should define the use case, legal basis, covered actors, testable conformance criteria, operating infrastructure, transition arrangements, and impact assessment. An IG version or number of Connectathons is only an input, not an automatic legal threshold. Circular 13/2025 does not establish FHIR certification.

Do we need a new law, or is a Circular enough?

Only competent authorities and legal counsel can determine the appropriate instrument after the content, actors, and degree of obligation are defined. The 2023 Law on Medical Examination and Treatment, Circular 13/2025/TT-BYT, Decree 102/2025/NĐ-CP, and Decree 278/2025/NĐ-CP do not themselves recognize VN Core or FHIR. Any option must be checked against issuance authority, impact-assessment procedures, and the scope of each instrument.

Does the HL7 Affiliate carry membership fees?

Conditions, fee categories, and benefits may change under the current HL7 International rules and the type of membership or Affiliate relationship. A current quotation and terms should be obtained directly when the option is evaluated; this page does not assign Vietnam to a tier, estimate total cost, or prescribe funding allocation.

Can the community translate and redistribute the VN Core IG?

The trial-use VN Core artifact set at hl7.org.vn is published under CC-BY-4.0. Translation, redistribution, and derivative works must follow the license's attribution and modification-notice conditions. FHIR base artifacts, third-party terminology, and referenced content remain subject to their own licenses; VN Core's license does not automatically extend to them.

Will Vietnam Social Security share governance over Claim/EOB?

This requires a formal agreement. Current KCB output data for BHYT is governed through Ministry of Health Decisions, including Decision 3176/QĐ-BYT; BHXH's operational intake and reconciliation role does not itself confer co-publication authority over VN Core. The trial-use package currently contains element-level mappings and examples, not an end-to-end ConceptMap confirmed by BHXH. Any parallel or replacement path should be announced only after scope agreement and round-trip testing.

Who handles network information security after the 2025 government reorganization?

Coordination scope must be checked against the instruments governing each body's current functions at implementation time. At the design level, clinical requirements, digital standards and infrastructure, cybersecurity, and personal-data protection should be separate workstreams with confirmed accountable parties. FHIR security labels, AuditEvent, Consent, or SMART do not transfer legal responsibility among authorities or establish compliance by themselves.

9. Further reading and references

Other knowledge hub pages directly relevant to national FHIR governance:

Official legal references

  • TT-13-2025 — Circular 13/2025/TT-BYT: Electronic medical records (issued 06/06/2025, effective 21/07/2025).
  • ND-102-2025 — Decree 102/2025/NĐ-CP: Management of digital health data (issued 13/05/2025, effective 01/07/2025).
  • ND-278-2025 — Decree 278/2025/NĐ-CP: Data connection and sharing (effective 22/10/2025; standardization milestone 31/12/2026).
  • L-91-2025 — Law 91/2025/QH15: Personal Data Protection (effective 01/01/2026).
  • ND-356-2025 — Decree 356/2025/NĐ-CP: Implementation guidance for the PDP Law (effective 01/01/2026).
  • L-24-2018 — Law 24/2018/QH14: Cybersecurity (superseded by Law 116/2025/QH15 since 01/07/2026 — kept for legacy reference).
  • L-116-2025 — Law 116/2025/QH15: Cybersecurity (amended) (in force since 01/07/2026, replacing Law 24/2018/QH14).
  • QD-3176-BYT — Decision 3176/QĐ-BYT: KCB output data standard (29/10/2024).
  • QD-697-BYT — Decision 697/QĐ-BYT: KCB billing summary template (issued 19/03/2026, deployed 01/07/2026).

International model references

FHIR R4 technical references