generated: '2026-07-19' method: searched source: https://developer.lifen.fr/docs/platform-services-documentation standards: - id: hl7-fhir-r4 conforms: true evidence: >- "Lifen uses the FHIR standard on the R4 version" — platform services documentation. Resources exposed: Patient, Coverage, Encounter, Appointment, Practitioner, Organization, CommunicationRequest, DocumentReference, Binary, Bundle, OperationOutcome. source: https://developer.lifen.fr/docs/platform-services-documentation - id: hl7-fhir-search conforms: true evidence: Search uses the FHIR POST {ResourceType}/_search form with _count/_sort/_id parameters and returns a searchset Bundle. source: https://developer.lifen.fr/docs/api-basics - id: hl7-fhir-operationoutcome conforms: true evidence: All error bodies are FHIR OperationOutcome resources with severity/code/diagnostics issues. source: https://developer.lifen.fr/docs/api-basics - id: hl7-v2-oru conforms: true evidence: Documents sent to hospital EHRs are delivered as HL7 ORU messages; the sending application name is carried in MSH-3. source: https://developer.lifen.fr/changelog/exposer-le-nom-de-lapplication-émettrice-dun-document-dans-le-dpi - id: mssante conforms: true evidence: The MSS API Service sends medical documents to healthcare professionals over the French national MSSanté secure health messaging standard. source: https://developer.lifen.fr/docs/send-a-document-to-healthcare-professional - id: ins-identite-nationale-de-sante conforms: true evidence: Patient resources expose the INS/NIA matricule only when the INS is qualified, per the French national patient-identity referencing rules. source: https://developer.lifen.fr/changelog/ne-plus-exposer-le-matricule-ins-si-il-nest-pas-qualifié - id: oauth2 conforms: true evidence: Machine-to-machine access uses the OAuth 2.0 client credentials grant against https://authentication.lifen.fr/v1/token. source: https://developer.lifen.fr/docs/machine-to-machine-communications - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: https://authentication.lifen.fr/.well-known/oauth-authorization-server returns 200 with issuer, authorization_endpoint, token_endpoint, jwks_uri, scopes_supported. source: well-known/lifen-oauth-authorization-server.json - id: oidc conforms: true evidence: The SSO API is an OIDC authorization-code flow with PKCE (S256) against issuer https://login.lifen.fr/, with openid/profile/email/address/phone/offline_access scopes. source: https://developer.lifen.fr/docs/sso-api - id: rfc7636-pkce conforms: true evidence: code_challenge_methods_supported = ["S256"] in the authorization-server metadata. source: well-known/lifen-oauth-authorization-server.json - id: llmstxt conforms: true evidence: https://developer.lifen.fr/llms.txt returns 200 with an llms.txt-format index of the documentation. source: llms/lifen-llms.txt - id: iso-27001 conforms: true evidence: >- "Certifications ISO 27001 et HDS" — Lifen health-data security page; Lifen states it is subject to regular audits against ISO 27001. source: https://www.lifen.fr/nos-expertises/securite-des-donnees-de-sante - id: hds-hebergeur-de-donnees-de-sante conforms: true evidence: Lifen solutions are certified Hébergeur de Données de Santé (the French health-data hosting certification). source: https://www.lifen.fr/nos-expertises/securite-des-donnees-de-sante - id: gdpr conforms: true evidence: Lifen states regular audits for RGPD/GDPR compliance and was among the first three innovative companies given reinforced support by the CNIL. source: https://www.lifen.fr/nos-expertises/securite-des-donnees-de-sante - id: rfc9457-problem-details conforms: false evidence: Errors use FHIR OperationOutcome as application/json, not application/problem+json. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support is documented. - id: idempotency-key conforms: false evidence: No idempotency key header or parameter is documented or present in the OpenAPI. - id: asyncapi conforms: false evidence: Lifen documents a webhook event catalog but publishes no AsyncAPI document. - id: soc2 conforms: false evidence: No SOC 2 attestation is published; Lifen's certification posture is ISO 27001 + HDS. - id: fapi conforms: false - id: scim conforms: false - id: odata conforms: false - id: json-api conforms: false - id: grpc conforms: false