openapi: 3.1.0 info: title: Orion Health FHIR Alerts Audit API description: The Orion Health FHIR API provides standards-based access to healthcare data using the HL7 FHIR (Fast Healthcare Interoperability Resources) specification. It enables healthcare organizations to read, search, create, and update clinical resources including patients, encounters, observations, conditions, medications, allergies, procedures, diagnostic reports, and care plans. The API conforms to FHIR R4 (v4.0.1) and supports both JSON and XML representations. version: 1.0.0 contact: name: Orion Health API Support email: apisupport@orionhealth.com url: https://www.orionhealth.com/support license: name: Proprietary url: https://www.orionhealth.com/terms-of-service termsOfService: https://www.orionhealth.com/terms-of-service servers: - url: https://api.orionhealth.com/fhir description: Production FHIR Server - url: https://sandbox.orionhealth.com/fhir description: Sandbox FHIR Server security: - oauth2: [] - bearerAuth: [] tags: - name: Audit description: Audit log access for compliance paths: /audit-logs: get: operationId: searchAuditLogs summary: Orion Health Search audit logs description: Search audit logs for data access and exchange events within the HIE network for compliance and accountability purposes. tags: - Audit parameters: - name: patientId in: query schema: type: string - name: userId in: query schema: type: string - name: action in: query schema: type: string enum: - query - retrieve - submit - update - consent-change - name: dateFrom in: query schema: type: string format: date-time - name: dateTo in: query schema: type: string format: date-time - name: outcome in: query schema: type: string enum: - success - failure - denied - $ref: '#/components/parameters/PageOffset' - $ref: '#/components/parameters/PageLimit' responses: '200': description: Audit log entries content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/AuditLogEntry' pagination: $ref: '#/components/schemas/Pagination' '401': $ref: '#/components/responses/Unauthorized' '403': description: Insufficient permissions for audit access content: application/json: schema: $ref: '#/components/schemas/Error' components: parameters: PageLimit: name: limit in: query description: Maximum number of items to return schema: type: integer minimum: 1 maximum: 100 default: 20 PageOffset: name: offset in: query description: Number of items to skip schema: type: integer minimum: 0 default: 0 schemas: Error: type: object properties: code: type: string message: type: string details: type: array items: type: object properties: field: type: string message: type: string AuditLogEntry: type: object properties: id: type: string format: uuid timestamp: type: string format: date-time action: type: string enum: - query - retrieve - submit - update - consent-change outcome: type: string enum: - success - failure - denied patientId: type: string userId: type: string userName: type: string organization: type: string organizationName: type: string resourceType: type: string resourceId: type: string sourceIp: type: string details: type: string Pagination: type: object properties: offset: type: integer limit: type: integer total: type: integer hasMore: type: boolean responses: Unauthorized: description: Authentication required content: application/json: schema: $ref: '#/components/schemas/Error' securitySchemes: oauth2: type: oauth2 description: OAuth 2.0 authorization using SMART on FHIR flows: authorizationCode: authorizationUrl: https://auth.orionhealth.com/oauth2/authorize tokenUrl: https://auth.orionhealth.com/oauth2/token scopes: patient/*.read: Read access to all patient data patient/*.write: Write access to all patient data patient/Patient.read: Read access to Patient resources patient/Observation.read: Read access to Observation resources patient/Condition.read: Read access to Condition resources patient/MedicationRequest.read: Read access to MedicationRequest resources launch: Launch context openid: OpenID Connect fhirUser: FHIR user identity bearerAuth: type: http scheme: bearer bearerFormat: JWT