Standards Directory
A standard is only useful if you know what it is for. The most common architectural mistake in this area is substitution: using a classification where a terminology is needed, an exchange format where an information model is needed, or an identity protocol where an authorisation model is needed.
The tables below state each standard's owner, its domain, and the architecture layer it belongs to.
Last verified: 2026-08-24. Versions move; check the official URL before citing a version number in a specification.
Exchange and messaging
| Standard | Organisation | Domain | Purpose | Availability | Layer |
|---|---|---|---|---|---|
| HL7 FHIR | HL7 International | Health data exchange | Resource model + REST API for clinical and administrative data | Free, CC0 for the specification | Data / Integration |
| HL7 v2 | HL7 International | Hospital messaging | Event-driven pipe-delimited messages: ADT, orders, results | Specification requires membership or purchase | Integration |
| HL7 CDA | HL7 International | Clinical documents | XML clinical documents with a fixed header and constrained body | Specification requires membership or purchase | Data |
| DICOM | DICOM Standards Committee (NEMA) | Medical imaging | Image format, metadata model and network services | Free | Data / Integration |
| DICOMweb | DICOM Standards Committee | Medical imaging | RESTful services for DICOM (WADO-RS, STOW-RS, QIDO-RS) | Free | Integration |
| IHE profiles | IHE International | Integration use cases | Constrained combinations of standards for named workflows (PIX/PDQ, XDS, ATNA, MHD) | Free | Integration |
| X12 (270/271, 837, 835) | ASC X12 | Administrative / claims | Eligibility, claims and remittance in the United States | Licensed | Integration |
Terminology and classification
The distinction that matters: a terminology describes clinical meaning for the record; a classification groups things into mutually exclusive categories for counting. You encode with the first and report with the second.
| Standard | Organisation | Domain | Purpose | Availability | Layer |
|---|---|---|---|---|---|
| SNOMED CT | SNOMED International | Clinical terminology | Concepts, descriptions and relationships for clinical meaning | Member-country licensing; free in member countries and for some uses | Information |
| LOINC | Regenstrief Institute | Laboratory and clinical observations | Universal identifiers for tests, measurements and instruments | Free, licence required | Information |
| ICD-10 / ICD-11 | WHO | Classification of diseases | Morbidity and mortality statistics, reimbursement | Free (ICD-11 via WHO), licence terms apply | Information |
| ICF | WHO | Functioning and disability | Classifying functioning, disability and health | Free | Information |
| ICPC-2/3 | WONCA / ICPC Foundation | Primary care | Reason for encounter, problems and process in primary care | Licensed | Information |
| RxNorm | US National Library of Medicine | Drug terminology | Normalised names and codes for clinical drugs (US-centric) | Free | Information |
| ATC/DDD | WHO Collaborating Centre for Drug Statistics Methodology | Drug classification | Anatomical Therapeutic Chemical classification and defined daily doses | Free to browse; licensing for bulk use | Information |
| UCUM | Regenstrief Institute | Units of measure | Unambiguous, computable units | Free | Information |
| ICD-O | WHO / IARC | Oncology | Topography and morphology of neoplasms | Free | Information |
On CPT: Current Procedural Terminology is owned by the American Medical Association and is licensed, US-specific, and not freely redistributable. Use it only where the jurisdiction requires it.
On national terminologies: many countries maintain their own drug dictionaries, procedure lists and facility taxonomies. These are legitimate and often unavoidable; the architectural requirement is that they live in a terminology service with published value sets and maps, not in each application's database.
Clinical information models
| Standard | Organisation | Domain | Purpose | Availability | Layer |
|---|---|---|---|---|---|
| openEHR | openEHR International | Clinical data | Two-level modelling: a stable reference model plus archetypes and templates | Open specifications, CKM archetypes openly licensed | Data |
| ISO 13606 | ISO/CEN | EHR communication | Reference model and archetypes for EHR extract communication | Purchase from ISO | Data |
| HL7 v3 RIM | HL7 International | Reference information model | Underlies CDA; largely superseded by FHIR for new work | Membership/purchase | Data |
| OMOP CDM | OHDSI | Observational research | Common data model for analysing observational health data at scale | Open | Data / Analytics |
Identity, security and authorisation
| Standard | Organisation | Domain | Purpose | Availability | Layer |
|---|---|---|---|---|---|
| OAuth 2.0 | IETF | Authorisation | Delegated access to APIs via tokens | Free (RFC 6749 and successors) | Security |
| OpenID Connect | OpenID Foundation | Identity | Authentication layer over OAuth 2.0 | Free | Security |
| SMART App Launch | HL7 | Health app authorisation | Launch context and scopes for FHIR apps | Free | Security / Integration |
| SAML 2.0 | OASIS | Federated identity | Browser-based single sign-on, common in enterprise and government | Free | Security |
| ISO/IEC 27001 | ISO/IEC | Information security | Management system for information security | Purchase | Security / Governance |
| ISO 27799 | ISO | Health information security | Applying ISO 27002 controls to personal health information | Purchase | Security |
| NIST Cybersecurity Framework | NIST | Security governance | Organising cybersecurity activity: govern, identify, protect, detect, respond, recover | Free | Governance |
| NIST SP 800-207 | NIST | Zero trust | Zero trust architecture reference | Free | Security |
Decision support and guidelines
| Standard | Organisation | Domain | Purpose | Availability | Layer |
|---|---|---|---|---|---|
| CQL | HL7 | Clinical logic | Author-friendly language for expressing clinical decision logic and measures | Free | Application |
| CDS Hooks | HL7 / Boston Children's | Decision support | Hook points in clinical workflow for external decision services | Free | Integration |
| FHIR Clinical Reasoning module | HL7 | Guidelines | PlanDefinition, ActivityDefinition, Library, Measure | Free | Data |
| BPMN 2.0 | OMG | Process modelling | Notation for business processes; used by WHO Digital Adaptation Kits | Free | Process |
| DMN | OMG | Decision modelling | Decision tables and logic, complements BPMN | Free | Process |
Choosing between overlapping standards
| If you need to… | Use | Not |
|---|---|---|
| Move a lab result between two systems | FHIR Observation or HL7 v2 ORU^R01 | An ad-hoc CSV |
| Record what the clinician meant | SNOMED CT | ICD |
| Count cases for a national report | ICD | SNOMED CT alone |
| Name a laboratory test | LOINC | A local test code alone |
| Model a clinical concept for long-term storage | openEHR archetypes, or FHIR profiles if exchange-driven | A bespoke database schema |
| Share an imaging study | DICOM / DICOMweb | A JPEG export |
| Let a third-party app read a patient's record | SMART on FHIR | An API key emailed to the vendor |
| Prove who accessed what | FHIR AuditEvent / IHE ATNA | Application logs |
Overlap is normal. FHIR and openEHR are complementary far more often than they are alternatives — see the comparison in openEHR.
In this section
Exchange — HL7 FHIR · HL7 v2 · CDA · DICOM
FHIR ecosystem — Implementation guides · SMART on FHIR · Bulk Data
Terminology — SNOMED CT · LOINC · ICD · Terminology services
Clinical models — openEHR
References
- HL7 International — https://www.hl7.org/
- HL7 FHIR specification — https://hl7.org/fhir/
- DICOM standard — https://www.dicomstandard.org/
- SNOMED International — https://www.snomed.org/
- LOINC — https://loinc.org/
- WHO ICD-11 — https://icd.who.int/
- UCUM — https://ucum.org/
- openEHR — https://openehr.org/
- OHDSI OMOP CDM — https://www.ohdsi.org/data-standardization/
- IHE — https://www.ihe.net/
- NIST Cybersecurity Framework — https://www.nist.gov/cyberframework
- NIST SP 800-207 Zero Trust Architecture — https://csrc.nist.gov/pubs/sp/800/207/final
- OMG BPMN — https://www.omg.org/spec/BPMN/