Skip to main content
Webhook event is sent when an external HIP pushes encrypted health data to your HIU. The Health Information User (HIU) can initiate a consent request through the Consent-API to get care context data. Once consent is validated, the Health Information Provider (HIP) sends the encrypted health data to the HIU.

Request

Headers: Body:

Field Descriptions

  • data: Contains additional details related to the event.
    • consent_id: Consent id for the data transfer
    • transaction_id: Transaction id for the data flow
    • entries: List of care contexts with encrypted fhir data
    • key_information : Contains the cryptographic key material and related parameters required for secure ECDH-based key exchange between HIU and HIP.
      • crypto_alg The cryptographic algorithm used for key exchange (e.g., “ECDH”).
      • curve The elliptic curve used in ECDH key generation (e.g., “Curve25519”, “P-256”).
      • dh_public_key Object containing the HIU’s public key and related metadata:
        • expiry The expiration timestamp (in ISO 8601 format) indicating how long the public key is valid.
        • parameters Additional parameters related to the ECDH key (optional or curve-specific).
        • key_value The base64-encoded public key value generated by the HIU.
      • nonce A 32-byte random nonce (Base64-encoded) generated by the HIU, used to ensure uniqueness in the session key derivation.