Architecture, compliance, and product writing
Long-form thinking on the FHIR backend layer, the access boundary that gates clinical data, and the regulatory frameworks that shape both. Written by the team that builds Fire Arrow.
Looking for release notes and the changelog?
See docs.firearrow.io/changelog →
-
DST Is Where Scheduling Systems Go to Die
FHIR's permissive timestamp types let scheduling bugs hide until daylight saving lands. The fix is to store wall-clock time with its IANA timezone, not an offset.
Read post → -
The FHIR Authorization Tax
Why authorization in a FHIR backend is harder than it looks, what the standard pattern is for getting it right, and how a default-deny rule chain at the data layer pays back over the life of the product.
Read post → -
Why We Built Fire Arrow
An origin post on the FHIR backend we kept rewriting on customer projects, and the architectural decisions that became the product.
Read post →