Taiwan's Ministry of Health and Welfare launched a medical informatics certification laboratory on August 18, 2026. The ministry, Taiwan's central health and welfare policy agency, plans certification tracks for software, hardware running Fast Healthcare Interoperability Resources (FHIR) Box and solution providers. FHIR Box is Taiwan's interoperability and application layer above existing hospital systems.

The planned tests do not show whether connected records are suitable for an artificial intelligence model or whether a model will perform safely at another hospital. The distinction matters wherever a health system uses an interoperability layer to connect medical AI with electronic records. The six checks below separate technical conformance from the clinical, operational and governance evidence needed for deployment.

FHIR solves exchange, not fitness for AI

HL7 International defines FHIR as a standard for exchanging health information electronically and describes Resources as its basic building blocks. Profiles can constrain fields, cardinality, terminology bindings, data types and extensions for a particular implementation. Those rules describe the shape and meaning of an exchange, not the accuracy of the source record.

Two hospitals can use different FHIR releases, implementation guides, profiles, extensions and code systems while both describe their systems as FHIR-based. Each deployment therefore needs a mapping record that identifies required fields, local codes, units, time stamps and the handling of missing or invalid values. Model outputs written back to a record also need provenance, model version, time stamps, user actions and an audit trail.

HL7's SMART App Launch guide defines OAuth 2.0-based patterns for applications to authorize, authenticate and connect to FHIR systems, with scopes that limit delegated access. That access layer does not determine whether a hospital has granted the right people the right permissions or whether the data and model are clinically reliable.

A medical AI model moves from a development hospital through data mapping, external validation, workflow testing and audit retention

Conformant records can still contain poor data

A laboratory value can fit a valid FHIR resource while carrying the wrong unit, a shifted time stamp or a local code that was mapped incorrectly. Missing values and differences in how hospitals label diagnoses or outcomes can also alter the population represented in a dataset. An interface can transmit each problem without detecting it.

A 2023 systematic review led by Abigail Lewis included 103 papers and found that completeness was the most common data-quality dimension, followed by correctness, concordance, plausibility and currency. The authors also identified conformance and bias as additional dimensions. They concluded that no standard approach for assessing electronic health record data quality existed across the literature reviewed.

Two FHIR-formatted laboratory datasets show missing values, inconsistent units, shifted time stamps, incompatible codes and labeling differences

External validation must match intended use

A model evaluated at its development hospital may encounter different patients, devices, prevalence and workflows elsewhere. Overall performance can hide weaker results in groups that were uncommon in the test data. Local acceptance testing should therefore use the deployed model version, intended population and actual data path.

The International Medical Device Regulators Forum's 2025 principles call for representative datasets, independent training and test sets, external validation proportionate to risk, assessment of the human-AI team and monitoring after deployment. The test record should state the intended use, reference standard, sites, sample selection, subgroup results and the role of clinical staff in reviewing the output. FHIR conformance and external validation belong in the same procurement record, but one cannot substitute for the other.

Privacy and responsibility sit outside the wire format

The World Health Organization's 2021 health AI guidance sets six consensus principles, places ethics and human rights at the center of design, deployment and use, and calls for public and private actors to remain accountable to health workers and affected communities. A compliant data format does not assign that accountability.

A deployment record should identify the purpose of each data use, the minimum fields required, who can access them, how long records and logs are retained, and who responds to incidents. Contracts should assign responsibility for mapping errors, unauthorized access, model failures, security patches and service termination. The legal basis and required patient information must be checked under the laws that apply in each country and use case.

Explainability is only one part of transparency

Joint 2024 principles from the US Food and Drug Administration, Health Canada and the United Kingdom's Medicines and Healthcare products Regulatory Agency treat explainability as one part of transparency for machine learning-enabled medical devices. They call for information on intended use, target populations, workflow, performance, risks, data gaps, local testing, ongoing monitoring and product changes. The amount and form of information should reflect the device's risks and its intended users.

A 2023 systematic review of explainable AI in health care found only six eligible studies among 882 records and reported no comprehensive, agreed framework or standardized approach for evaluating explanation effectiveness. Feature importance or another single explanation method therefore cannot serve as a general safety test. Explanations must be assessed alongside clinical performance, workflow controls and monitoring.

Six checks keep deployment claims in scope

A procurement or governance record can group the evidence into six areas. Each item should name the exact software version, site and intended use covered by the evidence so that a broad platform claim does not stand in for a product-specific test.

  1. Interoperability: Record the FHIR release, profiles, terminology bindings, implementation guide, validation results and local mapping rules.
  2. Data quality: Measure missing values, invalid codes, units, time stamps, outliers, label quality and representation of the intended population.
  3. External validation: Report performance across sites, devices and patient groups, including uncertainty and groups with small samples.
  4. Clinical workflow: Define inputs, outputs, human review, overrides, escalation, downtime procedures and alert management.
  5. Ongoing monitoring: Keep data and model versions, drift measures, subgroup performance, security incidents, manual overrides and update records.
  6. Accountability: Assign hospitals, platform operators, integrators and AI suppliers responsibility for errors, failures, incidents and contract exit.
Six-card medical AI checklist covers interoperability, data quality, external validation, clinical workflow, monitoring and accountability

Comparative evidence remains limited

The two systematic reviews cited here address electronic record quality and explanation effectiveness, not the clinical outcomes or cost of FHIR-based medical AI deployments across hospitals. The three-regulator principles concern transparency for machine learning-enabled medical devices and do not determine whether a product is authorized in a particular country.

As of August 26, 2026, APPI News could not find a published count of completed FHIR Box deployments or a public roster of products certified through Taiwan's planned tracks. APPI News also could not find international comparative data showing that a FHIR-based integration layer improves cross-hospital clinical outcomes or lowers deployment costs. Those gaps do not show there is no benefit; they limit how far interoperability evidence can support a clinical or economic claim.