Project news

Cross-Enterprise Security and Privacy Authorization (XSPA) Profile of SAML v2.0 for Healthcare v2.0 from XSPA TC approved as a Committee Specification

OASIS is pleased to announce that Cross-Enterprise Security and Privacy Authorization (XSPA) Profile of SAML v2.0 for Healthcare Version 2.0 from the OASIS Cross-Enterprise Security and Privacy Authorization (XSPA) TC [1] has been approved as an OASIS Committee Specification.

The XSPA profile defines a set of SAML attributes and corresponding vocabularies for healthcare information exchange applications.

The core use-cases are the cross-enterprise exchange of protected data objects from a Service Provider (SP) to a Service Consumer (SC). In the scenarios, the request includes SAML attribute assertions that vouch for the identity of the requesting Principal and other attributes that are consequential in making the access control decision at the SP’s side.

In addition to the main use-cases, the attributes’ name and values can be used in some other scenarios, such as including SAML Assertions to vouch for some of SP’s organizational attributes, or carrying the identity attributes of the signer of a data object.

This Committee Specification is an OASIS deliverable, completed and approved by the TC and fully ready for testing and implementation.

The prose specifications and related files are available here:

Cross-Enterprise Security and Privacy Authorization (XSPA) Profile of SAML v2.0 for Healthcare Version 2.0
Committee Specification 01
23 April 2019

Editable source (Authoritative):

Distribution ZIP file
For your convenience, OASIS provides a complete package of the prose specification and related files in a ZIP distribution file. You can download the ZIP file here:

Members of the XSPA TC [1] approved this specification by Special Majority Vote. The specification had been released for public review as required by the TC Process [2]. The vote to approve as a Committee Specification passed [3], and the document is now available online in the OASIS Library as referenced above.

Our congratulations to the TC on achieving this milestone and our thanks to the reviewers who provided feedback on the specification drafts to help improve the quality of the work.

========== Additional references:
[1] OASIS Cross-Enterprise Security and Privacy Authorization (XSPA) TC

[2] Public reviews:
– 30-day public review, 29 April 2014:
– Comment resolution log:
– 15-day public review, 27 March 2017:
– Comment resolution log:
– 15-day public review, 04 December 2018:
– Comment resolution log:
– 15-day public review, 15 March 2019:
– Comment resolution log:

[3] Approval ballot: