The HEART working group aims to enable patient-mediated health data exchange through RESTful and privacy-sensitive methods. HEART profiles OAuth, OpenID Connect, UMA, and FHIR to allow individuals to gather and share their health data how and when they choose, including giving and revoking data access permission. HEART involves health experts, technology implementers, and is led by co-chairs from HHS and ForgeRock. Current work products specify security mechanisms for the FHIR API and consider patient control over de-identified data sharing.