70.3.1Security

 

The Provider Access API ensures that only authorized providers can access patient data. Key security features include:

  • Authentication and Authorization – Managed through OAuth 2.0 using SMART on FHIR standards.
  • Transport Security – All endpoints must support TLS 1.2 or higher.
  • Access Control – Payers enforce role-based access and scope-limited permissions to ensure only authorized in-network providers can access data.