Expose a CMS Interoperability Patient Access API conforming to CMS final rule requirements

domain: hl7.org/fhir/us/carin-bb · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Implement a FHIR R4 server endpoint secured with SMART App Launch supporting patient-facing third-party application authorization
  2. Expose at minimum the resource types required by the CMS patient access API rule, including ExplanationOfBenefit (CARIN BB profile), Coverage, and Patient (US Core profile)
  3. Publish a FHIR CapabilityStatement advertising the supported profiles, search parameters, and SMART capabilities at the well-known endpoint
  4. Enforce patient-level scoping so a patient token can only access records for the authenticated beneficiary
  5. Log third-party application access in AuditEvent and provide patients with a mechanism to view and revoke application authorizations

Known gotchas

Related routes

Understand the CMS Interoperability and Patient Access final rule API requirements for payers
cms.gov · 6 steps · unrated
integrate with a payer Patient Access API under the CMS interoperability rule (Da Vinci / CARIN)
payer-patient-access · 6 steps · unrated
Implement a CMS Patient Access API (CMS-9115 / CMS Interoperability Rule) compliant FHIR endpoint that serves member claims, clinical, and formulary data to authorized third-party apps via SMART on FHIR
cms.gov · 5 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans