Privacy Policy
This policy applies to the Patient Access API Developer Portal.
This Privacy Policy describes how we collect, use, and protect information submitted through this developer portal. It applies only to the portal itself — not to the Patient Access API or the patient health data accessed through it.
1. Information We Collect
When you register an application through this portal, we collect the following information:
- Contact information: Your name (as part of your organization) and email address.
- Organization information: The name of your organization or company.
- Application details: App name, description, redirect URIs, and requested API scopes.
- Agreement records: The date and time you accepted our Terms of Service.
- Technical identifiers: The
client_idassigned to your application upon approval.
We do not collect payment information, Social Security Numbers, or patient health data through this portal.
2. How We Use This Information
Information collected through this portal is used exclusively for:
- Reviewing and processing your application registration request.
- Communicating with you about your registration status, credentials, and support requests.
- Maintaining records of authorized applications as required by the CMS Interoperability and Patient Access Final Rule (CMS-9115-F).
- Ensuring compliance with our Terms of Service and applicable law.
We do not sell, rent, or share your information with third parties for marketing or any purpose other than those listed above.
3. Public App Directory
As required by CMS-9115-F, we maintain a public directory of approved applications authorized to access patient data through this API. This directory displays your application name, organization name, and approval date. It does not include contact email addresses, client credentials, or any other personally identifiable information.
4. Data Retention
Registration records, including approved and rejected requests, are retained for a minimum of 6 years to support audit and compliance obligations. If your application is deactivated, your registration record is retained but marked as inactive.
To request deletion of your information, contact us at the address below. Note that records required for regulatory compliance cannot be deleted.
5. Security
We implement reasonable technical and organizational measures to protect information submitted through this portal, including access controls, encrypted transport (HTTPS), and secure credential storage. Client secrets are displayed once at the time of issuance and are not stored in recoverable form after that point.
6. Cookies and Analytics
This portal uses session cookies required for authentication and form security. We do not use tracking cookies, third-party analytics, or advertising technology.
7. Contact
For questions or requests related to this Privacy Policy, contact: api-support@wasatch.org.