Developer Terms of Service
Effective date: January 1, 2025
These Developer Terms of Service ("Agreement") govern access to and use of the Patient Access API ("API") provided under this developer portal. By registering an application, you agree to be bound by this Agreement.
1. Permitted Use
Access to the API is granted solely for the purpose of enabling patients to access their own health information in compliance with the CMS Interoperability and Patient Access Final Rule (CMS-9115-F) and applicable federal and state law.
You may use the API only to:
- Retrieve health data on behalf of patients who have explicitly authorized your application.
- Display, process, or transmit that data in a manner consistent with the patient's authorization and applicable law.
- Support patient care coordination, personal health record management, or other patient-directed use cases.
You may not use the API for any purpose not authorized by the patient, including but not limited to marketing, advertising targeting, sale of data to third parties, or any use prohibited by HIPAA or applicable state privacy law.
2. Developer Obligations
You agree to the following obligations as a condition of API access:
- PHI handling: You must not store, retain, or process Protected Health Information (PHI) beyond what is necessary to fulfill the patient's explicit request and must not retain PHI after the patient revokes authorization.
- Security: You must implement and maintain reasonable administrative, physical, and technical safeguards to protect patient data accessed through the API, consistent with HIPAA Security Rule standards.
- Transparency: Your application must present patients with a clear, plain-language privacy policy explaining how their health data will be used, stored, and shared before requesting authorization.
-
Credential security: You are responsible for safeguarding your
client_idandclient_secret. You must not share credentials or embed them in publicly accessible code. - Compliance: You are responsible for ensuring your application complies with all applicable federal and state laws, including but not limited to HIPAA, the 21st Century Cures Act, and applicable state breach notification requirements.
- Accurate registration: You must keep your registered redirect URIs and contact information current. Notify us promptly of any changes.
3. Termination and Revocation
We reserve the right to suspend or revoke your API access at any time, with or without notice, if we reasonably determine that:
- You have violated any provision of this Agreement.
- Your application poses a security risk to patients or our systems.
- You have misrepresented information in your registration request.
- Continued access would violate applicable law or regulatory requirements.
Upon termination, you must immediately cease use of the API and delete any PHI obtained through the API unless retention is required by law or with the patient's explicit consent.
All termination decisions will be documented with a specific reason consistent with the CMS Interoperability rule's anti-blocking requirements.
4. Disclaimers and Limitation of Liability
The API is provided "as is" without warranties of any kind, express or implied. We do not warrant that the API will be uninterrupted, error-free, or that data returned will be complete or accurate. We are not liable for any damages arising from your use of or inability to use the API.
5. Governing Law
This Agreement shall be governed by and construed in accordance with the laws of [Governing State Placeholder], United States, without regard to its conflict of law provisions.
6. Changes to This Agreement
We may update this Agreement from time to time. Continued use of the API after the effective date of any revision constitutes acceptance of the updated terms. The current effective date is shown at the top of this page.
Questions about this Agreement? Contact api-support@wasatch.org.