generated: '2026-07-27' method: searched source: >- https://fhir.advancedmd.com/faq-s, https://fhir.advancedmd.com/fhir/launch-and-authorization, https://fhir.advancedmd.com/terms-of-service, https://www.advancedmd.com/ai-information (the "Certifications & Compliance" section), plus derivation from fhir/advancedmd-fhir-r4-capabilitystatement.json, fhir/advancedmd-smart-configuration.json and the OpenAPI documents in openapi/. description: >- Which industry and cross-cutting standards the AdvancedMD API estate conforms to. AdvancedMD is a regulated US health-IT supplier, so most of this is asserted by the provider itself and independently certified rather than merely inferred from a spec. standards: - id: hl7-fhir-r4 conforms: true evidence: >- CapabilityStatement declares fhirVersion 4.0.1 and format application/fhir+json (fhir/advancedmd-fhir-r4-capabilitystatement.json). FAQ: "Currently, AdvancedMD supports R4 FHIR versions." - id: us-core-6.1.0 conforms: true evidence: >- CapabilityStatement instantiates http://hl7.org/fhir/us/core/CapabilityStatement/us-core-server; the published OpenAPI is titled "FHIR Single API - US Core 6.1.0", version 6.1.0. - id: fhir-bulk-data-access conforms: true evidence: >- CapabilityStatement instantiates http://hl7.org/fhir/uv/bulkdata/CapabilityStatement/bulk-data; the Bulk API implements $export kickoff, async status polling and an output-file server. - id: smart-app-launch conforms: true evidence: >- /v1/r4/.well-known/smart-configuration served (HTTP 200) advertising launch-standalone, launch-ehr, sso-openid-connect, permission-v1, permission-v2, context-ehr-patient/encounter, authorize-post and the client-public / client-confidential-symmetric / client-confidential-asymmetric capabilities. - id: smart-backend-services conforms: true evidence: >- client_credentials with an RS384-signed private_key_jwt client assertion and the system/*.read scope, documented on the Launch and Authorization page. - id: oauth2 conforms: true evidence: >- authorization_code and client_credentials grants advertised in the SMART discovery document; authorize/token/introspect/revoke endpoints published. - id: oauth2-pkce conforms: true evidence: code_challenge_methods_supported = ["S256"]; the portal documents a dedicated PKCE authorization flow. - id: oidc conforms: true evidence: >- /v1/r4/.well-known/openid-configuration served (HTTP 200); id_token signing algorithms RS384 and RS256; openid and fhirUser scopes supported. - id: rfc7517-jwks conforms: true evidence: /v1/oauth2/.well-known/jwks.json returns a live JSON Web Key Set (saved as well-known/advancedmd-jwks.json). - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: >- /.well-known/oauth-authorization-server returns 404 on every host and path probed; discovery is via smart-configuration and openid-configuration only. - id: onc-cures-act-170.315-g-10 conforms: true evidence: >- FAQ: "AdvancedMD's FHIR APIs are certified by The Drummond Group, LLC, an ONC Authorized Certification Body (ACB), and comply with the Cures Act regulations at 170.315 (g)(10) Standardized API for patient and population services." - id: uscdi-v3 conforms: true evidence: >- FAQ: "AdvancedMD supports USCDI v3 and is actively working with the following version updates." The Launch and Authorization page maps the granular scope set to USCDI v3 resource types. - id: onc-service-base-url-publication conforms: true evidence: >- https://providerapi.advancedmd.com/v1/r4/endpoints returns a public FHIR Bundle of Endpoint + Organization resources (6,048 pairs), also published as CSV; updated quarterly. - id: hipaa conforms: true evidence: >- The Developer Terms of Service contain a HIPAA section governing PHI handling by developer apps; https://www.advancedmd.com/ai-information lists "HIPAA compliant" under Certifications & Compliance. - id: epcs conforms: true evidence: >- "EPCS (Electronic Prescribing of Controlled Substances) certified" — https://www.advancedmd.com/ai-information. - id: macra-mips conforms: true evidence: >- "Supports MACRA/MIPS quality reporting and Promoting Interoperability requirements" — https://www.advancedmd.com/ai-information. - id: hl7-c-cda conforms: true evidence: >- GET /clinical/episodesummaries on the Application Access APIs returns an HL7 C-CDA v3 ClinicalDocument (application/xml), per openapi/advancedmd-application-access-apis-swagger.json. - id: tls-1.2-minimum conforms: true evidence: >- Getting Started: "API client must support SSL communication. Version TLS 1.2 and higher is supported." Live probe records TLSv1.3 on all AdvancedMD hosts (security/advancedmd-domain-security.yml). - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json anywhere. The FHIR APIs return FHIR OperationOutcome; the Application Access APIs return a bespoke {title, detail} envelope. See errors/advancedmd-problem-types.yml. - id: rfc8594-sunset-header conforms: false evidence: No Sunset/Deprecation header support or deprecation policy is published on either portal. - id: idempotency-key conforms: false evidence: >- No Idempotency-Key header is documented or present in any spec. The published API surface is read-only by regulatory design, so retries are inherently safe — see conventions/advancedmd-conventions.yml. - id: pagination conforms: true evidence: >- FHIR Bundle link[] relation-based paging (self/next) per HL7 FHIR R4 search; the Application Access APIs use a required startDate/endDate window instead of paging. - id: webhook-signing conforms: false evidence: AdvancedMD publishes no webhook or event surface on either public portal. - id: asyncapi conforms: false evidence: No AsyncAPI document and no event/streaming surface is published. - id: graphql conforms: false evidence: No GraphQL endpoint is advertised; the Apigee portal API records carry null graphqlEndpointUrl. - id: fapi conforms: false evidence: No FAPI profile is claimed; token endpoint accepts client_secret_basic alongside private_key_jwt. - id: scim conforms: false - id: odata conforms: false - id: da-vinci conforms: false evidence: No Da Vinci implementation guide is referenced anywhere on the portal. - id: carin-blue-button conforms: false evidence: No CARIN Blue Button implementation guide is referenced anywhere on the portal. - id: tefca-qhin conforms: false evidence: Not advertised on either developer portal. certifications: - name: ONC Health IT Certification — 21st Century Cures Act body: Drummond Group, LLC (ONC Authorized Certification Body) criterion: 170.315 (g)(10) Standardized API for Patient and Population Services source: https://fhir.advancedmd.com/faq-s - name: EPCS certified source: https://www.advancedmd.com/ai-information - name: HIPAA compliant source: https://www.advancedmd.com/ai-information unverified: - id: soc2 note: No SOC 2 report, ISO 27001 certificate, HITRUST or PCI DSS attestation is published on any public AdvancedMD page, and no trust center exists at trust.advancedmd.com (probed 2026-07-27 and again 2026-08-15, no DNS on either trust.advancedmd.com or security.advancedmd.com). Absence of publication, not evidence of absence. - id: iso-27001 conforms: false note: >- Adherence is claimed but certification is NOT. https://www.advancedmd.com/medical-office-software/security/ states AdvancedMD "operates an information security management program that generally adheres to ISO 27001 standards" — an adherence claim, not a certificate, and no certificate number, issuing body or audit date is published. Recorded here rather than under certifications[] for exactly that reason. Re-read 2026-08-15. - id: vulnerability-disclosure conforms: false note: >- Re-probed 2026-08-15 with 0-working/probe-security-programs.py plus a manual read of the security page: no security.txt on any host, no responsible-disclosure or vulnerability-disclosure page, no bug-bounty listing (HackerOne/Bugcrowd/Intigriti) and no security@ contact published. No VulnerabilityDisclosure or TrustCenter artifact was written because there is no verified hit to write.