generated: '2026-07-31' method: searched sources: - https://auth.ambiencehealthcare.com/.well-known/openid-configuration - https://www.ambiencehealthcare.com/informatics - https://trust.ambiencehealthcare.com/ standards: - id: oauth2 conforms: true evidence: 'Live OIDC/RFC 8414 metadata at auth.ambiencehealthcare.com advertises authorization, token, device-code and revocation endpoints and the authorization_code, client_credentials, refresh_token, device_code, token-exchange and jwt-bearer grants.' - id: oidc conforms: true evidence: /.well-known/openid-configuration returns 200 with issuer, jwks_uri, userinfo_endpoint and id_token_signing_alg_values_supported. - id: rfc8414-oauth-authorization-server-metadata conforms: true evidence: /.well-known/oauth-authorization-server returns 200 with the same metadata document. - id: rfc7636-pkce conforms: true evidence: 'code_challenge_methods_supported: [S256, plain].' - id: rfc9449-dpop conforms: true evidence: 'dpop_signing_alg_values_supported: [ES256].' - id: rfc7591-dynamic-client-registration conforms: true evidence: 'registration_endpoint: https://auth.ambiencehealthcare.com/oidc/register.' - id: fapi conforms: false evidence: 'HS256 advertised for ID token signing, implicit response types and the resource-owner password grant remain enabled, and PKCE advertises `plain` — all disallowed by FAPI profiles.' - id: hl7-fhir conforms: true role: consumer evidence: 'Provider states "Ambience leverages FHIR APIs to integrate securely and natively with Epic, Cerner, and Athena workflows" and writes into Oracle Cerner Millennium over FHIR and REST APIs (ambiencehealthcare.com/informatics). Ambience consumes EHR FHIR APIs; it does not publish a FHIR server of its own.' - id: smart-on-fhir conforms: true role: consumer evidence: '"Built directly into Hyperspace and Haiku using SMART on FHIR and Ambient APIs" — Epic Toolbox distribution (ambiencehealthcare.com/informatics).' - id: icd-10 conforms: true evidence: Integration API surface documented as "Integrated CDI with ICD-10 suggestions" (docs.ambiencehealthcare.com). - id: hipaa conforms: true evidence: '"Fully HIPAA compliant" (ambiencehealthcare.com/informatics); trust center states Ambience operates as a HIPAA Business Associate in the United States.' - id: soc2-type-1 conforms: true evidence: '"SOC 2 Type I & Type II certified — independently audited" (ambiencehealthcare.com/informatics).' - id: soc2-type-2 conforms: true evidence: '"SOC 2 Type I & Type II certified — independently audited" (ambiencehealthcare.com/informatics).' - id: gdpr conforms: true evidence: '"GDPR conformant — Ambience safeguards personal data with strict controls on processing, storage, and access" (ambiencehealthcare.com/informatics).' - id: hitrust conforms: false evidence: No HITRUST CSF certification claim found on the website or the trust center. - id: iso-27001 conforms: false evidence: No ISO 27001 claim found on the website or the trust center. - id: rfc9457-problem-details conforms: unknown evidence: No public OpenAPI or error reference is published; the Integration API error envelope could not be observed. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on every Ambience host. - id: asyncapi conforms: false evidence: No published event, streaming or webhook surface was found. - id: a2a conforms: false evidence: No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host. x-evidence: fetched: '2026-07-31' note: 'Every conforms=true row above is backed by either a live 200 response we fetched or a verbatim claim published by Ambience on its own domain. Nothing is inferred from marketing summaries or third-party directories.'