generated: '2026-08-06' method: searched source: >- Searched Array Behavioral Care's own public surface — arraybc.com/about/, arraybc.com/online-safety-and-security/ and the December 2024 HITRUST certification announcement at arraybc.com/news-media/array-achieves-hitrust-e1-certification — plus live probes of arraybc.com and mychart.arraybc.com for machine-readable discovery surfaces. No OpenAPI, AsyncAPI, GraphQL SDL, FHIR CapabilityStatement or MCP manifest was found on any host, so every API-technical standard below is recorded as not conformant on the evidence of a completed probe, not an assumption. description: >- Array Behavioral Care is a virtual clinical practice, not an API vendor. Its conformance posture is therefore almost entirely on the healthcare accreditation and information-security side (Joint Commission, HITRUST, HIPAA) rather than the API-standards side. The one interoperability standard it plausibly touches — HL7 FHIR, via its Epic-based EHR — is not publicly reachable: Array does not appear in Epic's public FHIR endpoint directory and no CapabilityStatement is served from its MyChart host. standards: - id: hitrust-e1 conforms: true evidence: >- HITRUST e1 Certification awarded to Array's integrated clinical systems, announced 2024-12-19. The e1 assessment is the foundational tier of HITRUST's three progressive evaluations, validating essential cybersecurity hygiene and information risk management controls. source: https://arraybc.com/news-media/array-achieves-hitrust-e1-certification date: '2024-12-19' - id: joint-commission-accreditation conforms: true evidence: >- Array Behavioral Care states it is accredited by The Joint Commission for its behavioral health care services; the Joint Commission + HITRUST badge is published on arraybc.com. source: https://arraybc.com/about/ - id: hipaa conforms: true evidence: >- Array publishes a HIPAA Notice of Privacy Practices and states its Array AtHome telebehavioral health platform is HIPAA-compliant, in contrast to consumer video tools. As a covered entity delivering clinical care, HIPAA applies by statute. source: https://arraybc.com/notice-privacy-practices/ - id: no-surprises-act conforms: true evidence: >- Array publishes a No Surprises Act disclosure page covering good-faith estimates and balance-billing protections. source: https://arraybc.com/no-surprises-act/ - id: hl7-fhir conforms: false evidence: >- Array's clinical platform is Epic-based, but no FHIR endpoint is publicly reachable. https://mychart.arraybc.com/Array/api/FHIR/R4/metadata returns a hard 404 (zero bytes), as do the DSTU2 and STU3 paths, and Array Behavioral Care does not appear in Epic's public R4 endpoint directory at https://open.epic.com/Endpoints/R4 (200, 479 endpoints, zero matches on "array"). Any FHIR interoperability runs through private Epic connections to partner health systems. probed: '2026-08-06' - id: smart-on-fhir conforms: false evidence: >- No SMART App Launch discovery document. /Array/.well-known/smart-configuration returns 200 with an HTML login page rather than JSON — the MyChart host is a catch-all that answers 200 with HTML for every /.well-known/* path, which is a soft 404, not a discovery document. probed: '2026-08-06' - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document on any host. Probed /openapi.json, /swagger.json, /api-docs, /api, /developer and /developers on arraybc.com — all 404. No api.* or developer.* subdomain resolves. probed: '2026-08-06' - id: oauth2 conforms: false evidence: >- No /.well-known/oauth-authorization-server (404) and no public authorization server. Patient authentication is Epic MyChart's own session login. probed: '2026-08-06' - id: oidc conforms: false evidence: 'https://arraybc.com/.well-known/openid-configuration returns 404.' probed: '2026-08-06' - id: rfc9116-security-txt conforms: false evidence: >- https://arraybc.com/.well-known/security.txt returns 404. No RFC 9116 security.txt is published on the corporate site, and the MyChart host answers the same path with a 200 HTML login page (soft 404). probed: '2026-08-06' - id: llmstxt conforms: true evidence: >- https://arraybc.com/llms.txt returns 200 text/plain (8,022 bytes), a valid llms.txt generated by Yoast SEO v28.2. It indexes marketing pages, FAQs, press releases and resources — it is a content-discovery file, not an API contract. source: https://arraybc.com/llms.txt probed: '2026-08-06' - id: a2a-agent-card conforms: false evidence: >- No agent card. /.well-known/agent-card.json and /.well-known/agent.json both 404 on arraybc.com; the MyChart host returns 200 HTML for the same paths (SPA catch-all soft 404, rejected as a false positive). probed: '2026-08-06'