generated: '2026-09-04' method: derived source: >- openapi/biogen-cdp-export-api-openapi.yml (derived from https://developer1.biogen.com/swagger/export/23683), openapi/biogen-keys-api-openapi.yml, openapi/biogen-services-api-openapi.yml, openapi/_original/biogen-cdp-export-api-iodoc.json, https://developer.biogen.com/io-docs, and https://www.biogen.com/responsibility/reporting-and-principles.html. note: >- Health-regime domain standards (FHIR, SMART on FHIR, US Core, USCDI, Da Vinci, CARIN Blue Button, FHIR Bulk Data, CDS Hooks, C-CDA, HL7 v2, DICOM) were checked against every Biogen contract this repo holds. NONE is declared: no FHIR resource type, no HL7 message type, no DICOM UID, no SMART/OAuth scope string appears in any path, schema, parameter or securityScheme. Biogen's readable API surface is a corporate/enterprise gateway (worker profile, an internal action centre, a service/package export catalogue), not a clinical data exchange, so the absence is a correct reading of the market Biogen's published APIs actually serve — recorded, not penalised, and NOT invented to fill the slot. No Compliance pointer is wired: no certification page (SOC 2, ISO 27001, HITRUST, HIPAA attestation) is published on any anonymously readable Biogen surface. conformance: - id: rest conforms: true evidence: >- Biogen's own portal documentation states each API "follows REST standard of web service implementation" and the provider definition declares protocol "rest" with HTTP GET methods on resource paths. https://developer1.biogen.com/swagger/export/23683 - id: https-only conforms: true evidence: >- "The API strictly uses HTTPS in the transport layer" — Biogen developer portal reference; and every Biogen host probed serves HTTPS (security/biogen-domain-security.yml, TLS 1.3 on developer.biogen.com). - id: api-key-header-auth conforms: true evidence: >- auth.key { param: "x-api-key", location: "header" } in openapi/_original/biogen-cdp-export-api-iodoc.json. - id: openapi conforms: false evidence: >- Biogen publishes a Mashery/Boomi IODoc JSON definition, not an OpenAPI document. The OpenAPI in openapi/biogen-cdp-export-api-openapi.yml is an API Evangelist transcription of that definition and is marked x-method: derived. - id: oauth2 conforms: false evidence: >- The Mashery io-docs UI renders an OAuth 2.0 flow selector on every portal, but the only Biogen API definition readable anonymously declares data-auth-type="key". No OAuth2 securityScheme appears in any Biogen contract. - id: oidc conforms: false evidence: /.well-known/openid-configuration missed on every Biogen host (well-known/biogen-well-known.yml). - id: rfc9457 conforms: false evidence: >- No application/problem+json media type in any Biogen contract; the documented error envelope is a proprietary {error, code} object (errors/biogen-problem-types.yml). - id: rfc8594 conforms: false evidence: No Sunset or Deprecation header contract is published (lifecycle/biogen-lifecycle.yml). - id: idempotency conforms: false evidence: No Idempotency-Key mechanism on any published operation (conventions/biogen-conventions.yml). - id: pagination conforms: false evidence: No pagination contract published on any operation. - id: fhir conforms: false evidence: >- Health-regime domain standard checked against every path, schema and parameter in openapi/ and openapi/_original/. No FHIR resource type, capability statement, or SMART scope is declared. - id: hl7-v2 conforms: false evidence: No HL7 v2 message type appears in any Biogen contract. - id: dicom conforms: false evidence: No DICOM identifier or WADO/QIDO/STOW path appears in any Biogen contract. - id: cdisc conforms: false evidence: >- Biogen DOES ship CDISC-aware tooling — the first-party CRAN package tidyCDISC operates on ADaM (CDISC) clinical datasets (packages/biogen-packages.yml). That is a published R package, NOT an API contract, so it does not satisfy domain_standard_conformance, which reads the contract. Recorded here so the distinction is explicit rather than lost. certifications: published: false entries: [] evidence: >- No trust centre and no certification listing found. trust.biogen.com does not resolve; probe-security-programs.py returned vdp=none trust=none. Biogen's corporate responsibility reporting page (https://www.biogen.com/responsibility/reporting-and-principles.html, HTTP 200) is ESG reporting, not a security-certification page, so it is not claimed as one.