generated: '2026-08-01' method: searched source: https://www.caresyntax.com/privacy-policy docs: - https://www.caresyntax.com/privacy-policy - https://caresyntax.com/gdpr/ - https://caresyntax.com/about/patient-safety-organization/ - https://caresyntax.com/white-paper/best-practices-for-implementing-cloud-based-hospital-solutions scope: | Caresyntax publishes no machine-readable API contract, so no spec-derived conformance can be asserted. The standards below are regulatory / healthcare data-protection claims Caresyntax makes on its own published pages. standards: - id: gdpr conforms: true evidence: 'Privacy Notice states compliance with EU General Data Protection Regulation 2016/679; a dedicated GDPR page is published at https://caresyntax.com/gdpr/' - id: hipaa conforms: true evidence: Privacy Notice states compliance with the US Health Insurance Portability and Accountability Act - id: hitech conforms: true evidence: Privacy Notice states compliance with the US Health Information Technology for Economic and Clinical Health (HITECH) Act - id: ahrq-pso conforms: true evidence: 'Caresyntax is listed as a Patient Safety Organization with the US Agency for Healthcare Research and Quality — https://caresyntax.com/about/patient-safety-organization/' - id: soc2 conforms: unverified evidence: 'A Caresyntax white paper describes SOC 2 Type I/II, HITRUST CSF, ISO 27001/27002, NIST SP 800-53 and NYDFS 23 NYCRR-500 as certifications covered under its AWS cloud hosting model. That is a hosting-model statement, not a published Caresyntax attestation, and no trust center or certification page was found — so it is recorded as unverified rather than asserted.' - id: openapi conforms: false evidence: no OpenAPI/Swagger document found on any host (see well-known/caresyntax-well-known.yml) - id: oauth2 conforms: false evidence: no public OAuth/OIDC discovery document; /.well-known/openid-configuration returns 404 on api.caresyntax.com - id: rfc9457-problem-details conforms: false evidence: no public error contract published x-evidence: fetched: '2026-08-01' note: 'caresyntax.com is behind a Vercel bot challenge (403/429 to automated fetches); page content was established through search-engine indexed extracts of the pages listed under docs:, not by direct retrieval.'