generated: '2026-08-14' method: searched source: >- https://help.elationhealth.com/articles/rest/overview/oauth, https://help.elationhealth.com/articles/rest/overview/scopes, https://help.elationhealth.com/articles/rest/overview/errors, https://help.elationhealth.com/articles/rest/overview/pagination, https://help.elationhealth.com/api-reference, https://help.elationhealth.com/.well-known/agent-card.json, https://www.elationhealth.com/solutions/ehr/ (ONC / HIPAA), openapi/elation-health-api-full-openapi.yaml, openapi/*.json standards: - id: oauth2 conforms: true evidence: >- OpenAPI securitySchemes type oauth2 with clientCredentials flow (tokenUrl /api/2.0/oauth2/token/); scopes apiv2, act_as_user, system/{resource}.read|write. Legacy password grant also documented. - id: oidc conforms: false evidence: >- No working OpenID Connect discovery document (/.well-known/openid-configuration returns empty/redirect); OAuth2 only. - id: hl7-fhir-r4 conforms: true evidence: >- Elation operates HL7 FHIR R4 and SMART-on-FHIR interoperability endpoints for ONC/CMS 21st Century Cures Act compliance (login-gated to registered apps; not part of the anonymous REST v2.0 surface captured here). - id: smart-on-fhir conforms: true evidence: >- SMART on FHIR 1.0.0 with US Core v5.0.1 over FHIR R4 v4.0.1, per Elation's own published Agent Skill. Base URLs https://fhir.elationemr.com/fhir/r4/ (production) and https://sandbox-fhir.elationemr.com/fhir/r4/ (sandbox). Gated: anonymous GET of /fhir/r4/metadata and /fhir/r4/.well-known/smart-configuration returned HTTP 401 on 2026-08-14, so the CapabilityStatement could not be harvested. - id: a2a-agent-card conforms: true evidence: >- A2A agent card served at https://help.elationhealth.com/.well-known/agent-card.json (HTTP 200, application/json, protocolVersion 0.3). Graded conformant - capabilities is an object, protocolVersion present, skills is an array; sole deviation is supportedInterfaces in place of additionalInterfaces. See a2a/elation-health-a2a.yml. - id: agent-skills-discovery conforms: true evidence: >- Agent Skills discovery index at https://help.elationhealth.com/.well-known/agent-skills/index.json (schemas.agentskills.io/discovery/0.2.0, HTTP 200), advertised by a rel="agent-skills" Link header; one published skill saved verbatim at skills/elation-health-provider-published-skill.md. - id: mcp conforms: true evidence: >- Two hosted MCP servers answering tools/list anonymously over HTTP (help.elationhealth.com/mcp, 3 tools; legacy docs.elationhealth.com/mcp, 5 tools), plus an MCP server card at /.well-known/mcp/server-card.json. Both are documentation servers, not resource servers over the clinical API. - id: rfc8414-oauth-metadata conforms: false evidence: >- No OAuth 2.0 authorization-server metadata is published; /.well-known/oauth-authorization-server returned 400/302/404 on every Elation host probed 2026-08-14. - id: onc-cehrt conforms: true evidence: Elation is ONC-Certified Electronic Health Record Technology (CEHRT). - id: hipaa conforms: true evidence: >- HIPAA-compliant EHR; signs a standard Business Associate Agreement (BAA) with covered entities. 256-bit TLS + AES-256 encryption at rest. - id: rfc9457-problem-details conforms: false evidence: >- Error responses use application/json, not application/problem+json; no RFC 9457 problem-type envelope documented. - id: pagination conforms: true evidence: >- Cursor-based pagination by default (cursor param; next/previous/results), plus optional offset-based (limit/offset; count/next/previous/results). Max 100 results per page. - id: idempotency conforms: false evidence: No idempotency-key header/parameter is documented or present in the OpenAPI. - id: json-api conforms: false evidence: Standard JSON resource envelopes; not JSON:API. - id: webhooks conforms: true evidence: >- Event Subscription API with 43+ subscribable resource models; POST callbacks signed with Ed25519 (El8-Ed25519-Signature header).