generated: '2026-08-04' method: derived source: - openapi/forta-health-platform-openapi.yml - https://www.fortahealth.com/privacy-policy - https://www.fortahealth.com/notice-of-privacy-practices notes: Standards posture derived from the publicly served OpenAPI document plus the compliance pages Forta Health publishes on its marketing site. Forta publishes no trust center, no certification report and no developer documentation, so no certification (SOC 2, ISO 27001, HITRUST) could be verified. standards: - id: hipaa conforms: true evidence: publishes a HIPAA Notice of Privacy Practices; privacy policy references HIPAA (6x), HITECH and Business Associate Agreements; site markets a "HIPAA-Secure Platform" url: https://www.fortahealth.com/notice-of-privacy-practices kind: regulatory - id: ccpa conforms: true evidence: dedicated CCPA opt-out page and CCPA references in the privacy policy url: https://www.fortahealth.com/ccpa-opt-out kind: regulatory - id: wcag-accessibility conforms: claimed evidence: publishes an accessibility statement url: https://www.fortahealth.com/accessibility-statement kind: regulatory - id: evv-21st-century-cures-act conforms: true evidence: dedicated evv tag and an X-EVV-Token authenticated callback operation — Electronic Visit Verification is federally mandated for Medicaid personal care and home health services kind: regulatory - id: nucc-npi conforms: true evidence: National Provider Identifier (npi) fields appear 29 times across provider and payor credential schemas kind: industry - id: ama-cpt conforms: true evidence: CPT procedure codes referenced in service_codes / claims schemas kind: industry - id: oauth2 conforms: false evidence: only securityScheme is HTTPBearer (http/bearer); no oauth2 flows declared - id: openid-connect conforms: false evidence: /.well-known/openid-configuration 404 on every host - id: rfc9457-problem-details conforms: false evidence: no application/problem+json media type in the spec; FastAPI "detail" envelope used instead - id: rfc8594-sunset-header conforms: false evidence: no Sunset or Deprecation header anywhere in the spec - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 on www, app and api hosts - id: fhir-r4 conforms: false evidence: no FHIR resource shapes, no fhir references in the spec - id: x12-837 conforms: false evidence: claims modelled as proprietary JSON schemas; no X12 EDI references - id: hl7-v2 conforms: false evidence: no HL7 references in the spec - id: scim conforms: false - id: odata conforms: false - id: json-api conforms: false certifications_published: [] certification_note: No SOC 2, ISO 27001, HITRUST or FedRAMP report or trust center is published on any Forta Health host.