generated: '2026-08-15' method: searched source: >- https://www.ibx.com/scripts/custom/swagger/cmsSwagger.json (provider-published Swagger 2.0, info.description), https://eapics.ibx.com/{patient,provider,formulary}/v1/fhir/.well-known/smart-configuration (live probes), https://www.ibx.com/privacy-policy/hipaa-compliance.html, https://www.ibx.com/htdocs/custom/tnc/Developer%20Portal%20TandC.pdf, https://www.ibx.com/developer-resources/index.html, openapi/_original/*.yml summary: >- Independence Blue Cross is a regulatory-driven FHIR publisher. Its conformance posture is entirely healthcare-interoperability shaped: HL7 FHIR R4 with SMART App Launch security, the CARIN Blue Button and Da Vinci implementation guides, and the CMS-9115-F final rule that compelled all three APIs. It does NOT adopt the general-purpose web-API conventions the rest of the catalog is measured on — there is no RFC 9457 problem+json, no RFC 8594 Sunset/Deprecation signalling, no idempotency key, and no RateLimit response headers. standards: - id: fhir-r4 name: HL7 FHIR 4.0.1 conforms: true evidence: >- Provider's own Swagger info.description states the APIs "conform to the DaVinci Health Level 7 (HL7) Fast Healthcare Interoperability Resources (FHIR) 4.0.1 standards"; every path is a FHIR resource type and every response is application/fhir+json. - id: fhir-rest name: FHIR RESTful API (search + read interactions) conforms: true evidence: >- All 60 published operations are FHIR type-level search (GET /{Resource}) or instance read (GET /{Resource}/{rid}); each base path exposes GET /metadata returning a CapabilityStatement. - id: smart-app-launch name: SMART App Launch 1.0.0 conforms: true evidence: >- Live smart-configuration documents at all three FHIR base paths advertise capabilities client-public, sso-openid-connect, launch-standalone, client-confidential-symmetric, context-standalone-patient, permission-offline, permission-patient. - id: oauth2 name: OAuth 2.0 authorization code conforms: true evidence: >- openapi/_original/independence-blue-cross-patient-openapi.yml declares securityScheme smart_on_fhir type oauth2, flow authorizationCode, authorizationUrl member.ibx.com/patientaccesssvc/oauth2/v1/authorize, tokenUrl eapics.ibx.com/oauth2/v2/token — matching the live smart-configuration. - id: oidc name: OpenID Connect conforms: true evidence: >- smart-configuration lists the sso-openid-connect capability and the OpenAPI declares the `openid` scope. NOTE — no /.well-known/openid-configuration discovery document is served on any host (404), so OIDC metadata cannot be discovered programmatically. - id: pkce name: OAuth 2.0 PKCE (RFC 7636) conforms: true evidence: >- smart-configuration advertises client-public, which under SMART App Launch requires PKCE for public clients. - id: carin-blue-button name: CARIN for Blue Button Framework / CPCDS conforms: true evidence: >- Provider Swagger info.description — "The Patient Access API conforms to the CARIN for Blue Button Framework and Common Payer Consumer Data Set (CPCDS) standard for patient claim and encounter data". - id: us-core name: US Core / USCDI (clinical data) conforms: true evidence: >- Provider Swagger info.description — "the U.S. Core Data for Interoperability standard for clinical data, based on the FHIR version 4 specification". - id: davinci-pdex-plan-net name: Da Vinci PDex Plan-Net (Provider Directory) conforms: true evidence: >- Provider Directory exposes exactly the Plan-Net resource set — Practitioner, PractitionerRole, Organization, OrganizationAffiliation, Location, HealthcareService, InsurancePlan, Endpoint — and the Swagger description names the Da Vinci HL7 FHIR 4.0.1 standards. - id: davinci-usdf name: Da Vinci US Drug Formulary conforms: true evidence: >- Formulary API exposes List and MedicationKnowledge, the USDF IG resource pair. - id: cms-9115-f name: CMS Interoperability and Patient Access Final Rule (CMS-9115-F) conforms: true evidence: >- Developer Portal Terms and Conditions section 1 states the APIs are "provided pursuant to the CMS Interoperability and Patient Access Final Rule (CMS-9115-F)". Scope is limited to current Keystone HMO CHIP and Medicare Advantage members (interoperability FAQ PDF). - id: transparency-in-coverage name: Transparency in Coverage machine-readable files (45 CFR 147.211) conforms: true evidence: >- Monthly in-network rate, allowed amount and prescription drug JSON files published for Keystone Health Plan East, QCC Insurance Company and Independence Assurance Co, Inc. at https://www.ibx.com/cmstic/?brand={khpe|qcc|iac}. - id: hipaa name: HIPAA Privacy Rule and Security Rule conforms: true evidence: >- https://www.ibx.com/privacy-policy/hipaa-compliance.html (HTTP 200) states IBX is compliant with the Privacy Rule, has implemented the Security Rule since 21 April 2005, "continually monitors and manages the required security controls", and names a Privacy and Security Office contact route. - id: rfc9457-problem-details conforms: false evidence: >- No application/problem+json anywhere. FHIR servers signal errors with an OperationOutcome resource in application/fhir+json instead; see errors/independence-blue-cross-problem-types.yml. - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation header support is documented. The Developer Portal Terms and Conditions reserve the right to "modify or discontinue, temporarily or permanently, the Developer Portal or Site (or any parts thereof) with or without notice" — the opposite of a deprecation guarantee. - id: ietf-ratelimit-headers conforms: false evidence: >- No RateLimit-* or X-RateLimit-* headers are documented and no numeric limits are published; see rate-limits/independence-blue-cross-rate-limits.yml. - id: idempotency-key conforms: false evidence: >- Not applicable in practice — all 60 published operations are GET (safe and naturally idempotent). There is no write surface and therefore no Idempotency-Key header; see conventions/independence-blue-cross-conventions.yml. - id: asyncapi conforms: false evidence: No event, streaming, webhook or subscription surface is published on any IBX host. - id: graphql conforms: false evidence: FHIR GraphQL is not exposed; no /$graphql or /graphql endpoint is documented or reachable. - id: scim conforms: false - id: odata conforms: false - id: fapi conforms: false evidence: >- No FAPI profile is claimed; the SMART configuration advertises client-confidential-symmetric (shared secret) rather than the private_key_jwt / mTLS that FAPI requires. certifications: - id: hitrust-essentials name: HITRUST Essentials Certification claimed_by: Independence Blue Cross announcement: https://news.ibx.com/hitrust-essentials-certification/ verified: false verification_note: >- NOT independently verified by this pass. news.ibx.com sits behind a bot challenge and returned HTTP 202 with an sgcaptcha redirect to both a browser user-agent and a plain client, so the announcement body could not be read. Recorded as a provider claim surfaced by search indexes, not as an evidence-backed certification. Re-probe from a browser session to confirm scope and date. compliance_program: published: true url: https://www.ibx.com/privacy-policy/hipaa-compliance.html status: 200 frameworks: - HIPAA Privacy Rule - HIPAA Security Rule - HIPAA Administrative Simplification (standard electronic transactions) - 45 C.F.R. 164.520 notice of privacy practices contact: https://www.ibx.com/htdocs/contact_us/forms/hipaa_contact_form.html note: >- This is the page the Compliance pointer in apis.yml resolves to. It is a genuine, readable, provider-published compliance posture page — not a derived assertion. No SOC 2, ISO 27001, PCI DSS or FedRAMP claim was found anywhere on an IBX host.