generated: '2026-09-02' method: searched source: openehr.org/industry-partners (fetched 2026-09-02, HTTP 200); CRAN package HPZoneAPI 1.3.0 source; https://connect.govconext.nl/.well-known/openid-configuration (HTTP 200) provider: InFact api: HPZone API (GraphQL) standards: - id: graphql conforms: true evidence: 'The single documented endpoint https://api.hpzone.nl:8899/Edie accepts POST bodies of the form {"query": "{ ... }"} and returns {data:{:{items,totalCount}}}; the published R client builds and sends GraphQL documents against it.' - id: oauth2 conforms: true profile: client_credentials (RFC 6749 §4.4) evidence: The published client performs httr2::req_oauth_client_credentials against https://connect.govconext.nl/oidc/token with an InFact-issued client_id/client_secret. - id: oidc conforms: true scope: authorization server only, operated by a third party evidence: The token issuer https://connect.govconext.nl serves a complete OpenID Provider discovery document at /.well-known/openid-configuration (probed 2026-09-02, HTTP 200) advertising authorization, token, userinfo, introspection, jwks and device-authorization endpoints. The provider of that endpoint is SURF/GovConext, not InFact; InFact is the relying resource server. - id: pagination conforms: true style: offset (skip/take) with an explicit order argument and a totalCount envelope; 500-row page ceiling evidence: HPZoneAPI README.md and R/HPZone_request.R. - id: rfc9457 conforms: false evidence: No application/problem+json is documented or observable; errors follow the GraphQL errors[] envelope. - id: idempotency conforms: null applicability: na evidence: The public surface is query-only; no write operation is documented, so the property does not apply. - id: scim conforms: false evidence: No SCIM schema URN or /scim surface is documented or discoverable. - id: fhir conforms: false evidence: No FHIR capability statement, resource path or claim appears in any public InFact material or in the published client; the API models HPZone's own case/contact/situation entities, not FHIR resources. domain_standard: candidate: openEHR market: health / electronic health records declared_in_contract: false conforms: unverified membership: body: openEHR International tier: Silver Industry Partner country: UK source: https://openehr.org/industry-partners/ probed: '2026-09-02' http_status: 200 note: The listing is published by the standards body itself and names InFact with the URL https://infact.solutions/. assessment: 'InFact is a paying member of the openEHR coalition, which is a real and citable commitment, but membership is NOT conformance. Nothing in the observable contract declares openEHR: the GraphQL surface exposes HPZone-native entities (Cases, Contacts, Situations, Enquiries, Actions, Contexts) with HPZone-native field names, not openEHR archetypes, templates, compositions or an EHR REST API. No AQL surface, no /ehr or /composition path, no archetype identifier and no openEHR conformance claim was found. Recorded as unverified rather than false because InFact''s own contract and documentation are customer-only, so an openEHR-shaped surface could exist behind that wall — but it is not visible from any public source and must not be credited on the strength of a membership row.' other_domain_standards_checked: - FHIR (not found) - HL7v2 (not found) - openEHR REST API / AQL (not found) - SNOMED CT bindings (not found) certifications: found: [] note: No SOC 2, ISO 27001, Cyber Essentials, DSPT/NHS Data Security and Protection Toolkit, or other certification is published on any reachable InFact surface. A UK/NL public-health supplier of this kind is very likely to hold DSPT and/or ISO 27001 under procurement, but nothing public evidences it, so no Compliance pointer is wired.