generated: '2026-07-19' method: searched source: https://lena.io/llms.txt notes: >- Lena Health publishes no public API, OpenAPI/AsyncAPI specification, or developer portal, so no technical API standards (OAuth2, OIDC, FHIR, RFC 9457, pagination, idempotency) could be asserted or derived. The entries below cover the healthcare compliance and security posture the company publishes on its own surfaces. standards: - id: soc2-type-ii conforms: true evidence: 'lena.io/llms.txt "SOC 2 Type II Certified"; homepage meta description and schema.org FAQPage both state SOC 2 Type II certification' source: https://lena.io/llms.txt - id: hipaa conforms: true evidence: 'lena.io/llms.txt "HIPAA Compliant"; homepage meta description and schema.org FAQPage both state HIPAA compliance' source: https://lena.io/llms.txt - id: llms-txt conforms: true evidence: first-party /llms.txt published at https://lena.io/llms.txt (HTTP 200, 2,663 bytes), saved verbatim to llms/lena-health-llms.txt source: https://lena.io/llms.txt - id: schema-org conforms: true evidence: homepage embeds a schema.org JSON-LD @graph with Organization, WebSite, Service, SoftwareApplication, and FAQPage nodes source: https://lena.io/ - id: sitemap-protocol conforms: true evidence: sitemaps.org 0.9 urlset published at https://lena.io/sitemap.xml (7 URLs) source: https://lena.io/sitemap.xml - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns the SPA index.html (soft-404), not an RFC 9116 document - id: oauth2 conforms: false evidence: no public API or OpenAPI specification found - id: fhir conforms: false evidence: no public API or FHIR endpoint found; EHR integration is described only as a managed-service capability, with no published conformance statement - id: rfc9457-problem-details conforms: false evidence: no public API or OpenAPI specification found