generated: '2026-08-25' method: searched source: https://medixinfusion.com/ description: >- Standards and compliance posture for Medix Infusion. The company publishes no API, no developer portal and no machine-readable contract, so every API-side and cross-cutting standard below is recorded as not conformant on the evidence of absence rather than of a failed check. What the company does publish is the healthcare-operations compliance surface a care-delivery organization is expected to carry: an ACHC accreditation claim, pharmacy-industry affiliations, and a HIPAA Notice of Privacy Practices. Those are recorded here because they are real, provider-published and evidence-backed — not because they satisfy any API-side check. api_standards: - id: openapi conforms: false evidence: >- No OpenAPI/Swagger document found. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc on both medixinfusion.com and www.medixinfusion.com — all 404 (WordPress 404 template, ~112KB HTML). - id: graphql conforms: false evidence: 'https://medixinfusion.com/graphql -> 404' - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is documented anywhere on the public site. - id: oauth2 conforms: false evidence: 'https://medixinfusion.com/.well-known/oauth-authorization-server -> 404; no OAuth documentation published.' - id: oidc conforms: false evidence: 'https://medixinfusion.com/.well-known/openid-configuration -> 404' - id: rfc9457 conforms: false evidence: No API, therefore no problem+json error envelope to assess. - id: rfc9116 conforms: false evidence: 'https://medixinfusion.com/.well-known/security.txt -> 404 (bare nginx 404, 548 bytes)' - id: wordpress-rest-api conforms: true evidence: >- https://medixinfusion.com/wp-json -> 200, 429KB of JSON, 565 routes across 24 namespaces (wp/v2, oembed/1.0, aioseo/v1, elementor/v1, jet-engine/v2, google-site-kit/v1, wp-abilities/v1 and others). It self-identifies as this company — name "Medix Infusion", url https://medixinfusion.com — so ownership is not in question. It is nevertheless CMS infrastructure that ships enabled by default with WordPress and its plugins, not an API this company designed, documented or offers to anyone. It is recorded here because it is the only machine-readable surface on the domain and the discovery pass genuinely found it; NO OpenAPI is derived from it and NO API entry or contract pointer is wired in apis.yml, because doing so would credit Medix Infusion with shipping an API it never shipped. - id: llmstxt conforms: true evidence: >- https://medixinfusion.com/llms.txt -> 200, 14,680 bytes, text/plain. Served by the site and saved verbatim to llms/medix-infusion-llms.txt. Generated by the All in One SEO WordPress plugin v5.0.0.1 rather than hand-authored, and it indexes marketing pages, team bios and clinic locations — it is a real served document, not an API description. domain_standards: - id: hl7-fhir conforms: false evidence: >- FHIR is the domain standard for this market (US healthcare / patient and clinical data). Medix Infusion exposes no FHIR endpoint, no CapabilityStatement and no /fhir path on any host it operates; it is a care-delivery organization, not a health IT vendor, and buys rather than builds its clinical systems. Not penalised — recorded so the absence is measured rather than assumed. - id: x12 conforms: false evidence: >- The company performs benefits investigation and prior authorization, which run on X12 270/271/278 transactions in this industry, but nothing about that exchange is published or exposed publicly. healthcare_accreditation: - id: achc name: Accreditation Commission for Health Care conforms: true evidence: >- Stated on the homepage: "Our commitment to quality of care and outcomes is showcased through our accreditation through the Accreditation Commission for Health Care (ACHC)." ACHC-Accredited badge served from https://medixinfusion.com/wp-content/uploads/2022/12/ACHC-Accredited-white.png and linked to https://www.achc.org/ (homepage, HTTP 200). - id: nabp name: National Association of Boards of Pharmacy conforms: unverified evidence: >- NABP logo displayed in the homepage accreditation strip and linked to https://nabp.pharmacy/. The site displays the mark but states no program, accreditation type or credential number, so the claim is recorded as displayed-but-unspecified rather than verified. - id: ig-ns name: IgNS — Immunoglobulin National Society conforms: unverified evidence: >- IgNS logo displayed in the homepage accreditation strip and linked to https://ig-ns.org/. Consistent with the company's IVIG service line; no certification detail published. - id: hipaa conforms: true evidence: >- https://medixinfusion.com/privacy-policy/ (HTTP 200) is a HIPAA Notice of Privacy Practices — "THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION" — effective 2016-06-01, revised 2022-12-30, covering the Arizona, Kansas, Missouri, Oregon and Texas clinics. This establishes the company as a HIPAA covered entity; it says nothing about any API. notes: >- No SOC 2, ISO 27001, PCI DSS, HITRUST or FedRAMP claim is published anywhere on the public site, and there is no trust center. No `Compliance` pointer is wired in apis.yml: the accreditations above are care-delivery credentials, and wiring them to a check that reads an API provider's published compliance program would credit Medix Infusion for something it has not done.