generated: '2026-07-20' method: searched source: >- https://www.poweredbyash.com/frequently-asked-questions and https://trust.poweredbyash.com — Ash Wellness published compliance and laboratory-certification claims. No public OpenAPI is available (developer docs at docs.ashwellness.io are partner/password-gated), so technical conformance (OAuth/OIDC/pagination/errors) could not be derived from a spec. standards: - id: hipaa conforms: true evidence: >- "Ash is fully HIPAA compliant and utilizes enterprise-grade encryption to protect Protected Health Information (PHI)." (poweredbyash.com FAQ) - id: soc2-type-ii conforms: true evidence: >- "SOC 2 Type II compliance, ensuring that all data transmitted via our API or stored on our servers meets the strictest healthcare security standards." (poweredbyash.com FAQ) - id: clia conforms: true evidence: >- All testing is conducted through a network of labs that maintain CLIA (Clinical Laboratory Improvement Amendments) certification. (poweredbyash.com FAQ) - id: cap conforms: true evidence: >- Lab network maintains CAP (College of American Pathologists) certification. (poweredbyash.com FAQ) - id: rest conforms: true evidence: >- Ash describes a "developer-friendly REST API" managing the test lifecycle (kit triggering, shipping, secure results transmission to EHR/patient portal). Spec is partner-gated; not independently verified.