generated: '2026-08-26' method: searched source: https://morehealth.com/en/security + https://morehealth.com/en/hospital-solutions note: >- MORE Health publishes no machine-readable API contract, so nothing here is derived from a spec. Every entry below is a compliance/certification claim read verbatim from a MORE Health marketing page, or a recorded non-conformance where the standard could not be evidenced. No API-protocol standard (OAuth 2.0, OIDC, FHIR, SMART on FHIR, RFC 9457, RFC 9116) could be assessed because there is no public contract, reference, or auth surface to assess it against. standards: - id: iso-27001 name: ISO/IEC 27001 Information Security Management conforms: true evidence: claim: 'ISO 27001 certified' url: https://morehealth.com/en/hospital-solutions status: 200 context: >- Listed under "Secure and Confidential" in the Physician Collaboration Platform section. caveat: >- Self-asserted on a marketing page. No certificate number, certification body, scope statement or expiry date is published, and MORE Health operates no trust center from which one could be downloaded. - id: hipaa name: HIPAA (US Health Insurance Portability and Accountability Act) conforms: true evidence: claim: 'certified GDPR and HIPAA compliance' url: https://morehealth.com/en/security status: 200 context: >- Also asserted on /en/hospital-solutions ("Secure, Encrypted, GDPR- and HIPAA-compliant") and applied specifically to the video-conferencing tooling ("HIPAA-compliant video conferencing"). - id: gdpr name: EU General Data Protection Regulation conforms: true evidence: claim: 'certified GDPR and HIPAA compliance' url: https://morehealth.com/en/security status: 200 - id: dicom name: DICOM (Digital Imaging and Communications in Medicine) conforms: partial evidence: claim: >- 'FDA-approved medical images, including CT-images & Radiation Therapy DICOM, as well as Pathology Imaging' url: https://morehealth.com/en/security status: 200 context: >- DICOM is named as a supported IMAGE FORMAT the platform ingests and displays, not as a network service (no DICOMweb / QIDO-RS / WADO-RS / STOW-RS endpoint is published). Recorded as partial for that reason: the company handles the format, it does not expose the protocol. - id: fhir name: HL7 FHIR conforms: false evidence: note: >- No mention of HL7, FHIR, SMART on FHIR, CDA or any interoperability standard anywhere on morehealth.com. Searched every page in the sitemap; the platform describes record collection and storage but names no exchange standard. url: https://morehealth.com/sitemap.xml status: 200 - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: url: https://morehealth.com/.well-known/security.txt status: 404 - id: oauth2 name: OAuth 2.0 conforms: unknown evidence: note: >- Not assessable. No public API, no authorization server metadata, and no developer documentation describing an auth model. url: https://morehealth.com/.well-known/oauth-authorization-server status: 404 domain_standard: applicable_regime: healthcare candidate_standards: - HL7 FHIR - HL7 v2 - DICOMweb - SMART on FHIR - X12 (270/271/837) - IHE XDS declared: none note: >- REWARD-ONLY check, and MORE Health earns nothing here — not because its market has no standard (healthcare has the densest standards landscape of any sector) but because the company publishes no contract in which a domain standard could be declared. DICOM appears only as an accepted file format on a marketing page, which is not a contract-level declaration.