generated: '2026-08-15' method: searched source: https://trust.notablehealth.com/ docs: https://www.notablehealth.com/security note: >- Notable publishes no public machine-readable API contract, so no standard below is asserted from a specification. Everything marked conforms:true is a published compliance/certification claim carried on Notable's SafeBase Trust Center or its own llms.txt; everything marked conforms:false is recorded as "not evidenced", which is a measurement, not an accusation. standards: - id: soc2-type-2 conforms: true evidence: 'Trust Center certification badge: "SOC 2 Type 2" (https://trust.notablehealth.com/)' - id: iso-iec-27001-2022 conforms: true evidence: 'Trust Center certification badge: "ISO/IEC 27001:2022" (https://trust.notablehealth.com/)' - id: pci-dss conforms: true evidence: 'Trust Center certification badge: "PCI DSS" (https://trust.notablehealth.com/)' - id: hitrust conforms: true evidence: 'Trust Center certification badge: "HITRUST" (https://trust.notablehealth.com/)' - id: hipaa conforms: true evidence: >- "The company is SOC 2 Type II audited, ISO 27001:2022 certified, and HIPAA compliant" — https://www.notablehealth.com/llms.txt (provider-published, fetched 2026-08-15) - id: penetration-testing-annual conforms: true evidence: 'Trust Center control "Penetration Testing": "Penetration tests are conducted on an annual basis."' - id: fhir conforms: unverified evidence: >- Notable's own integrations page and llms.txt state the platform consumes "FHIR APIs" and HL7 interfaces when integrating with Epic, Oracle Health/Cerner, MEDITECH, athenahealth and eClinicalWorks. That is Notable acting as a FHIR CLIENT of its customers' EHRs; no evidence was found that Notable EXPOSES a FHIR server of its own. https://api.notablehealth.com/fhir and /fhir/metadata both returned 404 on 2026-08-15. - id: hl7-v2 conforms: unverified evidence: same as fhir — consumed as an integration method, not published as a Notable interface - id: oauth2 conforms: false evidence: >- no published OAuth surface; /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource 404 on every Notable host - id: oidc conforms: false evidence: /.well-known/openid-configuration 404 on every Notable host - id: openapi conforms: false evidence: >- no OpenAPI/Swagger found on the API host root, the docs host, or the GitHub org after the full STEP 0b contract-discovery sweep (2026-08-15) - id: rfc9457-problem-details conforms: false evidence: >- the one JSON error envelope observed anonymously from api.notablehealth.com ({"type":"forbidden_error","message":"Forbidden","traceId":"..."}) is a custom shape, not application/problem+json - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt 404 on every Notable host (see well-known/notable-well-known.yml) - id: a2a-agent-card conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json 404 on every Notable host