generated: '2026-08-14' method: derived source: >- openapi/ribbon-health-*-openapi.yml + https://ribbon.readme.io/llms.txt + live probes of https://api.ribbonhealth.com (2026-08-14) + probe-security-programs.py (2026-08-14) summary: >- A plain HTTP/JSON REST API with bearer-token auth. It conforms to no healthcare interoperability standard — notably NOT FHIR, despite operating on providers, locations, networks, eligibility and prices, all of which have FHIR resource equivalents. It DOES use the US healthcare identifier and code vocabularies (NPI, CPT, TIN) as its primary keys, which is the real interoperability story here. standards: - id: openapi-3.0 conforms: true evidence: >- Ten OpenAPI 3.0.0 documents covering 55 paths / ~69 operations, split by tag from the provider-derived source spec. - id: oauth2 conforms: false evidence: >- No oauth2 securityScheme in any spec; no OAuth documented; /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource both 404 on api.ribbonhealth.com. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on every host. - id: rfc6750-bearer-token conforms: true evidence: >- 'Authorization: Bearer {customer_token}' per https://ribbon.readme.io/docs/authentication; securityScheme BearerAuth (type http, scheme bearer) in every spec. - id: rfc9457-problem-details conforms: false evidence: >- Errors return application/json with a custom nested {"error":{status,code,message}} envelope, not application/problem+json, and carry no `type` URI. See errors/ribbon-health-problem-types.yml. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt 404s on api.ribbonhealth.com, ribbon.readme.io, h1.co, h1.com and ribbonhealth.com. The only 200 belongs to Atlassian via the Statuspage host. - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation header observed on live responses; two endpoints are deprecated in prose only. - id: rfc8615-well-known conforms: false evidence: No /.well-known/ document is served on any host. - id: fhir-r4 conforms: false evidence: >- No FHIR resource shapes, no /metadata CapabilityStatement, no fhir+json content type, and no mention of FHIR in the 122-page documentation index. Provider, Location, Organization, InsurancePlan and Coverage all exist here as proprietary H1 schemas rather than as FHIR Practitioner / Location / Organization / InsurancePlan / Coverage. note: >- This is the single largest conformance gap for a provider-directory API. CMS interoperability rules push payer provider directories toward FHIR; H1's directory API does not speak it. - id: da-vinci-pdex-plan-net conforms: false evidence: >- No FHIR base, therefore no Plan-Net provider-directory IG conformance, despite this being the canonical standard for exactly this product category. - id: x12-270-271-eligibility conforms: false partial: true evidence: >- The eligibility surface (POST /v1/eligibility, GET /v1/eligibility_insurance_partners) returns deductible, out-of-pocket, copay and coinsurance data — the payload of an X12 271 response — but is exposed as proprietary JSON, not as X12 or as FHIR CoverageEligibilityResponse. The upstream clearinghouse is a third party; the published contract is H1's own. - id: npi-national-provider-identifier conforms: true evidence: >- NPI is the primary key for the entire provider surface — GET/PUT /v1/custom/providers/{npi} and every nested provider path. Documented at https://ribbon.readme.io/docs/npi-national-provider-identifier. - id: cpt-procedure-codes conforms: true evidence: >- Price Transparency v2 resolves procedures by CPT code (the docs' worked example is CPT 27447, total knee arthroplasty) via GET /v2/procedures. - id: tin-tax-identification-number conforms: true evidence: GET /v1/custom/tin and /v1/custom/tin/{tin_id}; documented at https://ribbon.readme.io/docs/tins. - id: cms-hospital-price-transparency conforms: partial evidence: >- The Price Transparency product is built on carrier-published negotiated-rate data (the machine-readable files mandated by the CMS Transparency in Coverage / Hospital Price Transparency rules) and exposes per-carrier data recency via /v1/pricing/carriers. H1 is a CONSUMER and redistributor of that regulated data, not a regulated publisher of it, so this is an ecosystem role rather than a conformance claim. - id: pagination conforms: true evidence: page / page_size query params, default page_size 25; v2 envelope publishes parameters/total_count/page/page_size/data. - id: idempotency conforms: false evidence: >- Zero matches for "idempoten" across all ten specs and the entire documentation index. No Idempotency-Key header. See conventions/ribbon-health-conventions.yml. - id: json-schema conforms: true evidence: 12 JSON Schema documents derived into json-schema/ from the OpenAPI response shapes. - id: asyncapi conforms: false evidence: >- No event, streaming or webhook surface exists. Zero matches for "webhook" in the documentation index. This is N/A for scoring rather than a failure. - id: graphql conforms: false evidence: No /graphql endpoint documented or discoverable. - id: mcp conforms: false evidence: >- No MCP server published; zero matches for "MCP" or "model context protocol" in the docs. See mcp/ribbon-health-mcp.yml. - id: a2a conforms: false evidence: /.well-known/agent-card.json and /.well-known/agent.json 404 on all five hosts. compliance_program: published: false probed: - url: https://h1.com/trust/ status: 404 checked: '2026-08-14' - url: https://h1.co/security/ status: 200 note: >- Soft 200 — redirects to https://h1.com/health-plans/, a marketing page with no security or compliance content. Not a security policy. checked: '2026-08-14' - url: https://trust.h1.com/ status: 000 note: DNS does not resolve. checked: '2026-08-14' note: >- No trust center, no named certification (SOC 2 / ISO 27001 / HITRUST / HIPAA attestation) is published on any public H1 or Ribbon Health page that this pass could reach. NO `Compliance` pointer and NO `TrustCenter` pointer are emitted. This is a notable absence rather than a neutral one: the eligibility endpoint transmits member PHI, so a covered entity's procurement team has nothing public to evaluate before contacting sales.