generated: '2026-09-05' method: derived source: openapi/znanylekarz-integrations-api.yml searched: https://integrations.docplanner.com/guide/ note: >- Cross-cutting standards asserted only where the contract or the docs actually demonstrate them. ZnanyLekarz operates in EU healthcare, where a real domain standard exists (HL7 / FHIR), and the honest finding is that this API does not speak it: it is a bespoke booking and calendar contract. That is recorded as conforms:false with evidence rather than left out, because the distinction matters to a buyer — an EHR vendor integrating here needs a bespoke connector, not a FHIR client. No certification or audit report is claimed: trust.docplanner.com was fetched and is a content- moderation Trust and Transparency Report, naming no SOC 2, ISO 27001, PCI DSS or HIPAA certification, so no Compliance pointer is emitted in apis.yml. conformance: - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: >- components.securitySchemes.oauth2 declares a clientCredentials flow with tokenUrl https://www.{domain}/oauth/v2/token and the scope `integration`; the description cites RFC 6749 directly and documents the Basic-auth token exchange and the Bearer request header. source: openapi/znanylekarz-integrations-api.yml - id: bearer-token name: OAuth 2.0 Bearer Token Usage (RFC 6750) conforms: true evidence: 'Authorization: Bearer {access_token} on every request; 401 on absent credentials, observed live.' source: https://integrations.docplanner.com/guide/fundamentals/authorization.html - id: openapi name: OpenAPI 3.0.3 conforms: true evidence: >- A complete OpenAPI 3.0.3 document, version 1.14.0, 32 paths, 44 operations, 82 schemas, 166 named examples, 17 typed callbacks, published by the provider and rendered at integrations.docplanner.com/docs/. source: openapi/znanylekarz-integrations-api.yml - id: rfc6585 name: HTTP 429 Too Many Requests (RFC 6585) with Retry-After conforms: true evidence: >- 429 documented as the exhaustion status; Retry-After typed as an integer of seconds on the 429 response of POST /notifications/release. source: https://integrations.docplanner.com/guide/fundamentals/rate-limits.html - id: rfc9116 name: security.txt (RFC 9116) conforms: true evidence: >- https://www.znanylekarz.pl/.well-known/security.txt returns HTTP 200, text/plain, with a Contact field. Minimal — it carries Contact only, with no Expires field, which RFC 9116 lists as REQUIRED, so this is a partial implementation. partial: true source: well-known/znanylekarz-security.txt - id: iso8601 name: ISO 8601 date and time formats conforms: true evidence: >- X-RateLimit-Reset is specified as "formatted in ISO8601"; booking start_at/end_at, break since/till and notification created_at all carry date-time formats. source: openapi/znanylekarz-integrations-api.yml - id: pagination name: Documented collection pagination conforms: true partial: true evidence: >- page and limit query parameters with a documented default of 100. Opt-in — omitting `page` returns the collection unpaginated — and responses carry no total, no page count, no next cursor and no Link header, so a client cannot detect the last page except by a short read. source: openapi/znanylekarz-integrations-api.yml - id: webhooks name: OpenAPI 3 callbacks (typed event contract) conforms: true evidence: >- 17 named callbacks on POST /{client-endpoint-url}, each with a $ref'd notification schema and documented response semantics, plus a pull queue with its own endpoints and retention rules. source: asyncapi/znanylekarz-notifications.yml - id: rfc9457 name: Problem Details for HTTP APIs (RFC 9457 / RFC 7807) conforms: false evidence: >- Errors use the vendor media type application/vnd.error+docplanner+json with a {errors: [], message: ""} envelope. No type URI, title, status, detail or instance member, and no application/problem+json anywhere in the contract. source: errors/znanylekarz-problem-types.yml - id: idempotency name: Idempotency-Key (draft-ietf-httpapi-idempotency-key-header) conforms: false evidence: >- No Idempotency-Key header or equivalent client-supplied request identifier on any of the 15 mutating operations. Duplicate suppression exists only as 409 conflict detection on natural keys for six operations. source: conventions/znanylekarz-conventions.yml - id: rfc8594 name: Sunset header / deprecation signalling (RFC 8594) conforms: false evidence: >- No Sunset or Deprecation header, no deprecation policy page, and zero operations, parameters or schemas marked deprecated across 70 documented versions. source: lifecycle/znanylekarz-lifecycle.yml - id: ratelimit-headers name: IETF RateLimit header fields (draft-ietf-httpapi-ratelimit-headers) conforms: false partial: true evidence: >- Rate limits ARE signalled, but with the legacy X-RateLimit-Limit / -Reset / -Used / -Remaining set rather than the standard-track RateLimit and RateLimit-Policy fields. The runtime signal is present; the standard form is not. source: rate-limits/znanylekarz-rate-limits.yml - id: oidc name: OpenID Connect Discovery conforms: false evidence: >- /.well-known/openid-configuration returns 404 on znanylekarz.pl, www.znanylekarz.pl and integrations.docplanner.com. The token endpoint is documented only inside the OpenAPI securityScheme; there is no OAuth 2.0 Authorization Server Metadata document (RFC 8414) either. source: well-known/znanylekarz-well-known.yml domain_standards: - id: fhir name: HL7 FHIR (Appointment / Schedule / Slot / Practitioner resources) conforms: false evidence: >- Checked and absent. The scheduling domain has a mature standard whose Slot, Schedule, Appointment, Practitioner, Location and Organization resources map almost one-to-one onto this API's Slot, Calendar, Booking, Doctor, Address and Facility. Nothing in the contract references it: no FHIR media type (application/fhir+json), no resourceType member on any of the 82 schemas, no canonical URL, no CapabilityStatement. Field names are bespoke (since/till, address_service, is_price_from). An EHR that already speaks FHIR needs a purpose-built connector for this API. source: openapi/znanylekarz-integrations-api.yml - id: hl7v2 name: HL7 v2 messaging (SIU scheduling messages) conforms: false evidence: >- No HL7 v2 message types, segments or MLLP transport anywhere in the contract or the guide. source: openapi/znanylekarz-integrations-api.yml - id: nfz name: NFZ — Polish National Health Fund public healthcare flow conforms: true partial: true evidence: >- The provider publishes a dedicated Poland-specific guide page, "NFZ public healthcare (Poland)", and the contract carries a matching response extension enum, address_service.public_insurance_flow, applied across getBookings, getBooking, getAddressServices, getAddressService and moveBooking (introduced in 1.8.0). This is national public-healthcare integration expressed in the vendor's own vocabulary rather than a published standard's, so it is recorded as a domain surface, not as conformance to an external schema. source: https://integrations.docplanner.com/guide/api-objects/public-healthcare-nfz-poland.html regulatory_context: jurisdiction: Poland (European Union) regimes: - id: gdpr name: EU General Data Protection Regulation applicable: true basis: >- The API returns patient health-appointment data including name, email, phone, birth date, national identification number (nin), gender and insurance number via the booking.patient response extension. Appointment data in a medical context is special-category personal data under GDPR Article 9. published_policy: https://www.znanylekarz.pl/prywatnosc additional_policy: https://www.znanylekarz.pl/polityka-prywatnosci-dla-profesjonalistow-ktorych-dane-pozyskalismy-samodzielnie api_specific_dpa_published: false note: >- Privacy policies are published for the marketplace, including a separate notice for professionals whose data was independently sourced. No API-specific data processing agreement, subprocessor list or data-residency statement is published on the developer surface; those are settled in the partner onboarding conversation. - id: eu-ai-act name: EU AI Act applicable: unknown note: >- Not asserted. The marketplace ships an AI assistant add-on (Noa Notes) but nothing on the public developer surface speaks to its classification, and no claim is made here. certifications: published: false checked: - url: https://trust.docplanner.com/ status: 200 finding: >- A Trust and Transparency Report about content moderation and user safety. Names no security certification, audit report or compliance framework. - url: https://www.znanylekarz.pl/.well-known/security.txt status: 200 finding: Contact field only; no Policy, Encryption, Acknowledgments or Expires. note: >- No SOC 2, ISO 27001, ISO 27701, HIPAA, PCI DSS or FedRAMP claim was found on any host probed. No Compliance or TrustCenter pointer is emitted for this record.