Compliance

CMS mandates delivered
ahead of deadline.

Every major CMS interoperability rule — CMS-9115-F and CMS-0057-F — implemented in production with full audit readiness and HIPAA compliance posture.

CMS mandates

Every API,
live in production.

CMS-9115-F
Interoperability & Patient Access Final Rule
Delivered 3 days early

Full CMS-9115-F implementation delivered three days ahead of the CMS enforcement date — Patient Access API, Provider Directory API, and Payer-to-Payer API covering 64,300 members and 4.7M FHIR resources.

Patient Access API — clinical, claims, and formulary data
Provider Directory API — FHIR-based network data
Payer-to-Payer API — 64,300 members, 4.7M resources
SMART on FHIR authorization for third-party app access
FHIR R4 + US Core profiles throughout
CMS-0057-F
Prior Authorization Final Rule
Production delivered

CMS-0057-F Prior Authorization API implemented across a multi-agency environment requiring coordination across state and federal stakeholders — full Da Vinci PAS with decision transparency and audit trail.

Prior Authorization API (Da Vinci PAS)
Decision transparency — reason codes in FHIR responses
Provider-facing PA submission and status API
Multi-agency coordination framework
Full audit trail for every PA decision
Medicaid-specific
State Medicaid Interoperability
7 implementations

Seven Medicaid implementations with zero missed CMS deadlines — building institutional knowledge of state-specific data governance, multi-agency coordination, and beneficiary data sovereignty.

AWS GovCloud — 3.1M members, 71M calls/month
State-specific data governance frameworks
CMS audit reporting and compliance dashboards
Zero missed deadlines across all 7 implementations
Standards & profiles

The full stack of
healthcare standards.

FHIR R4

HL7 FHIR R4

Full R4 specification — the current required CMS standard. JSON and XML, all core resource types, US Core profiles.

US Core 6.1.0

US Core Profiles

Delivered 3.1.1 → 6.1.0 upgrade in production — onboarding 340+ third-party apps without disruption.

CARIN BB

CARIN BlueButton 2.0

Consumer-directed exchange of payer-held claims and EOB data for member-facing applications.

Da Vinci

Da Vinci PDex / PAS

PDex for payer data exchange, PAS for prior authorization — implemented in production across multiple deployments.

SMART

SMART on FHIR

OAuth 2.0/PKCE authorization. 31 apps live, 38M API calls/month, granular scope enforcement per app.

Bulk FHIR

FHIR Bulk Data Access

Async bulk export and import for population-level exchange — powering P2P transfer and analytics pipelines.

Delivery history

A record of
on-time delivery.

CMS-9115-F · Patient Access Suite
Full patient access, provider directory, and payer-to-payer APIs
Delivered three days ahead of CMS enforcement. 64,300 members covered under Payer-to-Payer exchange, 4.7M FHIR resources transferred. SMART on FHIR and US Core profiles live from day one.
US Core Upgrade · 340+ apps
US Core 3.1.1 → 6.1.0 + CARIN BB upgrade in live production
Major profile upgrade across a live environment — 340+ third-party apps maintained through the transition. Zero breaking incidents, no enforcement issues.
SMART on FHIR · Scale
31 SMART apps live at 38M calls/month
Full authorization layer — app registration, OAuth 2.0/PKCE, scope enforcement, monitoring — serving 38 million API calls per month across 31 production applications.
CMS-0057-F · Prior Authorization
Prior Authorization API across multi-agency environment
Da Vinci PAS implementation with full audit trail, decision transparency, and multi-agency coordination across state and federal stakeholders.
AWS GovCloud · Medicaid scale
3.1M members · 71M FHIR calls/month
Largest production deployment: GovCloud infrastructure for 3.1M Medicaid beneficiaries with 56-minute P1 MTTR and 24/7 SRE.
Security posture

HIPAA-compliant by design,
not by checkbox.

Encryption

AES-256 at rest via AWS KMS, TLS 1.3 in transit. No PHI in unencrypted channels at any layer of the stack.

Access Control

Role-based access control with MFA for all platform access. SMART on FHIR OAuth 2.0/PKCE for third-party apps. Least privilege enforced at every tier.

Real-Time Monitoring

Continuous monitoring with automated anomaly detection. Every FHIR call traced end-to-end. 56-minute P1 MTTR with 24/7 SRE on-call coverage.

Audit Logging

Tamper-evident audit logs for every data access, API call, and system change. Structured for CMS audit readiness and exportable for federal compliance reporting.

Questions about your
compliance posture?

We'll walk through your regulatory obligations and show you exactly how FHIRFabric addresses them.