Patient Access API
The Patient Access API is a secure online connection that certain federally regulated health insurers (payers) must operate so that their members can access their own health data through third-party apps of their choosing. It generally makes available information such as claims, encounter, and cost data, along with a defined set of clinical data. It is intended to help patients more easily retrieve and use their health information.
The Patient Access API is a FHIR-based application programming interface that certain CMS-regulated payers are required to implement to make specified data available to enrollees. Per the evidence, the data set generally includes claims and encounter information (including cost), clinical data such as laboratory results, and, in some payer implementations, membership, coverage, and prescription (RX) formulary information. This requirement arises from CMS interoperability rules and is distinct from HIPAA's Privacy Rule right of access; readers should verify the specific applicable payers, data elements, and compliance dates against current CMS regulatory text, as scope and effective dates are subject to change. Note that CMS interoperability requirements and HIPAA are separate authorities, and this definition addresses only the CMS Patient Access API mandate as described in the evidence.
Why it matters
The Patient Access API represents a significant shift in how patients interact with their own health information. Historically, enrollees seeking their claims, encounter, and clinical data often faced fragmented processes and manual requests. By requiring certain CMS-regulated payers to operate a standardized, FHIR-based interface, the mandate is intended to let members retrieve their data through third-party applications of their choosing, generally including claims and encounter information (with cost), clinical data such as laboratory results, and, in some implementations, membership, coverage, and prescription formulary information.
For compliance professionals, it is important to recognize that the Patient Access API arises from CMS interoperability rules and is a distinct authority from HIPAA. The HIPAA Privacy Rule's individual right of access is a separate requirement enforced by HHS OCR, whereas the Patient Access API mandate is a CMS requirement applicable to specified payers. Conflating the two can lead to gaps in compliance planning, because each imposes its own scope, obligations, and timelines. Organizations subject to both should map their responsibilities under each authority separately rather than assuming one satisfies the other.
Because the applicable payers, data elements, and compliance dates for the CMS interoperability rules are subject to change, organizations should verify current requirements against the applicable CMS regulatory text rather than relying on general summaries. Enabling patient access through third-party apps also raises downstream privacy and security considerations, since data flowing to consumer-facing applications may move outside the direct control of the payer; readers should evaluate these considerations in light of current CMS guidance and any applicable state law.
Who it's relevant to
Inside Patient Access API
Common questions
Answers to the questions practitioners most commonly ask about Patient Access API.