{
  "app_to_server": {
    "answers": [
      {
        "answer": "declared",
        "answer_text": "declared",
        "asks": "Declares private_key_jwt client authentication at the token endpoint",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "token_endpoint_auth_methods_supported lists private_key_jwt among 3",
        "key": "private_key_jwt",
        "source": "SMART discovery: token_endpoint_auth_methods_supported"
      },
      {
        "answer": "field_absent",
        "answer_text": "not declared: the field is absent",
        "asks": "Declares the client_credentials grant, which SMART Backend Services uses",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "the document has no grant_types_supported",
        "key": "client_credentials",
        "source": "SMART discovery: grant_types_supported"
      },
      {
        "answer": "not_listed",
        "answer_text": "not listed",
        "asks": "Declares the client-confidential-asymmetric capability",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "capabilities lists 4 and not client-confidential-asymmetric",
        "key": "client_confidential_asymmetric",
        "source": "SMART discovery: capabilities"
      },
      {
        "answer": "declared",
        "answer_text": "declared",
        "asks": "Declares system-level scopes",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "1 of 4 scopes_supported are system/ scopes",
        "key": "system_scopes",
        "source": "SMART discovery: scopes_supported"
      },
      {
        "answer": "declared",
        "answer_text": "declared",
        "asks": "Declares an export operation",
        "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
        "detail": "export is declared on the whole server",
        "key": "export_operation",
        "source": "CapabilityStatement: rest.operation and rest.resource.operation"
      },
      {
        "answer": "not_listed",
        "answer_text": "not listed",
        "asks": "Instantiates the Bulk Data Access implementation guide",
        "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
        "detail": "0 canonicals are instantiated and none is Bulk Data's",
        "key": "bulk_data_guide",
        "source": "CapabilityStatement: instantiates"
      }
    ],
    "note": "What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded."
  },
  "dimensions": [
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/R4/http.html",
          "code": "R1",
          "max_points": 60,
          "message": "/metadata answers with HTTP 2xx over HTTPS: reachable from all 3 vantages, which are 3 hosts on one network (github-actions): one network's view sampled 3 times, not 3 independent networks",
          "observed": true,
          "ok": true,
          "points": 60,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/http.html",
          "code": "R2",
          "max_points": 40,
          "message": "/metadata responded in 274 ms (median across 3 reachable vantages on one network)",
          "observed": true,
          "ok": true,
          "points": 40,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "reachability",
      "score": 100,
      "title": "Reachability"
    },
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T1",
          "max_points": 30,
          "message": "fhirVersion declared: '4.0.0' (expected 4.x)",
          "observed": true,
          "ok": true,
          "points": 30,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T2",
          "max_points": 20,
          "message": "software name/version missing",
          "observed": true,
          "ok": false,
          "points": 0,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T3",
          "max_points": 25,
          "message": "24 resource types declared",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T4",
          "max_points": 25,
          "message": "0/24 declared resources document their interactions",
          "observed": true,
          "ok": false,
          "points": 0,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "transparency",
      "score": 55,
      "title": "Capability transparency"
    },
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/us/core/",
          "code": "I1",
          "max_points": 40,
          "message": "no profile canonical declared in rest.resource.supportedProfile, rest.resource.profile, instantiates, imports, or meta.profile",
          "observed": true,
          "ok": false,
          "points": 0,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
          "code": "I2",
          "max_points": 35,
          "message": "SMART discovery document present and complete",
          "observed": true,
          "ok": true,
          "points": 35,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
          "code": "I3",
          "max_points": 25,
          "message": "OAuth/SMART security service declared in CapabilityStatement",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "interop",
      "score": 60,
      "title": "Interop readiness"
    }
  ],
  "drift_alternations": [],
  "drift_events": [],
  "endpoint": {
    "availability": "answered 44 of the last 45 daily checks (98%)",
    "base_url": "https://ccpcmsioapi.zeomega.com/t/ccpprd.com/fhir/r4",
    "endpoint_id": "22-health-patient-access",
    "expects_fhir": "r4",
    "failure_kinds": [],
    "grade": "C",
    "interop_score": 60,
    "kind": "payer",
    "last_answered": "2026-10-03",
    "name": "22 Health (Community Care Plan) Patient Access API",
    "observed_since": "2026-08-20",
    "reachability_score": 100,
    "reachable": "true",
    "reverified_date": "",
    "transparency_score": 55,
    "vantages_reached": 3,
    "vantages_reporting": 3,
    "verification_basis": "live_capability",
    "verified_date": "2026-08-19",
    "verified_method": "live CapabilityStatement fetch. The base URL is printed verbatim, in a table headed 'Base URLs for connecting to these APIs are', on the issuer's own /api/ page; the host is the vendor's (ZeOmega HealthUnity), so attribution rests on the plan printing this exact string on its own domain. Two things the document declares are recorded rather than tidied: fhirVersion is 4.0.0, not the 4.0.1 every other listed endpoint declares, and it carries no software element, identifying itself only as 'ZeOmega FHIR R4 Implementation' dated 2021-01-01. The Drug Formulary base URL printed in the same table answers 404 and is in the candidate log"
  },
  "generated_at": "2026-10-03 15:21 UTC",
  "schema_version": 2,
  "vantage": "reconciled from github-actions/macos-latest, github-actions/ubuntu-latest, github-actions/windows-latest",
  "vantages": [
    {
      "elapsed_ms": 274,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/macos-latest"
    },
    {
      "elapsed_ms": 427,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/ubuntu-latest"
    },
    {
      "elapsed_ms": 266,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/windows-latest"
    }
  ]
}