{
  "app_to_server": {
    "answers": [
      {
        "answer": "not_retrieved",
        "answer_text": "not retrieved on this run",
        "asks": "Declares private_key_jwt client authentication at the token endpoint",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "the SMART discovery document was requested and not served on this run",
        "key": "private_key_jwt",
        "source": "SMART discovery: token_endpoint_auth_methods_supported"
      },
      {
        "answer": "not_retrieved",
        "answer_text": "not retrieved on this run",
        "asks": "Declares the client_credentials grant, which SMART Backend Services uses",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "the SMART discovery document was requested and not served on this run",
        "key": "client_credentials",
        "source": "SMART discovery: grant_types_supported"
      },
      {
        "answer": "not_retrieved",
        "answer_text": "not retrieved on this run",
        "asks": "Declares the client-confidential-asymmetric capability",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "the SMART discovery document was requested and not served on this run",
        "key": "client_confidential_asymmetric",
        "source": "SMART discovery: capabilities"
      },
      {
        "answer": "not_retrieved",
        "answer_text": "not retrieved on this run",
        "asks": "Declares system-level scopes",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "the SMART discovery document was requested and not served on this run",
        "key": "system_scopes",
        "source": "SMART discovery: scopes_supported"
      },
      {
        "answer": "not_listed",
        "answer_text": "not listed",
        "asks": "Declares an export operation",
        "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
        "detail": "27 operations are declared and none is named export",
        "key": "export_operation",
        "source": "CapabilityStatement: rest.operation and rest.resource.operation"
      },
      {
        "answer": "not_listed",
        "answer_text": "not listed",
        "asks": "Instantiates the Bulk Data Access implementation guide",
        "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
        "detail": "0 canonicals are instantiated and none is Bulk Data's",
        "key": "bulk_data_guide",
        "source": "CapabilityStatement: instantiates"
      }
    ],
    "note": "What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded."
  },
  "dimensions": [
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/R4/http.html",
          "code": "R1",
          "max_points": 60,
          "message": "/metadata answers with HTTP 2xx over HTTPS: reachable from all 3 vantages, which are 3 hosts on one network (github-actions): one network's view sampled 3 times, not 3 independent networks",
          "observed": true,
          "ok": true,
          "points": 60,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/http.html",
          "code": "R2",
          "max_points": 40,
          "message": "/metadata responded in 875 ms (median across 3 reachable vantages on one network)",
          "observed": true,
          "ok": true,
          "points": 40,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "reachability",
      "score": 100,
      "title": "Reachability"
    },
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T1",
          "max_points": 30,
          "message": "fhirVersion declared: '4.0.1' (expected 4.x)",
          "observed": true,
          "ok": true,
          "points": 30,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T2",
          "max_points": 20,
          "message": "software name and version declared",
          "observed": true,
          "ok": true,
          "points": 20,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T3",
          "max_points": 25,
          "message": "24 resource types declared",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T4",
          "max_points": 25,
          "message": "24/24 declared resources document their interactions",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "transparency",
      "score": 100,
      "title": "Capability transparency"
    },
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/us/core/",
          "code": "I1",
          "max_points": 40,
          "message": "US Core / CARIN / Da Vinci profiles declared in rest.resource.supportedProfile",
          "observed": true,
          "ok": true,
          "points": 40,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
          "code": "I2",
          "max_points": 35,
          "message": "SMART .well-known/smart-configuration absent or incomplete",
          "observed": true,
          "ok": false,
          "points": 0,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
          "code": "I3",
          "max_points": 25,
          "message": "OAuth/SMART security service declared in CapabilityStatement",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "interop",
      "score": 65,
      "title": "Interop readiness"
    }
  ],
  "drift_alternations": [],
  "drift_events": [],
  "endpoint": {
    "availability": "answered 45 of the last 45 daily checks (100%)",
    "base_url": "https://apigw.bcbsfl.com/interop/interop-developer-portal/cms/iop/v1/R4",
    "endpoint_id": "florida-blue-patient-access",
    "expects_fhir": "r4",
    "failure_kinds": [],
    "grade": "B",
    "interop_score": 65,
    "kind": "payer",
    "last_answered": "2026-10-03",
    "name": "Florida Blue Patient Access API (CMS Interoperability conformance endpoint)",
    "observed_since": "2026-08-20",
    "reachability_score": 100,
    "reachable": "true",
    "reverified_date": "",
    "transparency_score": 100,
    "vantages_reached": 3,
    "vantages_reporting": 3,
    "verification_basis": "live_capability",
    "verified_date": "2026-08-19",
    "verified_method": "live CapabilityStatement fetch (fhirVersion 4.0.1, HAPI FHIR Server 5.4.1.12_edfx, 24 rest resources). The base is the server URL plus the /R4/metadata route printed together in the OpenAPI spec Florida Blue's own developer portal embeds for its 'CMS Interoperability Patient Access Metadata' product, whose page says the Florida Blue Capability Statement endpoint for the CMS Interoperability APIs is accessed via that route. Florida Blue publishes its conformance document on a different base than its OAuth-gated member-data base (which answers 401 to an unauthenticated GET of /metadata and is in the candidate log); the entry is the base that serves the document this project grades. The document's implementation.url names an internal Edifecs host, so attribution rests on Florida Blue printing this base in its own portal. The portal covers the corporate family: its own disclaimer says HMO coverage is offered by Health Options Inc., DBA Florida Blue HMO, and no separate HMO endpoint is published"
  },
  "generated_at": "2026-10-03 15:21 UTC",
  "schema_version": 2,
  "vantage": "reconciled from github-actions/macos-latest, github-actions/ubuntu-latest, github-actions/windows-latest",
  "vantages": [
    {
      "elapsed_ms": 486,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/macos-latest"
    },
    {
      "elapsed_ms": 1181,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/ubuntu-latest"
    },
    {
      "elapsed_ms": 875,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/windows-latest"
    }
  ]
}