{
  "app_to_server": {
    "answers": [
      {
        "answer": "not_retrieved",
        "answer_text": "not retrieved on this run",
        "asks": "Declares private_key_jwt client authentication at the token endpoint",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "the SMART discovery document was requested and not served on this run",
        "key": "private_key_jwt",
        "source": "SMART discovery: token_endpoint_auth_methods_supported"
      },
      {
        "answer": "not_retrieved",
        "answer_text": "not retrieved on this run",
        "asks": "Declares the client_credentials grant, which SMART Backend Services uses",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "the SMART discovery document was requested and not served on this run",
        "key": "client_credentials",
        "source": "SMART discovery: grant_types_supported"
      },
      {
        "answer": "not_retrieved",
        "answer_text": "not retrieved on this run",
        "asks": "Declares the client-confidential-asymmetric capability",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "the SMART discovery document was requested and not served on this run",
        "key": "client_confidential_asymmetric",
        "source": "SMART discovery: capabilities"
      },
      {
        "answer": "not_retrieved",
        "answer_text": "not retrieved on this run",
        "asks": "Declares system-level scopes",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "the SMART discovery document was requested and not served on this run",
        "key": "system_scopes",
        "source": "SMART discovery: scopes_supported"
      },
      {
        "answer": "not_listed",
        "answer_text": "not listed",
        "asks": "Declares an export operation",
        "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
        "detail": "13 operations are declared and none is named export",
        "key": "export_operation",
        "source": "CapabilityStatement: rest.operation and rest.resource.operation"
      },
      {
        "answer": "not_listed",
        "answer_text": "not listed",
        "asks": "Instantiates the Bulk Data Access implementation guide",
        "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
        "detail": "0 canonicals are instantiated and none is Bulk Data's",
        "key": "bulk_data_guide",
        "source": "CapabilityStatement: instantiates"
      }
    ],
    "note": "What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded."
  },
  "dimensions": [
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/R4/http.html",
          "code": "R1",
          "max_points": 60,
          "message": "/metadata answers with HTTP 2xx over HTTPS: reachable from all 3 vantages, which are 3 hosts on one network (github-actions): one network's view sampled 3 times, not 3 independent networks",
          "observed": true,
          "ok": true,
          "points": 60,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/http.html",
          "code": "R2",
          "max_points": 40,
          "message": "/metadata responded in 2186 ms (median across 3 reachable vantages on one network)",
          "observed": true,
          "ok": true,
          "points": 40,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "reachability",
      "score": 100,
      "title": "Reachability"
    },
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T1",
          "max_points": 30,
          "message": "fhirVersion declared: '4.0.1' (expected 4.x)",
          "observed": true,
          "ok": true,
          "points": 30,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T2",
          "max_points": 20,
          "message": "software name and version declared",
          "observed": true,
          "ok": true,
          "points": 20,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T3",
          "max_points": 25,
          "message": "146 resource types declared",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T4",
          "max_points": 25,
          "message": "145/146 declared resources document their interactions",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "transparency",
      "score": 100,
      "title": "Capability transparency"
    },
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/us/core/",
          "code": "I1",
          "max_points": 40,
          "message": "146 profile canonical(s) declared in rest.resource.profile, none of them US Core, CARIN, or Da Vinci; also checked rest.resource.supportedProfile, instantiates, imports, meta.profile",
          "observed": true,
          "ok": false,
          "points": 0,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
          "code": "I2",
          "max_points": 0,
          "message": "SMART discovery not applicable: a Provider Directory API is public by design",
          "observed": true,
          "ok": true,
          "points": 0,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
          "code": "I3",
          "max_points": 0,
          "message": "OAuth security not applicable: a Provider Directory API is public by design",
          "observed": true,
          "ok": true,
          "points": 0,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "interop",
      "score": 0,
      "title": "Interop readiness"
    }
  ],
  "drift_alternations": [],
  "drift_events": [
    "2026-09-03: software_version: '5.0.23' -> '5.0.34'",
    "2026-09-05: software_version: '5.0.34' -> '5.0.35'",
    "2026-09-10: software_version: '5.0.35' -> '5.0.55'",
    "2026-09-24: software_version: '5.0.55' -> '5.0.65'",
    "2026-10-01: software_version: '5.0.65' -> '5.0.86'"
  ],
  "endpoint": {
    "availability": "answered 45 of the last 46 daily checks (98%)",
    "base_url": "https://members.imperialhealthplan.com/api/fhir",
    "endpoint_id": "imperial-provider-directory",
    "expects_fhir": "r4",
    "failure_kinds": [],
    "grade": "C",
    "interop_score": 0,
    "kind": "payer_provider_directory",
    "last_answered": "2026-10-03",
    "name": "Imperial Health Plan Provider Directory API",
    "observed_since": "2026-08-19",
    "reachability_score": 100,
    "reachable": "true",
    "reverified_date": "",
    "transparency_score": 100,
    "vantages_reached": 3,
    "vantages_reporting": 3,
    "verification_basis": "live_capability",
    "verified_date": "2026-08-19",
    "verified_method": "live CapabilityStatement fetch (fhirVersion 4.0.1, 146 resource types). The document names the platform vendor, not the plan: publisher 'Microsoft', software 'Azure Healthcare APIs' 5.0.23, and it carries no implementation block at all. Attribution to Imperial rests on the plan printing four resource URLs under this base on its own interoperability page at https://exchange.imperialhealthplan.com/interoperability/, describing them as resources that 'do not require any authentication to retrieve data', on an Imperial-controlled domain. The same page prints https://ihh-public.azurehealthcareapis.com/metadata, which answers identically and is the vendor-controlled name for what appears to be the same service; the issuer-controlled host is listed"
  },
  "generated_at": "2026-10-03 15:21 UTC",
  "schema_version": 2,
  "vantage": "reconciled from github-actions/macos-latest, github-actions/ubuntu-latest, github-actions/windows-latest",
  "vantages": [
    {
      "elapsed_ms": 2450,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/macos-latest"
    },
    {
      "elapsed_ms": 2106,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/ubuntu-latest"
    },
    {
      "elapsed_ms": 2186,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/windows-latest"
    }
  ]
}