{
  "app_to_server": {
    "answers": [
      {
        "answer": "not_listed",
        "answer_text": "not listed",
        "asks": "Declares private_key_jwt client authentication at the token endpoint",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "token_endpoint_auth_methods_supported lists 2 and not private_key_jwt",
        "key": "private_key_jwt",
        "source": "SMART discovery: token_endpoint_auth_methods_supported"
      },
      {
        "answer": "declared",
        "answer_text": "declared",
        "asks": "Declares the client_credentials grant, which SMART Backend Services uses",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "grant_types_supported lists client_credentials among 4",
        "key": "client_credentials",
        "source": "SMART discovery: grant_types_supported"
      },
      {
        "answer": "not_listed",
        "answer_text": "not listed",
        "asks": "Declares the client-confidential-asymmetric capability",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "capabilities is present and empty",
        "key": "client_confidential_asymmetric",
        "source": "SMART discovery: capabilities"
      },
      {
        "answer": "not_listed",
        "answer_text": "not listed",
        "asks": "Declares system-level scopes",
        "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
        "detail": "none of 4 scopes_supported is a system/ scope",
        "key": "system_scopes",
        "source": "SMART discovery: scopes_supported"
      },
      {
        "answer": "not_listed",
        "answer_text": "not listed",
        "asks": "Declares an export operation",
        "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
        "detail": "529 operations are declared and none is named export",
        "key": "export_operation",
        "source": "CapabilityStatement: rest.operation and rest.resource.operation"
      },
      {
        "answer": "not_listed",
        "answer_text": "not listed",
        "asks": "Instantiates the Bulk Data Access implementation guide",
        "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
        "detail": "0 canonicals are instantiated and none is Bulk Data's",
        "key": "bulk_data_guide",
        "source": "CapabilityStatement: instantiates"
      }
    ],
    "note": "What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded."
  },
  "dimensions": [
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/R4/http.html",
          "code": "R1",
          "max_points": 60,
          "message": "/metadata answers with HTTP 2xx over HTTPS: reachable from all 3 vantages, which are 3 hosts on one network (github-actions): one network's view sampled 3 times, not 3 independent networks",
          "observed": true,
          "ok": true,
          "points": 60,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/http.html",
          "code": "R2",
          "max_points": 40,
          "message": "/metadata responded in 671 ms (median across 3 reachable vantages on one network)",
          "observed": true,
          "ok": true,
          "points": 40,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "reachability",
      "score": 100,
      "title": "Reachability"
    },
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T1",
          "max_points": 30,
          "message": "fhirVersion declared: '4.0.1' (expected 4.x)",
          "observed": true,
          "ok": true,
          "points": 30,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T2",
          "max_points": 20,
          "message": "software name/version missing",
          "observed": true,
          "ok": false,
          "points": 0,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T3",
          "max_points": 25,
          "message": "195 resource types declared",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/R4/capabilitystatement.html",
          "code": "T4",
          "max_points": 25,
          "message": "195/195 declared resources document their interactions",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "transparency",
      "score": 80,
      "title": "Capability transparency"
    },
    {
      "findings": [
        {
          "citation": "https://hl7.org/fhir/us/core/",
          "code": "I1",
          "max_points": 40,
          "message": "no profile canonical declared in rest.resource.supportedProfile, rest.resource.profile, instantiates, imports, or meta.profile",
          "observed": true,
          "ok": false,
          "points": 0,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
          "code": "I2",
          "max_points": 35,
          "message": "SMART discovery document present and complete",
          "observed": true,
          "ok": true,
          "points": 35,
          "unanswered": false,
          "withheld_points": 0
        },
        {
          "citation": "https://hl7.org/fhir/smart-app-launch/conformance.html",
          "code": "I3",
          "max_points": 25,
          "message": "OAuth/SMART security service declared in CapabilityStatement",
          "observed": true,
          "ok": true,
          "points": 25,
          "unanswered": false,
          "withheld_points": 0
        }
      ],
      "key": "interop",
      "score": 60,
      "title": "Interop readiness"
    }
  ],
  "drift_alternations": [
    "2026-09-16 to 2026-10-01: returned 2 times to a declaration first observed 2026-09-04 (resource_count: 195 -> 157; resources_with_interactions: 195 -> 157) - counted, not recorded as a new change each time",
    "2026-09-22 to 2026-10-03: returned 2 times to a declaration first observed 2026-09-11 (resource_count: 157 -> 195; resources_with_interactions: 157 -> 195) - counted, not recorded as a new change each time"
  ],
  "drift_events": [
    "2026-09-11: resource_count: 157 -> 195; resources_with_interactions: 157 -> 195"
  ],
  "endpoint": {
    "availability": "answered 30 of the last 30 daily checks (100%)",
    "base_url": "https://portal.aidbox.myparamount.org",
    "endpoint_id": "paramount-interoperability",
    "expects_fhir": "r4",
    "failure_kinds": [],
    "grade": "B",
    "interop_score": 60,
    "kind": "payer",
    "last_answered": "2026-10-03",
    "name": "Paramount Health Care Interoperability API",
    "observed_since": "2026-09-04",
    "reachability_score": 100,
    "reachable": "true",
    "reverified_date": "",
    "transparency_score": 80,
    "vantages_reached": 3,
    "vantages_reporting": 3,
    "verification_basis": "live_capability",
    "verified_date": "2026-09-04",
    "verified_method": "base URL printed verbatim on the plan's own site at https://www.paramounthealthcare.com/Interoperability-APIs, section 'API Documentation' > 'Basic Requests', in the line 'For provider access, that is public'; the same host is printed on the next line for patient access, so one host serves both surfaces separated by OAuth scope rather than by address. Published with a '#/login' fragment, which is an Aidbox UI route never sent to the server. Now a Medical Mutual company, but the endpoint is published on Paramount's own domain under its own copyright, so no parent-document attribution is involved. Grade observed to move within one hour on 2026-09-04 (interop readiness 0 then 60 on two later probes), so its declaration is not stable across requests. Live CapabilityStatement retrieved"
  },
  "generated_at": "2026-10-03 15:21 UTC",
  "schema_version": 2,
  "vantage": "reconciled from github-actions/macos-latest, github-actions/ubuntu-latest, github-actions/windows-latest",
  "vantages": [
    {
      "elapsed_ms": 391,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/macos-latest"
    },
    {
      "elapsed_ms": 997,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/ubuntu-latest"
    },
    {
      "elapsed_ms": 671,
      "error": null,
      "failure_kind": null,
      "network": "github-actions",
      "reachable": true,
      "status": 200,
      "vantage": "github-actions/windows-latest"
    }
  ]
}