Public surface / Payer Provider Directory APIs
Blue Cross Blue Shield of Michigan Provider Directory API
This endpoint answers publicly but declares little about itself.
Observed surface
- Base URL
https://api.interopstation.com/bcbsm/fhir- Category
- Payer Provider Directory APIs
- Availability
- answered 30 of the last 30 daily checks (100%)
- Last answered
- 2026-10-03 (answered on this run)
- Vantage agreement
- reachable from all 3 vantages, which are 3 hosts on one network (github-actions): one network's view sampled 3 times, not 3 independent networks
What each vantage saw
| Vantage | Result | What it saw | Condition |
|---|---|---|---|
github-actions/macos-latest | reached | answered in 2980 ms | HTTP 200 |
github-actions/ubuntu-latest | reached | answered in 3005 ms | HTTP 200 |
github-actions/windows-latest | reached | answered in 2032 ms | HTTP 200 |
Vantages on one network are one network’s view sampled several times. A rule applied to that network’s address space reaches every one of them at once and reads exactly like agreement.
Interpretation
A grade describes two public discovery documents at one point in time. It does not inspect patient data, authenticated behavior, or clinical quality.
Read the scoring method →This endpoint's full report: what was observed, what was not, and what would change it →
What its CapabilityStatement declares, resource by resource →
Findings
- Needs attention: 28 profile canonical(s) declared in rest.resource.profile, none of them US Core, CARIN, or Da Vinci; also checked rest.resource.supportedProfile, instantiates, imports, meta.profileI1Spec ↗
- Note: SMART discovery not applicable: a Provider Directory API is public by designI2Spec ↗
- Note: OAuth security not applicable: a Provider Directory API is public by designI3Spec ↗
Observed since 2026-09-04; no changes to declared capability recorded.
Declared app-to-server access
What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded. An absent field is reported as absent, not as a refusal: a document that does not mention a field has not said anything about it.
| Question | Answer | What the document says | Where it is declared |
|---|---|---|---|
| Declares private_key_jwt client authentication at the token endpoint | not retrieved on this run | the SMART discovery document was requested and not served on this run | SMART discovery: token_endpoint_auth_methods_supported |
| Declares the client_credentials grant, which SMART Backend Services uses | not retrieved on this run | the SMART discovery document was requested and not served on this run | SMART discovery: grant_types_supported |
| Declares the client-confidential-asymmetric capability | not retrieved on this run | the SMART discovery document was requested and not served on this run | SMART discovery: capabilities |
| Declares system-level scopes | not retrieved on this run | the SMART discovery document was requested and not served on this run | SMART discovery: scopes_supported |
| Declares an export operation | not listed | 0 operations are declared and none is named export | CapabilityStatement: rest.operation and rest.resource.operation |
| Instantiates the Bulk Data Access implementation guide | not listed | 0 canonicals are instantiated and none is Bulk Data's | CapabilityStatement: instantiates |
Registry provenance
How this entry was verified
base URL is the common prefix of ten absolute URLs printed verbatim on the plan's own page (bcbsm.com/important-information/privacy-practices/patient-access/, section 'API Endpoints', eight under 'Provider Directory:' and two under 'Drug Formulary:'), and is also the prefix of the printed capability-statement URL. Two independent reviews reached it. Serves Blue Cross Blue Shield of Michigan and Blue Care Network jointly: the page lede and the linked FAQ (doc Y0074_IGPtAccAPIFAQ_C FVNR 0621) name both, and no Blue Care Network-specific base exists. Vendor is MiHIN's InterOp Station. The member claims base is not published and requires portal credentials, so no Patient Access entry is recorded. Live CapabilityStatement retrieved (recorded 2026-09-04). No later re-check is recorded, so the date above is the last time anyone checked this entry against the live endpoint.
This is an observational snapshot of a public, unauthenticated surface. It is not an audit, a ranking of care quality, or a statement about anyone's regulatory compliance. See how we grade.
Every observation on record for this endpoint, with the dates it answered and the dates it did not.