Public surface / Payer Patient Access APIs
Anthem Blue Cross Blue Shield Patient Access API (Elevance)
This endpoint could not be reached from any vantage on this run, so nothing about what it publishes was observed.
Observed surface
- Base URL
https://totalview.healthos.elevancehealth.com/resources/registered/AnthemBlueCrossBlueShield/api/v1/fhir- Category
- Payer Patient Access APIs
- Availability
- answered 0 of the last 30 daily checks (0%)
- Last answered
- not in the recorded window
- Vantage agreement
- answered HTTP 401 from 3 of 3 vantages but returned no usable document: the endpoint is running and refusing this request, which is not the same as being unreachable: HTTP 401
What each vantage saw
| Vantage | Result | What it saw | Condition |
|---|---|---|---|
github-actions/macos-latest | not reached | HTTP 401 | HTTP 401, authentication_required |
github-actions/ubuntu-latest | not reached | HTTP 401 | HTTP 401, authentication_required |
github-actions/windows-latest | not reached | HTTP 401 | HTTP 401, authentication_required |
Vantages on one network are one network’s view sampled several times. A rule applied to that network’s address space reaches every one of them at once and reads exactly like agreement.
Interpretation
A grade describes two public discovery documents at one point in time. It does not inspect patient data, authenticated behavior, or clinical quality.
Read the scoring method →This endpoint's full report: what was observed, what was not, and what would change it →
What its CapabilityStatement declares, resource by resource →
Findings
- No answer: /metadata answered HTTP 401 from 3 of 3 vantages but returned no usable document: the endpoint is running and refusing this request, which is not the same as being unreachable: HTTP 401 (observed 2026-10-03)R1Spec ↗
- No answer: latency not measured: no vantage was answered (observed 2026-10-03)R2Spec ↗
Observed since 2026-09-04; no changes to declared capability recorded.
Declared app-to-server access
What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded. An absent field is reported as absent, not as a refusal: a document that does not mention a field has not said anything about it.
| Question | Answer | What the document says | Where it is declared |
|---|---|---|---|
| Declares private_key_jwt client authentication at the token endpoint | not retrieved on this run | no vantage retrieved .well-known/smart-configuration | SMART discovery: token_endpoint_auth_methods_supported |
| Declares the client_credentials grant, which SMART Backend Services uses | not retrieved on this run | no vantage retrieved .well-known/smart-configuration | SMART discovery: grant_types_supported |
| Declares the client-confidential-asymmetric capability | not retrieved on this run | no vantage retrieved .well-known/smart-configuration | SMART discovery: capabilities |
| Declares system-level scopes | not retrieved on this run | no vantage retrieved .well-known/smart-configuration | SMART discovery: scopes_supported |
| Declares an export operation | not retrieved on this run | no vantage retrieved the CapabilityStatement | CapabilityStatement: rest.operation and rest.resource.operation |
| Instantiates the Bulk Data Access implementation guide | not retrieved on this run | no vantage retrieved the CapabilityStatement | CapabilityStatement: instantiates |
Registry provenance
How this entry was verified
Listed on the organization's own publication of this base URL, not on a retrieved conformance document: base URL taken from the embedded link annotation of the row labelled 'Anthem Blue Cross Blue Shield' in the table 'FHIR Endpoints (Production Base URL)', section 'Patient Access API - Production Environment', of Elevance's Interoperability API Endpoint Support Document, Doc ID IO105, Version 15.0, effective 2025-11-18, status Active. Named for the operator and the brand rather than for a state on purpose: the table has thirteen brand rows and no state column, and the strings 'Ohio' and 'Wisconsin' appear nowhere in the document, so listing this URL once per state would put one address under several names. Two independent reviews, from the Ohio and Wisconsin rosters, reached this same row (recorded 2026-09-04). Published at https://www.anthem.com/content/dam/digital/developers-portal/Anthem-IOProviderDirectoryAndFormulary-API-Documentation.pdf. On the verification date this probe observed: HTTP 401 to an unauthenticated GET of /metadata, matching the two sibling per-brand paths since 2026-08-19. A Patient Access API may require authentication for member data, so this is not a defect claim; what it records is that the conformance document is not retrievable, so nothing this endpoint declares can be checked from outside. The document is served byte-identically from anthem.com and wellpoint.com (SHA-256 f383858d13a0d138c9ccfeba52bfe9d1fcd023f70e281b212623e2f6214d3b62); the anthem.com copy is cited here because it is the Anthem-branded publisher. No later re-check is recorded, so the date above is the last time anyone checked this entry against the live endpoint.
This is an observational snapshot of a public, unauthenticated surface. It is not an audit, a ranking of care quality, or a statement about anyone's regulatory compliance. See how we grade.
Every observation on record for this endpoint, with the dates it answered and the dates it did not.