Public surface / Payer Patient Access APIs
Health Plan of San Mateo Patient Access API
This endpoint declares a solid public surface with minor gaps.
Observed surface
- Base URL
https://api.hpsmfhir.com/r4- Category
- Payer Patient Access APIs
- Availability
- answered 56 of the last 56 daily checks (100%)
- Last answered
- 2026-10-03 (answered on this run)
- Vantage agreement
- reachable from all 3 vantages, which are 3 hosts on one network (github-actions): one network's view sampled 3 times, not 3 independent networks
What each vantage saw
| Vantage | Result | What it saw | Condition |
|---|---|---|---|
github-actions/macos-latest | reached | answered in 269 ms | HTTP 200 |
github-actions/ubuntu-latest | reached | answered in 1032 ms | HTTP 200 |
github-actions/windows-latest | reached | answered in 531 ms | HTTP 200 |
Vantages on one network are one network’s view sampled several times. A rule applied to that network’s address space reaches every one of them at once and reads exactly like agreement.
Interpretation
A grade describes two public discovery documents at one point in time. It does not inspect patient data, authenticated behavior, or clinical quality.
Read the scoring method →This endpoint's full report: what was observed, what was not, and what would change it →
What its CapabilityStatement declares, resource by resource →
Findings
Declared capability changes
- 2026-09-17: software_version: '4.0.1 3.9.0 v1.0.0-rc+202607151200 bc93922' -> '4.0.1 3.11.1 v1.0.0-rc+202609141200 4c9554d'
- 2026-10-02: software_version: '4.0.1 3.11.1 v1.0.0-rc+202609141200 4c9554d' -> '4.0.1 3.11.2 v1.0.0-rc+202609291200 22bf7ee'
Declared app-to-server access
What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded. An absent field is reported as absent, not as a refusal: a document that does not mention a field has not said anything about it.
| Question | Answer | What the document says | Where it is declared |
|---|---|---|---|
| Declares private_key_jwt client authentication at the token endpoint | not retrieved on this run | the SMART discovery document was requested and not served on this run | SMART discovery: token_endpoint_auth_methods_supported |
| Declares the client_credentials grant, which SMART Backend Services uses | not retrieved on this run | the SMART discovery document was requested and not served on this run | SMART discovery: grant_types_supported |
| Declares the client-confidential-asymmetric capability | not retrieved on this run | the SMART discovery document was requested and not served on this run | SMART discovery: capabilities |
| Declares system-level scopes | not retrieved on this run | the SMART discovery document was requested and not served on this run | SMART discovery: scopes_supported |
| Declares an export operation | declared | export is declared on Account, ActivityDefinition, AdverseEvent, AllergyIntolerance, Appointment, AppointmentResponse, AuditEvent, Basic, BodyStructure, Bundle, CapabilityStatement, CarePlan, CareTeam, ChargeItem, ChargeItemDefinition, Claim, ClaimResponse, ClinicalImpression, CodeSystem, Communication, CommunicationRequest, CompartmentDefinition, Composition, ConceptMap, Condition, Consent, Contract, Coverage, CoverageEligibilityRequest, CoverageEligibilityResponse, DetectedIssue, Device, DeviceDefinition, DeviceMetric, DeviceRequest, DeviceUseStatement, DiagnosticReport, DocumentManifest, DocumentReference, EffectEvidenceSynthesis, Encounter, Endpoint, EnrollmentRequest, EnrollmentResponse, EpisodeOfCare, EventDefinition, Evidence, EvidenceVariable, ExampleScenario, ExplanationOfBenefit, FamilyMemberHistory, Flag, Goal, GraphDefinition, Group, GuidanceResponse, HealthcareService, ImagingStudy, Immunization, ImmunizationEvaluation, ImmunizationRecommendation, ImplementationGuide, InsurancePlan, Invoice, Library, Linkage, List, Location, Measure, MeasureReport, Media, Medication, MedicationAdministration, MedicationDispense, MedicationKnowledge, MedicationRequest, MedicationStatement, MedicinalProduct, MedicinalProductAuthorization, MedicinalProductContraindication, MedicinalProductIndication, MedicinalProductInteraction, MedicinalProductPackaged, MedicinalProductPharmaceutical, MedicinalProductUndesirableEffect, MessageDefinition, MessageHeader, MolecularSequence, NamingSystem, NutritionOrder, Observation, OperationDefinition, Organization, OrganizationAffiliation, Patient, PaymentNotice, PaymentReconciliation, Person, PlanDefinition, Practitioner, PractitionerRole, Procedure, Provenance, Questionnaire, QuestionnaireResponse, RelatedPerson, RequestGroup, ResearchDefinition, ResearchElementDefinition, ResearchStudy, ResearchSubject, RiskAssessment, RiskEvidenceSynthesis, Schedule, SearchParameter, ServiceRequest, Slot, Specimen, SpecimenDefinition, StructureDefinition, StructureMap, Subscription, Substance, SubstanceSpecification, SupplyDelivery, SupplyRequest, Task, TerminologyCapabilities, TestReport, TestScript, ValueSet, VerificationResult, VisionPrescription | CapabilityStatement: rest.operation and rest.resource.operation |
| Instantiates the Bulk Data Access implementation guide | not listed | 0 canonicals are instantiated and none is Bulk Data's | CapabilityStatement: instantiates |
Registry provenance
How this entry was verified
live CapabilityStatement fetch (fhirVersion 4.0.1, 144 resource types). The CapabilityStatement names the vendor, not the plan: publisher '1upHealth', software '1up FHIR Server'. Attribution to Health Plan of San Mateo rests on the plan printing this base URL on its own site, at https://www.hpsm.org/about-us/data-interoperability/app-developer-resources, under the heading 'Available Patient Access and Provider Directory API Endpoints'. The same base URL appears in ONC's Lantern export via the 1upHealth endpoint directory. One base serves both surfaces per the plan's own heading (recorded 2026-08-07). Re-checked 2026-08-19: live CapabilityStatement re-fetch from the davis-ca residential vantage; fhirVersion 4.0.1, 144 resource types, publisher '1upHealth', software '1up FHIR Server 4.0.1 3.9.0 v1.0.0-rc+202607151200 bc93922'.
This is an observational snapshot of a public, unauthenticated surface. It is not an audit, a ranking of care quality, or a statement about anyone's regulatory compliance. See how we grade.
Every observation on record for this endpoint, with the dates it answered and the dates it did not.