Skip to main content

Public surface / Payer Patient Access APIs

Paramount Health Care Interoperability API

This endpoint declares a solid public surface with minor gaps.

Current grade B
Reachability100
Capability transparency80
Interop readiness60

Observed surface

Base URL
https://portal.aidbox.myparamount.org
Category
Payer Patient Access APIs
Availability
answered 30 of the last 30 daily checks (100%)
Last answered
2026-10-03 (answered on this run)
Vantage agreement
reachable from all 3 vantages, which are 3 hosts on one network (github-actions): one network's view sampled 3 times, not 3 independent networks

What each vantage saw

reached from 3 of 3 reporting vantages, on 1 network
VantageResultWhat it sawCondition
github-actions/macos-latestreachedanswered in 391 msHTTP 200
github-actions/ubuntu-latestreachedanswered in 997 msHTTP 200
github-actions/windows-latestreachedanswered in 671 msHTTP 200

Vantages on one network are one network’s view sampled several times. A rule applied to that network’s address space reaches every one of them at once and reads exactly like agreement.

Interpretation

A grade describes two public discovery documents at one point in time. It does not inspect patient data, authenticated behavior, or clinical quality.

Read the scoring method →

This endpoint's full report: what was observed, what was not, and what would change it →

What its CapabilityStatement declares, resource by resource →

Findings

Reachability100
Capability transparency80
Interop readiness60

Declared capability changes

Declarations this endpoint returns to

This address has served a declaration, moved away from it, and served it again. That usually means one hostname in front of more than one backend rather than a publisher changing anything, so each return is counted here once instead of being reported as a fresh capability change every time a probe lands on the other backend.

Declared app-to-server access

What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded. An absent field is reported as absent, not as a refusal: a document that does not mention a field has not said anything about it.

What the SMART discovery document and the CapabilityStatement declare about SMART Backend Services and Bulk Data
QuestionAnswerWhat the document saysWhere it is declared
Declares private_key_jwt client authentication at the token endpointnot listedtoken_endpoint_auth_methods_supported lists 2 and not private_key_jwtSMART discovery: token_endpoint_auth_methods_supported
Declares the client_credentials grant, which SMART Backend Services usesdeclaredgrant_types_supported lists client_credentials among 4SMART discovery: grant_types_supported
Declares the client-confidential-asymmetric capabilitynot listedcapabilities is present and emptySMART discovery: capabilities
Declares system-level scopesnot listednone of 4 scopes_supported is a system/ scopeSMART discovery: scopes_supported
Declares an export operationnot listed529 operations are declared and none is named exportCapabilityStatement: rest.operation and rest.resource.operation
Instantiates the Bulk Data Access implementation guidenot listed0 canonicals are instantiated and none is Bulk Data'sCapabilityStatement: instantiates

Registry provenance

How this entry was verified

base URL printed verbatim on the plan's own site at https://www.paramounthealthcare.com/Interoperability-APIs, section 'API Documentation' > 'Basic Requests', in the line 'For provider access, that is public'; the same host is printed on the next line for patient access, so one host serves both surfaces separated by OAuth scope rather than by address. Published with a '#/login' fragment, which is an Aidbox UI route never sent to the server. Now a Medical Mutual company, but the endpoint is published on Paramount's own domain under its own copyright, so no parent-document attribution is involved. Grade observed to move within one hour on 2026-09-04 (interop readiness 0 then 60 on two later probes), so its declaration is not stable across requests. Live CapabilityStatement retrieved (recorded 2026-09-04). No later re-check is recorded, so the date above is the last time anyone checked this entry against the live endpoint.

Share this endpoint's grade
FHIR Scorecard: Paramount Health Care Interoperability API grade B

Link the badge back to this evidence page so readers can inspect the current findings.

<a href="https://fhir.chelseakr.com/endpoint/paramount-interoperability/"> <img src="https://fhir.chelseakr.com/badge/paramount-interoperability.svg" alt="FHIR Scorecard: grade B"></a>

This is an observational snapshot of a public, unauthenticated surface. It is not an audit, a ranking of care quality, or a statement about anyone's regulatory compliance. See how we grade.

Every observation on record for this endpoint, with the dates it answered and the dates it did not.