Public surface / Payer Patient Access APIs
Paramount Health Care Interoperability API
This endpoint declares a solid public surface with minor gaps.
Observed surface
- Base URL
https://portal.aidbox.myparamount.org- Category
- Payer Patient Access APIs
- Availability
- answered 30 of the last 30 daily checks (100%)
- Last answered
- 2026-10-03 (answered on this run)
- Vantage agreement
- reachable from all 3 vantages, which are 3 hosts on one network (github-actions): one network's view sampled 3 times, not 3 independent networks
What each vantage saw
| Vantage | Result | What it saw | Condition |
|---|---|---|---|
github-actions/macos-latest | reached | answered in 391 ms | HTTP 200 |
github-actions/ubuntu-latest | reached | answered in 997 ms | HTTP 200 |
github-actions/windows-latest | reached | answered in 671 ms | HTTP 200 |
Vantages on one network are one network’s view sampled several times. A rule applied to that network’s address space reaches every one of them at once and reads exactly like agreement.
Interpretation
A grade describes two public discovery documents at one point in time. It does not inspect patient data, authenticated behavior, or clinical quality.
Read the scoring method →This endpoint's full report: what was observed, what was not, and what would change it →
What its CapabilityStatement declares, resource by resource →
Findings
Declared capability changes
- 2026-09-11: resource_count: 157 -> 195; resources_with_interactions: 157 -> 195
Declarations this endpoint returns to
This address has served a declaration, moved away from it, and served it again. That usually means one hostname in front of more than one backend rather than a publisher changing anything, so each return is counted here once instead of being reported as a fresh capability change every time a probe lands on the other backend.
- 2026-09-16 to 2026-10-01: returned 2 times to a declaration first observed 2026-09-04 (resource_count: 195 -> 157; resources_with_interactions: 195 -> 157) - counted, not recorded as a new change each time
- 2026-09-22 to 2026-10-03: returned 2 times to a declaration first observed 2026-09-11 (resource_count: 157 -> 195; resources_with_interactions: 157 -> 195) - counted, not recorded as a new change each time
Declared app-to-server access
What the endpoint's own documents declare about app-to-server access, observed on this run. Nothing here was requested or exercised, and none of it is graded. An absent field is reported as absent, not as a refusal: a document that does not mention a field has not said anything about it.
| Question | Answer | What the document says | Where it is declared |
|---|---|---|---|
| Declares private_key_jwt client authentication at the token endpoint | not listed | token_endpoint_auth_methods_supported lists 2 and not private_key_jwt | SMART discovery: token_endpoint_auth_methods_supported |
| Declares the client_credentials grant, which SMART Backend Services uses | declared | grant_types_supported lists client_credentials among 4 | SMART discovery: grant_types_supported |
| Declares the client-confidential-asymmetric capability | not listed | capabilities is present and empty | SMART discovery: capabilities |
| Declares system-level scopes | not listed | none of 4 scopes_supported is a system/ scope | SMART discovery: scopes_supported |
| Declares an export operation | not listed | 529 operations are declared and none is named export | CapabilityStatement: rest.operation and rest.resource.operation |
| Instantiates the Bulk Data Access implementation guide | not listed | 0 canonicals are instantiated and none is Bulk Data's | CapabilityStatement: instantiates |
Registry provenance
How this entry was verified
base URL printed verbatim on the plan's own site at https://www.paramounthealthcare.com/Interoperability-APIs, section 'API Documentation' > 'Basic Requests', in the line 'For provider access, that is public'; the same host is printed on the next line for patient access, so one host serves both surfaces separated by OAuth scope rather than by address. Published with a '#/login' fragment, which is an Aidbox UI route never sent to the server. Now a Medical Mutual company, but the endpoint is published on Paramount's own domain under its own copyright, so no parent-document attribution is involved. Grade observed to move within one hour on 2026-09-04 (interop readiness 0 then 60 on two later probes), so its declaration is not stable across requests. Live CapabilityStatement retrieved (recorded 2026-09-04). No later re-check is recorded, so the date above is the last time anyone checked this entry against the live endpoint.
This is an observational snapshot of a public, unauthenticated surface. It is not an audit, a ranking of care quality, or a statement about anyone's regulatory compliance. See how we grade.
Every observation on record for this endpoint, with the dates it answered and the dates it did not.