Technical Interoperability Guidelines

Antidote Health Interoperability Overview

Antidote Health's Interoperability APIs are developer-friendly, FHIR-based APIs that enable third-party applications and vendors to connect their applications to Antidote Health patient and provider information.

Interoperability APIs enable Antidote Health members to consent to share their data with a third-party application of their choosing. These APIs also enable third-party application owners to connect to provider and pharmacy directories or publicly available data.

API Technology and Functionality

Authorization / Authentication

To use the Antidote Health interoperability APIs, a developer must register their application or portal through emailing the Interoperability group interoperability@antidotehealth.com. During this process, you will be required to complete a questionnaire about the purpose of your application's purpose and business details.

Once registered, an application and point of contact are given a client ID and a client secret. The secret should only be used if it can be kept confidential, such as communication between your server and the Antidote Health interoperability APIs.  

Supported Implementation Guides:

Antidote Health supports the following implementation guides:

Production Access:

Production applications with a need to access Public APIs (formulary, provider directory, and pharmacy directory) will still require registration but will be automatically approved. Production application requests for Patient Access APIs will require review from our security and compliance team prior to approving access. Our security and compliance team will reach out with any questions during this review process.

Authorization server URL documentations are shared after successful organization registration and approval.

For production application requests, please send an email with your contact information to: interoperability@antidotehealth.com.

App Privacy:

Sharing your health data through third-party apps offers real benefits, but it also comes with risks. Antidote safeguards your data while it is in our systems — including multi factor authentication (MFA) and challenge questions — but once you share your data with a third-party application, that app's own security practices govern how your information is protected. Here are concrete steps you can take to reduce risk:

  • Research any app before connecting it to your health data. Look for a clear, readable privacy policy and check independent reviews.
  • Use a strong, unique password for your account with any third-party app. Avoid reusing passwords from other services.
  • Enable multi-factor authentication (MFA) on any app that offers it — this adds a critical layer of protection even if your password is compromised.
  • Periodically review which applications have access to your data, and revoke access for any apps you no longer use or trust.
  • Read the app's full privacy policy before connecting — pay close attention to how your data is stored, who it may be shared with, and how it is deleted.
  • Monitor your health information for unauthorized or unexpected changes after connecting a third-party app.
  • Keep your devices and apps updated. Security vulnerabilities are frequently patched in software updates.
  • Be cautious of apps that request access to more data than they need to perform their stated function.

Selecting an app

When choosing a third-party application to connect to your health data, carefully evaluate the following factors before granting access:

Privacy and security practices - Review the application's privacy policy for how it stores and protects your data. Confirm the app uses strong authentication (such as MFA) and encrypted data transmission. Check whether the app has been independently audited or certified for security.

Data sharing policies - Understand who the app shares your data with and under what circumstances. Some apps share information with affiliated companies, advertisers, or analytics providers. Look for clear, specific language — vague policies like 'we may share with partners' warrant extra scrutiny.

Secondary use of your health data - Some third-party applications may use your health information for purposes that go beyond the app's primary function. This is known as secondary use of data, and it is important to understand before you connect any app to your health records.

Secondary uses of health data can include:

  • Selling or licensing your data to advertisers, data brokers, or other third parties
  • Using your data to build marketing profiles or target you with advertisements
  • Sharing your information with employers, insurers, or other organizations
  • Using your data for commercial research without your explicit consent
  • Retaining your data indefinitely, even after you close your account or delete the app
  • Transferring your data to a new owner if the company is acquired or goes out of business

Before connecting any application to your health data, ask yourself:

  • Does this app sell or license my health information to third parties?
  • Will my data be used for advertising or marketing purposes?
  • What happens to my data if I close my account or the company is sold?
  • Does the app provide a way to request deletion of my data?

Antidote Health does not sell your health data and will not share it with third-party applications without your explicit consent. Once data is shared with an app you authorize, the app's own policies govern its use — which is why reviewing those policies before connecting is so important.

HIPAA, the FTC, and your rights

What is a HIPAA covered entity?

The Health Insurance Portability and Accountability Act (HIPAA) protects the privacy and security of certain health information, but it applies only to specific types of organizations known as covered entities and their business associates. Under HIPAA, covered entities are:

  • Health plans (including health insurers like Antidote Health)
  • Health care clearinghouses
  • Health care providers who electronically transmit health information for covered transactions

As a health plan, Antidote Health is a HIPAA covered entity and is legally required to protect your health information in accordance with HIPAA's Privacy, Security, and Breach Notification Rules.

Who is not a HIPAA covered entity?

Many organizations that handle health information are not covered entities and are therefore not required to follow HIPAA. Understanding this distinction is critical when you share your data with third-party apps. Organizations that are typically not HIPAA covered entities include: Mobile health and wellness apps — such as fitness trackers, diet apps, and mental health apps — are generally not HIPAA covered entities. The same is true of social media platforms that offer health-related features, consumer wearable device manufacturers, employer wellness programs operated independently of a health plan, and pharmacy discount apps or coupon services. In short, many of the apps and digital tools that people use to manage their health fall outside the scope of HIPAA's protections, even though they handle sensitive health information.

If you share your health data with an app that is not a HIPAA covered entity, HIPAA's protections do not apply to how that app uses or discloses your information. This makes it especially important to carefully read any app's privacy policy before connecting it to your health records.

The role of OCR and the FTC

The HHS Office for Civil Rights (OCR) enforces HIPAA's Privacy, Security, and Breach Notification Rules, as well as the Patient Safety Act. OCR can investigate complaints against covered entities and their business associates. For more information on your rights under HIPAA and who must comply, visit: hhs.gov/hipaa/for-individuals.

The Federal Trade Commission (FTC) has primary oversight authority over organizations that are not HIPAA covered entities. The FTC enforces the Health Breach Notification Rule, which requires certain non-HIPAA organizations — including many health apps and connected device makers — to notify their customers, the FTC, and in some cases the media, if there is a breach of individually identifiable health information.

Reporting Identity Theft and Fraud

If you believe a non-Antidote application that you've shared your data with is misusing that information in violation of their stated privacy policy, contact the Federal Trade Commission to investigate the matter by going to ReportFraud.ftc.gov or calling 877-382-4357.  If you believe the privacy of your health care data has been violated by a non-Antidote Application, contact the FTC and file a complaint at: https://reportfraud.ftc.gov/#/assistant. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR), enforces federal civil rights laws, conscience and religious freedom laws, the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification Rules, and the Patient Safety Act and Rule, which together protect your fundamental rights of nondiscrimination, conscience, religious freedom, and health information privacy at covered entities.

If you believe that a HIPAA-covered entity or its business associate violated your (or someone else’s) health information privacy rights or committed another violation of the Privacy, Security, or Breach Notification Rules, you may file a complaint with the Office for Civil Rights (OCR). OCR can investigate complaints against covered entities (health plans, health care clearinghouses, or health care providers that conduct certain transactions electronically) and their business associates. To learn more about filing a complaint with OCR under HIPAA, visit: https://www.hhs.gov/hipaa/filing-a-complaint/index.html. Individuals can file a complaint with OCR using the OCR complaint portal: https://ocrportal.hhs.gov/ocr/smartscreen/main.jsf. Individuals can file a complaint with the FTC using the FTC complaint assistant: https://reportfraud.ftc.gov/#/assistant.

FAQ:

Member revokes access: A member may revoke access to your application. When you encounter an invalid token indicating a member has revoked access, you should make a reasonable attempt to handle that case, making it easy for the member to understand what is happening with their data. 

Contact us:

Inquire about access to Antidote Health Patient Access, Provider Directory, or Payer to Payer Data Exchange APIs as part of the Interoperability and Patient Access final rule (CMS-9115-F) from the Centers for Medicare & Medicaid Services, please send an email with your contact information to interoperability@antidotehealth.com.