Last reviewed: July 1, 2026 · OnePath Health, Inc.
OnePath Health, Inc. operates as a HIPAA Business Associate (45 CFR §160.103) when it receives, maintains, or transmits Protected Health Information ("PHI") on behalf of Covered Entities and Business Associates using OnePath Connect. All production API Partners must execute a Business Associate Agreement ("BAA") with OnePath before any PHI is exchanged. OnePath does not use or disclose PHI for any purpose other than those permitted by the applicable BAA and HIPAA regulations.
Through the OnePath Connect API, Partners may submit:
OnePath stores only a cryptographic hash (SHA-256) of the Partner's external patient identifier — never the raw identifier itself. PHI is scoped to each Partner's isolated FHIR namespace and is never shared across Partner applications.
The API enforces a dual-layer consent model for every PHI-returning request:
Each consent assertion JWT specifies the scopes required for the specific API operation (e.g., labs.read, chat.user). Partners are expected to request only the scopes required for each specific use case.
HIPAA Safeguards
In the event of a Security Incident constituting a Breach of Unsecured PHI under HIPAA (45 CFR §164.400 et seq.), OnePath will notify affected Partners without unreasonable delay and no later than sixty (60) calendar days from discovery. Partners must report suspected incidents to security@onepath.health promptly.
OnePath maintains an immutable audit record for every PHI-returning API call capturing:
These records are append-only and cannot be modified or deleted. Audit log access may be made available to Partners on request.
Contact our Privacy and Security team at privacy@onepath.health or security@onepath.health.
Ready to execute a BAA and begin integration?
Request Partner Access