OnePath logoOnePathConnect
For BusinessFor Developers
PlatformDocsChangelogUse CasesCompanyLive Demo
StatusSign InGet API Access
Security & Compliance

HIPAA-grade security. Not optional. By default.

Every OnePath Connect integration ships with dual-layer authentication, per-partner data isolation, and an immutable PHI audit trail. There's no downgrade path — security is the foundation, not a feature tier.

HIPAA Business Associate Agreement

A fully executed BAA is required before any partner receives production API access. OnePath operates as a HIPAA Business Associate (45 CFR §160.103) on behalf of your organization as a Covered Entity or Business Associate.

Dual-Layer Authentication

Every PHI-returning request requires two independent proofs: an application-scoped API key and a short-lived, per-patient RS256 consent assertion JWT signed with your private key. A compromised API key alone cannot access any data.

Per-Partner Data Isolation

All FHIR data is namespaced by partner application. Your records are structurally isolated from every other partner's data. Cross-partner access is not possible — it's a structural guarantee, not a policy control.

Immutable PHI Audit Trail

Every PHI-returning API call writes an immutable audit record keyed to the consent assertion that authorized it. Cryptographic evidence of who accessed what, and when — ready for HIPAA audit.

Instant Consent Revocation

Consent revocation propagates immediately. Once revoked, all subsequent PHI requests are blocked regardless of a valid API key or JWT — consent is the first check, not the last.

FHIR R4 + Clinical Terminology

LOINC-coded observations, SNOMED CT conditions, RxNorm medications. Every data element is coded to open standards, ensuring your integration interoperates with downstream clinical systems.

Partner Requirements

What we require from partners

Security is a shared responsibility. These obligations are required components of the BAA and integration agreement.

  • Execute a BAA with OnePath prior to production access
  • Maintain patient consent records with timestamps, disclosure version, and mechanism
  • Secure your RSA private key in an HSM or secrets manager in production
  • Request only the minimum necessary scopes per API operation
  • Immediately honor consent revocation and purge any locally cached PHI
  • Report suspected HIPAA breaches per Breach Notification Rule timelines
  • Never log raw PHI to application logs

Questions about compliance?

Our team can walk you through the BAA process and answer any security questions before you commit.

Talk to Our Team View HIPAA Compliance
OnePath logoOnePathConnect

HIPAA-compliant health intelligence API for any organization working with health data.

Status

Product

DocsPlatformChangelogStatusUse Cases

Developers

Getting StartedAPI ReferenceSDKsWebhooksError Reference

Company

AboutSecurityContactLinkedIn

Legal

Privacy PolicyTerms of ServiceHIPAA ComplianceBAA InformationSecurity Disclosure

© 2026 OnePath Health, Inc. All rights reserved.

HIPAA-compliant · FHIR R4 native · SOC 2 in progress