Every OnePath Connect integration ships with dual-layer authentication, per-partner data isolation, and an immutable PHI audit trail. There's no downgrade path — security is the foundation, not a feature tier.
A fully executed BAA is required before any partner receives production API access. OnePath operates as a HIPAA Business Associate (45 CFR §160.103) on behalf of your organization as a Covered Entity or Business Associate.
Every PHI-returning request requires two independent proofs: an application-scoped API key and a short-lived, per-patient RS256 consent assertion JWT signed with your private key. A compromised API key alone cannot access any data.
All FHIR data is namespaced by partner application. Your records are structurally isolated from every other partner's data. Cross-partner access is not possible — it's a structural guarantee, not a policy control.
Every PHI-returning API call writes an immutable audit record keyed to the consent assertion that authorized it. Cryptographic evidence of who accessed what, and when — ready for HIPAA audit.
Consent revocation propagates immediately. Once revoked, all subsequent PHI requests are blocked regardless of a valid API key or JWT — consent is the first check, not the last.
LOINC-coded observations, SNOMED CT conditions, RxNorm medications. Every data element is coded to open standards, ensuring your integration interoperates with downstream clinical systems.
Partner Requirements
Security is a shared responsibility. These obligations are required components of the BAA and integration agreement.
Our team can walk you through the BAA process and answer any security questions before you commit.