Interoperability and API Access
At MCCMH, we are committed to providing the people we serve with secure and seamless access to their healthcare data, in compliance with CMS interoperability requirements. As part of the ONC 2015 Edition Cures Update (170.315(g)(10)), MCCMH ensures that individuals served and approved third-party developers can access health data through our secure APIs.
HIPAA Protections and Your Healthcare Data
We are dedicated to protecting your healthcare data and ensuring it is handled in accordance with the Health Insurance Portability and Accountability Act (HIPAA). HIPAA provides critical protections for your personal health information (PHI), ensuring that it remains private, secure, and accessible only to authorized individuals or entities. Below is an overview of your rights under HIPAA and how to learn more about your protections.
Your Rights Under HIPAA
As a person served, HIPAA grants you specific rights over your healthcare data, including:
- Right to Access: You have the right to access your healthcare information and request copies of your medical records from covered entities like health plans and healthcare providers.
- Right to Request Amendments: If you believe that your healthcare data is incorrect or incomplete, you have the right to request amendments to your health records.
- Right to Privacy: Your healthcare data is protected from unauthorized disclosure. Covered entities must follow strict privacy and security standards to ensure your information is only shared with authorized parties.
- Right to File a Complaint: If you believe your healthcare privacy rights have been violated, you have the right to file a complaint with the U.S. Department of Health & Human Services (HHS) Office for Civil Rights (OCR).
For more detailed information about your HIPAA rights, visit the HHS website.
Important Notice: Third-Party Applications and HIPAA
While your healthcare data is protected under HIPAA when it is in the hands of covered entities such as health plans or healthcare providers, third-party applications that you choose to use for accessing your healthcare data may not be required to follow HIPAA protections. This means that once you authorize a third-party app to access your data, it may not be obligated to adhere to the same privacy and security rules that health plans and providers must follow.
Before choosing a third-party application, carefully review its privacy policy to understand how your data will be handled. If you have concerns about how an app may use or share your personal information, you may want to consider alternative options or limit the data you share with it.
For more information about the use of third-party apps and how HIPAA applies, please visit the HSS website.
Understanding Our APIs
MCCMH offers two distinct APIs to meet the CMS interoperability requirements, providing both individuals served and developers with access to critical healthcare information. Below is a brief overview of each API:
Patient Access API
The Patient Access API is designed to enable individuals served by MCCMH to securely access their personal healthcare data. This API enables individuals to retrieve a wide range of information from their health plan, including claims, encounter data, clinical information, and formulary data.
Key features of the Patient Access API:
- Provides secure access to health data such as diagnoses, treatments, and prescriptions
- Allows third-party applications to retrieve data with the individual’s consent.
- Empowers individuals to share their health information with trusted applications to manage their care
The Patient Access API supports the CMS mandate for giving patients more control and transparency over their healthcare information. This API provides a standardized method for patients to securely view and manage their data, enhancing the overall healthcare experience.
Provider Directory API
The Provider Directory API is designed to help people served by MCCMH and developers access a comprehensive directory of in-network healthcare providers and pharmacies. This API enables individuals and third-party applications to easily search for information, including provider names, contact details, specialties, and locations.
Key features of the Provider Directory API:
- Allows individuals to search for providers and pharmacies covered by their health plan
- Supports third-party applications in displaying accurate provider details
- Helps individuals find the right healthcare professionals and services to meet their needs
The Provider Directory API plays a crucial role in promoting transparency and ease of access to in-network providers, ensuring that individuals served can make informed choices about their care.
