Home > Patient Access API: the ONC/CMS final rules 2020/2021

Patient Access API: the ONC/CMS final rules 2020/2021

On 9 March 2020, the U.S. Department of Health and Human Services (HHS) finalized two rules (the ONC final rule and the CMS final rule) that will give patients “unprecedented” access to their health data. These final rules require both public and private entities to share health information between patients and third-party developers, which will be allowed to include claims data and other patient health information in their apps.


We build APIs for EHR systems, patient portals, and mobile applications. Need help with API development or testing?
Let's talk.

ONC’s final rule establishes API requirements to support a patient’s securely and easily access and use their electronic health information from their provider’s medical records for free, using the smartphone app.

Beginning January 1, 2021, Medicare Advantage, Medicaid, CHIP, and, for plan years beginning on or after January 1, 2021, plans on the federal Exchanges will be required to share claims and other information related to their medical encounter, such as cost or clinical information, with patients through the Patient Access API (HL7 FHIR version 4.0.1).

This rule also requires MA organizations, Medicaid FFS programs, CHIP FFS programs, Medicaid managed care plans, and CHIP managed care entities to make provider directory information publicly available via FHIR-based Provider Directory API. This rule also has an implementation deadline of January 1, 2021.

This API will allow patients to access their data through any third-party application they choose and could also be used to integrate a health plan’s information to a patient’s EHR. Patients can take this information with them as they move from plan to plan, and provider to provider.

The CMS final rule establishes a new Condition of Participation for all Medicare and Medicaid participating hospitals, requiring them to send electronic notifications to another healthcare facility or community provider or practitioner when a patient is admitted, discharged, or transferred.

Follow these steps to get start

  1. One of your patients identifies a patient health app, for example, the Apple Health app that they would like to use to access their health information.
  2. Ask your EHR provider to give you links to the appropriate APIs, Including the patient's ID, Allergies, Assessments, all current Care Team members, all current Goals, all current Health Concerns, Immunizations, Lab Results, pending and future Lab Tests, current and past Medications, implanted and removed Medical Equipment records, current demographics (Race, Ethnicity, Name, Sex, Date of Birth, and Preferred Language), active, inactive and resolved Problems, Procedures, Social History data (Including Smoking Status), and Vital Signs.
  3. For third-party applications chosen by individuals to facilitate their access to their Electronic Health Information Export, you don’t need (page 465) to “vet” these applications on security grounds.
  4. Provide these links to the Apple Health app developers to allow them to connect to your EHR. Once they integrate them into their app, they should provide instructions for accessing health information for their users, including your patient.

Some EHR vendors express criticism

Among the most vocal critics of these final rules was EHR vendor Epic. It posted a long note, which points to a recent study showing that 79% of healthcare apps resell or share data.  "By requiring health systems to send patient data to any app requested by the patient, the ONC rule inadvertently creates new privacy risks," according to Epic.

Earlier, Tommy Thompson, former HHS Secretary – and former governor of Wisconsin -  wrote in the Wisconsin State Journal that the regs “would compel Epic to give its trade secrets away to venture capitalists, Big Tech, Silicon Valley interests, and overseas competitors for little or no compensation...HHS' rule would conscript Epic to work for these new entrants, subverting free-market principles at the expense of Wisconsin residents”.

Companies such as Apple, Google and Microsoft are all proponents of the new rules. They are members of the CARIN Alliance, which has advocated that "the two proposed rules should be finalized and released immediately." (By the way, Epic this month announced plans to stop integrations with Google Cloud.)

Never miss a post! Share it!

Written by
Deputy Business Development Director at Belitsoft
I am a customer’s advocate and an expert in Healthcare IT.
5 reviews

Rate this article

Belitsoft Blog for Entrepreneurs
How to Build an EHR System

You would like to build an EHR System or EMR software, now what? Start with this case study from the...

The Best Open Source EHR Systems To Consider

This article is a review of the most popular open source EHRs. The recommendations inside are based on the 4+...

Patient Portal Development

You have an idea of an integrated medical patient portal, now what? If you don’t know where to start, how...

60 ONC's EHR Certification Requirements for the USA

Would you like to be listed in the Certified Health IT Product List (CHPL)? Do you need to get assistance...

Telehealth Software Development for Mental Health Providers
Telehealth Software Development for Mental Health Providers
A founder of a healthcare startup from the USA reached out to us. His idea was to develop a turnkey telemedicine portal that would connect mental/behavioral health professionals and their patients.
Custom Electronic Healthcare Record SaaS Development
Custom Electronic Healthcare Record SaaS Development

Belitsoft has successfully developed an MVP version of a cloud-based electronic healthcare record (EHR) platform for a well-known Company in the healthcare industry.

Project Management System for a Health, Security and Environment Company
Project Management System for a Health, Security and Environment Company
JavaScript, React, React Native, Redux, Redux-persist, Recompose, Reselect, Koa, Knex, PostgreSQL
Team size:
React Native developers, Backend developer, Designer, Project manager
Custom Healthcare Web Development
Custom Healthcare Web Development
PHP, MySQL, xAjax, Joomla!® CMS
8 man-months



I expected and demanded a lot of you at Belitsoft company, but you exceeded my expectations. You acted pro-actively, challenged me at the right moments. Thanks!

Martin Beijer

CEO at Ticken B.V. (Netherlands)


We have been working for over 10 years and they have become our long-term technology partner. Any software development, programming, or design needs we have had, Belitsoft company has always been able to handle this for us.

Bjarne Mortensen

СEO at ElearningForce International (United States, Denmark)


They use their knowledge and skills to program the product, and then completed a series of quality assurance tests. We were working in an agile way with them. Belitsoft performed very well throughout our project. We are definitely looking at Belitsoft as a long-term partner.

Eddie Nicholas

Service Delivery Director at Crimson (United Kingdom)


I highly recommend Belitsoft for website design and development. We were up against a tight deadline to launch the project. The work was delivered on time and within budget! I will continue working with Belitsoft as a valued partner for our web development!

Adrienne Herd

Program Administrator at UC Berkeley (United States)


We have worked with Belitsoft team over the past few years on projects involving much customized programming work. They are knowledgeable and are able to complete tasks on schedule, meeting our technical requirements. We would recommend them to anyone who is in need of custom programming work.

Kevin M. Rice

Main Partner at Hathway Tech (United States)


Belitsoft company is able to make changes instantly. One of our internal engineers has commented about how clean their code is. Belitsoft seems to know what they're doing, which I appreciate.

Darlene Liebman

Co-Founder at HOWCAST MEDIA (United States)


It was a great pleasure working with Belitsoft. Software Development Company. New requirements and adjustments were implemented fast and precisely. We can recommend Belitsoft and are looking forward to start a follow-up project.

Renè Reiners

Deputy Head of Division at Fraunhofer FIT (Germany)

Apollo Matrix

Belitsoft company has been able to provide senior developers with the skills to support back end, native mobile and web applications. We continue today to augment our existing staff with great developers from Belitsoft.

Pete Johnson

CEO at Apollo Matrix (United States)


Belitsoft company delivered dedicated development team for our products and technical specialists for our clients time to time custom development needs. We highly recommend that you use this company if you want the same benefits.

Bo Sejer Frandsen

Managing Director at Key2Know A/S in 2012 (Denmark)

Regen Med

We approached BelITsoft with a concept, and they were able to convert it into a multi-platform software solution. Their team members are skilled, agile and attached to their work, all of which paid dividends as our software grew in complexity.

Nicolas Tierney

COO at Regenerative Medicine LLC (United States)


Having worked with Belitsoft as a service provider, I must say that I'm very pleased with the company's policy. Belitsoft guarantees first-class service through efficient management, great expertise, and a systematic approach to business.. I would strongly recommend Belitsoft's services to anyone wanting to get the right IT products in the right place at the right time.

Guy Doron

CEO at Moblers (Israel)


If you are looking for a true partnership Belitsoft company might be the best choice for you. They have proven to be most reliable, polite and professional. The team managed to adapt to changing requirements and to provide me with best solutions. I strongly recommend Belisoft.

Ivo Downes

Director at ShowCast Limited (Germany)

Let's Talk Business
Do you have a software development project to implement? We have people to work on it. We will be glad to answer all your questions as well as estimate any project of yours. Use the form below to describe the project and we will get in touch with you within 1 business day.
Contact form
* Maximum file size is 20MB
to top