PHI and security
RCM integrations often handle patient identifiers, insurance identifiers, clinical documentation, claim data, and payer responses. Treat the public API as a healthcare data interface, not a generic SaaS API.
Integration rules
- Do not send PHI in query strings. Prefer JSON request bodies for patient, member, diagnosis, transcript, document, and claim details.
- Do not log raw request or response bodies unless logs are encrypted, access-controlled, and approved for PHI.
- Use least-privilege API keys and rotate keys when staff, vendors, or integration ownership changes.
- Never place API keys, payer credentials, S3 credentials, OAuth tokens, private keys, EDI payloads, transcripts, or raw payer/EHR responses in tickets or chat.
- Treat memberId, dateOfBirth, patient names, diagnosis codes, clinical notes, claim details, and document contents as PHI.
Query string rule
Do not send PHI in URL query strings. URLs are commonly captured by proxies, browser history, CDN logs, load balancer logs, and monitoring tools.