How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Penn Medicine Patient Access API

Patient-mediated clinical and claims data resources required under CMS-9115-F.

Penn Medicine Patient Access API is one of 7 APIs that Penn Medicine publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 4 JSON Schema definitions.

Tagged areas include Patient Access. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, authentication docs, and 4 JSON Schemas.

This API exposes 14 operations across 14 paths. It is described by OpenAPI 3.1.0, at version 4.0.1.

Requests are made against a single base URL, https://ssproxy.pennhealth.com/PRD-FHIR/api/FHIR/R4.

14 operations 14 paths 0 schemas 14 GET

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.1.0
API Version
4.0.1
Base URL
https://ssproxy.pennhealth.com/PRD-FHIR/api/FHIR/R4
Authentication
OAuth 2.0
Resource Areas
1

Authentication & Security 1

Penn Medicine Patient Access API declares 1 security scheme for authenticating requests. It supports OAuth 2.0 (smartOnFhir) using the authorizationCode and clientCredentials flows, exposing 6 scopes. By default, every request must be authenticated.

Paths & Operations 14

Across 14 paths, the API surfaces 14 operations — 14 GET. Each is listed below with its method, path, parameters, and response codes.

Patient Access 14

Patient-mediated clinical and claims data resources required under CMS-9115-F.

GET
/Patient/{id}
Read Patient
readPatient 1 param → 200
GET
/Patient
Search Patient
searchPatient 2 params → 200
GET
/AllergyIntolerance
Search Allergy Intolerance
searchAllergyIntolerance 1 param → 200
GET
/Condition
Search Condition
searchCondition 2 params → 200
GET
/Observation
Search Observation
searchObservation 3 params → 200
GET
/MedicationRequest
Search Medication Request
searchMedicationRequest 1 param → 200
GET
/Immunization
Search Immunization
searchImmunization 1 param → 200
GET
/Procedure
Search Procedure
searchProcedure 1 param → 200
GET
/Encounter
Search Encounter
searchEncounter 1 param → 200
GET
/DiagnosticReport
Search Diagnostic Report
searchDiagnosticReport 2 params → 200
GET
/DocumentReference
Search Document Reference
searchDocumentReference 1 param → 200
GET
/Coverage
Search Coverage
searchCoverage 1 param → 200
GET
/ExplanationOfBenefit
Search Explanation of Benefit
searchExplanationOfBenefit 1 param → 200
GET
/Claim
Search Claim
searchClaim 1 param → 200

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

penn-medicine-patient-access-api-openapi.yml Raw ↑

Other APIs Penn Medicine publishes across the network.

MyPennMedicine Patient Portal
PhysicianLink Referring Physician Portal
Penn Medicine Open Source Health Informatics
Penn Medicine Bulk Data API
Penn Medicine Provider Directory API
Penn Medicine SMART API
Where this information came from

This is an independent, third-party profile of Penn Medicine Patient Access API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.