Scope before access
The FHIR version, profile, endpoint class, checks and access route are recorded before execution. Unsupported and excluded checks remain visible.
Security & data handling
FHIR Pilot is designed for authorised non-production testing. The current service does not require production access, PHI or secrets in the public intake flow.
We treat the official test-kit version, selected groups, test scope and data boundary as part of the deliverable, not fine print. Public unauthenticated endpoints may use the connected route; credentialed environments use zero-access unless a separate secure-access gate is approved.
Service controls
The FHIR version, profile, endpoint class, checks and access route are recorded before execution. Unsupported and excluded checks remain visible.
FHIR Pilot accepts authorised sandbox or test environments. Production systems and protected health information are prohibited.
Baseline connected checks are read-only. Any additional interaction required by a confirmed official suite must be explicitly authorised, limited to test data and remain inside the recorded boundary.
The public request form rejects endpoint URLs and common credential patterns. Credentials are never requested by email or stored in the inquiry record.
If external access is not acceptable, execution stays in your environment and only sanitised evidence enters the review workflow.
Inquiry and first-party funnel records are automatically pruned after 90 days. Optional Google Analytics event data is set to 14 months. Customer report retention is agreed per scope.
Data map
Connected-run gate
Public unauthenticated sandboxes may use the connected route. Credentialed scopes use zero-access by default and move to connected execution only after a separate secure-access gate is approved in writing.
Zero-access route
Public sample runs use public demo/test environments and are labelled accordingly.
Contact support@digitalcognitivesolutions.com. Include a request/report reference, but do not send credentials, endpoint URLs, PHI or FHIR payloads by email.