Standardized API Terms and Conditions

Certified standardized FHIR API (170.315(g)(7), (g)(9), and (g)(10))

1. Scope

These Terms and Conditions govern access to and use of the Thyra EHR certified standardized FHIR API (170.315(g)(7), (g)(9), and (g)(10)). By registering for or using the API, an application developer agrees to these Terms.

2. Openness and transparency

Thyra EHR provides API access on terms no more restrictive than those it applies to itself, its affiliates, or its business partners. API documentation is publicly available without preconditions or fees. Thyra EHR will not impose conditions prohibited by 45 CFR 170.404.

3. Registration

Application developers register with the Thyra EHR authorization server to obtain a client identifier and, for confidential clients, credentials. Registration is available on non-discriminatory terms using standard SMART App Launch / OAuth 2.0, with no unnecessary preconditions.

4. Permitted use

Approved applications may access electronic health information consistent with the scopes authorized by the patient or user and with applicable law. Applications must not exceed the scopes granted and must handle all data in accordance with applicable privacy and security laws, including HIPAA where applicable.

5. Fees

Any fees charged in connection with the API are limited to those permitted under 45 CFR 170.404(a)(3)–(4) and are based on objective, verifiable criteria applied uniformly. No fees are charged to access API documentation or to register an application.

6. Security

All connections require TLS 1.2 or above. Authentication and authorization use SMART App Launch / OAuth 2.0 with PKCE (S256). Thyra EHR may revoke an application authorization consistent with its published token-revocation process and applicable law.

7. Service base URLs

Production: https://api.thyrahealth.com/fhir/R4

Sandbox: https://api.dev.thyrahealth.com/fhir/R4

8. Compliance and changes

Thyra EHR maintains these Terms consistent with the API Maintenance of Certification requirements. Material changes will be published at this location. Continued use constitutes acceptance of the then-current Terms.

9. Contact

API onboarding and questions: hello@thyrahealth.com.