UPMC website screenshot

UPMC

A world-renowned health care provider and insurer headquartered in Pittsburgh, Pennsylvania. One of the largest nonprofit health systems in the United States, operating hospitals, physician practices, and a health insurance division (UPMC Health Plan) serving millions of members. UPMC Health Plan exposes an ONC 21st Century Cures Act Developer API for patient-authorized access to clinical and claims data over HL7 FHIR.

UPMC publishes 1 API on the APIs.io network. Tagged areas include Healthcare, Health Insurance, Hospitals, Pennsylvania, and FHIR.

UPMC’s developer surface includes engineering blog, documentation, and 5 more developer resources.

8.1/100 minimal ▬ flat Agent 0/100 human only Full breakdown ↓
scored 2026-07-28 · rubric v0.6
1 APIs 4 Features 4 Use Cases
HealthcareHealth InsuranceHospitalsPennsylvaniaFHIR

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 8.1/100 · minimal
Contract Quality 0.0 / 25
Developer Ergonomics 2.2 / 20
Commercial Clarity 0.0 / 20
Operational Transparency 0.7 / 13
Governance 0.0 / 12
Discoverability 5.4 / 10
Agent readiness — 0/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 10
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/upmc: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

UPMC Health Plan ONC 21st Century Cures Act Developer API

The UPMC Health Plan Developer API is the payer-side FHIR API mandated by the ONC 21st Century Cures Act and the CMS Interoperability and Patient Access Final Rule. It allows re...

Features 4

Notable capabilities this provider offers.

Patient Access FHIR API

Member-authorized access to clinical (USCDI) and claims data per CMS Interoperability and Patient Access Final Rule

Provider Directory API

Public machine-readable provider directory required by CMS Interoperability rules

SMART-on-FHIR Authorization

OAuth 2.0 / SMART-on-FHIR app authorization flow for patient-mediated access

HL7 FHIR R4 Data Model

USCDI-aligned FHIR R4 resources for clinical and claims data exchange

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Upmc Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Use Cases 4

What developers build with this provider.

Patient Data Portability

Members move their clinical and claims data into third-party apps for personal use

Care Coordination

Authorized clinical applications retrieve member records to improve care coordination across providers

Health Apps and PHRs

Consumer-facing personal health record and wellness apps connect to UPMC member data with patient consent

Provider Directory Lookups

Apps and portals discover in-network UPMC Health Plan providers through the public provider directory API

Integrations 2

Pre-built integrations with other platforms and tools.

SMART App Launch

Apps register with UPMC Health Plan as SMART-on-FHIR clients to authenticate members

USCDI Clinical Data

USCDI-aligned clinical resources flow to member-authorized third-party applications

Resources

Documentation 1

Reference material describing how the API behaves

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 1

Authentication, authorization, and security posture

Company 4

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: upmc
url: https://raw.githubusercontent.com/api-evangelist/upmc/refs/heads/main/apis.yml
name: UPMC
type: Index
accessModel:
  pricing: unknown
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Unknown
  confidence: low
  source: []
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/upmc.png
tags:
- Healthcare
- Health Insurance
- Hospitals
- Pennsylvania
- FHIR
description: A world-renowned health care provider and insurer headquartered in Pittsburgh, Pennsylvania. One of the largest
  nonprofit health systems in the United States, operating hospitals, physician practices, and a health insurance division
  (UPMC Health Plan) serving millions of members. UPMC Health Plan exposes an ONC 21st Century Cures Act Developer API for
  patient-authorized access to clinical and claims data over HL7 FHIR.
created: '2026-05-05'
modified: '2026-05-16'
specificationVersion: '0.19'
apis:
- aid: upmc:cures-act-developer-api
  name: UPMC Health Plan ONC 21st Century Cures Act Developer API
  tags:
  - FHIR
  - Patient Access
  - Healthcare
  - Health Insurance
  - Cures Act
  - HL7
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
  humanURL: https://www.upmchealthplan.com/
  properties:
  - url: https://www.upmchealthplan.com/
    type: Documentation
  description: The UPMC Health Plan Developer API is the payer-side FHIR API mandated by the ONC 21st Century Cures Act and
    the CMS Interoperability and Patient Access Final Rule. It allows registered third-party applications to retrieve a member's
    clinical (USCDI) and claims data on the member's behalf using SMART-on-FHIR / OAuth 2.0 authorization. The API surface
    includes the Patient Access API (clinical + claims) and the Provider Directory API. UPMC Health Plan exposes a public
    link to the developer API resource center in the footer of every page on upmchealthplan.com.
common:
- type: DomainSecurity
  url: security/upmc-domain-security.yml
- url: https://www.upmc.com/media
  type: Blog
- type: GitHubOrganization
  url: https://github.com/UPMC
- type: LinkedIn
  url: https://www.linkedin.com/company/upmc
- type: Website
  url: https://www.upmc.com/
- type: Website
  url: https://www.upmchealthplan.com/
- type: Documentation
  url: https://www.upmchealthplan.com/
- type: Features
  data:
  - name: Patient Access FHIR API
    description: Member-authorized access to clinical (USCDI) and claims data per CMS Interoperability and Patient Access
      Final Rule
  - name: Provider Directory API
    description: Public machine-readable provider directory required by CMS Interoperability rules
  - name: SMART-on-FHIR Authorization
    description: OAuth 2.0 / SMART-on-FHIR app authorization flow for patient-mediated access
  - name: HL7 FHIR R4 Data Model
    description: USCDI-aligned FHIR R4 resources for clinical and claims data exchange
- type: UseCases
  data:
  - name: Patient Data Portability
    description: Members move their clinical and claims data into third-party apps for personal use
  - name: Care Coordination
    description: Authorized clinical applications retrieve member records to improve care coordination across providers
  - name: Health Apps and PHRs
    description: Consumer-facing personal health record and wellness apps connect to UPMC member data with patient consent
  - name: Provider Directory Lookups
    description: Apps and portals discover in-network UPMC Health Plan providers through the public provider directory API
- type: Integrations
  data:
  - name: SMART App Launch
    description: Apps register with UPMC Health Plan as SMART-on-FHIR clients to authenticate members
  - name: USCDI Clinical Data
    description: USCDI-aligned clinical resources flow to member-authorized third-party applications