Hi Blue Button 2.0 Community,
This is a reminder that the
Blue Button 2.0 Terms of Service states that:
- “By accessing or using Centers for Medicare & Medicaid Services (CMS) Blue Button 2.0 APIs and other developer services (collectively, Blue Button 2.0 APIs), you are agreeing to the terms below, any relevant sections of CMS’s Privacy Policies, and the Medicare.gov Terms and Conditions (collectively, Terms).”
- You may not request, access, use, or share a Medicare beneficiary’s Medicare.gov login credentials.
Please note that this includes building in user authentication flows where anyone other than the Medicare enrollee is entering their own Medicare.gov credentials.
The Blue Button 2.0 API requires that the enrollee authenticate themselves, and apps which direct a family member or caregiver to login on their behalf violate these terms.
Please reach out if you have any questions about your specific application, and please let us know if you are planning changes to the authentication flow that differ from what was presented at your production access demo.
Thank you,
The Blue Button 2.0 Team