Skip to main content

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Production Access

We’re pleased that you’re considering applying for production access to the Blue Button API. Our production access process and Terms of Service are designed to ensure that Medicare enrollee data is kept secure, and that enrollees are given the information to make informed decisions when sharing their healthcare data with third-party applications.

The production access process

The major steps you will take when developing your application and applying for Blue Button API production access are as follows:

  1. Read the terms of service

    The Blue Button API Terms of Service include all official policies for production use of the API. It is essential that you read and understand the Terms of Service before developing your application and applying for production access.

  2. Develop your application in the sandbox

    Refer to our application development resources and guidelines for links to essential documentation and tips to help make sure that your app is ready for production approval.

    Visit the Sandbox
  3. Draft your privacy policy and terms of service

    All organizations applying for production API access must submit their privacy policy and terms of service.

  4. Apply for production access and demo your application

    When you are ready to apply for production approval for your application, send an email to BlueButtonAPI@cms.hhs.gov. We’ll respond with a form requesting basic information about your organization and application, then follow up to schedule your demo. After your demo, and once any concerns with your application, privacy policy, and terms of service have been met, we will schedule the handoff of production credentials. Please read about our production access request and demo process for complete information on applying and scheduling your demo.

Application development resources and guidelines

These resources and guidelines will help you develop your application and make sure that the finished app is ready for production approval by the Blue Button API team.

Documentation and other resources

The following resources are available for your use while developing your application:

User interface guidelines

Keeping the user informed

Your privacy policy and terms of service are important for keeping enrollees informed about how their data will be used and shared. However, many users will click through and authorize access to their medical information without reading them completely. For this reason, your in-app messaging should also clearly describe how user data will be collected, used, and shared.

For example, If an enrollee’s data is about to be shared, you could use a message, modal, or the general UI to clearly and concisely convey what is about to happen, why it is about to happen, and give the enrollee the ability to choose to move forward or not. Short contextual messages like this are far easier for users to digest and understand than the same information as presented in your privacy policy.

Create your application with this in mind: “A Medicare enrollee should never be surprised to learn how their data is being used.” Your application should always collect, use, and disclose health information in ways that are consistent with user expectation and consent.

Giving the user control

Remember that Medicare enrollees will be sharing very sensitive personally identifiable information (PII) and protected health information (PHI) with your application. Giving enrollees the ability to take action on information presented in the UI ensures that they have complete and thoughtful control over their healthcare data. Users should also be given opportunities to opt into or revoke service, request that their data be securely and completely deleted, or otherwise control access to and retention of their data.

Security and privacy

While developing your application, please comply with all applicable laws and industry best practices to minimize the risk of unauthorized access, use, destruction, annotation, or disclosure of Medicare enrollees’ PII and PHI. If applicable to your organization and/or use case, your application’s handling of PII and PHI must also be in compliance with HIPAA regulations.

Referring to Blue Button data

If your application allows connections to several data sources and users must search or pick from a list, please use “Medicare” as the name of the Blue Button data source. Do not use “Blue Button,” “CMS Blue Button,” “Medicare.gov,” or any other terminology.

Production access request and demo

Production access request

When you are ready to apply for production access, send an email to BlueButtonAPI@cms.hhs.gov. The team will reply with a link to the Blue Button production access form. We typically respond to requests within 24 business hours.

The production access form will request your privacy policy and terms of service, along with some basic information about your organization and application:

  • The name of your organization
  • The name of your application
  • Your application’s use case for Medicare enrollees
  • Your application’s redirect URI
  • A point of contact for your organization

Fill out and submit the production access form, attaching PDF versions of your terms of service and privacy policy.

Application demo

After you submit the production access form, we will follow up to schedule a 1-hour demo over Zoom. The demo meeting is an opportunity for you to showcase your application to the Blue Button API team.

You should be prepared to demonstrate a substantially complete view of the journey enrollees take using your app, including these aspects:

  • User account creation
  • User authorization to share Medicare data
  • How the application displays enrollees’ data
  • How enrollees’ data is used
  • If applicable, how the app allows enrollees to share their data with others (e.g., providers or caregivers)

You should also be ready to discuss your privacy policy and terms of service, and any security-related questions or other concerns that the Blue Button API team may have about your application.

After the demo, the Blue Button API team will review your application, privacy policy, and terms of service, and determine if you are ready for production access. We may follow up with you after the demo about concerns that must be addressed before issuing production credentials. In some cases, we may ask to schedule an additional demo.

Production credentials

Once you have met any concerns raised by the team and your application is approved, we will send you a link to the Blue Button post-approval form. This form includes information about how you want your app listed in the Medicare connected apps directory. After you submit the post-approval form, we will schedule the handoff of production API credentials.

Looking for U.S. government information and services?
Visit USA.gov