These API Terms of Use and Developer Agreement ("API Terms") govern access to and use of the ApexEHR application programming interfaces ("API"). They supplement the ApexEHR Terms of Use. If there is a conflict, these API Terms govern API use.
1. Acceptance and authorized developers
By registering for, accessing, or using the API, you accept these API Terms on your own behalf and, where applicable, for the organization you represent. You must have authority to bind that organization. ApexEHR may require additional onboarding, credentials, or a written agreement before issuing production API access.
2. Credentials and security
You must protect all accounts, session credentials, API keys, and tokens; use HTTPS; limit access to authorized personnel; and promptly notify ApexEHR of suspected compromise. You may not share credentials, attempt to bypass authentication or authorization controls, or use the API to access data outside the authorized clinic and user context.
3. Permitted use and restrictions
You may use the API only to build or operate an application authorized by ApexEHR and only for the documented purpose of the API. You may not scrape, probe, overload, reverse engineer, interfere with, or use the API in violation of law, patient privacy rights, or these API Terms.
4. Protected health information
API responses may contain protected health information. You must apply the minimum necessary standard, maintain appropriate administrative, technical, and physical safeguards, and comply with all applicable privacy and security obligations. Where required, use of the API is subject to an applicable Business Associate Agreement or other written agreement with ApexEHR.
5. Availability, limits, and changes
ApexEHR may apply reasonable rate, concurrency, and security limits. ApexEHR may modify, deprecate, suspend, or discontinue API functionality when necessary for security, legal, or operational reasons. Developers are responsible for monitoring published documentation and testing integrations before adopting a new API version.
6. Suspension and termination
ApexEHR may suspend or terminate API access for a security concern, violation of these API Terms, unauthorized access, excessive use, or when required by law. On termination, you must stop using the API and securely delete information when required by applicable law or agreement.
7. Support and contact
Questions about API access, documentation, or security incidents should be sent to api-support@apexehr.com. Legal questions should be sent to legal@apexehr.com.
8. Related documents
The current technical reference is available at ApexEHR Patient Selection API Documentation. These API Terms should be reviewed and approved by ApexEHR's authorized legal owner before production publication.