Implementation Considerations
For developers building Blue Button-connected applications, and for payers implementing Patient Access APIs modeled on Blue Button.
Consent and transparency. Apps that access Blue Button data should clearly communicate to users what data is being accessed, how it will be used, and how it will be protected. Even though HIPAA may not apply to the app, FTC Act protections against unfair or deceptive practices do — and CMS monitors the Blue Button ecosystem for apps that mishandle beneficiary data.
