Your 22 Health Digital Medical Records

To help make it easier for you to access and manage your health information, the CMS Interoperability and Patient Access Rule (CMS-9115-F) was introduced under the 21st Century Cures Act to give patients more control over their medical data. In plain terms, this rule requires health plans to give you electronic access to your own records through secure, standardized APIs. An API (Application Programming Interface) is a secure way for different computer systems to share information.  

This means you can quickly access your health records when needed and even view them on your smartphone at no cost. The goal is to empower you with information – helping you make informed decisions, avoid repeat tests, and coordinate your care more easily. 

What This Means for You 

If you enroll in a 22 Health Marketplace plan, starting January 1, 2026, you’ll have the ability to connect your digital medical records to the health app(s) of your choice. This means you can have:

  • Instant access to your medical history: You go to a new doctor, and you can easily show them an up-to-date summary of your health history, right on your phone, through an app.*

  • Quick answers about claims: You have a question about an insurance claim – instead of calling Member Services, you open an app and in minutes see whether the claim was paid, denied, or still processing.

  • Finding the right care easily: You need to find a specialist or check if a medication is covered. Using an app connected to your health plan, you can search an up-to-date provider directory and pharmacy information to make sure you get the care you need within your network. 

22 Health’s digital records access puts you in control of your healthcare information. You’ll be able to view your health plan data and certain clinical data through any compatible app – all with your permission and under your control.  

How 22 Health Provides Access: FHIR APIs and ZeOmega

Open Standards (FHIR APIs): 22 Health uses a technology standard called FHIR – Fast Healthcare Interoperability Resources – to share data. FHIR is an industry-standard format for exchanging health information securely across different systems. Under the CMS rule, health insurers (like 22 Health) must maintain secure API connections using FHIR standards so that members can view their claims and certain clinical information through the app of their choice. These APIs act as channels that allow authorized apps to retrieve your data in a consistent, secure way.

ZeOmega: To power this feature, 22 Health works with ZeOmega, a leading healthcare technology company known for its interoperability solutions. ZeOmega’s platform (called HealthUnity Interoperability Solution) was one of the first to be nationally accredited and certified for the CMS Patient Access requirements. This means the infrastructure behind your data access is trusted, secure, and fully compliant with federal standards. In practical terms, when you use a third-party app to access your 22 Health records, ZeOmega’s technology ensures that the connection meets all required FHIR standards and that your personal health information (PHI) is transmitted securely.

How It Works 

22 Health’s system will securely release your data only when you give permission via a third-party app. The process is simple. 

  1. Choose a health app – You can pick any app that supports FHIR-based health data (for example, a personal health record app, a medication tracker, etc.). We will provide a list of apps that have partnered with 22 Health or agreed to our privacy standards, but the choice is yours (more on choosing apps in the FAQs below).

  2. Download and sign up on the app – Get the app from the Apple App Store or Google Play and create your account.

  3. Link to 22 Health – Within the app, look for the option to connect your health or insurance data. When prompted, select 22 Health as your health plan.

  4. Secure login – You’ll be directed to a secure 22 Health login screen. Enter your 22 Health member portal username and password (the same credentials you use for our member portal). 

  5. Authorize access – The app will display a consent screen (an “Access Your Health Data” statement). Read the details and, if you agree, confirm to Allow Access. This step explicitly grants the app permission to fetch your records from 22 Health.

  6. Access your information – Once authorized, the app will securely retrieve your data via our FHIR API. You can then view your information in the app and use it to manage your health or insurance needs.

This service comes at no extra charge to you – it’s a benefit of being a 22 Health member.  Importantly, you remain in control. Data is shared only after you’ve given consent to an app, and you can revoke access at any time (see How to Stop Sharing in the FAQ section).  

22 Health will not send any data to an app without your direction, and we will inform you which apps have agreed to our privacy guidelines so you can make an informed choice. 

What Information You Can Access 

Once connected, the third-party app will be able to fetch a rich set of your health plan records and certain clinical data that 22 Health maintains. Examples of the types of data you can access through the API are:

  • Personal Demographics: Basic information about you, like your name, date of birth, gender, and contact information (addresses, phone numbers, email). This ensures your identity and info are correct on any records.

  • Claims and Coverage: Details about your health insurance claims – for example, claims you or your providers have submitted, the status (paid or denied), amounts paid by insurance, and any member responsibility. You can quickly see what services were billed and how they were processed.

  • Allergies and Intolerances: Any allergies you’ve reported (e.g. medication allergies or other substance intolerances) along with your reactions. This helps apps alert you or your providers to avoid certain drugs if you’re allergic.

  • Medications: A list of your current and past medications prescribed, including dosage information if available. This can help you track your prescriptions and share an accurate medication list with doctors.

  • Immunizations: Records of your vaccinations (such as flu shots, COVID-19 vaccines, childhood immunizations, etc.), including dates received. This makes it easy to check if you’re up to date on important vaccines.

  • Procedures and Treatments: Information on medical procedures or surgeries you have had. For instance, if you have undergone surgery or a specific treatment, this information can be part of your record and accessible via the app.

  • Lab Tests and Results: Data from laboratory tests, like blood work or screenings, including the test name, date, and results. Having lab results at your fingertips can be very handy for specialist visits or personal tracking.

  • Health Conditions/Problems: A summary of your documented health conditions or concerns. This might include diagnoses or health issues that doctors have noted in your records (often part of your clinical data set).

  • Care Team: A list of healthcare providers who have been involved in your care – for example, your primary care doctor, specialists, or other practitioners. This “care team” info helps you keep track of the providers coordinating your care.

  • Plan Details and Provider Directory: In addition to personal medical data, the connected apps can also access our Provider Directory API, which includes information about healthcare providers and pharmacies in 22 Health’s network. This means an app might help you find in-network doctors or facilities using the most up-to-date data. They can also show plan details, like what services are covered or your plan’s drug formulary, if needed.

All of the above data is made available in a standardized format defined by the U.S. Core Data for Interoperability (USCDI) and related frameworks. Essentially, 22 Health’s system converts your records into FHIR “resources” that the app can understand and display to you. No sensitive data will be shared without your approval, and you decide which app gets access.

*Data availability: 22 Health will provide data that it has collected during your coverage with us (starting from January 1, 2026, forward, and potentially some historical data if applicable). For most categories, you’ll see information from 2016 onward as required; however, since 22 Health’s Marketplace plans begin in 2026, your personal data with us will accumulate from that point. If you were previously with another plan, those records don’t automatically transfer to us (this rule is about you accessing data from each plan). However, you could potentially use an app to gather records from your previous insurer as well, giving you a more complete health history in one place.

Keeping Your Information Safe

While having easy access to your health data is empowering, protecting that data is critically important. 22 Health is committed to safeguarding your privacy and security every step of the way.  

Only apps you authorize can connect, and they must do so using secure authentication (OAuth 2.0, etc.). All data is encrypted in transit and at rest in our systems for protectionfile://file-lnhucrtehhfl9vdhrw23su/. We also implement access controls, auditing, and monitoring to prevent any unauthorized access. 

Before connecting an app, 22 Health will ask you to acknowledge consent, reminding you of these considerations.  

Your Role in Protecting Your Data

Learn about how you can help keep your information safe and private on our Privacy Policy page. 

Frequently Asked Questions (FAQs)

What apps can I use to access my 22 Health records?

You can use any third-party health app that supports the required standards (FHIR APIs) to access your records. This includes a variety of personal health management apps, medical record aggregators, or even fitness and wellness apps that offer healthcare data integration. If you find a healthcare app you trust, you can use it as long as it can connect using the OAuth2/FHIR standard. Keep in mind that not all apps are equal when it comes to privacy. You have the freedom to choose your app but choose wisely. If you’re unsure where to start, we can point you to some popular apps that many of our members use. 

Linking your records is easy and should only take a few minutes. Here’s a step-by-step guide:  

  1. Select an App: First, download a health app of your choice from the App Store (iOS) or Google Play (Android). Open the app and create an account if you haven’t already. 

  2. Find the Connect Option: Within the app, look for a feature like “Connect to your health plan” or “Add health data.” This might be under settings or a menu for health records. 

  3. Choose 22 Health: When prompted to select your insurer or health plan, choose 22 Health from the list. (If there’s a search box, type “22 Health” to find us.) 

  4. Secure Login: The app will redirect you to our secure member login. You’ll see a 22 Health-branded login screen. Enter your 22 Health member portal username and password – the same credentials you use for our website or member portal. 

  5. Grant Permission: After successfully logging in, you’ll see a screen explaining what data the app is requesting (e.g., claims, clinical data) and asking if you consent to share this information. Read this “Consent to Access Your Health Data” statement carefully. If you agree, click “Allow Access.” This will authorize the app to retrieve your data. 

  6. Confirmation: Once you allow access, the screen will confirm that the connection was successful. The app will then start pulling in your data. The first sync might take a moment if there’s a lot of information, but soon you should see your records appear in the app’s interface. 

  7. Use the App: That’s it – your 22 Health data is now linked! You can navigate within the app to view different categories (claims, medications, etc.). Going forward, the app will periodically update with new data (for example, new claims or lab results) as they become available.

If you run into any issues linking an app (for instance, you can’t find 22 Health in the app’s list, or login isn’t working), you can contact 22 Health for help. We can guide you through the process or troubleshoot as needed. But in most cases, the process above should be smooth. Many apps also have their own help guides for connecting to a health plan – feel free to consult the app’s FAQ as well. 

The app will have access to your health plan records and certain clinical information that 22 Health has about you. This includes: 

  • Claims information: All your claims and explanations of benefits (EOBs) from 22 Health. You can see what medical services or prescriptions were billed, how much was covered, and what you might owe. This helps you track your healthcare spending and insurance usage. 

  • Personal and policy details: Your demographic info (name, birth date, etc.) and plan enrollment details. Some apps might show your plan name, member ID, coverage dates, and even your deductible or out-of-pocket status if made available. 

  • Clinical data we’ve collected: Any clinical data that comes through claims or care management that we maintain as part of your record. This can include lists of diagnoses or health conditions, medications, allergies, immunizations, procedures, lab test results, and care team contacts. Essentially, it’s the standardized clinical dataset (USCDI v1) that the federal rule requires. For example, if a claim indicates you had a certain diagnosis or lab test, that information becomes part of your record and would be accessible. 

  • Provider and pharmacy directory data: Through our API, apps can also fetch up-to-date information about in-network providers, pharmacies, and facilities. This means within the app you might be able to search for doctors covered by 22 Health or find nearby clinics in-network, etc., using our directory info. This is a great tool to help you find care while ensuring it’s covered by your plan. 

It’s important to note that the app will only gather data and not change any of it. The app is like a window into your records – it can display and organize information, but it cannot alter the underlying data in 22 Health’s systems. If something looks incorrect, the app can’t fix it. Also, the app will not have access to information that isn’t included in the standardized dataset or not allowed by the rule. For example, it won’t have your actual medical images (like X-rays) or detailed doctor’s notes, as those are typically not part of the payers’ mandated data exchange. It’s primarily the key health indicators and claims info. Always review what an app is requesting and make sure you are comfortable with it. If an app asks for more than you expect, you can deny or revoke access. 

Protecting your privacy is our top priority. 22 Health uses secure technology and strict policies to safeguard your information. To learn about our privacy policies, visit our Privacy Policy page. 

How do I stop sharing my data if I no longer want an app to have access? 

You have the right to disconnect an app from your 22 Health data at any time. Deleting the app from your phone is not always enough to revoke its access – you should explicitly withdraw the permission. Here’s what to do: – 

  • Through the App: Most apps that connect to health plans will have an option in their settings or account menu to disconnect or revoke access to your health data. Look for something like “Connected Health Accounts” or “Data Sources.” From there, you can usually remove or unlink your 22 Health account. Once you do this, the app should no longer be able to retrieve new data from 22 Health.  

  • Contact App Support: If you’re unsure how to revoke access within the app, contact the app’s customer support. They can guide you on how to ensure the connection is fully terminated. We recommend also asking the app what happens to the data it already collected – do they delete it or retain it? A good app will delete or anonymize your data upon request. – 

  • Change Your 22 Health Password: As an extra precaution, you could change your 22 Health MyChart member portal password after disconnecting the app. This will invalidate the app’s credentials if for some reason the disconnection didn’t fully go through. (If the app tries to pull data again, it won’t be able to log in.)  

  • Call 22 Health: If you have trouble getting an app to disconnect, you can always reach out to 22 Health Member Services. We can manually disable the app’s access token on our end, which will cut off its access. According to our policies, we might also do this automatically if we detect inactivity or suspect any misuse. 

Remember that revoking access does not automatically delete the data that the app already obtained. It just stops any new data from flowing. For the data already in the app, you should check the app’s policy – you may need to request the app delete your data if you want it removed. Many apps have a process to delete your user account or data upon request. It’s a good practice to follow up on that if you no longer trust or use the app. 

To stop sharing data: unlink via the app or ask us for help. Whenever possible, confirm that the app can no longer access your information. Taking these steps will ensure you’re back in full control and that no further data is shared. 

If you notice an error or discrepancy in the data (for example, a wrong address or a medical service listed that you never received), the correction has to be made at the source. Third-party apps cannot fix errors in your actual medical records; they only display data provided by 22 Health or other sources.  

Here’s what to do if something looks wrong:  

  • Identify the data source: Determine whether the incorrect information likely came from 22 Health (your insurance records) or from a healthcare provider’s records. For instance, if it’s a claim detail or something about your insurance coverage, that’s 22 Health’s domain. If it’s a clinical detail like a diagnosis or medication that you think is wrong, that might have originated from a doctor’s office or hospital when they submitted a claim or medical record. 
  • Contact 22 Health for insurance-related errors: If the error is in your insurance data (e.g., wrong personal info, or a claim error), reach out to our member support. We can update demographic information, such as your address or phone number, in our system. For claim errors, we might need to investigate and possibly coordinate with the provider who submitted the claim. We’ll guide you through that process. – 
  • Contact your healthcare provider for clinical errors: If the error is in the clinical data (like an allergy you don’t have, or a condition that was listed by mistake), you should contact the doctor or facility that recorded that information. They have the ability to amend your medical records. Once they correct it in their records, that correction can flow through to us if it was part of a claim, or at least it will be correct the next time data is accessed. 
  • App data caching: Be aware that some apps might cache (store) data for offline access. Even after an error is fixed with 22 Health or your provider, the app might not update the displayed info until it refreshes its data from our API. Most apps refresh periodically or have a “refresh” button. After confirming the source has corrected the mistake, you can refresh the app data or disconnect and reconnect to view the updated information. 

 

It’s important to keep your medical records accurate, as they could affect your treatment. We encourage you to check the data and speak up if something seems off. 22 Health will do our best to assist you in routing your request to the right place. Also, under federal law (HIPAA), you have the right to request corrections to your health records. Providers and health plans are required to consider your request and make corrections if warranted. We’ll honor any such requests on the insurance data we maintain. 

Troubleshooting tip: If the app shows data that you believe is incorrect or outdated, first verify if our MyChart member portal (or the Explanation of Benefits you received) shows the same data. That will confirm if it’s an issue in the record itself or possibly a glitch in how the app is reading it. In nearly all cases, it’s the record source, but it doesn’t hurt to double-check. 

No, using a third-party app is optional. You are not required to use an app to get your health information. The CMS rule is about giving you more options, not taking away existing ones. Here are other ways you can access your records if you prefer not to use an app:  

  • 22 Health MyChart Member Portal: We provide a secure online member portal, MyChart, where you can view your claims, benefits, and some health information. You can always log in to our portal to see your recent claims, download your insurance documents, check your out-of-pocket totals, etc. While it might not have as extensive clinical details as a dedicated health app, it covers a lot of ground and is directly managed by us.
  • Direct Requests: You can request your health records directly from 22 Health. Under HIPAA, you have the right to receive your claims and certain clinical data from us in a readable form. If you prefer paper or a simple digital download, we can provide that. Just contact Member Services and we’ll guide you through a records request. Typically, we might direct you to a form or a secure email process to send you data. 

  • Healthcare Providers: Remember that much of your clinical information starts with your doctors and hospitals. You can always ask your provider for your medical records or use their patient portal if they have one (many providers use systems like MyChart, etc.). The Patient Access Rule doesn’t change the fact that you can get data straight from the source. In fact, many doctors’ offices also support apps now, separate from your insurer. – 

  • No or Multiple Apps: If you choose not to use any app, that’s completely fine. Your healthcare will continue as usual – this feature is just there if and when you want it. Conversely, you can use multiple apps if that suits you. For example, you might use one app for general record-keeping and another specialized app for managing a specific condition. You can connect both (you’d authorize each one separately). It’s all about giving you control over how you manage your information. 

22 Health will never force you to use a third-party application. It’s an added convenience for those who want a seamless digital experience. If you prefer not to trust any third party with your data, you can rely on us directly or our own tools. We do encourage you to explore the option, though – many members find it useful to have their information consolidated in one place. But ultimately, it’s your choice. We’re here to support you either way. 

If you suspect that a third-party app you connected is misusing your data – for example, you find out it shared your information without permission, or you experience a security breach – it’s important to act quickly: –  

  • Immediately revoke the app’s access: As a first step, disconnect the app from your 22 Health account (see how to stop sharing). This will prevent any further data from flowing to the app.  
  • Contact the App Developer: Reach out to the app’s support team to report your concerns. Ask them for details and demand resolution. For instance, if you discovered your data was shared improperly, ask why and to whom. If your data was stolen (a breach), ask what information was involved and what the app is doing to contain the issue. Reputable app companies should be forthcoming about incidents and have a process to address them. – 
  • Review the App’s Privacy Policy (Notice of Privacy Practices): This document should outline how the app handles such situations. It might detail whether they will notify users of breaches and how, what their obligations are, and if they offer any remedies (like credit monitoring, etc., in case of a breach). The privacy policy should also state whether the app sells or shares user data for research/advertising purposes – if it does something contrary to its policy, that’s a serious red flag.  
  • Notify 22 Health: While the app is independent, we still care about your experience. Let us know if something went wrong. We can at least document it and warn other members if necessary. For instance, if an app is found to misuse data and doesn’t adhere to our Code of Conduct, we might remove it from our recommended list and possibly report it to authorities. –  
  • File a Complaint with Regulators: You have the right to seek help from government regulators: – If the issue is a privacy violation and the app is not covered by HIPAA (which is likely), you can file a complaint with the Federal Trade Commission (FTC). The FTC can investigate unfair or deceptive business practices. Sharing personal data without permission, contrary to what was promised, is considered a deceptive practice. You can submit a complaint at the FTC’s website. – If the app is a HIPAA-covered entity or business associate (for example, say a hospital’s app), and your protected health information was improperly disclosed, you can file a complaint with the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services. OCR enforces HIPAA. Complaints can be filed via their online portal. – In either case (FTC or OCR), it’s helpful to provide as much detail as possible: what happened, dates, any communication from the app, etc. – 
  • Monitor Your Accounts: If data was stolen, especially sensitive info like insurance IDs or medical details, keep an eye on your accounts. Watch for any suspicious medical bills or insurance claims you don’t recognize (identity thieves might try to use stolen insurance info). Also, ensure you change any passwords if you suspect they were compromised. 
  • Seek Additional Remedies: If the breach or misuse causes you harm (financial or otherwise), the app’s privacy policy might offer some recourse, or you might consider legal advice. Some apps may have arbitration clauses or other legal terms, but you still have consumer rights under law. The FTC or state attorneys general can sometimes pursue bad actors to get restitution for consumers. 

 

We at 22 Health will also do our part to help. We can’t directly control the app, but if we become aware of a widespread issue (say multiple members report a particular app mishandling data), we will alert the rest of our members and possibly work with regulators or the app store to get the app corrected or removed. Your trust is important to us, so we take any report of misuse very seriously. 

Lastly, remember that you should only share what you’re comfortable with. If an app is asking for permissions or data that seem unrelated to its purpose (like access to your phone’s location or contacts when it’s not needed), consider saying no. Many mobile devices allow you to control app permissions (for example, you can disallow an app from accessing your GPS or files if it doesn’t make sense for it to have them). Being cautious with permissions can minimize risks. 

Learn about how you can help keep you information safe and private on our Privacy Policy page.