How to Apply
The production access process
The major steps you will take when developing your application and applying for Blue Button API production access are as follows:
-
Submit your application
When you are ready to apply for production access, send an email to BlueButtonAPI@cms.hhs.gov. The team will reply with a link to the Blue Button production access form. We typically respond to requests within one business day.
The production access form will ask for your privacy policy, terms of service, and confirmation that you’ve signed the CARIN Alliance Code of Conduct. The form will also ask for basic information about your organization and application.
Fill out and submit the production access form, attaching PDF versions of your terms of service, privacy policy, and sign the CARIN Alliance Code of Conduct.
-
Schedule your demo
After you submit the production access form, we will follow up to schedule a 1-hour Teams demo. The demo meeting is an opportunity for you to showcase your application to the Blue Button API team.
You should demonstrate a substantially complete view of the journey enrollees take using your app, including these aspects:
-
User account creation
-
User authorization to share Medicare data with your app
-
How the application displays enrollees’ data
-
How the application uses enrollees’ data
-
If applicable, how the app allows enrollees to share their data with others (e.g., providers or caregivers)
You should also be ready to discuss
-
privacy policy
-
terms of service
-
any security-related questions
-
other concerns the Blue Button API team may have about your application.
Who must be present in the demo
When scheduling the demo, please be sure someone attends who can answer questions about your app’s:
-
Business and market focus
-
Security practices
-
Technical nuances
For some apps, that could be one person. For others, it could be multiple people. Be sure to have everyone present who can answer those questions.
-
-
Address any feedback
After the demo, the team reviews your app, privacy policy, and terms of service. They may:
- Approve: You’re ready for production credentials
- Request changes: Specific items to address before approval (e.g., privacy policy gaps, UI issues, AI usage)
- Request another demo: In some cases, the Blue Button team may require a follow-up demo
Turnaround time varies, but the team will communicate clearly about what’s needed.
-
Register your application
Once the team approves your app and any necessary changes, we will send you a link to the Blue Button post-approval form.
Complete the post-approval form with any information you would like us to include about your app in the Medicare Connected Apps directory.
Enrollees will use the information you provide to learn about your app and how it might help them. You can update this information at any time by emailing us at BlueButtonAPI@cms.hhs.gov.
-
Receive production credentials
After you complete the post-approval form, we’ll ask to schedule a 15-minute Teams call to provide you with your credentials.
Once you have your credentials, you’ll be officially onboarded to the CMS Blue Button API!
Timeline
Typical Approval Timeline
| Step | Typical duration |
|---|---|
| Initial response to email | ~1 business day |
| Form review + demo scheduling | 1-2 weeks |
| Demo | 1 hour |
| Post-demo review | 1-2 weeks |
| Credential handoff | Scheduled after approval |
These are typical timelines; your experience may vary based on the complexity of your app and whether you will need to make changes.
Questions
Email BlueButtonAPI@cms.hhs.gov or ask in the Blue Button API Google Group. The team typically responds to emails and Google Group posts within one business day.