Last updated: 31 July 2026 · Data handling: Privacy Policy
By using the software or website, you agree to these Terms and the Privacy Policy. If you do not agree, do not use them.
YourPHR is distributed under the GNU GPL v3. Rights to use, modify, and redistribute the code are defined by the GPL; these Terms do not restrict those rights.
You (or the operator of the instance you use) run the software and are responsible for securing that deployment and complying with applicable law. The project does not host your health records. Details of where data lives and who can see it are in the Privacy Policy.
You may connect patient-access APIs (including CMS Blue Button / Medicare) only for records you are authorized to access. You must also follow that provider’s and CMS’s terms and API rules. Keep client credentials confidential; do not put production secrets in public repositories. CMS production credentials, if issued, may only be used with the application CMS approved.
How OAuth, tokens, and the sign-in relay handle data is described in the Privacy Policy, not here.
When Blue Button APIs are used, this product is not endorsed or certified by CMS or HHS. Required notice:
This product uses the Blue Button APIs but is not endorsed or certified by the Centers for Medicare & Medicaid Services or the U.S. Department of Health and Human Services.
YourPHR is for viewing and organizing records. It is not medical advice, diagnosis, or treatment. Records may be incomplete or wrong. Consult a qualified clinician for medical decisions.
You agree not to:
Software is provided “AS IS”, without warranty of any kind, as set out in the GPL v3. You use and host it at your own risk.
To the maximum extent permitted by law, the project, contributors, and maintainers are not liable for damages from use of (or inability to use) the software, including loss or inaccuracy of health data, as further described in the GPL v3. CMS/HHS disclaimers apply to the Blue Button APIs themselves under CMS’s terms.
yourphr.org is a static informational site and does not store health records.
We may update these Terms; the date above will change. For CMS-approved Blue Button production apps, follow CMS rules on changing terms and notifying enrollees.