Safe-to-Host & production

ABDM certification path: sandbox → NHA tests → CERT-In VAPT → Safe-to-Host → X-CM-ID: abdm

Live CERT-In-empanelled audit, NHA production approval, and production credentials remain Blocked. This checklist tracks prototype evidence only — it does not contact NHA or auditors.

Phase

Self-test in progress

MeevaMed Health Network HMS

X-CM-ID

sbx

Sandbox header

Evidence score

11%

Complete FHIR / HIP / HIU

Safe-to-Host #

Prod approval pending
Self-test gapsNHA neededVAPT neededSTH pending

Certification metadata

Self-test in progress

Evidence checklist

ItemStatusLink
ABDM V3 sandbox registration
Org registered; sessions use X-CM-ID: sbx (stub credentials only).
Partial
/scan-share
NRCeS FHIR bundle self-test
Signed encounters available for NRCeS-style OPConsult / Discharge / Rx / Lab bundles.
Partial

Derived from stubs / cert id

/fhir-bundles
HIP share sandbox push
Consent-gated care-context push with sandbox encryption envelope.
Missing

Derived from stubs / cert id

/hip-share
HIU pull sandbox decrypt
Request → decrypt stub → clinical render of HIP receipts.
Missing

Derived from stubs / cert id

/hiu-pull
NHA patient-journey scenarios
Official functional test pack executed (external evidence).
Missing
External
CERT-In-empanelled VAPT
OWASP/Web app security assessment by empanelled auditor.
Missing
/cert-in
Safe-to-Host certificate
NHA Safe-to-Host id on file after auditor report acceptance.
Missing

Derived from stubs / cert id

External
Production X-CM-ID: abdm
NHA production approval; bridge verify + HFR per facility follow.
Missing

Derived from stubs / cert id

External
Facility HFR + bridge verify
Per-facility Health Facility Registry registration and bridge verification.
Missing
/facilities