Skip to main content

The Money Overview

Medicare.gov now lists private health apps that connect to a beneficiary’s Medicare record

Medicare.gov’s new health-apps directory tells beneficiaries that every listed app has been independently verified to meet high privacy and security standards before it can touch a Medicare record. Three entries in that same directory carry a different label: apps still waiting on Medicare’s own final checks before they are cleared. The Centers for Medicare & Medicaid Services does not say what separates an approved listing from one still under review, or how a beneficiary browsing the page is supposed to tell the difference. That gap sits at the center of a program built specifically to hand private companies access to a person’s Medicare claims and billing history.

The Pledge, the Accreditation, and Who Signs Off

Before an app can appear on Medicare.gov, its developer signs the CMS Health Tech Ecosystem Pledge, a commitment CMS frames as the entry point into the library rather than a formality. From there, the developer must verify patient identity through ID.me or CLEAR, connect to Medicare’s claims data using the FHIR R4 and SMART on FHIR technical standards, and route that connection through what CMS calls a CMS Aligned Network. Only after those pieces are in place does an app move to outside accreditation, the step that decides whether it appears in the library at all.

That accreditation is not performed by CMS staff directly. A developer completes an independent review through either the DiMe Seal or the CARIN Alliance Code of Conduct paired with DirectTrust Accreditation, both industry-run vetting bodies that CMS has agreed to recognize rather than an in-house government audit. CMS’s own submission requirements describe security, interoperability and accreditation as three separate pledge categories an app must clear, but the published pledge does not spell out how CMS checks the outside reviewers’ work once a certificate is issued, or how often a listed app is re-verified after it first qualifies.

One category of developer skips that outside review altogether. CMS states that participants in its ACCESS care model are exempt from the standard CMS Review and Trial Access requirements and instead receive a special designation inside the Medicare App Library. CMS does not explain in its published materials what standard replaces the exempted review for those developers, or why a model built around chronic-condition management earns a faster path onto a page that otherwise promotes independent, third-party accreditation as the guarantee of trustworthiness.


Free retirement updates: Plain-English updates on the changes, deadlines, and costly mistakes retirees miss, from the free Retirement Shield newsletter. Subscribe free.

Three Apps Still Finishing Medicare’s Final Checks

The current version of Medicare’s app library lists three products under a header CMS titles apps that are almost ready for Medicare, with the site explaining that Medicare is finishing the final checks to make sure these apps are ready. Massive Bio Patient Navigator, built to match cancer patients to clinical trials using diagnosis and genomic data, sits in that pending category alongside Polygon Health, a caregiver-connection tool, and Xealth, a platform designed to guide patients through care instructions before and after medical visits.

That pending listing sits directly beside apps CMS calls fully verified, with no visual distinction beyond the section header separating the two groups on the page. A beneficiary who lands on Medicare.gov and clicks toward Massive Bio, Polygon Health or Xealth today would be connecting to a company whose privacy and security review CMS has not yet completed, even though the same page’s opening language promises that every listed app has already cleared independent verification before appearing there.

CMS’s submission process also routes developers toward three named use cases it is actively recruiting for: replacing clipboard intake forms with FHIR-based data exchange at the point of care, building AI assistants that pull from a patient’s clinical record, and powering diabetes and weight-management coaching tied to Medicare data. Two of the three pending apps fall outside those categories entirely, which suggests the review queue is broader than the priorities CMS has publicly named, without CMS saying how it ranks or schedules the applications waiting behind them.

An Older Directory, and the Financial Data at Stake

The App Library is not Medicare’s first attempt at this kind of data sharing. Medicare.gov has run a separate Connected Apps Directory for years, built on what CMS calls Medicare’s Blue Button, letting beneficiaries link outside apps to their Part A, Part B and Part D claims history. That older directory still operates today, filterable by app feature, and it carries its own disclaimer that CMS is not responsible for the privacy practices of the third-party apps and companies listed on it.

The data both directories move is financial as much as clinical. A Medicare claims record includes what a provider billed, what Medicare paid, and what a beneficiary owes, the same information CMS says it is trying to protect through an expanding use of artificial intelligence to detect fraud early and stop improper payments. The handbook that introduces the health-apps library sits inside the same publication that tells beneficiaries to guard their Medicare card and Medicare Number and report suspected fraud, a reminder that arrives just as the number of private companies with a legitimate reason to touch that same claims data is growing.

The App Library and the fraud-detection push both appear in the same 2027 handbook as evidence CMS is modernizing how Medicare data moves. What is missing from the public record is a single standard connecting the two initiatives. The pledge that gets a developer listed does not reference the fraud-detection tools screening the claims that developer will access, and the fraud-prevention materials do not name the app library as a channel CMS is monitoring. Each initiative appears in the handbook without describing how, or whether, one checks the other.

That leaves the practical question unanswered at the source: whether a beneficiary connecting a Medicare account to Massive Bio, Polygon Health or Xealth today is trusting a fully accredited program or a company still working through CMS’s final checks. Both sit on the same Medicare.gov page, under the same claim of privacy protection, while the underlying claims and billing data those apps can reach remains exactly what CMS’s own fraud unit is racing to secure.

This article was produced with AI assistance and reviewed by The Money Overview editorial team.

More Financial Reading

Avatar photo

Daniel Harper

Daniel is a finance writer covering personal finance topics including budgeting, credit, and beginner investing. He began his career contributing to his Substack, where he covered consumer finance trends and practical money topics for everyday readers. Since then, he has written for a range of personal finance blogs and fintech platforms, focusing on clear, straightforward content that helps readers make more informed financial decisions.​


Plain-English help keeping more of your money in retirement. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.