Hi,
Thanks for your comment and for opening the ticket, we will look into that as well. Appreciate you sharing your thoughts.
The built in SMART Proxy in our service does not directly support the SMART scenarios in the ONC (g)(10) Standard API Certification. However, the fhir-proxy https://github.com/microsoft/fhir-proxy in concert with Azure Active Directory supports the following ONC (g)(10) test scenerios:
1 Standalone Patient App - Full Access (Non-Session Scoping)
2 Standalone Patient App - Limited Access (Non-Session Scoping)
In addition, you are right that our service does not automatically give CMS compliance but only allows organizations to build on top of it in order to be compliant with CMS mandates. We provide the tools and support IG specified API calls (e.g.. $member-match) etc. but is not an out of the box solution.
Hope this helps clarify!