Skip to main content
Policy

Fair Usage Policy

Purpose

This Fair Usage Policy applies to the following Medicus API interfaces:

  • Medicus Patient Facing Services API (IM1)
  • Medicus Transactional API
  • Medicus Bulk Data Extracts API

The Medicus API interfaces are available solely to accredited partner organisations (API Consumers). To ensure performance, reliability, and patient safety, all API Consumers must adhere to this Policy and operate within fair and reasonable usage parameters.

General principles of fair usage

Your use of the API Services must not adversely impact system stability, performance, security, or availability. API Consumers must:

  • Limit usage to a reasonable number of concurrent requests, as defined by Medicus Health.
  • Allow an appropriate wait period for completion of API calls before initiating new requests.
  • Design systems to avoid unnecessary polling, duplication of calls, or inefficient request cycles.

We understand that usage may vary throughout the year and may include predictable peak periods. Wherever possible, you must schedule high-volume or resource-intensive API activity outside core hours (such as overnight or at weekends) to minimise disruption to other users.

Monitoring, review, and optimisation

Medicus Health may monitor API usage to ensure compliance with this Policy. We reserve the right to review usage at any time. If your usage exceeds what Medicus Health deems reasonable or proportionate, we may:

  • Notify you of excessive or inefficient patterns.
  • Request technical or operational changes to optimise or reduce consumption.
  • Introduce additional rate limits or controls if necessary.

Failure to make required optimisations may result in temporary suspension or restriction of access.

Data governance and regulatory compliance

By accessing or consuming data from any Medicus API, you agree to comply with all applicable legislation and obligations.

GDPR and Data Protection Act 2018

You must ensure:

  • A lawful basis for processing all personal data.
  • Adherence to data minimisation and purpose limitation.
  • Secure processing of data in transit and at rest.
  • Appropriate technical and organisational safeguards.
  • Fulfilment of patient rights under data protection law.

NHS Act 2006, section 251 (Control of Patient Information)

Where access involves personal confidential data (PCD), you must ensure:

  • Valid approval under section 251 where required, or
  • Explicit patient consent, or
  • Another legally compliant route for processing.

Data covered under section 251 must not be extracted, cached, or stored without explicit written permission from Medicus Health and confirmation of your legal basis.

Patient safety

You agree that:

  • Patient safety must never be compromised through your system design, data usage, or presentation.
  • Clinical or patient-facing outputs must not misrepresent, omit, or distort information retrieved via the API.

Use case review and permissions

You agree to:

  • Discuss and agree all intended use cases with Medicus Health prior to implementation.
  • Obtain explicit permission before retrieving, displaying, caching, or storing data.
  • Seek approval before making material changes to your data workflows or API consumption patterns.

This applies to both transactional data access and bulk extraction via the Bulk Data Extracts API.

Authentication and security responsibilities

Each consumer system uses assigned authentication keys to identify itself to Medicus. You are responsible for:

  • Secure installation, storage, and usage of these keys.
  • Ensuring keys are not shared with third parties.
  • Ensuring only authorised personnel and systems access the API.
  • Promptly notifying Medicus Health of any actual or suspected compromise.

Misuse or unauthorised sharing of keys will be treated as a breach of this Policy and may result in immediate suspension.

Changes to this policy

Medicus Health reserves the right, at its sole discretion and at any time, to amend or modify this Fair Usage Policy. Changes take effect immediately upon publication in our externally facing documentation.

As an API Consumer, you are responsible for reviewing the Fair Usage Policy regularly to remain aware of any updates.