The document summarizes the findings of a research report on vulnerabilities in FHIR APIs. The research tested three production FHIR APIs serving 48 apps and was able to access over 4 million patient and clinician records with a single patient login due to widespread authorization vulnerabilities. While EHR provider systems had good security, vulnerabilities became systemic in third-party clinical data aggregators and mobile apps allowing unauthorized access to EHR data. The report provides recommendations to regulators, API owners, and app developers to improve security practices and adopt API shielding solutions to prevent exploitation and data leakage.