FHIR Integration With Epic: 5 Patterns for Third-Party Apps

How to Leverage FHIR Epic for Seamless Healthcare Integration

FHIR Integration With Epic: 5 Patterns for Third-Party Apps

Epic's FHIR API is the most widely-supported integration surface in US healthcare. Five patterns cover essentially all third-party integration.

1. SMART app registration and launch. Register in Epic App Orchard; launch via SMART on FHIR.

2. US Core-conformant reads. Epic exposes US Core profiles for core resources.

3. Bulk data export. Epic supports Bulk Data IG $export.

4. CDS Hooks integration. CDS Hooks at patient-view, order-select, order-sign.

5. SMART Backend Services. Server-to-server via JWT + client credentials.

Epic-specific details

1. Documentation: fhir.epic.com. 2. Sandbox for development. 3. App Orchard security review for production. 4. Signed distribution agreement.

Rate limits (typical)

Scope Rate
patient/* 60/min
user/* 100/min
system/* 1000/min
Bulk export 1 concurrent

Common Epic integration mistakes

1. Write scopes without Epic configuration. 2. CORS not registered. 3. Sandbox vs. production scope mismatch. 4. Missing 429 handling. 5. Skipping App Orchard review.

Testing strategy

1. Sandbox first. 2. Production-like scopes. 3. Rate limit boundaries. 4. Terminology fidelity. 5. Auth error paths.

Epic FHIR integration is well-defined. Get through App Orchard once; subsequent integrations follow the pattern.