Epic
Epic integration relies on SMART on FHIR launch flows. Profound Health does not store Epic credentials; instead we leverage partner-provided app registrations paired with our service account.
Supported Workflows
- Contextual launch: Partner PCPs launch Profound Health inside Epic; we receive patient and encounter context via the SMART payload.
- Clinical data sync: We pull allergies, medications, problems, and lab results using the Epic FHIR APIs (R4). Each resource is normalized into the
care.fhir_resourcestable. - Task write-back: We create or update
ServiceRequestresources for behavioral health follow-ups when the partner contract enables it.
Deployment Checklist
- Partner submits Epic App Orchard request using our supplied manifest.
- We exchange redirect URIs and configure allowed scopes (
openid,profile,patient/*.read,ServiceRequest.write). - Epic grants production credentials; we store them in Infisical under the partner’s organization slug.
Considerations
- Sessions expire after 30 minutes; background sync uses the system-to-system API with signed JWTs.
- Epic requires whitelisting our redirect domains (
https://*.profoundinstitute.org). - Error details are logged but stripped of PHI before being forwarded to operators.
Refer to the Partner Ops Portal for onboarding timelines and contact points at Epic.
Last updated October 1, 2025 by Profound Health.
