Agnotic Technologies Logo
    SMART on FHIR app launching inside an EHR workflow
    SMART on FHIR

    SMART on FHIR App Development

    We build SMART on FHIR apps that launch inside Epic, Cerner, and athenahealth — EHR launch contexts, scoped OAuth 2.0 access, and FHIR R4 data flows, HIPAA-ready and correctly scoped from day one.

    FHIR R4OAuth 2.0 ScopesEHR Launch ContextApp Orchard

    Trusted by global innovators

    Benchmark
    Chibasco
    Fundency
    Lantimer
    Lauren
    Lera
    One Minute
    Pento Pix
    TAP
    Xtrium
    Healthevolve
    Benchmark
    Chibasco
    Fundency
    Lantimer
    Lauren
    Lera
    One Minute
    Pento Pix
    TAP
    Xtrium
    Healthevolve
    Benchmark
    Chibasco
    Fundency
    Lantimer
    Lauren
    Lera
    One Minute
    Pento Pix
    TAP
    Xtrium
    Healthevolve
    Benchmark
    Chibasco
    Fundency
    Lantimer
    Lauren
    Lera
    One Minute
    Pento Pix
    TAP
    Xtrium
    Healthevolve

    What SMART on FHIR app development actually involves

    SMART on FHIR is the open standard that lets a single healthcare app run inside many EHRs. It layers an application launch and authorization framework on top of FHIR: the EHR launch hands your app patient, user, and system context, and OAuth 2.0 grants it scoped access — patient/*, user/*, system/* — to just the FHIR endpoints it needs. That's what lets one app work across Epic, Cerner, and athenahealth without brittle point-to-point work.

    The engineering is in the launch and the scopes: EHR launch vs standalone launch, OAuth 2.0 scope negotiation and refresh, OpenID Connect identity, and the marketplace review each EHR requires before an app reaches real sites. We design the launch flow and scope model up front, then build and register the app so it clears review instead of stalling in a sandbox.

    What SMART on FHIR is

    SMART on FHIR is how apps run inside the EHR

    SMART on FHIR is an open standard that lets healthcare apps securely connect to EHRs using FHIR data and OAuth 2.0 authorisation — so a single app can run across systems like Epic, Cerner, and Athenahealth without custom point-to-point work.

    It layers an application launch and authorisation framework on top of FHIR: the EHR launches your app with patient, user, and system-level context, and grants it scoped access to the FHIR endpoints it needs.

    SMART on FHIR app architecture

    A blueprint for an EHR-embedded SMART app — launch context, OAuth 2.0 scope negotiation, FHIR R4 resource access, and the consent, terminology, and monitoring layers production needs.

    Architecture diagram of a SMART on FHIR app launching inside an EHR

    SMART on FHIR APIs & standards we work with

    We name the exact launch model and scopes up front — because that determines what the app can do inside the chart.

    15-Minute Scoping Call

    EHR launch + OAuth scopes

    EHR and standalone SMART launch with OAuth scopes — patient/*, user/*, and system/* — plus launch context, token refresh, and OpenID Connect identity for apps that run inside Epic, Cerner, and athenahealth.

    FHIR R4 resource access

    Scoped read/write against the EHR's FHIR R4 API — Patient, Encounter, Observation, MedicationRequest, DocumentReference — with US Core conformance.

    App Orchard & marketplace listing

    Registration and review through Epic App Orchard, Cerner Code, and equivalent EHR marketplaces so the app reaches real sites, not just a sandbox.

    CDS Hooks & in-workflow guidance

    Decision-support surfaced in the clinician's workflow via CDS Hooks and SMART apps, not disruptive pop-ups.

    Wearable & device data

    Consented pipelines that bring Bluetooth and IoT device vitals (Fitbit, Dexcom, Apple Health) into the SMART app as FHIR Observations.

    Consent, PHI & observability

    Patient-consented data flows, PHI-aware logging, and app health monitoring so access stays scoped, audited, and reliable in production.

    Where it runs

    SMART on FHIR use cases

    EHR-embedded apps

    Provider-facing apps launched in-context from Epic, Cerner, and Athenahealth.

    Patient engagement apps

    Patient-authorised apps with access to their own clinical data across systems.

    Clinical decision support

    In-workflow guidance surfaced through SMART apps and CDS Hooks.

    Specialty workflows

    Specialty-specific modules tailored to clinical logic and care plans.

    Remote monitoring

    Wearable and device vitals flowing into SMART apps via consented pipelines.

    Third-party marketplaces

    Apps distributed through Epic App Orchard and equivalent EHR marketplaces.

    Bridge every system across your care ecosystem

    SMART on FHIR gives your applications a standards-based way to connect with EHRs, devices, and third-party services — without brittle point-to-point integrations.

    300+
    EHRs reachable through SMART on FHIR
    <2 wks
    Typical production-ready timeline
    100%
    Patient-consented, BAA-covered data flows

    Compliance-First Healthcare App Development Services Backed by Global Standards

    15-Minute Scoping Call
    01HIPAA logo

    HIPAA

    Health Insurance Portability and Accountability Act

    Protect PHI with privacy-first architecture, encrypted storage and transmission, strict access controls, and traceable audit logs.

    02GDPR logo

    GDPR

    General Data Protection Regulation

    Implement lawful consent flows, data minimization, retention controls, and secure processing for sensitive health data.

    03FHIR logo

    FHIR

    Fast Healthcare Interoperability Resources

    Enable standardized health data exchange across apps, care teams, and systems through robust FHIR-ready APIs.

    04HL7 logo

    HL7

    Health Level Seven International

    Support enterprise-grade interoperability with HL7-based integrations for records, events, and clinical messaging workflows.

    05HITRUST logo

    HITRUST

    Health Information Trust Alliance

    Align security programs to healthcare-specific control and risk management practices trusted by providers and ecosystem partners.

    06HITECH logo

    HITECH

    Health Information Technology for Economic and Clinical Health Act

    Design with breach notification readiness, digital record safeguards, and operational controls that support regulated care programs.

    07SaMD logo

    SaMD

    FDA Software as a Medical Device

    Plan software quality, traceability, and documentation pathways for products that may require SaMD review and submission.

    08MDR (EU) logo

    MDR (EU)

    Medical Device Regulation (European Union)

    Prepare EU market-ready processes for risk classification, evidence tracking, and lifecycle governance under MDR expectations.

    09SAMHSA logo

    SAMHSA

    Substance Abuse and Mental Health Services Administration

    Apply confidentiality controls and consent-aware sharing models for behavioral and mental health data experiences.

    Standards we build against

    SMART on FHIR standards

    FHIRSMARTOAuth2OIDCHIPAASOC 2
    Our Process

    How we ship a SMART on FHIR app

    Launch and scope design, build, and marketplace review run as parallel tracks so the app reaches real EHR sites on a predictable timeline.

    1.

    Discovery & Scope

    We confirm target EHRs, EHR vs standalone launch, the OAuth 2.0 scopes and FHIR resources the app needs, and the marketplace path before any code.

    Launch-first
    2.

    Sandbox & App Registration

    We register the SMART app, provision sandbox credentials, and validate launch context, scope approval, and token refresh against the vendor's test data.

    Sandbox-gated
    3.

    Build & Test

    We build the embedded app, scoped FHIR request orchestration, US Core mapping, and consent flows, validated with partner-assisted and security testing.

    Scope-tested
    4.

    Go-Live & Monitoring

    Marketplace review, phased production rollout, and app health monitoring with alerting as EHR sites enable the app.

    Observable in production

    Build vs buy vs aggregate

    Evaluate your integration path

    A direct breakdown for CTOs and integration engineers weighing build vs. buy vs. aggregation.

    CriteriaAggregatorBuild it yourselfAgnotic
    EHR compatibilityLimited to top-tier EHRs onlyMonths of per-EHR custom dev work300+ EHRs supported out of the box
    Implementation timeline4–6 weeks for onboarding and setup6–18 months minimum viable integrationProduction-ready in under two weeks
    Compliance & certificationPartial — you inherit audit gapsFull burden on your security teamHIPAA, SOC 2 Type II, ONC certified
    Data ownership & portabilityVendor holds your data, hard to exitYou own it — migration cost is highYou own all data; export any time

    We engineer for the operational reality — not the demo.

    Featured case study

    Read Case Study

    Lera Health: compliant health platform

    Related proof of app-layer delivery: for Lera Health we built a patient experience and privacy-first data layer end to end, with consent-aware, scoped data access — the same foundation an EHR-embedded SMART app requires.

    Lera health responsive web platform
    Lera health mobile app experience

    Frequently Asked Questions

    A scoped SMART app — one launch model, defined scopes, and a couple of EHR targets — typically ships in 6–10 weeks of build, plus marketplace review time that varies by vendor. We plan review timelines in from the start so they don't surprise you.

    Ready to connect your systems with SMART on FHIR?

    See how SMART on FHIR apps can bridge your EHR, devices, and clinical workflows — mapped to your systems before the call ends.

    Email

    contact@agnotic.com

    Partnerships

    contact@agnotic.com