EHR-embedded apps
Provider-facing apps launched in-context from Epic, Cerner, and Athenahealth.

We build SMART on FHIR apps that launch inside Epic, Cerner, and athenahealth — EHR launch contexts, scoped OAuth 2.0 access, and FHIR R4 data flows, HIPAA-ready and correctly scoped from day one.
Trusted by global innovators
























SMART on FHIR is the open standard that lets a single healthcare app run inside many EHRs. It layers an application launch and authorization framework on top of FHIR: the EHR launch hands your app patient, user, and system context, and OAuth 2.0 grants it scoped access — patient/*, user/*, system/* — to just the FHIR endpoints it needs. That's what lets one app work across Epic, Cerner, and athenahealth without brittle point-to-point work.
The engineering is in the launch and the scopes: EHR launch vs standalone launch, OAuth 2.0 scope negotiation and refresh, OpenID Connect identity, and the marketplace review each EHR requires before an app reaches real sites. We design the launch flow and scope model up front, then build and register the app so it clears review instead of stalling in a sandbox.
What SMART on FHIR is
SMART on FHIR is an open standard that lets healthcare apps securely connect to EHRs using FHIR data and OAuth 2.0 authorisation — so a single app can run across systems like Epic, Cerner, and Athenahealth without custom point-to-point work.
It layers an application launch and authorisation framework on top of FHIR: the EHR launches your app with patient, user, and system-level context, and grants it scoped access to the FHIR endpoints it needs.
A blueprint for an EHR-embedded SMART app — launch context, OAuth 2.0 scope negotiation, FHIR R4 resource access, and the consent, terminology, and monitoring layers production needs.

We name the exact launch model and scopes up front — because that determines what the app can do inside the chart.
EHR and standalone SMART launch with OAuth scopes — patient/*, user/*, and system/* — plus launch context, token refresh, and OpenID Connect identity for apps that run inside Epic, Cerner, and athenahealth.
Scoped read/write against the EHR's FHIR R4 API — Patient, Encounter, Observation, MedicationRequest, DocumentReference — with US Core conformance.
Registration and review through Epic App Orchard, Cerner Code, and equivalent EHR marketplaces so the app reaches real sites, not just a sandbox.
Decision-support surfaced in the clinician's workflow via CDS Hooks and SMART apps, not disruptive pop-ups.
Consented pipelines that bring Bluetooth and IoT device vitals (Fitbit, Dexcom, Apple Health) into the SMART app as FHIR Observations.
Patient-consented data flows, PHI-aware logging, and app health monitoring so access stays scoped, audited, and reliable in production.
Where it runs
Provider-facing apps launched in-context from Epic, Cerner, and Athenahealth.
Patient-authorised apps with access to their own clinical data across systems.
In-workflow guidance surfaced through SMART apps and CDS Hooks.
Specialty-specific modules tailored to clinical logic and care plans.
Wearable and device vitals flowing into SMART apps via consented pipelines.
Apps distributed through Epic App Orchard and equivalent EHR marketplaces.
SMART on FHIR gives your applications a standards-based way to connect with EHRs, devices, and third-party services — without brittle point-to-point integrations.
Health Insurance Portability and Accountability Act
Protect PHI with privacy-first architecture, encrypted storage and transmission, strict access controls, and traceable audit logs.
General Data Protection Regulation
Implement lawful consent flows, data minimization, retention controls, and secure processing for sensitive health data.
Fast Healthcare Interoperability Resources
Enable standardized health data exchange across apps, care teams, and systems through robust FHIR-ready APIs.
Health Level Seven International
Support enterprise-grade interoperability with HL7-based integrations for records, events, and clinical messaging workflows.
Health Information Trust Alliance
Align security programs to healthcare-specific control and risk management practices trusted by providers and ecosystem partners.
Health Information Technology for Economic and Clinical Health Act
Design with breach notification readiness, digital record safeguards, and operational controls that support regulated care programs.
FDA Software as a Medical Device
Plan software quality, traceability, and documentation pathways for products that may require SaMD review and submission.
Medical Device Regulation (European Union)
Prepare EU market-ready processes for risk classification, evidence tracking, and lifecycle governance under MDR expectations.
Substance Abuse and Mental Health Services Administration
Apply confidentiality controls and consent-aware sharing models for behavioral and mental health data experiences.
Standards we build against
Launch and scope design, build, and marketplace review run as parallel tracks so the app reaches real EHR sites on a predictable timeline.
We confirm target EHRs, EHR vs standalone launch, the OAuth 2.0 scopes and FHIR resources the app needs, and the marketplace path before any code.
We register the SMART app, provision sandbox credentials, and validate launch context, scope approval, and token refresh against the vendor's test data.
We build the embedded app, scoped FHIR request orchestration, US Core mapping, and consent flows, validated with partner-assisted and security testing.
Marketplace review, phased production rollout, and app health monitoring with alerting as EHR sites enable the app.
Build vs buy vs aggregate
A direct breakdown for CTOs and integration engineers weighing build vs. buy vs. aggregation.
| Criteria | Aggregator | Build it yourself | Agnotic |
|---|---|---|---|
| EHR compatibility | Limited to top-tier EHRs only | Months of per-EHR custom dev work | 300+ EHRs supported out of the box |
| Implementation timeline | 4–6 weeks for onboarding and setup | 6–18 months minimum viable integration | Production-ready in under two weeks |
| Compliance & certification | Partial — you inherit audit gaps | Full burden on your security team | HIPAA, SOC 2 Type II, ONC certified |
| Data ownership & portability | Vendor holds your data, hard to exit | You own it — migration cost is high | You own all data; export any time |
We engineer for the operational reality — not the demo.
Related proof of app-layer delivery: for Lera Health we built a patient experience and privacy-first data layer end to end, with consent-aware, scoped data access — the same foundation an EHR-embedded SMART app requires.


See how SMART on FHIR apps can bridge your EHR, devices, and clinical workflows — mapped to your systems before the call ends.
contact@agnotic.com
Partnerships
contact@agnotic.com