Production access is free and self-serve with an account. · Synthetic demo · no account needed

FinchNode

Patient-authorized EHR integration

Glossary

The terms these docs use, each defined once.

Hover or focus a dotted term anywhere in the docs to see its definition.

Patient
The person whose health records are being shared. FinchNode never shows your app their FinchNode login.
Subject
The ID your app uses for one patient, such as u_4f3a9c1e2b7d6a05 (synthetic). It is stable for your app and different for every other app.
Health system
The hospital, clinic, or insurer that holds the records, reached through its EHR or payer API.
Connect session
A link your server creates for one patient, so they can connect a health system and choose what to share with your app.
The record of what a patient shared with your app, for how long, and whether it is still active.
Sandbox
Your app with a ck_test_ key: synthetic patients, simulated sessions, and sandbox controls. Nothing touches a real health system.
Demo API
A keyless API with fictional records for prototypes. It needs no account.
Beta
Built and usable for testing, with behavior that may still change before it is generally available.
FHIR
Fast Healthcare Interoperability Resources, the HL7 standard for health data. FinchNode reads FHIR R4 from health systems and returns normalized records; the demo API also serves FHIR R4 resources.
SMART on FHIR
The OAuth 2.0 profile patients use to authorize an app to read their records from an EHR.
TEFCA
The Trusted Exchange Framework and Common Agreement: the US framework that connects health information networks nationally.
QHIN
Qualified Health Information Network: a network designated to exchange records under TEFCA.
IAS
Individual Access Services: the TEFCA exchange purpose that lets a person request their own records.
T-IAS
The TEFCA Exchange Purpose code for Individual Access, sent with every IAS request.
CSP
Credential service provider: the service that proofs who the person is and issues the credential they sign in with before an IAS request.
IAL2
Identity Assurance Level 2 from NIST SP 800-63: identity proofing with strong evidence such as a government ID, done remotely or in person. The IAS SOP requires it.
AAL2
Authenticator Assurance Level 2 from NIST SP 800-63: sign-in with two factors.
XCPD
Cross-Community Patient Discovery: the IHE transaction that asks network participants whether they hold records for a person.
XCA
Cross-Community Access: the IHE transactions that list and then retrieve documents from a participant that holds them.