Patient-authorized EHR integration
Glossary
The terms these docs use, each defined once.
Hover or focus a dotted term anywhere in the docs to see its definition.
- Patient
- The person whose health records are being shared. FinchNode never shows your app their FinchNode login.
- Subject
- The ID your app uses for one patient, such as u_4f3a9c1e2b7d6a05 (synthetic). It is stable for your app and different for every other app.
- Health system
- The hospital, clinic, or insurer that holds the records, reached through its EHR or payer API.
- Connect session
- A link your server creates for one patient, so they can connect a health system and choose what to share with your app.
- Consent receipt
- The record of what a patient shared with your app, for how long, and whether it is still active.
- Sandbox
- Your app with a ck_test_ key: synthetic patients, simulated sessions, and sandbox controls. Nothing touches a real health system.
- Demo API
- A keyless API with fictional records for prototypes. It needs no account.
- Beta
- Built and usable for testing, with behavior that may still change before it is generally available.
- FHIR
- Fast Healthcare Interoperability Resources, the HL7 standard for health data. FinchNode reads FHIR R4 from health systems and returns normalized records; the demo API also serves FHIR R4 resources.
- SMART on FHIR
- The OAuth 2.0 profile patients use to authorize an app to read their records from an EHR.
- TEFCA
- The Trusted Exchange Framework and Common Agreement: the US framework that connects health information networks nationally.
- QHIN
- Qualified Health Information Network: a network designated to exchange records under TEFCA.
- IAS
- Individual Access Services: the TEFCA exchange purpose that lets a person request their own records.
- T-IAS
- The TEFCA Exchange Purpose code for Individual Access, sent with every IAS request.
- CSP
- Credential service provider: the service that proofs who the person is and issues the credential they sign in with before an IAS request.
- IAL2
- Identity Assurance Level 2 from NIST SP 800-63: identity proofing with strong evidence such as a government ID, done remotely or in person. The IAS SOP requires it.
- AAL2
- Authenticator Assurance Level 2 from NIST SP 800-63: sign-in with two factors.
- XCPD
- Cross-Community Patient Discovery: the IHE transaction that asks network participants whether they hold records for a person.
- XCA
- Cross-Community Access: the IHE transactions that list and then retrieve documents from a participant that holds them.