# Glossary

> The terms these docs use, each defined once.

Hover or focus a dotted term anywhere in the docs to see its definition.

- **Patient**: The person whose health records are being shared. FinchNode never shows your app their FinchNode login.
- **Subject**: The ID your app uses for one patient, such as u_4f3a9c1e2b7d6a05 (synthetic). It is stable for your app and different for every other app.
- **Health system**: The hospital, clinic, or insurer that holds the records, reached through its EHR or payer API.
- **Connect session**: A link your server creates for one patient, so they can connect a health system and choose what to share with your app.
- **Consent receipt**: The record of what a patient shared with your app, for how long, and whether it is still active.
- **Sandbox**: Your app with a ck_test_ key: synthetic patients, simulated sessions, and sandbox controls. Nothing touches a real health system.
- **Demo API**: A keyless API with fictional records for prototypes. It needs no account.
- **Beta**: Built and usable for testing, with behavior that may still change before it is generally available.
- **FHIR**: Fast Healthcare Interoperability Resources, the HL7 standard for health data. FinchNode reads FHIR R4 from health systems and returns normalized records; the demo API also serves FHIR R4 resources.
- **SMART on FHIR**: The OAuth 2.0 profile patients use to authorize an app to read their records from an EHR.
- **TEFCA**: The Trusted Exchange Framework and Common Agreement: the US framework that connects health information networks nationally.
- **QHIN**: Qualified Health Information Network: a network designated to exchange records under TEFCA.
- **IAS**: Individual Access Services: the TEFCA exchange purpose that lets a person request their own records.
- **T-IAS**: The TEFCA Exchange Purpose code for Individual Access, sent with every IAS request.
- **CSP**: Credential service provider: the service that proofs who the person is and issues the credential they sign in with before an IAS request.
- **IAL2**: Identity Assurance Level 2 from NIST SP 800-63: identity proofing with strong evidence such as a government ID, done remotely or in person. The IAS SOP requires it.
- **AAL2**: Authenticator Assurance Level 2 from NIST SP 800-63: sign-in with two factors.
- **XCPD**: Cross-Community Patient Discovery: the IHE transaction that asks network participants whether they hold records for a person.
- **XCA**: Cross-Community Access: the IHE transactions that list and then retrieve documents from a participant that holds them.
