MedSynthea
Epic Integration

Secure Eligibility Automation for Authorized Epic Environments

MedSynthea helps healthcare organizations automate insurance eligibility verification by securely retrieving approved appointment, patient, and coverage information from Epic and submitting inquiries through an authorized payer or clearinghouse connection.

Customer-controlled scopeSandbox before productionHIPAA-aligned safeguards
Operating model

Built for controlled healthcare operations

The healthcare organization remains in control of the connection, data scope, departments, locations, users, retention settings, and final operational decisions.
0101

Connection

You authorize and configure how MedSynthea connects to your Epic environment.

0202

Data scope

Departments, locations, populations, and fields stay within your approved configuration.

0303

Operations

Users, retention settings, and final operational decisions remain with your organization.

Capabilities

What the Integration Supports

0101

Appointment retrieval

Retrieve upcoming appointments for approved departments, providers, locations, and date ranges.

0202

Patient identification

Identify the patient connected to each appointment.

0303

Coverage details

Retrieve approved insurance coverage details stored in Epic.

0404

Plan validation

Validate payer, member, subscriber, provider, and plan information.

0505

Real-time inquiry

Submit a real-time eligibility inquiry through an approved eligibility channel.

0606

Benefits display

Display coverage status, benefit dates, copay, coinsurance, deductible, out-of-pocket details, and payer messages when available.

0707

Exception routing

Route incomplete, conflicting, or rejected responses to authorized staff.

Workflow

How the Workflow Operates

  1. 1

    Appointment Retrieval

    Retrieve only appointments included in the healthcare organization’s approved configuration.

  2. 2

    Patient Resolution

    Use the patient reference to retrieve the minimum matching information required.

  3. 3

    Coverage Retrieval

    Retrieve approved payer, plan, member, subscriber, and coverage information.

  4. 4

    Eligibility Inquiry

    Transform and submit the approved data through a payer, clearinghouse, or eligibility service.

  5. 5

    Response Review

    Normalize the response and route incomplete or uncertain cases for human review.

Data scope

Data That May Be Accessed

The exact resources and fields are agreed during onboarding. MedSynthea should request only the information needed for the approved workflow.

Patient & Appointment

Patient ID, name, date of birth, approved matching fields, appointment date, status, provider, department, and location.

Insurance Coverage

Payer, plan, member or policy ID, subscriber relationship, group number, priority, status, and coverage dates.

Provider & Organization

Organization, facility, service location, rendering or billing provider, NPI, and payer-required details.

NOTE01

Coverage data is not the final eligibility result

Epic Coverage information reflects insurance details stored in the patient record. A current eligibility check still requires a separate payer or clearinghouse inquiry.

Security

HIPAA-Aligned Security and Privacy

MedSynthea is designed to support HIPAA-regulated workflows through administrative, technical, and operational safeguards. Compliance depends on the implemented architecture, contracts, risk analysis, policies, workforce practices, and customer configuration.

Minimum-Necessary Access

Access only approved resources, fields, populations, departments, locations, and date ranges.

Secure Authentication

Use backend OAuth 2.0, signed client assertions, protected private keys, and controlled public-key configuration.

Encryption & Isolation

Encrypt protected information in transit and at rest and keep each healthcare organization logically separated.

Audit & PHI-Safe Logging

Record important access and workflow events while excluding tokens, secrets, full payloads, and unnecessary PHI from ordinary logs.

Least Privilege

Restrict users, services, administrators, exports, and configuration changes according to approved responsibilities.

Human Oversight

Route incomplete, conflicting, low-confidence, or high-impact results to authorized staff.

Validation

Sandbox Before Production

MedSynthea should first test in Epic’s non-production environment using test data. Sandbox testing validates authentication, FHIR requests, patient and appointment retrieval, coverage parsing, errors, audit events, and workflow orchestration without accessing a practice’s real patients.

Separate environments

Use separate sandbox and production client IDs, keys, JWKS endpoints, secrets, and data stores.

Separate eligibility testing

Test the payer or clearinghouse eligibility sandbox separately from Epic’s sandbox.

Production gate

Enable production access only after technical, security, legal, and operational review.

Customer control

Production Access and Customer Control

Creating an Epic developer application does not automatically provide production access. Each Epic customer must authorize and configure the connection.
0101

Approve the workflow

Approve the workflow, FHIR access, departments, locations, providers, and patient populations.

0202

Execute agreements

Execute required agreements, including a Business Associate Agreement before production PHI is processed.

0303

Configure the backend

Configure the backend client, public-key endpoint, background-user mapping, and local permissions.

0404

Define write access

Decide whether the connection remains read-only or includes separately approved write-back.

0505

Maintain controls

Maintain user access, retention, key rotation, and revocation procedures.

Governance

Data Use, Retention, and Incident Response

Epic-derived information should be used only for approved healthcare operations. It should not be sold, used for advertising, or used to train publicly shared AI models without separate written authorization and appropriate safeguards. Data should be retained only as required for the service, customer instructions, audit evidence, or legal obligations. Documented incident procedures should cover detection, containment, investigation, communication, and remediation.
0101

Approved use only

Epic-derived information should be used only for approved healthcare operations. It should not be sold, used for advertising, or used to train publicly shared AI models without separate written authorization and appropriate safeguards.

0202

Retention limits

Data should be retained only as required for the service, customer instructions, audit evidence, or legal obligations.

0303

Incident response

Documented incident procedures should cover detection, containment, investigation, communication, and remediation.

Limitations

Important Limitations

Eligibility is not a guarantee of payment

Responses may depend on the date of service, network status, plan rules, deductible, prior authorization, medical necessity, coding, timely filing, and payer adjudication. The healthcare organization retains final billing and operational responsibility.

Contact MedSynthea

Request an Epic integration review, sandbox demonstration, security assessment, BAA discussion, or production onboarding plan.

Public Disclaimer

This page describes MedSynthea’s intended integration approach. Capabilities and compliance commitments depend on the approved scope, executed agreements, customer configuration, Epic environment, payer connectivity, and production deployment. MedSynthea is an independent platform and is not affiliated with, sponsored by, or endorsed by Epic Systems Corporation.