Secure Eligibility Automation for Authorized Epic Environments
MedSynthea helps healthcare organizations automate insurance eligibility verification by securely retrieving approved appointment, patient, and coverage information from Epic and submitting inquiries through an authorized payer or clearinghouse connection.
Built for controlled healthcare operations
Connection
You authorize and configure how MedSynthea connects to your Epic environment.
Data scope
Departments, locations, populations, and fields stay within your approved configuration.
Operations
Users, retention settings, and final operational decisions remain with your organization.
What the Integration Supports
Appointment retrieval
Retrieve upcoming appointments for approved departments, providers, locations, and date ranges.
Patient identification
Identify the patient connected to each appointment.
Coverage details
Retrieve approved insurance coverage details stored in Epic.
Plan validation
Validate payer, member, subscriber, provider, and plan information.
Real-time inquiry
Submit a real-time eligibility inquiry through an approved eligibility channel.
Benefits display
Display coverage status, benefit dates, copay, coinsurance, deductible, out-of-pocket details, and payer messages when available.
Exception routing
Route incomplete, conflicting, or rejected responses to authorized staff.
How the Workflow Operates
- 1
Appointment Retrieval
Retrieve only appointments included in the healthcare organization’s approved configuration.
- 2
Patient Resolution
Use the patient reference to retrieve the minimum matching information required.
- 3
Coverage Retrieval
Retrieve approved payer, plan, member, subscriber, and coverage information.
- 4
Eligibility Inquiry
Transform and submit the approved data through a payer, clearinghouse, or eligibility service.
- 5
Response Review
Normalize the response and route incomplete or uncertain cases for human review.
Data That May Be Accessed
Patient & Appointment
Patient ID, name, date of birth, approved matching fields, appointment date, status, provider, department, and location.
Insurance Coverage
Payer, plan, member or policy ID, subscriber relationship, group number, priority, status, and coverage dates.
Provider & Organization
Organization, facility, service location, rendering or billing provider, NPI, and payer-required details.
Coverage data is not the final eligibility result
Epic Coverage information reflects insurance details stored in the patient record. A current eligibility check still requires a separate payer or clearinghouse inquiry.
HIPAA-Aligned Security and Privacy
Minimum-Necessary Access
Access only approved resources, fields, populations, departments, locations, and date ranges.
Secure Authentication
Use backend OAuth 2.0, signed client assertions, protected private keys, and controlled public-key configuration.
Encryption & Isolation
Encrypt protected information in transit and at rest and keep each healthcare organization logically separated.
Audit & PHI-Safe Logging
Record important access and workflow events while excluding tokens, secrets, full payloads, and unnecessary PHI from ordinary logs.
Least Privilege
Restrict users, services, administrators, exports, and configuration changes according to approved responsibilities.
Human Oversight
Route incomplete, conflicting, low-confidence, or high-impact results to authorized staff.
Sandbox Before Production
Separate environments
Use separate sandbox and production client IDs, keys, JWKS endpoints, secrets, and data stores.
Separate eligibility testing
Test the payer or clearinghouse eligibility sandbox separately from Epic’s sandbox.
Production gate
Enable production access only after technical, security, legal, and operational review.
Production Access and Customer Control
Approve the workflow
Approve the workflow, FHIR access, departments, locations, providers, and patient populations.
Execute agreements
Execute required agreements, including a Business Associate Agreement before production PHI is processed.
Configure the backend
Configure the backend client, public-key endpoint, background-user mapping, and local permissions.
Define write access
Decide whether the connection remains read-only or includes separately approved write-back.
Maintain controls
Maintain user access, retention, key rotation, and revocation procedures.
Data Use, Retention, and Incident Response
Approved use only
Epic-derived information should be used only for approved healthcare operations. It should not be sold, used for advertising, or used to train publicly shared AI models without separate written authorization and appropriate safeguards.
Retention limits
Data should be retained only as required for the service, customer instructions, audit evidence, or legal obligations.
Incident response
Documented incident procedures should cover detection, containment, investigation, communication, and remediation.
Important Limitations
Eligibility is not a guarantee of payment
Responses may depend on the date of service, network status, plan rules, deductible, prior authorization, medical necessity, coding, timely filing, and payer adjudication. The healthcare organization retains final billing and operational responsibility.
Contact MedSynthea
Request an Epic integration review, sandbox demonstration, security assessment, BAA discussion, or production onboarding plan.
Public Disclaimer
This page describes MedSynthea’s intended integration approach. Capabilities and compliance commitments depend on the approved scope, executed agreements, customer configuration, Epic environment, payer connectivity, and production deployment. MedSynthea is an independent platform and is not affiliated with, sponsored by, or endorsed by Epic Systems Corporation.