Healthcare · EHR integration
EHR and FHIR integration services for health apps that need clinical data
We connect patient apps, telehealth platforms and clinical tools to electronic health records through HL7 FHIR, SMART on FHIR and HL7 v2, with the security controls and vendor approvals that work requires.

Short answer
EHR integration lets your product read and write patient data in systems such as Epic, Oracle Health and athenahealth. Modern integrations use the HL7 FHIR standard with SMART on FHIR for authorisation; older systems use HL7 v2 messages. Innovation Insight builds these integrations with HIPAA technical safeguards for $15k to $40k per system over 4 to 10 weeks of engineering, plus the EHR vendor's own review time.
Reviewed by Zain Khalid Malik, CTO & Co-founder · Updated
What EHR integration involves
An electronic health record (EHR) is the system a clinic or hospital uses to store patient charts, appointments, orders and results. If your product needs a patient's medications, wants to book into a provider's calendar or has to file a visit note, it needs to exchange data with that system. Each EHR vendor controls access to its APIs, so integration is part engineering and part process: registering your app, passing the vendor's review and being switched on by each health system that uses it.
The standards, in plain terms
| Standard | What it is | When you use it |
|---|---|---|
| HL7 FHIR | A modern web API standard that represents health data as resources such as Patient, Appointment, Observation and MedicationRequest | Most new integrations. US rules require certified EHRs to offer FHIR APIs for patient data |
| SMART on FHIR | An authorisation layer built on OAuth 2 that lets an app launch inside the EHR or connect on a patient's behalf | Apps used by clinicians inside the EHR, and patient-facing apps |
| HL7 v2 | An older message format for events such as admissions, orders and results | Hospitals and labs whose feeds have not moved to FHIR |
| Bulk FHIR | Export of data for many patients at once | Analytics, population health and migrations |
| Integration platforms | Services that offer one API across many EHRs | When you must support many health systems quickly and can accept a per-connection fee |
What we build
- SMART on FHIR apps that launch from inside the clinician's EHR with single sign-on and patient context.
- Patient-facing connections that let a user link their record to your app.
- Read integrations: demographics, problems, medications, allergies, results and documents.
- Write-back where the EHR supports it: appointments, notes and documents.
- HL7 v2 interfaces for admissions, orders and results, through an interface engine.
- A mapping layer that turns each EHR's variations into one clean model for your product.
- Audit logging of every access to protected health information.
How an integration project runs
- Scope the data: exactly which resources you need to read and write, and for which workflow. Smaller scopes pass review faster.
- Register with the vendor and build against its sandbox while the paperwork proceeds.
- Build the mapping layer and contract tests, so a change on the EHR side is caught before users see it.
- Security review: encryption, access control, audit trail and a Business Associate Agreement where required.
- Vendor review and listing, then activation with the first health system, which has its own security questionnaire.
- Monitor in production: token refresh, error rates and data-quality checks per connection.
Security and compliance
- Encryption in transit and at rest, with keys in a managed vault.
- Least-privilege FHIR scopes: request only the resources the workflow needs.
- Role-based access and a complete audit trail of who viewed or changed patient data.
- Hosting in a HIPAA-eligible cloud account in your name, with a Business Associate Agreement.
- No patient data in logs, analytics or error reports.
Healthcare integration work we have shipped
On the Zeuss telehealth platform we built more than 12 integrations around protected health information, including pharmacy fulfilment with webhook status tracking, identity verification, payment tokenisation and multi-channel notifications, on an event-driven Azure back end. The platform applies HIPAA-aligned safeguards: AES-256 encryption, Azure Key Vault secrets, role-based access by route, a complete HTTP audit trail and masking of personal data in API responses. EHR connections use the same engineering patterns: contract tests, queued processing, retries and audit logging, applied to FHIR resources.
What it costs
| Scope | Range | Timeline |
|---|---|---|
| Discovery: data scope, vendor path, security design | $3k to $8k | 1 to 2 weeks |
| Integration with one EHR | $15k to $40k | 4 to 10 weeks, plus vendor review |
| Patient app MVP with one integration | $30k to $60k | 10 to 16 weeks |
| Monitoring and upkeep | $1.5k to $8k per month | Monthly |
Vendor programme fees, where they apply, and integration-platform fees are paid directly to those companies and are not included.
Sources and further reading
Next step
Tell us what you're building and get a written estimate.
A senior engineer replies within one business day. NDA on request.
Products we've shipped, and what happened next.
Case studies written from the technical documentation of each project: the stack, the scale and the outcome.
Questions we get asked a lot.
What is FHIR?
FHIR (Fast Healthcare Interoperability Resources) is the HL7 standard for exchanging health data through web APIs. It represents records as resources such as Patient, Appointment and Observation, and is the basis of most new EHR integrations.
Can you integrate with Epic or Oracle Health?
Yes, through their FHIR APIs and developer programmes. We build against the vendor sandbox while registration and review proceed, and plan for each health system's activation step.
How long does EHR integration take?
Engineering takes 4 to 10 weeks per system. Vendor review and activation with each health system add time that neither of us controls, so we start that process first.
Do we need HL7 v2 as well as FHIR?
Only if the hospital or lab you work with still sends admissions, orders or results as v2 messages. Many do, so we check during discovery.
Should we use an integration platform instead of building direct?
A platform is faster when you need many health systems at once and can accept its fees. Direct integration costs less to run at scale and gives full control. We help you compare both for your case.
Will you sign a Business Associate Agreement?
Yes, before any access to protected health information.
